sndcfg16.exe - Useless
Manual removal instructions:
On launch, the worm checks the victim machine for VMWare.
If it is launched under VMWare, some of the malicious functions will not be executed.
Copies itself to the Windows system directory as sndcfg16.exe.
It registers this file in the system registry to ensure this file is run each time the system is started:
[Software\Microsoft\Windows\CurrentVersion\Run] Services = sndcfg16.exe
This worm propagates via P2P networks.
If the worm detects a P2P client, it will copy itself under a random name.
The worm checks the system registry value every second.
It downloads and launches files from the Internet.
The worm also connects to a number of IRC channels to inform the author of the worm about infected machines.
You can remove it by RegRun.
by NightWatchersndcfg16.exe Dangerous Rating: 5 out of 5
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial of UnHackMe.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.