sysmgr.exe - Dangerous

sysmgr.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

sysmgr.exe
W32/Sdbot-OO is an IRC backdoor that can spread via network shares protected by weak passwords.
The worm copies itself to the file sysmgr.exe and cool.exe in the Windows System folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft System Checkup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NT Logging Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft System Checkup

W32/Sdbot-OO connects to an IRC server specified by the author and joins a channel from which it will receive further commands.
These commands can start any of the following actions:
- HTTP server
- sock4 proxy server
- UDP, SYN or PING flooding
- TCP redirection
- download files
- execute arbitrary commands
- spread via weakly-protected network shares

It may also attempt to terminate the security related processes.

Use RegRun Startup Optimizer to remove it from startup.

Remove sysmgr.exe now!