mstcpip.exe - Dangerous
mstcpip.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
When run the worm copies itself into the Windows system folder with the name mstcpip.exe and continues execution from this file.
Each time W32/Sdbot-LR is run it attempts to connect to a remote IRC server and join a specific channel.
The worm then runs in the background allowing a remote intruder to issue commands which control the computer.
Manual removal:
Navigate to the keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
and delete the value: TCPIP Protocol=mstcpip.exe