System Protector

By GoldSparrow in Rogue Anti-Spyware Program | 1,056 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...
More... More

System Protector Description

Image Screenshot

[+] Click Image to Enlarge

System Protector, or SystemProtector, is a rogue anti-spyware program designed to trick users into believing it’s a legitimate anti-spyware program.

System Protector may be installed in the user’s computer system by a Trojan, such as Zlob, through a rogue video codec download or the user may have downloaded it from a rogue website. Once Zlob is installed, the user will receive a large amount of fake notification messages stating that his/her computer is infested with spyware. In order to remove these threats, the user will be redirected to a fraudulent website to further purchase System Protector’s full version. System Protector is also able to emulate a computer system scan. After System Protector’s scanner is launched, the user will receive a list of spyware infections supposedly found in his/her computer system as a result.

System Protector may be configured to run on every Windows startup. System Protector may also cause computer system’s performance to decrease.

Type: Rogue AntiSpyware Programs

How Can You Detect System Protector?

System Protector Technical Report

As new System Protector details are reported by our customers and findings from our Threat Research Center, we will update this section.

The following System Protector files with its MD5s were created in the system:

File Name File Size MD5
lsascs.exe 1943040 83651530f4cf55168524e5e28c9d3c2a
sysprotector_install[1].exe 40960 b53da5469558504015005dd31dc2fb78
install[1].exe 1312706 da0a130cca9faa4e031f5cdf4128103e
shellex.dll 159744 32b18b7832ab674cb0f5ce64c808706c
sysprotector_install_71174136[1].exe 26624 f3550430259981ac278c00c920e24943
shellex.dll 159744 fddfcdabbdcee22f4a5bc714ae3523ec
sysprotector_install[1].exe 26624 3818a6ca4e8912c077c527e63c814c7d
lsascs.exe 1943040 686aae04c8fea3f414692c1f48788808

‘How System Protector Infects Your Computer’ Video

System Protector Removal Details

System Protector has typically the following processes in memory:

  • %UserProfile%\Application Data\lsascs.exe
  • %UserProfile%\Application Data\shellex.dll
  • sysprotector_install[1].exe
  • %UserProfile%\Application Data\Microsoft\windll32.exe
  • sys-protector.exe
  • %UserProfile%\Application Data\install.exe

System Protector creates the following files in the system:

  • C:\WINDOWS\system32\spyprotector.cpl
  • %UserProfile%\Application Data\SpyProtectorSC_Config.ini
  • %UserProfile%\Start Menu\Programs\System Protector\Support Page.url
  • System Protector.lnk
  • %UserProfile%\Desktop\System Protector.lnk
  • %UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk
  • dfgfgh.ini
  • C:\Program Files\System Protector
  • %UserProfile%\Application Data\SpyProtectorSC_Base_new.dat
  • %UserProfile%\Start Menu\Programs\System Protector\Purchase License.url

System Protector created the following directories, files, paths:

  • %UserProfile%\Start Menu\Programs\System Protector
  • %ProgramFiles%\System Protector

System Protector creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” => 1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System Protector
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System Protector
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\System Protector
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System Protector
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “System Protector”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “System Protector”

Important Article Disclaimer

ESG Support Center

This entry was last updated on 06/29/09 and posted on 03/29/09. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

One Response to “System Protector”

  1. jamie Says:

    These scams sucks! Thank you guys for saving me before I have bought this “protector” thing.

    [Reply]

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.