Home Malware Programs Rogue Anti-Spyware Programs SystemArmor

SystemArmor

Posted: May 14, 2010

SystemArmor (System Armor) is a rogue antispyware program from the WiniGuard family of rogues. System Armor gets into your PC when you download a video codec, or update your flash player. Once active, the rogueware starts threatening users with scareware. SystemArmor scans your machine every time you boot Windows up, and delivers fake warnings and alerts that your PC is in danger. This is a blatant scam and attempt at trying to get users to purchase SystemArmor. Do not fall for this trickery and have System Armor removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\
    2 c:\Documents and Settings\All Users\Desktop\SystemArmor.lnk
    3 c:\Documents and Settings\All Users\Start Menu\Programs\SystemArmor
    4 c:\Documents and Settings\All Users\Start Menu\Programs\SystemArmor\1 SystemArmor.lnk
    5 c:\Documents and Settings\All Users\Start Menu\Programs\SystemArmor\2 Homepage.lnk
    6 c:\Documents and Settings\All Users\Start Menu\Programs\SystemArmor\3 Uninstall.lnk
    7 c:\Program Files\SystemArmor Software\
    8 c:\Program Files\SystemArmor Software\SystemArmor\
    9 c:\Program Files\SystemArmor Software\SystemArmor\SystemArmor.exe
    10 c:\Program Files\SystemArmor Software\SystemArmor\uninstall.exe
    11 c:\WINDOWS\system32\

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"HKEY_CURRENT_USER\Software\SystemArmorHKEY_LOCAL_MACHINE\SOFTWARE\SystemArmorHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SystemArmor"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SystemArmor
Loading...