System Defragmenter

System Defragmenter Description

ScreenshotSystem Defragmenter aka SystemDefragmenter is a fake anti-spyware program that is part of the FakeSysDef family and disguises as a legitimate application. System Defragmenter is secretly installed onto a PC before bombarding the desktop with fake security alerts and scan reports claiming the detection of dangerous malware. Victims of System Defragmenter are coerced into purchasing its "licensed version" in order to remove all the purportedly detected malware. Of course this is a scam and victims that encounter security notifications from System Defragmenter should use a legitimate security tool to remove this rogueware completely.

The FakeSysdef family is a big family of threats that has among its members Ultra Defragger, HDD Control, Win HDD, Win Defrag, Win Defragmenter, Disk Doctor, Hard Drive Diagnostic, HDD Diagnostic, HDD Plus, HDD Repair, HDD Rescue, Smart HDD, Defragmenter, HDD Tools, Disk Repair, Windows Optimization Center, Scanner, HDD Low, Hdd Fix, PUP.PC Health Kit.

Aliases: Suspicious:W32/IndoVirus.a!Gemini [F-Secure], W32/Banload.C.gen!Eldorado [F-Prot], Win-AppCare/Xema.290816.S [AhnLab-V3], VirTool/Win32.VB.gen [Antiy-AVL], VirTool.VB.bg, TR/Virtl.VB.EK [AntiVir], VirTool.Win32.VB.ek [Kaspersky], Win32.TRVirtl.VB.Ek [eSafe], W32/Suspicious_Gen2.CFDXF, VirTool.VB.JNND, Trojan/KillWin.da, Artemis!1C6662F0CA5E [McAfee], TR/Kazy.894.31 [AntiVir], Artemis!FA3F7B06B8D6 [McAfee] and TR/Kazy.893.38 [AntiVir].

Technical Information

Screenshots & Other Imagery

System Defragmenter Image 1 System Defragmenter Image 2 System Defragmenter Image 3

File System Details

System Defragmenter creates the following file(s):
# File Name Size MD5 Detection Count
1 F:\tie n dye\packupdate107_2204.exe 331,776 f0d1e74dab39e41abd6af3e98f6ca0ed 16
2 %TEMP%AphedsKjsy.exe 446,976 1b6e7017f90eadd5092c808be767e675 16
3 %TEMP%QKNqyUcYtD.exe 448,000 9a741d49b65e8dfcc1634240460c3308 10
4 C:ComboFix.exe 3,899,459 2f4423a7d956c419eb4cf3edd292922b 8
5 rpcmgr.dll 474,112 2822da0c584b267ff8c0c009285e8c4f 8
6 themedlg10.dll 57,856 fce3aa9013a625737c654ebc84657d40 8
7 %WINDIR%andy143.exe 188,416 b71bfe65a8bfcbc6e2b96868643d66bf 8
8 %USERPROFILE%\My Documents\Downloads\Directory.Eraser.exe 658,472 1c6662f0ca5e01396aff6b9a0b5b8280 7
9 %LOCALAPPDATA%85543106.exe 1,003,008 fc06b7917e5bdab1ca98f65523d1ee6f 7
10 C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe 102,400 39e0dfca3d007c071f798ef04a7ef136 6
11 %TEMP%ebeprikq.exe 4,162,560 787009e2810169f1fbc3dd87a12b517f 4
12 %COMMONPROGRAMFILES%openfile.exe 143,360 c0e62835a9079005bc0787fe6b1037d9 4
13 %WINDIR%nvsvc32.exe 90,112 62d8dbe9a4a9cdd64ee9aa9402e4f60d 3
14 %WINDIR%\system32\msxslt3.exe 155,648 67669d9209c7e787a3626a8c578659b9 3
15 %PROGRAMFILES%\Hide IP Platinum\hideippla.exe 1,527,296 8e22b4761899ecda5e6d137b7d7e635f 3
16 %APPDATA%\CTFmon\ctfmon.exe 276,865 c46632ce2850c5721756b3b546c2f93e 2
17 %WINDIR%\system32\nidem.exe 315,392 57cf9d0771bb49bd5ee6326dac70cfd9 2
18 %WINDIR%\SysWow64\awddi532.dll 379,392 c03c2bd50b594790a7d3e7c6ccd06af9 1
19 %WINDIR%wscntfywow.exe 507,392 0fada1b5b854ee6cfe9d0aaaca75b793 1
20 %WINDIR%\system32\kbdit32.dll 245,248 531be9088a46ca2a88029b9431fdbb39 1
21 %WINDIR%\system32\atl32.dll 363,008 acb562c6d7d621ec80264bcd50e4c386 1
22 %TEMP%83519406.exe 356,352 6a83e782eb09d4a37a67abbdc3bf3a6a 1
23 %WINDIR%\system32\quupoby.exe 201,216 d38fa6f9d3ac3967ab18864734430328 1
24 %APPDATA%wizu.exe 65,536 240a47fe208c87a39bc2d79f67279ffa 1
25 %APPDATA%xyst.exe 65,536 dedd025c4a7da68348268e2ea5c26892 1
26 w32cap.dll 59,392 c4c23c189557ed3f70453cdda3177b97 1
27 %TEMP%Ujo.exe 187,904 17755ee0215f17dfb852a5211ac3065a 1
More files

Registry Details

System Defragmenter creates the following registry entry or registry entries:
File name without path
System Defragmenter.lnk

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.