Windows 7 System Repair

By Domesticus in Rogue Anti-Spyware Program | 107 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

Windows 7 System Repair Description

Windows 7 System Repair is a fake security program that exclusively attacks computers using the Windows 7 operating system. When infecting a computer with another operating system, this same rogue security program changes its name and skin to match the operating system it is attacking. Therefore, on a computer with Windows XP, it would be named XP System Repair; on a computer running Windows Vista, it is likely that this same fake security program would be named Windows Vista System Repair. This fake security program has a large number of clones, which include Win 7 Total Security, Vista Total Security, XP Total Security, Windows 7 Home System Repair, XP Home System Repair, Vista Home System Repair, and many others. If you find that Windows 7 System repair is installed on your computer, remove Windows 7 System Repair immediately with a legitimate anti-malware utility.
 

What is Windows 7 System Repair Trying to Do?

Windows 7 System Repair and Windows 7 System Repair’s clones were created with a single purpose in mind: to steal your money. To scam you, Windows 7 System Repair mimics a real security tool. However, Windows 7 System Repair has no security elements; Windows 7 System Repair is made up solely of a convincing interface, a form where Windows 7 System Repair asks for your credit card information and a collection of Trojans and malicious scripts to cause problems on your computer. Windows 7 System Repair is designed to cause harmful effects on your computer, to convince you to pay for this fake security tool. Some effects Windows 7 System Repair can have on a computer system include the following:
-Changes to your Internet browser settings, blocked access to your Internet browser, or constant redirection to Windows 7 System Repair’s websites while browsing.
-Blocked access to your security programs or executable files in general; usually, Windows 7 System Repair will display a fake error message when trying to open any of these.
-General system instability, random crashes, decreased system performance, and excessively high CPU and memory use.
-Constant error messages, fake security alerts, pop-up notifications, and fake system scans that are very hard to close and impossible to remove.
 

Don’t Become a Victim of Windows 7 System Repair!

Don’t fall for Windows 7 System Repair! Windows 7 System Repair is trying to steal your money. You should not give this fraudulent program your credit card information and, if you already have, you can call your credit card company to block the charges. ESG researchers recommend that you use an updated anti-malware tool from a reliable source to get rid of Windows 7 System Repair. If you have trouble accessing your legitimate security programs, you can stop Windows 7 System Repair from loading up at start-up, by launching Windows in Safe Mode; all you need to do is press F8 during start-up.

Type: Rogue AntiSpyware Programs

How Can You Detect Windows 7 System Repair?

Windows 7 System Repair Technical Report

As new Windows 7 System Repair details are reported by our customers and findings from our Threat Research Center, we will update this section.

Fake message for Windows 7 System Repair:

The following fake error message(s) appears for Windows 7 System Repair:

Critical Error!
Damaged hard drive clusters detected. Private data is at risk.

Critical Error
Windows can’t find hard disk space. Hard drive error.

Critical Error!
Windows was unable to save all the data for the file \System32\496A8300. The data has been lost. This error may be caused by a failure of your computer hardware.

Critical Error
RAM memory usage is critically high. RAM memory failure.

Critical Error
A critical error has occurred while indexing data stored on hard drive. System restart required.

Critical Error
Hard Drive not found. Missing hard drive.

Low Disk Space
You are running very low disk space on Local Disk (C:).

System Restore
The system has been restored after a critical error. Data integrity and hard drive integrity verification required.

32% of HDD space is unreadable

Windows – No Disk
Exception Processing Message 0×0000013

Hard drive doesn’t respond to system commands.

Data Safety Problem. System integrity is at risk.

Ram Temperature is 83 C. Optimization is required for normal operation.

Bad sectors on hard drive or damaged file allocation table.

Read time of hard drive clusters less than 500 ms.

GPU RAM temperature is critically high. Urgent RAM memory optimization is required.

Requested registry access is not allowed. Registry defragmentation required.

Windows 7 System Repair Removal Details

Windows 7 System Repair has typically the following processes in memory:

  • %AllUsersProfile%\Application Data\[RANDOM CHARACTERS].exe
  • %AllUsersProfile%\Application Data\[RANDOM CHARACTERS].dll

Windows 7 System Repair creates the following files in the system:

  • %Desktop%\Windows 7 System Repair.lnk
  • %TempDir%\dfrgr
  • %Programs%\Windows 7 System Repair\Windows 7 System Repair.lnk
  • %TempDir%\dfrg
  • %Programs%\Windows 7 System Repair

Windows 7 System Repair creates the following registry entries:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ‘1′
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ‘0′
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s’s:/ogn:/uyu:/dyd:/c’u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/’wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v’w:/rbs:’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[RANDOM CHARACTERS].exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ‘0′
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ‘1′
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[RANDOM CHARACTERS]”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ‘1′
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘0′
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1′

Important Article Disclaimer

ESG Support Center

This entry was last updated on 07/16/11 and posted on 07/16/11. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.