ZY2RMRCVL.EXE - Dangerous
ZY2RMRCVL.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
ZY2RMRCVL.EXE is known as: Trojan.Win32.Swisyn.bhee [Kaspersky Lab] Trojan-Spy.Win32.VB [Ikarus] packed with UPX [Kaspersky Lab].
MD5 of ZY2RMRCVL.EXE = 1AF296E06C91D9B375E84C7C5F46B88A
ZY2RMRCVL.EXE size is 128512 bytes.
Full path on a computer: %APPDATA%\ZY2RMRCVL.EXE
Related Files:
%APPDATA%\7ER44EQ.EXE
%APPDATA%\9FX1P.LOG
%APPDATA%\CONIMA.EXE
%WINDIR%\CFTNOM.EXE
%APPDATA%\INLOG
%APPDATA%\INPUT.BAT
%APPDATA%\LOCALACCOUNTAUTHORITY.BAT
%APPDATA%\LSSAS.EXE
%APPDATA%\MANAGER.EXE
%APPDATA%\MLOG
%APPDATA%\MOUSEDRIVER.BAT
%APPDATA%\PLUG.BAT
%APPDATA%\QUS0BCRS.EXE
%APPDATA%\YLOG
%APPDATA%\ZY2RMRCVL.EXE
%TEMP%\NSX2.TMP\SYSTEM.DLL
%PROGRAMS%\STARTUP\[FILENAME OF THE SAMPLE #1 WITHOUT EXTENSION].LNK
%WINDIR%\CFTNOM.BAT
%SYSTEM%\DRIVERS\[FILENAME OF THE SAMPLE #1]
%SYSTEM%\NWSAPAGENTS.DLL
%SYSTEM%\USER.INI
%WINDIR%\TEMP\VGX4.TMP
%WINDIR%\TEMP\VGX5.TMP
%WINDIR%\TEMP\VGX6.TMP
%WINDIR%\TEMP\VGX7.TMP
%WINDIR%\TEMP\VGX8.TMP
%WINDIR%\TEMP\VGX9.TMP
%WINDIR%\TEMP\VGXA.TMP
%WINDIR%\TEMP\VGXB.TMP
%WINDIR%\TEMP\X1JKFDSAL.INF