View Single Post
Old 08-06-2006, 11:59 AM   #7 (permalink)
Vikesrock8411
Analyst, Security Team
 
Vikesrock8411's Avatar
 
Join Date: Jun 2005
Posts: 3,065
OS: Windows XP


Click to watch a movie on how to remove this rootkit. You are looking for the part about 30 seconds from the end where GMER is used. Ignore the other tools. In the movie GMER is used with the pe386 service yours should be called mssync2020.

Reboot and post a new Blacklight log after deleting the service.
__________________
Vikesrock8411 is offline