windriver.exe - Dangerous
windriver.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
The worm also allows unauthorised remote access to the computer via a network.
W32/Lovgate-AP copies itself to the Windows system folder as windriver.exe and winexe.exe and adds entries to the registry at the following locations to run itself on system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
The worm also modifies the entry in the registry at the following location to run itself before files with an EXE extension:
HKCR\exefile\Shell\open\command