SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  Syschk.exe

Name Syschk.exe

Description

W32.Galil.F@mm is a mass-mailing worm that uses its own SMTP engine or Microsoft Outlook to spread.
It harvests email addresses from the files in the current user's Temporary Internet Files folder, Yahoo Messenger, Microsoft Outlook address book, as well as the files whose extensions are .asf, .avi, .doc, .jpg, .mdb, .mpe, .mpeg, .mpg, .pps, .ram, .rar, or .xls.

The worm may spoof the "From" field. The email message has a randomly selected subject line, which may also be the attachment name. The attachment has a .bhx, .exe, .hqx, .mim, .uu , .uue, or .xxe extension. The message body is also different.

When it runs, it does the following:
Displays a fake message.
May create a folder, %Windir%\Sys32s, and copy itself as %Windir%\Sys32s\ZaCker.exe with attributes set to Read-only, Hidden, and System.
Copies itself as %System%\MizZabbat32.exe.

May create the following files:
%System%\Syschk.exe: (With attributes may set to Read-only, Hidden, and System. This is the worm's propagation component.) 29,183 bytes
%System%\Smtp.Ocx: (An SMTP library. This file is not viral by itself.) 25,736 bytes
%System%\Runhelp.cab: (Which contains a file runhelp.inf. This file is not viral by itself.) 6,323 bytes
%Windir%\Sys32s\Runhelp.cab: (With attributes set to Read-only, Hidden, and System.) 6,323 bytes
%Windir%\Web\Folder.htt: (With attributes is set to Hidden and Archive.) 15,483 bytes

Manual removal.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value:
"SystemChecker"="%System%\Syschk.exe"

Navigate to the key:
HKEY_CURRENT_USER
and delete the value
"Cya"

Use antivirus (also check How To Remove section)Startup Optimizer to automatically clean your system.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

НАСКОЛЬКО ВАЖ

С одной блочн

Big Black Grls!Old Fat MILF !# 5223794

Black Fat - Ebony moms boobs# 9322028

Fat Pussy BBW!Black Girls photo!# 5222471

Callow Project

Смотреть филь

Hardcore Gay photo blogging service

Full-grown galleries

Mature purlieus

sortie de chemise de spyder

Sexual pictures

Pictures from collective networks

ozualay

wdgdccl

Open full-grown galleries

Новости строи

Протестируй н

Hardcore Gay photo blogging ritual

Free galleries

Open grown-up galleries

indian classical music

classical piano music remix

Loose galleries

Matured site

straightforward tips for aid removing panic disorders

Pictures from community networks

Stared fashionable concoct

Latest install

Grown up galleries




SoftwareTipsandTricks, All Rights Reserved.