Home Malware Programs Rogue Anti-Spyware Programs BlockProtector

BlockProtector

Posted: November 5, 2009

Threat Metric

Threat Level: 10/10
Infected PCs: 16
First Seen: December 1, 2009
Last Seen: January 10, 2019
OS(es) Affected: Windows

ScreenshotBlockProtector is a fake anti-spyware application from the WiniGuard family of rogues that use devious trojans to do their dirty work on an infected system. The malicious parasite creates additional files on the registry that are detected as threats on PC scans. BlockProtector is configured to start as the infected computer is turned on and will run a scan on the machine to find a list of viruses. BlockProtector will attempt to scare the user by displaying warnings and alerts on the screen. If detected, it is recommended that you take extreme caution and remove BlockProtector immediately.

ScreenshotScreenshotScreenshot

Aliases

Packed.Generic.254 [Symantec]BlockProtector [Sunbelt]Mal/FakeAV-BP [Sophos]Suspicious file [Panda]a variant of Win32/Kryptik.BAC [NOD32]Artemis!2BB2CB3D809A [McAfee+Artemis]TrojWare.Win32.Trojan.FakeAV.~IQ [Comodo]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



setup[1].exe File name: setup[1].exe
Size: 900.09 KB (900096 bytes)
MD5: 2aea8f7d2172905a677140c8ffdad76b
Detection count: 79
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
BlockProtector.exe File name: BlockProtector.exe
Size: 772.6 KB (772608 bytes)
MD5: 2bb2cb3d809a217918a4bfb80cf3ab98
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

Additional Information

The following directories were created:
%ProgramFiles%\BlockProtector Software\BlockProtector
Loading...