sysmgr.exe - Dangerous
sysmgr.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
The worm copies itself to the file sysmgr.exe and cool.exe in the Windows System folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft System Checkup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NT Logging Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft System Checkup
W32/Sdbot-OO connects to an IRC server specified by the author and joins a channel from which it will receive further commands.
These commands can start any of the following actions:
- HTTP server
- sock4 proxy server
- UDP, SYN or PING flooding
- TCP redirection
- download files
- execute arbitrary commands
- spread via weakly-protected network shares
It may also attempt to terminate the security related processes.
Use RegRun Startup Optimizer to remove it from startup.