syschkrs.exe

The application syschkrs.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “System checker Service”. This file is typically installed with the program System-Checker by system-checker.com which is a potentially unwanted software program.
MD5:
57864b500ae9e233b2d2f6f7dd1df7a4

SHA-1:
8e28a1d672cee938b510cb02c243c7e28d8890b9

SHA-256:
d17b6979f74ddd8e570b431377b6f6e87e3342f793216a59c41b79ed5a94bcf5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 4:17:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SystemChecker
16.2.1.13

File size:
182.5 KB (186,880 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\system-checker\syschkrs.exe

File PE Metadata
Compilation timestamp:
3/31/2015 4:57:35 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
3072:D5zMRRRIfyXppDZib9s2niSYIl+oyAp0axKk954t:D5zWReSrDIeSYIlGAV554t

Entry address:
0xC8B0

Entry point:
E8, 1E, B5, 00, 00, E9, 7B, FE, FF, FF, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 04, D2, 42, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, E8, B4, 42, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 04, D2, 42, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00...
 
[+]

Code size:
130 KB (133,120 bytes)

Service
Display name:
System checker Service

Service name:
syschkrs

Type:
Win32OwnProcess


The file syschkrs.exe has been discovered within the following program.

System-Checker  by system-checker.com
www.system-checker.com
83% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (52.216.18.112:80)

Remove syschkrs.exe - Powered by Reason Core Security