PUP.Optional.SystemKeeperPro is Malwarebytes' detection name for a potentially unwanted program (PUP) that claims to be a system optimizer for Windows systems.
Affected systems will have these icons in their startmenu, taskbar, and on their desktop.
This is the GUI of the program:
Users may notice tooltips like this one:
System optimizers like PUP.Optional.SystemKeeperPro are usually installed by users themselves based on false promises.
Malwarebytes can detect and remove PUP.Optional.SystemKeeperPro without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com-Log Details- Scan Date: 12/12/16 Scan Time: 9:24 AM Logfile: mbamSystemKeeperPro.txt Administrator: Yes-Software Information- Version: 3.0.4.1269 Components Version: 1.0.39 Update Package Version: 1.0.697 License: Premium
-System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username}
-Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 351017 Time Elapsed: 8 min, 36 sec
-Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled
-Scan Details- Process: 1 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SYSTEMKEEPERPRO\SYSTEMKEEPERPRO.EXE, Quarantined, [2748], [351883],1.0.697
Module: 1 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SYSTEMKEEPERPRO\SYSTEMKEEPERPRO.EXE, Quarantined, [2748], [351883],1.0.697
Registry Key: 1 PUP.Optional.SystemKeeperPro, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{742AFBBD-00FF-4811-B38D-004CF0620922}_is1, Delete-on-Reboot, [2748], [351883],1.0.697
Registry Value: 1 PUP.Optional.SystemKeeperPro, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SystemKeeperPro, Delete-on-Reboot, [2748], [351883],1.0.697
Data Stream: 0 (No malicious items detected)
Folder: 4 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SystemKeeperPro, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SystemKeeperProUninst, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SKP, Delete-on-Reboot, [2748], [351890],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\SYSTEMKEEPERPRO, Delete-on-Reboot, [2748], [351882],1.0.697
File: 23 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SYSTEMKEEPERPRO\SYSTEMKEEPERPRO.EXE, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SmartKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\SYSTEMKEEPERPRO.LNK, Delete-on-Reboot, [2749], [351879],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\aff.txt, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\rawlog.txt, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\unins000.dat, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\unins000.exe, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperPro\unins000.msg, Delete-on-Reboot, [2748], [351883],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\botva2.dll, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\CloseBtn.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\glow.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\ico.ico, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\innocallback.dll, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\installer_bg.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\ISSkin.dll, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\ProgressBackground.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\ProgressImg.png, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\Untitled3.cjstyles, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst\wpidmap.dll, Delete-on-Reboot, [2748], [351884],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\APPDATA\ROAMING\SKP\RAWLIST.DAT, Delete-on-Reboot, [2748], [351890],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\DESKTOP\SYSTEMKEEPERPRO.LNK, Delete-on-Reboot, [2748], [351880],1.0.697 PUP.Optional.SystemKeeperPro, C:\USERS\METALLICA\DESKTOP\SYSTEMKEEPERPROINST.EXE, Delete-on-Reboot, [2748], [351887],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemKeeperPro\Get Help.url, Delete-on-Reboot, [2748], [351882],1.0.697 PUP.Optional.SystemKeeperPro, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemKeeperPro\SystemKeeperPro.lnk, Delete-on-Reboot, [2748], [351882],1.0.697
Physical Sector: 0 (No malicious items detected)
(end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
You may see these entries in FRST logs:
() C:\Users\{username}\AppData\Roaming\SystemKeeperPro\SystemKeeperPro.exe HKCU\...\Run: [SystemKeeperPro] => C:\Users\{username}\AppData\Roaming\SystemKeeperPro\SystemKeeperPro.exe [1615840 2016-08-11] () C:\Users\{username}\AppData\Roaming\skp C:\Users\{username}\AppData\Roaming\SystemKeeperPro C:\Users\{username}\Desktop\SystemKeeperPro.lnk C:\Users\{username}\AppData\Roaming\SystemKeeperProUninst C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SystemKeeperProSystemKeeperPro (HKCU\...\{742AFBBD-00FF-4811-B38D-004CF0620922}_is1) (Version: 12.1.0.26 - Monterix, LLC)Alterations made by the installer:
Select your language