SystemCop
SystemCop Description
SystemCop is a fake spyware remover originating from the same family as BlockDefense, SaveDefense, WiniFighter, Trust Ninja and WiniBlueSoft. Due to affiliated trojans infiltrating the computer via security exploits, SystemCop is installed onto the system and from there, begins launching various fake security alerts. Along with the fictitious and sometimes grossly exaggerated infection reports supplied by the counterfeit system scans, these tactics ensure the user is intimidated enough into purchasing the fake spyware remover SystemCop in order to combat these non-existent threats.
Type: Rogue AntiSpyware Programs
How Can You Detect SystemCop?
SystemCop Technical Report
As new SystemCop details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following SystemCop files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| setup.exe | 803637 | a59d785f02a20367376bd0c1b9b94dec |
| SystemCop.exe | 724992 | b45db346486482868a2886fcc5e2e01f |
SystemCop has typically the following processes in memory:
- 1044zhackt9ol5b2.dll
- uninstall.exe
- SystemCop.exe
SystemCop created the following directories, files, paths:
- %ProgramFiles%\SystemCop Software\SystemCop
SystemCop creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\SystemCop
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “ha8tozmj.exe”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemCop
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemCopSvc
- HKEY_CURRENT_USER\Software\SystemCop
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYSTEMCOPSVC
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “SystemCop”
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
SystemCop 











