system-check.de – fraudulent (fake) site to avoid

System Check fake hard drive defragmenter remains quite persistent nowadays. It attacked many countries worldwide and keeps infecting thousands of PCs all over the world. It gets often spread via fake USPS emails with suspicious attachments containing Trojans and exe-files that, upon execution without user’s consent of their maliciousness, implant the malware program onto the compromised workstation. Sometimes these attachments come as .zip files that, upon extraction and subsequent launching, bring the same hoax onto user’s PC. When it enters your system it messes it up substantially. For example, it hides the majority of files, folders, icons, shortcuts and programs in the Start menu. This is done by adding hidden attribute to the files and relocating them to specially created folder. Then the hoax tells of various fake errors and threats that aren’t inherent to your computer at all. Nevertheless, the malware runs various fake system scans and then reports plenty of fake errors and tells you to buy its licensed version to have them all fixed (repaired). This is the serious mistake to pay for this totally useless software sample. German users should be very careful when they see the fake site that is used as payment processing interface for System Check fake HDD. This fraudulent online platform is known as system-check.de . This site does not exist in the world wide web, nevertheless, this built-in interface is actively used as the machine to collect funds from unwary users. Therefore, avoid this fake site system-check.de and ignore the malware’s offers to buy it. If your system has become the victim of System Check infection please follow this guide below to remove it and to restore your missing items.


System Check automatic remover:

How to restore your missing data with GridinSoft Trojan Killer:

  1. Click “Tools” menu and select “Restore hidden files” option. Alternatively, you may simply use the hotkey “Ctrl + 4” while GridinSoft Trojan Killer is running.
  2. GridinSoft Tools to restore hidden files

    GridinSoft Tools to restore hidden files

  3. Click “Yes” in the window that appeared.

System Check removal video guide:

System Check manual removal:

Delete System Check files:

  • %LocalAppData%\
  • %LocalAppData%\.exe
  • %LocalAppData%\~
  • %LocalAppData%\~
  • %StartMenu%\Programs\System Check\
  • %StartMenu%\Programs\System Check\System Check.lnk
  • %StartMenu%\Programs\System Check\Uninstall System Check.lnk
  • %Temp%\smtmp\
  • %Temp%\smtmp\1
  • %Temp%\smtmp\1
  • %Temp%\smtmp\2
  • %Temp%\smtmp\3
  • %Temp%\smtmp\4
  • %UserProfile%\Desktop\System Check.lnk


Delete System Check registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" =
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU "MRUList"

Leave a comment

*