PUP.Optional.SystemKeeperPro is Malwarebytes’ detection name for a potentially unwanted program (PUP) that claims to be a system optimizer for Windows systems.
Affected systems will have these icons in their startmenu, taskbar, and on their desktop.
This is the GUI of the program:
Users may notice tooltips like this one:
System optimizers like PUP.Optional.SystemKeeperPro are usually installed by users themselves based on false promises.
Malwarebytes protects users from PUP.Optional.SystemKeeperPro by using real-time protection
and by blocking their domain;
Malwarebytes can detect and remove PUP.Optional.SystemKeeperPro without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 12/12/16 Scan Time: 9:24 AM Logfile: mbamSystemKeeperPro.txt Administrator: Yes -Software Information- Version: 3.0.4.1269 Components Version: 1.0.39 Update Package Version: 1.0.697 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 351017 Time Elapsed: 8 min, 36 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 1 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SYSTEMKEEPERPRO\SYSTEMKEEPERPRO.EXE, Quarantined, [2748], [351883],1.0.697 Module: 1 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SYSTEMKEEPERPRO\SYSTEMKEEPERPRO.EXE, Quarantined, [2748], [351883],1.0.697 Registry Key: 1 PUP.Optional.SystemKeeperPro, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{742AFBBD-00FF-4811-B38D-004CF0620922}_is1, Delete-on-Reboot, [2748], [351883],1.0.697 Registry Value: 1 PUP.Optional.SystemKeeperPro, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SystemKeeperPro, Delete-on-Reboot, [2748], [351883],1.0.697 Data Stream: 0 (No malicious items detected) Folder: 4 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SystemKeeperPro, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SystemKeeperProUninst, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SKP, Delete-on-Reboot, [2748], [351890],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SYSTEMKEEPERPRO, Delete-on-Reboot, [2748], [351882],1.0.697 File: 23 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SYSTEMKEEPERPRO\SYSTEMKEEPERPRO.EXE, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SmartKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\SYSTEMKEEPERPRO.LNK, Delete-on-Reboot, [2749], [351879],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\aff.txt, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\rawlog.txt, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\unins000.dat, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\unins000.exe, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\unins000.msg, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\botva2.dll, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\CloseBtn.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\glow.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\ico.ico, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\innocallback.dll, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\installer_bg.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\ISSkin.dll, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\ProgressBackground.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\ProgressImg.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\Untitled3.cjstyles, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\wpidmap.dll, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SKP\RAWLIST.DAT, Delete-on-Reboot, [2748], [351890],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\DESKTOP\SYSTEMKEEPERPRO.LNK, Delete-on-Reboot, [2748], [351880],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\DESKTOP\SYSTEMKEEPERPROINST.EXE, Delete-on-Reboot, [2748], [351887],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemKeeperPro\Get Help.url, Delete-on-Reboot, [2748], [351882],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemKeeperPro\SystemKeeperPro.lnk, Delete-on-Reboot, [2748], [351882],1.0.697 Physical Sector: 0 (No malicious items detected) (end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
The Exclusions tab includes a list of items to be excluded from scans. The items may include files, folders, websites, or applications that connect to the Internet, as well as previously detected exploits.
To access the exclusions in Malwarebytes:
You may see these entries in FRST logs:
() C:\Users\{username}\AppData\Roaming\SystemKeeperPro\SystemKeeperPro.exe HKCU\...\Run: [SystemKeeperPro] => C:\Users\{username}\AppData\Roaming\SystemKeeperPro\SystemKeeperPro.exe [1615840 2016-08-11] () C:\Users\{username}\AppData\Roaming\skp C:\Users\{username}\AppData\Roaming\SystemKeeperPro C:\Users\{username}\Desktop\SystemKeeperPro.lnk C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemKeeperPro SystemKeeperPro (HKCU\...\{742AFBBD-00FF-4811-B38D-004CF0620922}_is1) (Version: 12.1.0.26 - Monterix, LLC)
Alterations made by the installer:
Select your language