windowxs.exe - Dangerous

windowxs.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

windowxs.exe
W32/Sdbot-KT
This is an IRC backdoor Trojan and network worm which can run in the background as a service process and allow unauthorised remote access via the IRC channel.
It copies itself to the Windows System folder as WINDOWXS.EXE and creates the following registry entries so that this worm is run automatically on system restart:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\winlog = windowxs.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\winlog = windowxs.exe

W32/Sdbot-KT remains resident listening for commands from the remote hacker.
If the appropriate commands are received the worm will begin scanning the internet for network shares with weak administrator passwords and will attempt to copy itself to these shares.
This worm can also initiate SYNFlood attacks, exploit computers infected with W32/MyDoom and attempt to steal CD keys from several computer games.

Use RegRun Startup Optimizer to remove it from startup.

Remove windowxs.exe now!