sysmgr.exe - Dangerous
sysmgr.exe
Manual removal instructions:
Antivirus Report of sysmgr.exe:
sysmgr.exe
W32/Sdbot-OO is an IRC backdoor that can spread via network shares protected by weak passwords.
The worm copies itself to the file sysmgr.exe and cool.exe in the Windows System folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft System Checkup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NT Logging Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft System Checkup
W32/Sdbot-OO connects to an IRC server specified by the author and joins a channel from which it will receive further commands.
These commands can start any of the following actions:
- HTTP server
- sock4 proxy server
- UDP, SYN or PING flooding
- TCP redirection
- download files
- execute arbitrary commands
- spread via weakly-protected network shares
It may also attempt to terminate the security related processes.
Use RegRun Startup Optimizer to remove it from startup.
sysmgr.exe | Malware |
sysmgr.exe | Dangerous |
sysmgr.exe | High Risk |
The worm copies itself to the file sysmgr.exe and cool.exe in the Windows System folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft System Checkup
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NT Logging Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft System Checkup
W32/Sdbot-OO connects to an IRC server specified by the author and joins a channel from which it will receive further commands.
These commands can start any of the following actions:
- HTTP server
- sock4 proxy server
- UDP, SYN or PING flooding
- TCP redirection
- download files
- execute arbitrary commands
- spread via weakly-protected network shares
It may also attempt to terminate the security related processes.
Use RegRun Startup Optimizer to remove it from startup.
Dmitry Sokolov:
I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.
Since that time I work every day to fix the issues that antiviruses cannot.
If your antivirus have not helped you solve the problem, you should try UnHackMe.
We are a small company and you can ask me directly, if you have any questions.