Home Malware Programs Rogue Anti-Spyware Programs Desktop Protector 2010

Desktop Protector 2010

Posted: January 5, 2010

Desktop Protector 2010 is rogue anti-spyware program and variant of the Desktop Defender 2010 rogue security program. When installed Desktop Protector 2010 automatically runs with Windows by altering the registry and creating its own values. Desktop Protector 2010 deceives computer users with fake security scans and annoying pop-ups, which warn that several system files have been infected and a purchase of the Desktop Protector 2010 is needed for virus removal. Desktop Protector 2010 should not be trusted or purchased, instead have this rogue removed immediately using a reliable anti-spyware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Desktop Protector 2010.lnk
    2 c:\Documents and Settings\All Users\Desktop\Desktop Protector 2010.lnk
    3 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Protector 2010
    4 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Protector 2010.lnk
    5 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Protector 2010\Activate Desktop Protector 2010.lnk
    6 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Protector 2010\Desktop Protector 2010.lnk
    7 c:\Documents and Settings\All Users\Start Menu\Programs\Desktop Protector 2010\How to Activate Desktop Protector 2010.lnk
    8 c:\Program Files\Desktop Protector 2010
    9 c:\Program Files\Desktop Protector 2010\AF.dll
    10 c:\Program Files\Desktop Protector 2010\daily.cvd
    11 c:\Program Files\Desktop Protector 2010\Desktop Protector 2010.exe
    12 c:\Program Files\Desktop Protector 2010\guide.chm
    13 c:\Program Files\Desktop Protector 2010\hjengine.dll
    14 c:\Program Files\Desktop Protector 2010\IEAddon.dll
    15 c:\Program Files\Desktop Protector 2010\MFC71.dll
    16 c:\Program Files\Desktop Protector 2010\MFC71ENU.DLL
    17 c:\Program Files\Desktop Protector 2010\msvcp71.dll
    18 c:\Program Files\Desktop Protector 2010\msvcr71.dll
    19 c:\Program Files\Desktop Protector 2010\MyTaskMgrDll.dll
    20 c:\Program Files\Desktop Protector 2010\pthreadVC2.dll
    21 c:\Program Files\Desktop Protector 2010\shellext.dll
    22 c:\Program Files\Desktop Protector 2010\siglsp.dll
    23 c:\Program Files\Desktop Protector 2010\tdifw_drv_WLH.sys
    24 c:\Program Files\Desktop Protector 2010\tdifw_drv_WXP.sys
    25 c:\Program Files\Desktop Protector 2010\uninstall.exe
    26 c:\WINDOWS\system32\[random]
    27 c:\WINDOWS\system32\tdidis32.sys

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "C:\Program Files\Desktop Protector 2010\Desktop Protector 2010.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Desktop Protector 2010HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform "Desktop Protector 2010"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AppID\IEAddon.DLLHKEY_CLASSES_ROOT\AppID\{C0E56AC2-9F72-436E-B6E7-AEC28AF9E4EB}HKEY_CLASSES_ROOT\CLSID\{08EEC6AD-7486-487F-89B7-5A3716DDAE14}HKEY_CLASSES_ROOT\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\antivirus_contextscanHKEY_CLASSES_ROOT\Drives\shellex\ContextMenuHandlers\antivirus_contextscanHKEY_CLASSES_ROOT\IEAddon.StatusBarPaneHKEY_CLASSES_ROOT\IEAddon.StatusBarPane.1HKEY_CLASSES_ROOT\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}HKEY_CLASSES_ROOT\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}HKEY_CLASSES_ROOT\shellex\ContextMenuHandlers\antivirus_contextscanHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\tdidis32.sysHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDIDIS32.SYSHKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TDIDIS32.SYSHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tdidis32.sysHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDIDIS32.SYSHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDIDIS32.sysHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdifw_drvHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Desktop Protector 2010"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run ""HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Desktop Protector 2010
Loading...