Jump to content

System Doctor 2014 Rogue Removal Instructions


Recommended Posts

The Emsisoft malware research team has discovered a new outbreak of the System Doctor 2014. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SystemDoctor2014.

System Doctor 2014 is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.

 

Create new files:

  • %AppData%\[random]\
  • %AppData%\[random]\WindowsSecurityUpdate.exe
  • %AppData%\[random]\[random].exe
  • %AppData%\[random]\[random].ico
  • %AppData%\[random]\[random].ini
  • %AppData%\[random]\[random].log
  • %UserProfile%\Desktop\System Doctor 2014 support.url
  • %UserProfile%\Desktop\System Doctor 2014.lnk
  • %UserProfile%\Start Menu\Programs\System Doctor 2014\
  • %UserProfile%\Start Menu\Programs\System Doctor 2014\System Doctor 2014 support.url
  • %UserProfile%\Start Menu\Programs\System Doctor 2014\Uninstall System Doctor 2014.lnk
  • %UserProfile%\Start Menu\Programs\System Doctor 2014\System Doctor 2014.lnk

 

Create new registry entry:

  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run
    SD2014 = “%AppData%\[random]\[random].exe”
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\System Doctor 2014
    DisplayName = “System Doctor 2014″
    InstallLocation = “%AppData%\[random]\”
    NoModify = dword:00000001
    NoRepair = dword:00000001
    UninstallString = “%AppData%\[random]\[random].exe -uninstall”
    DisplayIcon = “%AppData%\[random]\[random].ico,0″

 

Screenshots:

 

 

To register this rogue application you can try the following serial number:

 

AA39754E-715219CE

 

How to remove the infection of System Doctor 2014 (Rogue.Win32.SystemDoctor2014)?

 

To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

 

  • Upvote 1
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...