System Fix Removal Guide

Category: Fake Antispyware

If your PC is getting annoying popup messages from System Fix stating that the system is being overrun with crippling errors then you have serious cause for concern. System Fix is a malicious rogue defragmenter only out to rip you off. Deriving from the same despicable family of rogues as FakeHDD, it will not rest until it succeeds in fleecing its victim out of his money. This rogue is not able to detect or fix any type of error and is nothing more than a malicious infection in itself.

System Fix pretends to scan the System Drive, Ram Memory and System Registry and My Computer sections of the PC. It will report errors on all these sections of the system and will offer to fix it only once the user purchases System Fix. This rogue enters the system surreptitiously using fake online scanners and websites that employ drive-by download tactics.

The fake scan it generates will shortly be followed by fake system notifications informing the user of the same errors. Some of the fake alerts to be on the lookout for include the following:

Windows detected a hard disk problem
a potential disk failure may cause loss of files, applications and documents stored on the hard disk. Please try not to use this computer until the hard disk is fixed or replaced.

Windows detected a hard disk problem
a potential disk failure may cause loss of files, applications and documents store on the hard disk. It's highly recommended to scan and solve HDD problems before continue using this PC.

Hard Drive Failure
The system has detected a problem with one or more installed IDE / SATA hard disks. It is recommended that you restart the system.

System Error
An error occurred while reading system files. Run a system diagnostic utility to check your hard disk drive for errors.

Symptoms reportedly associated with the System Fix infection include users being unable to launch applications on the infected PC. Users have also complained about severe poor system performance and increased erratic system behavior.

System Fix has also been known to generate and delete random Desktop items, and to hide certain system folders and its contents from users.

In order to limit the damage this rogue will cause to your PC and to regain control of your system destroy System Fix immediately using a legitimate security tool. This will obliterate System Fix and protect your system against similar attacks in future.


System Fix Screenshots:

System Fix

System Fix technical info for manual removal:

Files Modified/Created on the system:

# File Name File Size (Bytes) File Hash
2lvvm.exe189952 bytesMD5: 01ddb1f6d60ee53a5f27746a622e4365
3B2C9A.exe174592 bytesMD5: 66ad60d42754559638d94554f999b563
5ovLtSvlXCxH.exe434944 bytesMD5: 5775d6d45730566c4ad1a08f69396799
6AnxAWyvzgmN5fQ.exe352512 bytesMD5: bb262d54a6fa8b89d3f30b2e37edd247
7%Desktop%\System Fix.lnk
897E.exe289792 bytesMD5: 3a132d79ff5b577c8ea00bad8da6304d
9%AppData%\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
10POrAEHHCNGan.exe422656 bytesMD5: 1cd587b82c91914d9a3de874a5362437
112492.exe2006528 bytesMD5: 99f98b2d53930c287c58f410110a260f
12186.exe275456 bytesMD5: bcd0e7764edf6cb3119990826fb70662
14%StartMenu%\Programs\System Fix\System Fix.lnk
15dSPEfJqNGav.exe444672 bytesMD5: b8b4d7fd7f49141f2a2459cdf18b975a
17ABrSmUWHNf.exe433408 bytesMD5: 2a2d3bfc5c0b76ad0ccd7afafc7c4769
19A2E36.exe167424 bytesMD5: 08c68373bf729420dc3747f139e3ea57
20gcM4SGa6XY2qLk.exe335104 bytesMD5: e3de193284cc955efc5fb4b0e4b348de
21%StartMenu%\Programs\System Fix\
22Wx7FHng4rJ4QFn.exe335616 bytesMD5: 8d2327e5ff0ebabfab262b7c146b8b60
2462D.exe276480 bytesMD5: 739b6a890c374f3f2a4d928de4953ff6
25RhsEkxxjfUhuhw.exe420096 bytesMD5: cd3c642eaacd86c7893e1608d8c57dc7
2687B.exe275968 bytesMD5: 81bbd7daa950826d94b1a5f19f41e432
27java.exe2918912 bytesMD5: 64eaa4d0f5feb73c65174a25f2d9942f
28IoWwDnqsYPU.exe491520 bytesMD5: 9979ba49d3bc0db9e237b1986e319987
295EE61.exe166400 bytesMD5: d962c1c3149b4f99f3ab339137ae8921
31%StartMenu%\Programs\System Fix\Uninstall System Fix.lnk

Registry Modifications:

The following Registry Keys were created:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'


