sysz.exe - Dangerous
sysz.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
This Trojan allows an attacker to access your computer.
By default the Trojan listens on TCP port 2688.
Creates the following files in the %System%\SYSTEMCONFIG33 folder:
4w4y.txt; cu.dat (detected as Backdoor.IRC.Aladinz.P); remote.ini; users.txt; w1n.dll; win32.exe (detected as Backdoor.SDBot.Gen)
Creates some files in the %System%\SYSTEMCONFIG33 folder with the files attribute set to Hidden.
Creates these subfolders: logs; sounds
Adds the values:
"Internat"="%System%\SYSTEMCONFIG33\systray.exe"
"SystemTray"="SysTray.Exe"
"SYSTEMZ Patch"="SYSZ.exe"
to the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Modifies the value: "UninstallString"=""%System%\SYSTEMCONFIG33\systray.exe" -uninstall"
in the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\mIRC
Connects to a remote IRC server.
Allows a remote attacker to control the computer.
The functions available to the attacker include:
- Retrieving information about the computer
- Stopping and restarting the Trojan
- Downloading and running the files
- Scanning hosts for vulnerabilities