System Protection Tools

Threat Scorecard

Ranking: 1,647
Threat Level: 100 % (High)
Infected Computers: 25,288
First Seen: May 23, 2012
Last Seen: September 20, 2023
OS(es) Affected: Windows

System Protection Tools is a fake security program that is projected to embezzle money from inexperienced computer users. Despite its name, System Protection Tools does not provide protection for your computer system. Quite the opposite, System Protection Tools is part of a coordinated multi-component malware attack created to cause issues on your computer, so you will be convinced you that you need to register – and, of course, pay – for a useless 'full version' of this bogus security product. ESG security researchers consider System Protection Tools an important threat that should be removed immediately with a reliable anti-malware program.

System Protection Tools is Part of a Common Online Scam

System Protection Tools' interface is a blatant copy of popular security programs on the market. The main goal of System Protection Tools is to convince the victim that System Protection Tools is a real security program. To do this, System Protection Tools uses a highly-convincing interface, has websites that market System Protection Tools as a legitimate security application, and runs a fake system scan. However, this system scan will always indicate that the victim's computer is severely infected with malware. System Protection Tools will also display fake security alerts and error messages in order to scare the victim further. Taking these error messages seriously, inexperienced computer users may fall for System Protection Tools' scam and purchase a useless 'upgrade' in order to fix these nonexistent malware problems.

System Protection Tools is simply a newer version of previously released fake security programs from the FakeVimes like Virus Melt, Presto TuneUp, Fast Antivirus 2009, Extra Antivirus, Windows Security Suite, Smart Virus Eliminator, Packed.Generic.245, Volcano Security Suite, Windows Enterprise Suite, Enterprise Suite, Additional Guard, PC Live Guard, Live PC Care, Live Enterprise Suite, Security Antivirus, My Security Wall, CleanUp Antivirus, Smart Security, Windows Protection Suite, Windows Work Catalyst. Essentially, System Protection Tools is the same program as these and many others with a new name and interface.

Dealing with a System Protection Tools Infection

ESG security analysts energetically advise against buying this program's fake full version, even if it is only because you wish to stop its fake error messages and irritating symptoms. Even though you will still need to remove System Protection Tools with a real security tool, you can stop many of this fake security program's irritating error messages with one of the following two registration codes: U2FD-S2LA-H4KA-UEPB or K7LY-R5GU-SI9D-EVFB. However, it is definitely not advisable to let System Protection Tools remain on your computer system. This fake security program will rarely attack alone and will usually indicate the presence of other Trojans and, possibly, rootkits on the infected computer system. System Protection Tools can also make your computer system more vulnerable to other attacks, compromising your personal data and the integrity of other computers that may come into contact with yours.

File System Details

System Protection Tools may create the following file(s):
# File Name Detections
1. %UserProfile%\Start Menu\Programs\System Protection Tools.lnk
2. %AppData%\Microsoft\Internet Explorer\Quick Launch\System Protection Tools.lnk
3. %UserProfile\%Start Menu\System Protection Tools
4. %AppData%\System Protection Tools
5. %UserProfile\%Desktop\System Protection Tools
6. %AllUsersProfile\%Application Data\[RANDOM CHARACTERS][RANDOM CHARACTERS]

Registry Details

System Protection Tools may create the following registry entry or registry entries:
CLSID
{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Disallow\Run [1...15]
HKEY....{Value}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Disallow\Run = 01000000
HKEY_LOCAL_MACHINE\Software\Microsoft..{RunKeys}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Best Antivirus Software = "%AllUsersProfile%Application Data[RANDOM CHARACTERS][RANDOM CHARACTERS].exe" /s /d
HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options[RANDOM CHARACTERS].exeDebugger = svchost.exe

Messages

The following messages associated with System Protection Tools were found:

System alert
Suspicious software which may be dangerous has been
detected on your PC. Click here to remove this threat
immediately using System Protection Tools.
System alert
System Protection Tools has detected potentially harmful software in
your system. It is strongly recommended that you register
System Protection Tools to remove all found threats immediately.
System warning
No real-time malware, spyware and virus protection was
found. Click here to activate.
Warning
Warning! Virus detected
Warning! Identity theft attempt detected
Hidden connection IP: 128.154.26.11
Target: Microsoft Corporation keys

Trending

Most Viewed

Loading...