System Fix Removal Guide

Threat Level:
9/10
Rate this Article:
Comments (0)
Article Views: 9108
Category: Fake Antispyware

If your PC is getting annoying popup messages from System Fix stating that the system is being overrun with crippling errors then you have serious cause for concern. System Fix is a malicious rogue defragmenter only out to rip you off. Deriving from the same despicable family of rogues as FakeHDD, it will not rest until it succeeds in fleecing its victim out of his money. This rogue is not able to detect or fix any type of error and is nothing more than a malicious infection in itself.

System Fix pretends to scan the System Drive, Ram Memory and System Registry and My Computer sections of the PC. It will report errors on all these sections of the system and will offer to fix it only once the user purchases System Fix. This rogue enters the system surreptitiously using fake online scanners and websites that employ drive-by download tactics.

The fake scan it generates will shortly be followed by fake system notifications informing the user of the same errors. Some of the fake alerts to be on the lookout for include the following:

Windows detected a hard disk problem
a potential disk failure may cause loss of files, applications and documents stored on the hard disk. Please try not to use this computer until the hard disk is fixed or replaced.

Windows detected a hard disk problem
a potential disk failure may cause loss of files, applications and documents store on the hard disk. It's highly recommended to scan and solve HDD problems before continue using this PC.

Hard Drive Failure
The system has detected a problem with one or more installed IDE / SATA hard disks. It is recommended that you restart the system.

System Error
An error occurred while reading system files. Run a system diagnostic utility to check your hard disk drive for errors.

Symptoms reportedly associated with the System Fix infection include users being unable to launch applications on the infected PC. Users have also complained about severe poor system performance and increased erratic system behavior.

System Fix has also been known to generate and delete random Desktop items, and to hide certain system folders and its contents from users.

In order to limit the damage this rogue will cause to your PC and to regain control of your system destroy System Fix immediately using a legitimate security tool. This will obliterate System Fix and protect your system against similar attacks in future.

 

Download Remover for System Fix *
*SpyHunter scanner, published on this site, is intended to be used only as a detection tool. To use the removal functionality, you will need to purchase the full version of SpyHunter.

System Fix Screenshots:

System Fix

System Fix technical info for manual removal:

Files Modified/Created on the system:

# File Name File Size (Bytes) File Hash
1%Temp%\smtmp\4
2ABrSmUWHNf.exe433408 bytesMD5: 2a2d3bfc5c0b76ad0ccd7afafc7c4769
3IoWwDnqsYPU.exe491520 bytesMD5: 9979ba49d3bc0db9e237b1986e319987
4dSPEfJqNGav.exe444672 bytesMD5: b8b4d7fd7f49141f2a2459cdf18b975a
587B.exe275968 bytesMD5: 81bbd7daa950826d94b1a5f19f41e432
6%AllUsersProfile%\[random].exe
7%Temp%\smtmp\
8%Temp%\smtmp\2
95EE61.exe166400 bytesMD5: d962c1c3149b4f99f3ab339137ae8921
10A2E36.exe167424 bytesMD5: 08c68373bf729420dc3747f139e3ea57
11Wx7FHng4rJ4QFn.exe335616 bytesMD5: 8d2327e5ff0ebabfab262b7c146b8b60
12186.exe275456 bytesMD5: bcd0e7764edf6cb3119990826fb70662
13%StartMenu%\Programs\System Fix\Uninstall System Fix.lnk
14java.exe2918912 bytesMD5: 64eaa4d0f5feb73c65174a25f2d9942f
15RhsEkxxjfUhuhw.exe420096 bytesMD5: cd3c642eaacd86c7893e1608d8c57dc7
16%StartMenu%\Programs\System Fix\
172492.exe2006528 bytesMD5: 99f98b2d53930c287c58f410110a260f
18%AppData%\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
19POrAEHHCNGan.exe422656 bytesMD5: 1cd587b82c91914d9a3de874a5362437
20%Temp%\smtmp\1
21%StartMenu%\Programs\System Fix\System Fix.lnk
2297E.exe289792 bytesMD5: 3a132d79ff5b577c8ea00bad8da6304d
23lvvm.exe189952 bytesMD5: 01ddb1f6d60ee53a5f27746a622e4365
24AnxAWyvzgmN5fQ.exe352512 bytesMD5: bb262d54a6fa8b89d3f30b2e37edd247
25%Temp%\smtmp\3
26ovLtSvlXCxH.exe434944 bytesMD5: 5775d6d45730566c4ad1a08f69396799
27B2C9A.exe174592 bytesMD5: 66ad60d42754559638d94554f999b563
28%Desktop%\System Fix.lnk
29gcM4SGa6XY2qLk.exe335104 bytesMD5: e3de193284cc955efc5fb4b0e4b348de
30%AllUsersProfile%\~[random]
3162D.exe276480 bytesMD5: 739b6a890c374f3f2a4d928de4953ff6

Registry Modifications:

The following Registry Keys were created:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'

Reply

Your email address will not be published.

Name
Website
Comment

Enter the numbers in the box to the right *