Home Malware Programs Rogue Anti-Spyware Programs System Protector

System Protector

Posted: March 30, 2009

Threat Metric

Threat Level: 10/10
Infected PCs: 89
First Seen: July 24, 2009
Last Seen: May 15, 2022
OS(es) Affected: Windows

ScreenshotSystem Protector is a fake anti-spyware program that is designed to trick the user into buying their full version of the program by displaying misleading pop-ups and "system alerts," claiming that your machine is infected with malicious software. System Protector may use its system scanner to display false positives which work as an incentive to make unsuspecting users purchase System Protector's commercial version.
Do not click on any link provided by System Protector. Once you click on the link provided, you'll be redirected to System Protector's website to download and purchase System Protector's rogue anti-spyware program. System Protector has the ability to recreate itself after reboot and its "System scan" messages may continue to pop up on your task manager. It is advised to run a scan with a reliable anti-spyware program to check for the presence of System Protector on your computer.

ScreenshotScreenshotScreenshot

Aliases

TROJ_FAKEVIR.CN [TrendMicro]Trojan Horse [Symantec]SpyProtector [Sunbelt]probably a variant of Win32/TrojanDownloader.Agent [NOD32]Trojan.DisableTask.1943040.3 [McAfee-GW-Edition]FakeAlert-DO [McAfee]not-a-virus:FraudTool.Win32.Spyprotector.bg [K7AntiVirus]Misc/FakeAlert [Fortinet]Rogue:W32/AntiSpyware.AP [F-Secure]Trojan.Fakealert.origin [DrWeb]UnclassifiedMalware [Comodo]FraudTool.Spyprotector.bg (Not a Virus) [CAT-QuickHeal]Fake_AntiSpyware.CFX [AVG]Win32:Malware-gen [Avast]W32/FakeAlert.CF.gen!Eldorado [Authentium]
More aliases (69)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



shellex.dll File name: shellex.dll
Size: 159.74 KB (159744 bytes)
MD5: 32b18b7832ab674cb0f5ce64c808706c
Detection count: 90
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
sysprotector_install[1].exe File name: sysprotector_install[1].exe
Size: 26.62 KB (26624 bytes)
MD5: 3818a6ca4e8912c077c527e63c814c7d
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
sysprotector_install[1].exe File name: sysprotector_install[1].exe
Size: 40.96 KB (40960 bytes)
MD5: b53da5469558504015005dd31dc2fb78
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
sysprotector_install_71174136[1].exe File name: sysprotector_install_71174136[1].exe
Size: 26.62 KB (26624 bytes)
MD5: f3550430259981ac278c00c920e24943
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
sys-protector.exe File name: sys-protector.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
System Protector.lnk File name: System Protector.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
dfgfgh.ini File name: dfgfgh.ini
Mime Type: unknown/ini
Group: Malware file
C:\WINDOWS\system32\spyprotector.cpl File name: C:\WINDOWS\system32\spyprotector.cpl
Mime Type: unknown/cpl
Group: Malware file
C:\Program Files\System Protector File name: C:\Program Files\System Protector
Group: Malware file
%UserProfile%\Application Data\lsascs.exe File name: %UserProfile%\Application Data\lsascs.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Application Data\install.exe File name: %UserProfile%\Application Data\install.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Application Data\Microsoft\windll32.exe File name: %UserProfile%\Application Data\Microsoft\windll32.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Application Data\shellex.dll File name: %UserProfile%\Application Data\shellex.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\Desktop\System Protector.lnk File name: %UserProfile%\Desktop\System Protector.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Application Data\SpyProtectorSC_Config.ini File name: %UserProfile%\Application Data\SpyProtectorSC_Config.ini
Mime Type: unknown/ini
Group: Malware file
%UserProfile%\Application Data\SpyProtectorSC_Base_new.dat File name: %UserProfile%\Application Data\SpyProtectorSC_Base_new.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk File name: %UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%UserProfile%\Start Menu\Programs\System Protector\Support Page.url File name: %UserProfile%\Start Menu\Programs\System Protector\Support Page.url
Mime Type: unknown/url
Group: Malware file
%UserProfile%\Start Menu\Programs\System Protector\Purchase License.url File name: %UserProfile%\Start Menu\Programs\System Protector\Purchase License.url
Mime Type: unknown/url
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" => 1HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\System Protector HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "System Protector"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System ProtectorHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System ProtectorHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System ProtectorHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellexHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System Protector"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exe

Additional Information

The following cookies were detected:
system-protector

Related Posts

8 Comments

Loading...