Posted: July 6, 2009

Malware Protection 2009 (also known as MalwareProtection2009) is a fake spyware remover that sneaks onto your computer with the aid of trojans, penetrating holes in the security in order to get inside the system without your knowledge or permission. Once active, Malware Protection 2009 begins bombarding your PC with numerous pop-up warning messages and fabricated infection results from counterfeit system scans, all in order to make you believe your computer is infected with various parasites. Malware Protection 2009 prompts you into purchasing and downloading the commercial version in order to combat these non-existent threats. Do not fall for this scheme, and instead delete Malware Protection 2009 as soon as it appears on your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 Database.dat
    2 Malware Protection 2009.lnk
    3 MFC71.dll
    4 MFC71ENU.DLL
    5 msvcr71.dll
    6 Register Malware Protection 2009.lnk
    7 shcev9j0e1b1.exe
    8 Uninstall.exe
    9 Uninstall.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"SMshcev9j0e1b1" = "C:\Program Files\shcev9j0e1b1\shcev9j0e1b1.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Malware Protection 2009"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}shcev9j0e1b1\"DisplayName" = "MProtector"shcev9j0e1b1\"UninstallString" = "C:\Program Files\shcev9j0e1b1\uninstall.exe"

