File Behavior
SYSLIB.SYS has been seen to perform the following behavior:
- Found on infected systems and resists interrogation by security products
- This Process Disables Other Security Products
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Registers a Windows APPINIT DLL To be loaded in all processes
- Creates new file extentions so that Internet Explorer will automatically open and potentially execute additional file types
- Changes the Internet Explorer Home Page Settings
- Adds new menu items in the Internet Explorer Right Click menu
- Changes the Internet Explorer Search Page
- Creates a Toolbar Extension for Internet Explorer
- Creation and Registers a Browser Helper Object in Internet Explorer
- Adds a Registry Key (RUNONCE) to auto start Programs on system start up
- Changes to the file command map within the registry
- Modifies the Windows Built in Screen Saver
- Ability to execute files automatically on your PC
- Adds a Winlogon Notification DLL to automatically load on system start up
- Adds a Registry Key (EXPLORER) to auto start Programs on system start Boot up
- Adds a Registry Key (DELAY) to auto start Programs on system start up
- Modifies System Runtime Policies to limit system usability
- Automatically changes your firewall settings to allow itself or other programs to communicate over the internet
SYSLIB.SYS has been the subject of the following behavior:
- Created as a new Background Service on the machine
- Created as a process on disk
Country Of Origin
The filename SYSLIB.SYS was first seen on Oct 15 2007 in the following geographical regions of the Webroot community:
- Vietnam on Oct 15 2007
- Spain on Dec 1 2008
- The United States on Jan 26 2010
Filesizes
The following file size has been seen:
- 1,721,127 bytes
- 297,511 bytes
- 10,000,000 bytes
- 2,641,920 bytes
- 5,946,086 bytes
File Type
The filename SYSLIB.SYS is used by multiple object types including objects,Dynamic Link LIbraries.
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.