runsvc32.exe - Dangerous

runsvc32.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

runsvc32.exe
W32/Agobot-MP is a network worm and an IRC backdoor Trojan.
It establishes an IRC channel to a remote server to give an unauthorised access to the compromised computer.
It moves itself into the Windows system folder as RUNSVC32.EXE and creates the following registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\RunServices = runsvc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\RunServices = runsvc32.exe

It may attempt to terminate anti-virus and other security-related processes, in addition to other viruses, worms or Trojans.
Also, may search for shared folders on a network with weak passwords and copy itself into them.
A text file named HOSTS in C:\ Most of them are antivirus sites.

Please, remove it from startup with RegRun Startup Optimizer.

Remove runsvc32.exe now!