secsrvrc.exe - Dangerous
secsrvrc.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
Also, includes detection for the following components: VPASPScanner.exe; CGIScanner.exe; PHPScanner.exe
which represent a monitoring tool that captures users' activity, saves it to an encrypted logfile and periodically sends it to the hacker.
When executed the main component extracts a main executable and a dll file to the Windows system32 folder, installs a background service, changes the system registry and sends the notification email to the remote address.
Sets the value:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "secsrvrc"=C:\\WINDOWS\\System32\\secsrvrc.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ win_spool2 ="C:\\WINDOWS\\System32\\win_spool2.exe"
Use RegRun Startup Optimizer to remove this spyware.