Protection System
Protection System Description
Protection System is a rogue anti-spyware application originating from the same family as CoreGuard Antivirus 2009 fake spyware remover. Protection System infiltrates the computer via security vulnerabilities and backdoors provided by affiliated trojans. Once active, Protection System is configured to start automatically, prompting the user to run a fake online scan. When this scan is complete, fabricated infection reports are displayed, usually intimidating the user into purchasing the rogue spyware remover Protection System.
Type: Rogue AntiSpyware Programs
How Can You Detect Protection System?
Protection System Technical Report
As new Protection System details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following Protection System files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| psystem[1].exe | 2514944 | a75dc448bcb618c50c8ad76701228ee4 |
| psystem.exe | 97640 | 180a93e777521710895083a0a22205b6 |
| psystem.exe | 1568768 | efb0890aa991793c26579a3c46e95fcb |
| psystem.exe | 1568768 | d9f2b005920d56abe854aa54a23bc0d6 |
| coreext.dll | 44032 | 1a734c8ed2c02fb06cf4dcf918cf7c0a |
Protection System has typically the following processes in memory:
- %Program Files%\Protection System\firewall.dll
- %Program Files%\Protection System\Protection System.exe
- psystem[1].exe
- %Program Files%\Protection System\CoreExt.dll
- %Program Files%\Protection System\Uninstall.exe
Protection System creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Protection System
- HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
- HKEY_CURRENT_USER\Software\ ProtectionSystem
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Protection System”
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
Protection System 
(1 votes, average: 4.00 out of 5)










