SystemArmor
Rate it:
SystemArmor Description
SystemArmor is a fake anti-spyware program from the notorious WiniGuard family. SystemArmor may enter a computer disguised as a video codec download or a flash player update. On entering a system, SystemArmor will launch fake security notifications claiming that the system is infected with dangerous malware that can only be removed with the “licensed” version of SystemArmor. Do not fall for this scam; SystemArmor is unable to detect or remove malware.
Type: Rogue AntiSpyware Programs
How Can You Detect SystemArmor?
SystemArmor has typically the following processes in memory:
- c:\WINDOWS\system32\
- c:\Program Files\SystemArmor Software\SystemArmor\uninstall.exe
- c:\Program Files\SystemArmor Software\SystemArmor\SystemArmor.exe
- %Temp%\
SystemArmor creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\SystemArmor
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemArmor
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “SystemArmor”
- HKEY_CURRENT_USER\Software\SystemArmor
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
Important Article Disclaimer
This entry was posted on 05/14/10 and is filed under Rogue Anti-Spyware Program.
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

SystemArmor 










