SystemDoctor

It is a Rogue Security Program that purports to scan and detect malware or other problems on the computer, but which attempts to dupe or badger users into purchasing the program by presenting the user with intrusive, deceptive warnings and/or false, misleading scan results. Rogue Security Programs typically use aggressive, deceptive advertising and may be installed without adequate notice and consent, often though exploits. It includes Elevated threats that are typically installed without adequate notice and consent, and may make unwanted changes to our system, such as reconfiguring our browser’s homepage and search settings. These threats may install advertising-related add-ons, including toolbars and search bars, or insert advertising-related components into the Winsock Layered Service Provider chain.0

General information:

Malware Name: SystemDoctor
Malware Type: Rogue Security Program
Company Name: SystemDoctor
Company URL: http://www.systemdoctor.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation.

Company Description:

SystemDoctor starts functioning immediately upon installation, following a quick download. We will hardly notice SystemDoctor as it slightly scans and removes unnecessary files recorded in our drive. By simply installing it, the program will delete all those files that are putting our system stability in risk. SystemDoctor is for users who want to get the most out of their computers. If our PC is our most valuable daily tool, at work or in our own house, we are going to love this solution, because it will keep our drive clean and stable by getting rid of data we don't need to have recorded. SystemDoctor allows users to be in control of the data in their PCs. By simply using this program they can wipe unnecessary files, prevent data loss and keep a clean drive.

Spyware Description:

It is a Rogue Security Program that purports to scan and detect malware or other problems on the computer, but which attempts to dupe or badger users into purchasing the program by presenting the user with intrusive, deceptive warnings and/or false, misleading scan results. Rogue Security Programs typically use aggressive, deceptive advertising and may be installed without adequate notice and consent, often though exploits. It includes Elevated threats that are typically installed without adequate notice and consent, and may make unwanted changes to our system, such as reconfiguring our browser’s homepage and search settings. These threats may install advertising-related add-ons, including toolbars and search bars, or insert advertising-related components into the Winsock Layered Service Provider chain.0

Characteristics/Symptoms:

    -> False positives work as good to purchase -> False scan results -> Uses inadequate scan/detection scheme -> Uses out of date ref database0

Additional information might be found here:

google Search at Google for SystemDoctor
bing Search at Bing for SystemDoctor
yahoo Search at Yahoo for SystemDoctor

Processes Running:

Sd2006.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\All Users\Start Menu\Programs\SystemDoctor 2006 Unregistered Version\Uninstall SystemDoctor 2006.lnk 696 Shortcut
C:\Documents and Settings\sapna\Desktop\SystemDoctor 2006.lnk 672 Shortcut
C:\Program Files\SystemDoctor 2006 Free\updater.dat 283 DAT File

Folder information Created after Installation:

Folder Location
C:\Program Files\SystemDoctor 2006 Free
C:\Program Files\SystemDoctor 2006 Free\SafeMedia

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstallUSDR6_is1 DisplayName
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstallUSDR6_is1 HelpLink
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Run SystemDoctor 2006 Free