Advanced System Protector is a potentially unwanted program that often is installed with several other low-level forms of PC threats. Although Advanced System Protector doesn’t block you from using many other programs, Advanced System Protector sometimes may interfere with competing anti-virus products and, on occasion, may detect false positives (fake infection alerts that point to harmless files). malware experts certainly can’t think of any reason why you’d want to do anything but remove Advanced System Protector with a real anti-malware product, and additionally warn that Advanced System Protector usually is installed without your permission – along with various other types of petty malware.

Advanced System Protector: ‘Protecting’ Your Computer Even If You’d Rather Do Without It

Advanced System Protector may be distributed by questionable actions, including being silently installed through generic software bundles and, most interestingly, being installed automatically whenever the PC user tries to install a separate brand of anti-malware software. While Advanced System Protector usually is installed without any permission, its presence becomes immediately evident – since Advanced System Protector will launch and appear to start scanning your PC for malware.

Advanced System Protector is more subtle than most potentially unwanted programs, with system scans that don’t always detect large numbers of fake infections.

In fact, some of Advanced System Protector’s scans only will detect a limited number of legitimate PC threats – such as the ones that are installed with Advanced System Protector. Because of this relatively circumspect behavior, Advanced System Protector is not always readily identifiable as scamware and may very easily be mistaken for just a legitimate product that’s installed through illegitimate methods. However, a prolonged examination of Advanced System Protector’s ‘features’ allowed malware experts to confirm that Advanced System Protector does display fake results occasionally, along with a very restricted set of legitimate scan results.

The Simple Way to Beat an Advanced Digital Con

Consistent with its overall trend towards a ‘lighter’ form of hoax, Advanced System Protector does not indulge in any widespread software-blocking attacks, which other scamware families like FakeRean or WinWebSec have been known for utilizing. malware experts have, nonetheless, seen some scenarios where Advanced System Protector attempted to block some specific security programs, including a number of real anti-malware products. This classifies Advanced System Protector as a danger to your computer’s security as well as a fraud, and removing Advanced System Protector, therefore, always should be high on your priority list.

Advanced System Protector maintains itself as a background process and, as would be expected, resists being terminated and being deleted by all of the usual means. To make deleting Advanced System Protector as simple as possible, malware researchers suggest restarting your PC in Safe Mode and then using anti-malware software to remove Advanced System Protector during a thorough anti-malware scan. Keep in mind that Advanced System Protector has been seen in the company of both low and high-level PC threats that can complicate the process of Advanced System Protector’s removal or create other security problems.

Technical Details

File System Modifications

  • The following files were created in the system:
    # File Name Detection Count
    1 %PROGRAMFILES%\ System Speedup\ SystemSpeedup.exe 12,027
    2 %ALLUSERSPROFILE%\Application Data\Microsoft\Windows\Start Menu\Programs\Advanced System Protector 222
    3 %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Advanced System Protector 219
    4 %WINDIR%\System32\Tasks\Advanced-System Protector_startup 200
    5 Advanced System Protector.lnk 144
    6 %ALLUSERSPROFILE%\Systweak\Advanced System Protector 112
    7 %USERPROFILE%\Microsoft\Windows\Start Menu\Programs\Advanced System Protector 109
    8 %APPDATA%\Microsoft\Windows\Start Menu\Programs\Advanced System Protector 106
    9 %APPDATA%\Advanced System Protector 103
    10 %PROGRAMFILES(x86)%\Advanced System Protector 100

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~4A5BE654_is1HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{21ACC95A-E98B-4294-83EC-4B6FDBD7E02C}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21ACC95A-E98B-4294-83EC-4B6FDBD7E02C}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36223E3C-084E-4BDA-88B1-4BAE95BCDAD5}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB570358-C1F8-4700-B442-6D35190CCEB4}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEFCA33F-9007-493E-AFEB-502B526A3043}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced System ProtectorSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced System Protector_startupSOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1SOFTWARE\Wow6432Node\Systweak\Advanced System ProtectorUnknown\shell\openas\command, value: Advanced System Protector.bak
