winit.exe - Dangerous
winit.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
W32.Mugly.A@mm is a worm that uses its own SMTP engine to spread by sending itself as an email attachment to the email addresses gathered from the infected computer. It also drops and runs a W32.Spybot.Worm variant, and may attempt to open a backdoor on the infected computer.
Related files:
%System%\attached.zip (zipped copy of worm)
%System%\winit.exe (attributes are set to read_only, hidden, and system. This is a variant of W32.Spybot.Worm.)
%System%\uglym.jpg
%System%\ANSMTP.DLL (valid ActiveX email engine)
%System%\bszip.dll (valid archive engine)
%System%\SVKP.sys (not viral)
http://www.sarc.com/avcenter/venc/data/p...
Kill the process winit.exe and remove winit.exe from Windows startup.