• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove System Check virus

Myantispyware team January 2, 2012    

System Check is a malicious program which pretends to be a computer defragmenter and system analysis software. It is from the same family of malware as System Fix, Data Recovery, Master Utilities, PC Repair, System Repair, Windows XP Repair, Windows XP Fix, etc. It is promoted and installed itself on your computer without your permission and knowledge through the use of trojans or other malicious software. Moreover, the scammers may also distribute System Check on Twitter, My Space, Facebook, and other social networks. Please be careful when opening attachments and downloading files or otherwise you can end up with a rogue program on your PC.

When System Check is installed, it will perform a fake scan of your computer then tells you it has found numerous critical errors. Next, it will prompt you to pay for the fake software before it “repairs” your machine of the problems. Of course, all of these errors are a fake. So, you can safety ignore the false scan results.

While System Check is running, it will block legitimate Windows applcations on your computer and won’t let you download anything from the Internet. Moreover, it will display various fake critical errors alerts that the computer’s hard drive is corrupt in order to frighten you into purchasing this useless application. Some of the fake errors are:

The system has detected a problem with one or more installed IDE / SATA hard disks.
It is recommended that you restart the system.

Critical Error
A critical error has occurred while indexing data stored on hard drive. System restart required.

Critical error
Windows can`t find disk space. Hard drive error.

System Restore
The system has been restored after a critical error. Data integrity and hard drive integrity verification required.

Windows – No Disk
Exception Processing Message 0×0000013.

Of course, all of these warnings are a fake. This is an attempt to make you think your computer in danger. Like false scan results you can safely ignore them.

As you can see, obviously, System Check is a scam, which created with only one purpose – to steal your money. Most important, don`t purchase the program! You need as quickly as possible to remove the malicious software. Follow the removal instructions below, which will remove System Check and any other infections you may have on your computer for free.

Use the following instructions to remove System Check infection

1

Click Start, Type in Search field %allusersprofile% and press Enter (if you use the Windows XP, then click Start, Run and type a command in Open field). It will open a contents of “ProgramData” folder (“All Users” folder for Windows XP).

2

System Check hides all files and folders, so you need to change some settings and thus be able to see your files and folders again. Click Organize, select ”Folder and search options”, open View tab (if you use Windows XP, then open Tools menu, Folder Options, View tab). Select “Show hidden files and folders” option, uncheck “Hide extensions for known file types”, uncheck “Hide protected operating files” and click OK button.

3

Open “Application Data” folder. This step only for Windows XP, skip it if you use Windows Vista or Windows 7.

4

Now you will see System Check associated files as shown below.

5

Basically, there will be files named with a series of numbers or letter (e.g. 2636237623.exe or JtwSgJHkjkj.exe), right click to it and select Rename (don`t rename any folders). Type any new name (123.exe) and press Enter.
You can to rename only files with .exe extension. Its enough to stop this malware from autorunning.

6

Reboot your computer.
 

7

Now you can unhide all files and folders that has been hidden by System Check. Click Start, type in Search field cmd and press Enter. Command console “black window” opens. Type cd \ and press Enter. Type attrib -h /s /d and press Enter. Close Command console.

8

If your Desktop is empty, then click Start, type in Search field %UserProfile%\desktop and press Enter. It will open a contents of your desktop.

9

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

10

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

11

If an update is found, it will download and install the latest version.

 

12

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window
13

Select Perform Quick Scan, then click Scan, it will start scanning your computer. This procedure can take some time, so please be patient.

14

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

System Check remover
Malwarebytes Anti-malware, list of infected items
15

Make sure that everything is checked, and click Remove Selected for start System Check removal process. When disinfection is completed, a log will open in Notepad. Reboot your computer.

16

System Check may be bundled with TDSS trojan-rootkit, so you should run TDSSKiller to detect and remove this infection.

17

Download TDSSKiller from here and unzip to your desktop. Open TDSSKiller folder. Right click to tdsskiller and select rename. Type a new name (123myapp, for example). Press Enter. Double click the TDSSKiller icon. You will see a screen similar to the one below.


TDSSKiller
18

Click Start Scan button to start scanning Windows registry for TDSS trojan. If it is found, then you will see window similar to the one below.


TDSSKiller – Scan results
19

Click Continue button to remove TDSS trojan.

If you can`t to download or run TDSSKiller, then you need to use Combofix. Download Combofix. Close any open browsers. Double click on combofix.exe and follow the prompts. If ComboFix will not run, please rename it to myapp.exe and try again!

20

Your system should now be free of the System Check virus. If you need help with the instructions, then post your questions in our Spyware Removal forum.

System Check removal notes

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: your current antispyware and antivirus software let the infection through ? Then you may want to consider purchasing the FULL version of MalwareBytes Anti-malware to protect your computer in the future.

System Check creates the following files and folders

%UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
%CommonAppData%\[RANDOM]
%CommonAppData%\~[RANDOM]
%UserProfile%\Desktop\System Check.lnk
%CommonAppData%\[RANDOM].exe
%Temp%\smtmp\
%Temp%\smtmp\1
%Temp%\smtmp\2
%Temp%\smtmp\3
%Temp%\smtmp\4

Note: %CommonAppData% is C:\Documents and Settings\All Users\Application Data (for Windows XP/2000) or C:\ProgramData (for Windows 7/Vista)

System Check creates the following registry keys and values

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\USE FORMSUGGEST = Yes
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\CERTIFICATEREVOCATION = 0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\WARNONBADCERTRECVING = 0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\WARNONZONECROSSING = 0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\ZONES\3\1601 = 0
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\WINTRUST\TRUST PROVIDERS\SOFTWARE PUBLISHING\STATE = 146944
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\CONTROL\SESSION MANAGER\PENDINGFILERENAMEOPERATIONS = \??\%CommonAppData%\[RANDOM].exe

System Check removal – Video instructions

System Check is basically clone of Windows XP Repair, so you can use the video guide below to remove this malware.

Malware removal Rogue Anti Spyware

 Previous Post

Remove Tidserv Activity 2 alert

Next Post 

How to remove Internet Security Guard virus

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

332 Comments

  1. Isaac
    ― January 29, 2012 - 5:56 am  Reply

    Thanks guys worked perfectly
    Good job

  2. Dan Roling
    ― January 29, 2012 - 6:00 am  Reply

    I followed the directions and removed several threats, however, I am still running as though I am not the system administrator and have limited access. What should my next steps be?

  3. Fee
    ― January 29, 2012 - 7:29 am  Reply

    I renamed these exe.datas but the malware still appears after rebooting the computer..

  4. M
    ― January 29, 2012 - 9:19 pm  Reply

    Hii..

    I m trying to get ride of this virus but somehow it has disabled the Internet.. I can’t connect to the Internet..
    I tried doing a system restore but it’s not working
    I have also tried to delete registry entries but I m so sure any it
    Help!!!
    Please….

  5. Mark
    ― January 29, 2012 - 10:11 pm  Reply

    thank you soooooo much guys.

  6. JuliaA
    ― January 30, 2012 - 12:42 am  Reply

    Thanks for posting this. Thought my computer was toast! Appreciate the thorough solution!

  7. jon
    ― January 30, 2012 - 3:04 am  Reply

    you guys are amazing.Thanks for taking your time i putting this amazing information out here…. trust me this thing does work. it takes some time but it does wrk…. thanks a lot.. God bless u all

  8. Max
    ― January 30, 2012 - 5:26 pm  Reply

    When I “Type attrib -h /s /d and press Enter. Close Command console.”, there are some errors, Could you rewrite this step? Thank you so much.

  9. Rebecca
    ― January 30, 2012 - 8:13 pm  Reply

    System check has gone but I cannot view any of my system files in C drive or log on to the internet to download root kill.. HELP

  10. Rexorsist
    ― January 30, 2012 - 8:36 pm  Reply

    When I reboot my pc, system check comes back. I’m using a vista and followed all instructions properly.

  11. austin
    ― January 31, 2012 - 12:05 am  Reply

    After i did all these steps.. i still had some remnants left of the virus… i just deleted em all manually but i still get a beep/error sound every 4-5 minutes or so… how do i get rid of this?

  12. George
    ― January 31, 2012 - 2:28 am  Reply

    i have windows 7 ,the virus has been removed but if i open the start menu 90% of the programs links are gone

  13. triseps
    ― January 31, 2012 - 2:55 pm  Reply

    thankx a lot from Holland. Found youre site right away an fixed the problems within an hour after occuring!!

    Thankx a lot!

  14. Graham
    ― January 31, 2012 - 8:07 pm  Reply

    this didn’t get rid of the virus… anything I’m missing?

  15. Mike
    ― January 31, 2012 - 9:36 pm  Reply

    Thanks it worked a great deal.
    However, I noticed System Check has created a folder with uninstall options…when I tried to uninstall it, it activated the virus again!
    For the 2 .exe files which we renamed, can we delete it immediately?
    Thanks!

  16. Rohan
    ― January 31, 2012 - 10:44 pm  Reply

    Hey, need a bit of help here. When I type in attrib -h /s /d it looks like its doing what its meant to but says acess denied after every line. what is going on here?

  17. john
    ― February 1, 2012 - 12:43 am  Reply

    thank a lot.. you really saved me

  18. H
    ― February 1, 2012 - 3:19 am  Reply

    This is the best solution ever i try so many websites and this is the best do not waste your time anywhere else this is the solution at least it was for me…thanks

  19. mr. hayes
    ― February 1, 2012 - 10:24 am  Reply

    First off, this works awesome, thank you. I am having a problem with step 7, I did the spaces in the command like JSM had to, but i get a long list of access denied’s. Any help would be appreciated.

  20. Ankur Sood
    ― February 1, 2012 - 1:52 pm  Reply

    Wow!!!!!!!!!! Thank you!!!

  21. GH
    ― February 1, 2012 - 6:51 pm  Reply

    It won’t let me open ‘Application Data’ folder…

  22. Megan
    ― February 2, 2012 - 7:58 pm  Reply

    I am stuck at renaming the .exe files my computer is saying access denied with windows xp.

  23. cls
    ― February 2, 2012 - 10:28 pm  Reply

    I am stuck on number 7. I have windows xp. I can’t find \run\ to enter a command. Please help.

  24. Darkal
    ― February 3, 2012 - 3:32 am  Reply

    man thanks a million, worked perfectly, tho i used microsoft security essencials to clean the virus from my laptop, think it will work in the same way? anyways thanks again, u trully are a gift from god !!

  25. Simona
    ― February 3, 2012 - 5:38 am  Reply

    Hi, I had problem with the “attrib -h /s /d” part! after I pressed Enter I read in every lines “access denied”. I complete the instructions anyway and I don’t have the virus anymore, but all my folders are still hide.
    Can you help me? Thank you!

    P.s I hope I made myself clear, because I’m Italian and my English is a bit rusty.

  26. Joe Howard
    ― February 3, 2012 - 5:15 pm  Reply

    This worked for me exactly as you described. I CANNOT THANK YOU ENOUGH!!!!!

    BUT I STILL HAVE SOME PROBLEMS.
    —I cannot use System Restore–get “critical error” message
    —When I click on Start, the box above is completely empty as is the “computer” box. When I choose “all programs” I get only two showing up (malwarebytes and open office).
    —My Libraries show up looking like hidden files. How do I unhide?

    Can you help?

  27. Peter
    ― February 6, 2012 - 5:31 am  Reply

    Everything worked fine except now my taskbar is different and when I hit the windows icon start button and click all programs, all my program folders are empty. I have to manually locate programs to open them. Also my control panel option and others are missing too. I’m on windows 7. How can I fix these?
    Please and thank you.

  28. Jared
    ― February 6, 2012 - 4:50 pm  Reply

    I seem to have removed the virus but when I hit the windows start button (windows 7) there used to be links / icons to frequently used files, control panel, etc. Now it’s blank other than a link to “Computer” and “All Programs.” All of my task bar icons are gone too. How do I get this all back?

    Thank so much for all the help!

  29. Jamie
    ― February 6, 2012 - 5:39 pm  Reply

    Does it delete my saved files like pictures?? How do I restore my desktop icons?? Thanks for any help you can give me!!

  30. Johntrix
    ― February 7, 2012 - 3:03 am  Reply

    Hello, everything worked perfect, thanks a lot, but I still can´t unhide my files, the command give denied access, can you help me?

    Thank you a lot!

« Previous 1 … 3 4 5 6 7 … 12 Next »

Leave a Reply Cancel reply

New Guides

scam alert
Remove Searchernow.com Redirect: Chrome, Edge, Firefox
Avoid the ExLig.com Bitcoin Scam: Insights on Promo Code Frauds
scam alert
Denwex.com Review: Bitcoin Promo Codes as a Scam
scam alert
CEFOLEX.com Review: A Closer Look at the Bitcoin Promo Code Scam
The Bigexcoin.com Bitcoin Promo Code Scam: How to Stay Safe

Follow Us

Search

Useful Guides

ads by adware
How to remove Adware from Windows 10 (Virus removal guide)
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
How to reset Mozilla Firefox (Updated Apr. 2018)
Best free malware removal tools
Best Free Malware Removal Tools 2025

Recent Guides

Remove Tidserv Activity 2 alert
How to remove Home Security Solutions virus
How to remove Antivirii 2011 virus
How to remove XP Internet Security 2012 virus
How to remove Cloud AV 2012 virus

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.