Home Malware Programs Rogue Anti-Spyware Programs Digital Protection

Digital Protection

Posted: April 12, 2010

Threat Metric

Threat Level: 9/10
Infected PCs: 944
First Seen: April 14, 2010
Last Seen: August 13, 2021
OS(es) Affected: Windows

The rogue anti-malware scanner Digital Protection is a copy of other identical rogue anti-malware products like Your Protection and Dr. Guard. Just like those other rogue anti-malware applications, Digital Protection takes over your computer through registry abuse, uninstalls legitimate security programs and displays scan results and pop-up alerts that are completely fabricated. Refraining from removing Digital Protection is a needless risk that hurts the operation of your computer as well as placing your machine in a state of heightened security risk.

Digital Protection is Only a Protector of Malware

Digital Protection usually infects new computers through Trojans that disguise themselves as legitimate Windows infection alerts. Prompts to install security application will drop Digital Protection on your computer. After being dropped, Digital Protection drops entries in your Windows registry, which lets it run whenever Windows starts without requiring your input or permission.

New desktop shortcuts linked to pornography sites may appear on any computer infected by Digital Protection, but these new shortcuts are just mild annoyances compared to this malware's main attacks. Digital Protection is exceptionally aggressive in countering real PC security programs, and will attempt to uninstall the following applications: Avast!, Agnitum Outpost Security Suite, AntiVir, AVG8, Avira AntiVir, F-Secure, Malwarebytes' Anti-Malware, NOD32 and Norton Internet Security.

Don't Trust the Blips on Digital Protection's Radar

Each time after your computer reboots, Digital Protection will usually simulate a scan for infections. The results will be crammed full of infections your other security programs will not detect, but that's because the infections aren't real! Digital Protection will also display plentiful inaccurate error messages like this:

Danger!
Unauthorized person tries to steal your passwords and private information. Click on the message to prevent identity theft.

A security threat detected on your computer! This malicious program may steal your private data. Click on the message to ensure the protection of your computer.

There is unauthorized anti-virus software detected on your computer. It is recommended you to remove it, otherwise it could conflict with Digital Protection. Press ‘OK’ to remove.

Warning! Network attack detected!
Network intrusion detected!
Your computer is being attacked from a remote PC.
Process is trying to steal your passwords listed below. It is highly recommended to block this threat now.

Warning! Virus threat detected!
Virus activity detected!
Trojan -Clicker.Win32 adware has been detected. This adware module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click the button below to locate and remove this threat now.

Antivirus Alert – Critical threat detected
WARNING
Network attack detected
Network attack has been detected. Process is attempting to access you private data.
IP Address:
Local port:
Alert level: High
Suggestion: It is strongly recommended to block this threat now to prevent privacy data theft.

Paying attention to these messages can only result in harm to your PC, since Digital Protection is very likely to accuse innocent files and programs of being infected. Instead of letting this rogue anti-malware program have its way with your computer, delete Digital Protection so that you can restore all your real security applications back to tip top shape.

Aliases

Mal/FakeAV-CS [Sophos]Trojan:Win32/FakeCog [Microsoft]Heuristic.LooksLike.Trojan.Agent.B [McAfee-GW-Edition]Virus.Win32.Jifas [Ikarus]Win32/DigitalProtection.A [eTrust-Vet]Gen:Variant.TDss.11 [BitDefender]Win32:Jifas-FD [Avast]Virus.Win32.Jifas!IK [a-squared]Mal/Rootkit-Q [Sophos]Suspicious file [Panda]Trojan.Crypt.XPACK.Gen [McAfee-GW-Edition]Suspicious:W32/Malware!Gemini [F-Secure]TR/Crypt.XPACK.Gen [AntiVir]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\diskchk.sys File name: diskchk.sys
Size: 2.3 KB (2304 bytes)
MD5: 0156b39f429336866c9be9589ba1dfbd
Detection count: 504
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32
Group: Malware file
Last Updated: September 15, 2010
%PROGRAMFILES%\Digital Protection\digprot.exe File name: digprot.exe
Size: 1.71 MB (1712128 bytes)
MD5: abbdf5a13bcd37676776cc967505ed57
Detection count: 424
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Digital Protection
Group: Malware file
Last Updated: September 15, 2010
digprot.exe File name: digprot.exe
Size: 1.71 MB (1712128 bytes)
MD5: 1c7ba87cfeb12e222b119ed4e0344862
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 15, 2010
digext.dll File name: digext.dll
Size: 40.96 KB (40960 bytes)
MD5: 2be51fa22423dab08d12d2a5566f61bb
Detection count: 41
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: September 15, 2010

Registry Modifications

The following newly produced Registry Values are:

File name without pathDigital Protection.lnk

Additional Information

The following directories were created:
%ProgramFiles%\Digital Protection
The following messages's were detected:
# Message
1A security threat detected on your computer! This malicious program may steal your private data. Click on the message to ensure the protection of your computer.
2A security threat detected on your computer. TrojanASPX.JS.Win32. It strongly recommended to remove this threat right now. Click on the message to remove it.
3DANGEROUS! ANTIVIRUS DETECTED SOME HARMFUL PROGRAMS ON YOUR PC! THEY MAY CORRUPT YOUR INFORMATION OR SEND IT TO HACKERS.
4Harmful viruses detected on your computer. This malicious software may harm your computer. Click on the message to ensure the protection of your computer.
5System files of your computer are damaged. Please, restart your system ASAP.
6Unauthorized person tries to steal your passwords and private information. Click on the message to prevent identity theft.
7Warning! Virus threat detected!
Virus activity detected!
Trojan-Clicker.Win32 adware has been detected. This adware module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click the button below to locate and remove this threat now.

One Comment

  • Minhas says:

    it wont let me go to task messenger it says task messenger has been disabled by adminastrator PLEASE HELP

Loading...