MyPCCheck

MyPCCheck is a rogue anti-virus program currently making the rounds, but you may not even know that what has infected your computer is MyPCCheck. This malware has some characteristics that make it pretty unusual.

MyPCCheck’s Unusual Characteristics

Similar to most other rogue anti-virus applications, MyPCCheck has a fake user interface, and it performs fake virus scans. MyPCCheck can also generate pop-up alerts. Reportedly, the content of these falsified scan results and alerts is nothing but what you can expect from one of these fake security programs – the fake messages warn that MyPCCheck has found threats on your computer, which it can only remove if you pay the "license" fee. Of course, paying the fee doesn't get you anything, because this is a scam. MyPCCheck has no actual functionality.

The strange thing about MyPCCheck is that it is in Korean, but it will infect computers anywhere in the world, so many of the people whose computers are affected cannot really be targeted by the scare tactics of the scam. That would require an ability to understand what all of MyPCCheck's alerts and results screens were saying, and the only thing in English is the name. So for many people, this malware is a confusing annoyance, and MyPCCheck has little hope of squeezing money out of them. Nonetheless, its frequent bogus scans and alert messages are disruptive, and the shortcuts it creates are a sign that something is really wrong. Unless your computer has Korean Language support options installed, Windows will interpret the non-Unicode characters of MyPCCheck's shortcuts, along with the text of many of its alerts, as a string of gibberish special characters.

How MyPCCheck Spreads

So at this point, you may be wondering how such an unusual infection made its way onto your computer.  MyPCCheck uses a Trojan, which is hidden in a fake video codec or bundled with software or files you download online. The idea is that it is included with a download that you wouldn't give a second thought. If the Trojan succeeds in its purpose, you don't even know it was downloaded. Then the Trojan opens a backdoor and downloads MyPCCheck, which will be set up to run the next time you start up the computer. It's unclear how long MyPCCheck has been going on, but it is at least since January 2011.

If your computer can display Korean fonts or you speak Korean, you should be warned that all of MyPCCheck's claims about your computer's security are false. It is inadvisable to follow any prompts or links that MyPCCheck may provide in its scan "results" or pop-up warnings, since these will likely lead you to the payment page for this malware. Paying for MyPCCheck doesn't unlock anything or add any functionality to the program. MyPCCheck also has no relation to the legitimate anti-malware application PC Check, and it is just taking advantage of that company's reputation. MyPCCheck is a fraud, plain and simple.

File System Details

MyPCCheck may create the following file(s):
# File Name Detections
1. C:\Documents and Settings\\My Documents\New Folder\hookdll.dll
2. C:\Documents and Settings\\My Documents\New Folder\mypccheck.exe
3. C:\Windows\System32\My PC Check.exe

Registry Details

MyPCCheck may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “MyPCCheck.exe”
HKEY_CURRENT_USER\Software\My PC Check Inc\MyPCCheck\virus_signatures=62171
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\My PC Check\DisplayIcon=C:\Documents and Settings\malwarehelp.org\My Documents\New Folder\setupapp7070010000.exe,0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\My PC Check\InstallLocation=C:\Documents and Settings\malwarehelp.org\My Documents\New Folder\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\My PC Check
HKEY_CURRENT_USER\Software\My PC Check Inc\MyPCCheck\database_version=256
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\setupapp7070010000.exe=C:\Documents and Settings\malwarehelp.org\My Documents\New Folder\setupapp7070010000.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\My PC Check\UninstallString=C:\Documents and Settings\malwarehelp.org\My Documents\New Folder\setupapp7070010000.exe /uninstall
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\My PC Check\NoRepair=1
HKEY_CURRENT_USER\Software\My PC Check Inc\My PC Check
HKEY_CURRENT_USER\Software\My PC Check Inc
HKEY_CURRENT_USER\Software\My PC Check Inc\MyPCCheck\affid=7070010000
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\My PC Check\DisplayName=My PC Check
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\My PC Check\NoModify=1

Trending

Most Viewed

Loading...