System Cleaner

By Domesticus in Rogue Anti-Spyware Program

System Cleaner, or SystemCleaner, is a rogue anti-spyware program that may have creeped into your computer with the help of Trojans or you manually downloaded it from a badware website. System Cleaner creates exaggerated and misleading warning messages stating that there's viruses in the PC. System Cleaner also runs fake system scans that are only listing predefined malware. No matter how many times you run a scan it will give you the same results because it's designed to give you the same malware list. Do not click on any links provided System Cleaner and use a real anti-spyware program to delete its presence on your PC.

File System Details

System Cleaner may create the following file(s):
# File Name Detections
1. %AllUsersProfile%\Application Data\[RANDOM CHARACTERS].exe
2. %AllUsersProfile%\Application Data\[RANDOM CHARACTERS].dll
3. %AllUsersProfile%\Application Data\[RANDOM CHARACTERS]
4. %AllUsersProfile%\Application Data\~[RANDOM CHARACTERS]

Registry Details

System Cleaner may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s's:/ogn:/uyu:/dyd:/c'u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/'wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v'w:/rbs:'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'

Related Posts

Trending

Most Viewed

Loading...