syschk.exe - Dangerous
syschk.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
It harvests email addresses from the files in the current user's Temporary Internet Files folder, Yahoo Messenger, Microsoft Outlook address book, as well as the files whose extensions are .asf, .avi, .doc, .jpg, .mdb, .mpe, .mpeg, .mpg, .pps, .ram, .rar, or .xls.
The worm may spoof the "From" field. The email message has a randomly selected subject line, which may also be the attachment name. The attachment has a .bhx, .exe, .hqx, .mim, .uu , .uue, or .xxe extension. The message body is also different.
When it runs, it does the following:
Displays a fake message.
May create a folder, %Windir%\Sys32s, and copy itself as %Windir%\Sys32s\ZaCker.exe with attributes set to Read-only, Hidden, and System.
Copies itself as %System%\MizZabbat32.exe.
May create the following files:
%System%\Syschk.exe: (With attributes may set to Read-only, Hidden, and System. This is the worm's propagation component.) 29,183 bytes
%System%\Smtp.Ocx: (An SMTP library. This file is not viral by itself.) 25,736 bytes
%System%\Runhelp.cab: (Which contains a file runhelp.inf. This file is not viral by itself.) 6,323 bytes
%Windir%\Sys32s\Runhelp.cab: (With attributes set to Read-only, Hidden, and System.) 6,323 bytes
%Windir%\Web\Folder.htt: (With attributes is set to Hidden and Archive.) 15,483 bytes
Manual removal.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value:
"SystemChecker"="%System%\Syschk.exe"
Navigate to the key:
HKEY_CURRENT_USER
and delete the value
"Cya"
Use RegRun Startup Optimizer to automatically clean your system.