System Check virus and its fake error reports

System Check virus

System Check virus

System Check (also known as SystemCheck) is the virus program requiring immediate removal. No doubt, if your computer has now been contaminated with System Check scam then definitely something must be done immediately in order to have it entirely wiped off from your system. Otherwise, if you are waiting too long, the hoax can make the horrible mess out of your file and folder system.

As soon as System Check penetrates inside of the attacked machine it immediately starts poisoning computer with its malware roots. It tunes up your system in such a manner that it gets started together with every system startup. This means that once you turn your PC on you would face System Check virus in front of your desktop. This shameless forgery would immediately commence its evil deeds there. It would imitate some kind of system scan which would at its end report plenty of errors, bugs, problems with your computer, primarily with its disks, file and folder system. All of such problems do not really exist in reality. This is just the bunch of lies initiated by System Check in order to scare you. Then System Check would tell you that it can fix all such errors if you pay for its full version. Don’t you see that it is just trying to get your money and does not do anything else really serious? Money is the only goal of System Check, since this command has been given to it by its developers who are cyber crooks, criminals, hackers deserving to be put to jail for their malicious actions. Please find the excellent removal instructions to delete this virus here – http://www.2-viruses.com/remove-system-check


Fake information presented by System Check malware:

  • Hard drive rotational speed decreased by 20%
  • Drive C initializing error
  • Disk drive C:\ is unreadable
  • System files are damaged. System is unstable.
  • GPU RAM temperature is critically high. Urgent RAM memory optimization is required to prevent system failure
  • The problem may cause errors while loading your operation system
  • RAM memory speed decreased significantly and may cause a system failure
  • Hard drive does not correspond to system requests
  • Damaged hard drive clusters detected. Private data is at risk. Restore is required
  • C:\System32\drivers is damaged. This problem may cause a system failure
  • Hard drive rotational speed exceeds system limits and may cause a system failure
  • Boot sector of the hard drive is damaged
  • Hard drive space less than technical limits
  • RAM Memory temperature is 83

The following fake error messages normally popup in the right-bottom part of user’s desktop. No doubt, they all should also be disregarded by you.

  • Critical Error!
    HDD clusters are partly damaged. Segment load failure
  • Critical Error!
    Windows OS can’t detect a free hard disk space. HDD error
  • Critical Error!
    Damaged hard drive clusters detected. Private data is at risk.
  • Critical Error!
    Hard Drive not found. Missing hard drive.
  • Critical Error!
    RAM memory usage is critically high. RAM memory failure.
  • Critical Error!
    Windows can’t find hard disk space. Hard drive error
  • Critical Error!
    Windows was unable to save all the data for the file \System32\496A8312. The data has been lost. This error may be caused by a failure of your computer hardware.
  • Critical Error!
    A critical error has occurred while indexing data stored on hard drive. System restart required.
  • System Restore
    The system has been restored after a critical error. Data integrity and hard drive integrity verification required.
  • Activation Reminder


    System Check Activation
    Advanced module activation required to fix detected errors and performance issues. Please purchase Advanced Module license to activate this software and enable all features.
  • Low Disk Space
    You are running very low disk space on Local Disk (C:).
  • Windows – No Disk
    Exception Processing Message 0x0000013

System Check automatic removal milestones:

System Check amendments:

System Check files:

  • %LocalAppData%\
  • %LocalAppData%\.exe
  • %LocalAppData%\~
  • %LocalAppData%\~
  • %StartMenu%\Programs\System Check\
  • %StartMenu%\Programs\System Check\System Check.lnk
  • %StartMenu%\Programs\System Check\Uninstall System Check.lnk
  • %Temp%\smtmp\
  • %Temp%\smtmp\1
  • %Temp%\smtmp\1
  • %Temp%\smtmp\2
  • %Temp%\smtmp\3
  • %Temp%\smtmp\4
  • %UserProfile%\Desktop\System Check.lnk

System Check registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘Yes’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘0’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ‘0’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” =
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoDesktop” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ‘0’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = ‘0’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU “MRUList”

Video guide on anti-malware program installation for System Check infected PC:



System Check system amendments:

System Check files added:

  • %CommonAppData%\[random].exe
  • %AppData%\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
  • %Desktop%\System Check.lnk
  • %StartMenu%\Programs\System Check\
  • %StartMenu%\Programs\System Check\System Check.lnk
  • %StartMenu%\Programs\System Check\Uninstall System Check.lnk
  • %Temp%\smtmp\
  • %Temp%\smtmp\1
  • %Temp%\smtmp\1
  • %Temp%\smtmp\2
  • %Temp%\smtmp\3
  • %Temp%\smtmp\4

System Check registry entries added:

  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘Yes’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘0’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ‘0’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoDesktop” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ‘1’
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ‘0’
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = ‘0’

Leave a Reply

Your email address will not be published. Required fields are marked *