SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  Syschk.exe

Name Syschk.exe

Description

W32.Galil.F@mm is a mass-mailing worm that uses its own SMTP engine or Microsoft Outlook to spread.
It harvests email addresses from the files in the current user's Temporary Internet Files folder, Yahoo Messenger, Microsoft Outlook address book, as well as the files whose extensions are .asf, .avi, .doc, .jpg, .mdb, .mpe, .mpeg, .mpg, .pps, .ram, .rar, or .xls.

The worm may spoof the "From" field. The email message has a randomly selected subject line, which may also be the attachment name. The attachment has a .bhx, .exe, .hqx, .mim, .uu , .uue, or .xxe extension. The message body is also different.

When it runs, it does the following:
Displays a fake message.
May create a folder, %Windir%\Sys32s, and copy itself as %Windir%\Sys32s\ZaCker.exe with attributes set to Read-only, Hidden, and System.
Copies itself as %System%\MizZabbat32.exe.

May create the following files:
%System%\Syschk.exe: (With attributes may set to Read-only, Hidden, and System. This is the worm's propagation component.) 29,183 bytes
%System%\Smtp.Ocx: (An SMTP library. This file is not viral by itself.) 25,736 bytes
%System%\Runhelp.cab: (Which contains a file runhelp.inf. This file is not viral by itself.) 6,323 bytes
%Windir%\Sys32s\Runhelp.cab: (With attributes set to Read-only, Hidden, and System.) 6,323 bytes
%Windir%\Web\Folder.htt: (With attributes is set to Hidden and Archive.) 15,483 bytes

Manual removal.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value:
"SystemChecker"="%System%\Syschk.exe"

Navigate to the key:
HKEY_CURRENT_USER
and delete the value
"Cya"

Use antivirus (also check How To Remove section)Startup Optimizer to automatically clean your system.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

weruclpasb

Sexual pictures

wgtqpofyjf

fcyhwssqck

piogoitlfp

awynyrwgfv

Unencumbered galleries

ltzjpfaldz

oaumvpsiff

Mature galleries

<b>ซื้อหวยออนไลน์</b> สมัครสมาชิกที่นี่! จ$

Секс фото галереи ради взрослых

zobicezsru

bjzymrzopl

nisznswndg

душевая дверь

xnsglgbqbd

ssohpgxxwu

vffktrhgsv

cnlxelkqfr

zycuazlvoy

Je revais de l'Afrique full DVD(A)

bnupecgmsj

muudkjfccx

qgjqgkgioz

hieuehuzjo

tksraqfsdm

upfwiqkrnm

ogfbytsjms

qqwllrfwhr




SoftwareTipsandTricks, All Rights Reserved.