windriver.exe - Dangerous

windriver.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

windriver.exe
W32/Lovgate-AP is a worm which spreads by emailing itself via its own SMTP engine and by copying itself to network shares.
The worm also allows unauthorised remote access to the computer via a network.

W32/Lovgate-AP copies itself to the Windows system folder as windriver.exe and winexe.exe and adds entries to the registry at the following locations to run itself on system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

The worm also modifies the entry in the registry at the following location to run itself before files with an EXE extension:
HKCR\exefile\Shell\open\command

Remove windriver.exe now!