Home Malware Programs Rogue Anti-Spyware Programs System Cleaner

System Cleaner

Posted: March 19, 2011

The rogue anti-malware program System Cleaner may look and sound like a good thing to have on your PC, but, in truth, it's nothing more than a case of fraudulent advertising. System Cleaner won't clean anything except, perhaps, your wallet - this free but malicious application has no beneficial functions and may even harm your computer if you let it stick around. If you can learn to ignore this rogue software's bad errors and fake scans, you can remove System Cleaner by using trustworthy anti-malware applications that actually do what they say they'll do.

Watch Out for Those Cybercriminals

Like many kinds of rogue programs, System Cleaner is distributed through several different ways (all of them underhanded):

  • If you unintentionally stumble across a website linked to System Cleaner, you may be alerted with warnings about your PC that tell you to download security software to solve the issue. This message is preset and will always display in an attempt to get users to download rogue malware of their own free will. One common message System Cleaner has been found spreading under is this one:

    Your system has not passed the cybercriminal activity test and cannot be considered safe.
    You might be a victim of cybercriminals.
    Click here to learn more.

  • Websites affiliated with System Cleaner can also try to force you to download System Cleaner by exploiting security flaws in your web browser. Keeping plugins and scripts turned off will reduce your chances of getting victimized by these drive-by downloads, but ultimately, visiting a malware-promoting website is never completely safe.
  • System Cleaner is also available on various free software websites with poor upload control. In most cases, rogue products like System Cleaner will have good ratings and reviews artificially generated until the wider public catches on to the scam and the download is removed.

What System Cleaner Delivers Isn't Exactly Sparkling Clean

Computers that play host to System Cleaner are subject to quite a range of attacks, all of which are standard for rogue malware. System Cleaner will emit frequent alerts, warnings and other types of pop-ups that insist your PC is practically overflowing with malware threats and system problems. Its scans will also show bad results, no matter what you do – System Cleaner claims that only registering it will help you cure what ails your machine. It shouldn't surprise you to learn that these are all false alarms, with no purpose other than to nudge you into giving your credit card information to hackers!

Deleting System Cleaner is a better choice than just trying to ignore it, since System Cleaner may also block real security programs or alter your browser settings to enable hijackings. A real anti-malware program will be able to clean System Cleaner out in the blink of an eye if you stop the malware from running first.

The easiest way to shut down System Cleaner and similar malware to allow for a proper system scan is by rebooting into Safe Mode, accessible through the F8 key during the boot-up process. Since System Cleaner hasn't been reported to have any root-access functions, chances are the version of it that you get can be deleted the same way you'd delete any virus or other malware pest.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AllUsersProfile%\Application Data\[RANDOM CHARACTERS]
    2 %AllUsersProfile%\Application Data\[RANDOM CHARACTERS].dll
    3 %AllUsersProfile%\Application Data\[RANDOM CHARACTERS].exe
    4 %AllUsersProfile%\Application Data\~[RANDOM CHARACTERS]

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s's:/ogn:/uyu:/dyd:/c'u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/'wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v'w:/rbs:'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"

Related Posts

Loading...