Remove Chaim. Description and removal instructions

 
Title: Chaim

Type: Worms
Severity scale:Chaim severity is 56  (56 / 100)
 
Chaim is an Internet worm that spreads through instant messages containing links to malicious files using the AOL Instant Messenger program. Once executed, the parasite secretly installs itself to the system. Then it runs a payload. Chaim opens a back door providing the attacker with unauthorized remote access to the compromised computer. The intruder can start the worm's spreading routine, download and upload arbitrary files. Chaim disables the Windows Firewall, stops essential Windows services, lowers system security settings and prevents important updates from being installed. It can also download from the Internet and execute potentially malicious files. The worm runs as a service on every Windows startup.


Related files: ntps.exe, spec.exe

Chaim properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Chaim removal:

remover for Chaim

Chaim manual removal:

Kill processes:
ntps.exe, spec.exe
Delete registry values:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NETAPI
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start=4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Shell Extensions\Melt
Delete files:
ntps.exe, spec.exe
Misc:
Exact file location:
spec.exe - C:
ntps.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Chaim:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 20/09/06
Information updated: 20/09/06

Additional resources related to Chaim:

Attention: If you know or you have a website or page about Chaim removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Chaim parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: