SystemFighter

By LoneStar in Rogue Anti-Spyware Program | 6 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Translate To:     Español  |   Português
More... More

SystemFighter Description

Image Screenshot

[+] Click Image to Enlarge

SystemFighter is a fake security tool used by cyber-criminals to swindle unsuspecting users into spending their money. A malicious Trojan is used to infect users’ systems and distribute SystemFighter. Generally, SystemFighter will run a fake system scan that will produce distressing results of multiple malware infections on the compromised PC. All notifications or pop-ups displayed by SystemFighter are fabricated and should not be trusted.

Type: Rogue AntiSpyware Programs

How Can You Detect SystemFighter?

SystemFighter Technical Report

As new SystemFighter details are reported by our customers and findings from our Threat Research Center, we will update this section.

The following SystemFighter files with its MD5s were created in the system:

File Name File Size MD5
SystemFighter.exe 784896 aeb5826664e24f67caa6e8f60c6b257a
setup[1].exe 919040 55be5ee94ecf3ae3919757d3b25513a0

SystemFighter Removal Details

SystemFighter has typically the following processes in memory:

  • SystemFighter.exe

SystemFighter creates the following files in the system:

  • %Documents and Settings%\All Users\Start Menu\Programs\SystemFighter\2 Homepage.lnk
  • SystemFighter.lnk
  • %Documents and Settings%\All Users\Start Menu\Programs\SystemFighter\1 SystemFighter.lnk
  • SystemFighter
  • %Documents and Settings%\All Users\Start Menu\Programs\SystemFighter
  • %Documents and Settings%\All Users\Start Menu\Programs\SystemFighter\3

SystemFighter created the following directories, files, paths:

  • %ProgramFiles%\SystemFighter Software\SystemFighter

SystemFighter creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “zsx1.tmp.exe”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemFighter
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “SystemFighter”

Important Article Disclaimer

ESG Support Center

This entry was last updated on 11/9/09 and posted on 11/9/09. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.