Home Malware Programs Malware Datprot.exe

Datprot.exe

Posted: May 18, 2010

Datprot.exe is the core malware component of the rogue antispyware program Data Protection. Datprot.exe enters the compromised computer via a malicious Trojan which creates a backdoor on the system. Datprot.exe imitates a system scan and claims that your computer is infected with all sorts of malware and that you should purchase the full version of the program to remove the infections. While datprot.exe is running, it will flood your computer with nag screens, fake security alerts and notifications from your Windows taskbar. Remove Datprot.exe and all other threats associated with the Data Protection cyberscam immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Protection.lnk
    2 %UserProfile%\Desktop\Data Protection Support.lnk
    3 %UserProfile%\Desktop\Data Protection.lnk
    4 %UserProfile%\Start Menu\Programs\Data Protection
    5 %UserProfile%\Start Menu\Programs\Data Protection\About.lnk
    6 %UserProfile%\Start Menu\Programs\Data Protection\Activate.lnk
    7 %UserProfile%\Start Menu\Programs\Data Protection\Buy.lnk
    8 %UserProfile%\Start Menu\Programs\Data Protection\Data Protection Support.lnk
    9 %UserProfile%\Start Menu\Programs\Data Protection\Data Protection.lnk
    10 %UserProfile%\Start Menu\Programs\Data Protection\Scan.lnk
    11 %UserProfile%\Start Menu\Programs\Data Protection\Settings.lnk
    12 %UserProfile%\Start Menu\Programs\Data Protection\Update.lnk
    13 C:\Program Files\Data Protection
    14 C:\Program Files\Data Protection\about.ico
    15 C:\Program Files\Data Protection\activate.ico
    16 C:\Program Files\Data Protection\buy.ico
    17 C:\Program Files\Data Protection\dat.db
    18 C:\Program Files\Data Protection\datext.dll
    19 C:\Program Files\Data Protection\dathook.dll
    20 C:\Program Files\Data Protection\datprot.exe
    21 C:\Program Files\Data Protection\help.ico
    22 C:\Program Files\Data Protection\scan.ico
    23 C:\Program Files\Data Protection\settings.ico
    24 C:\Program Files\Data Protection\splash.mp3
    25 C:\Program Files\Data Protection\uninstall.exe
    26 C:\Program Files\Data Protection\update.ico
    27 C:\Program Files\Data Protection\virus.mp3

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgrHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\data protectionHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr
Loading...