Threat Database Rogue Websites System-protector.org

System-protector.org

System-protector.org is a browser hijacker promoting the rogue anti-spyware program called System Protector. Through trojans that infiltrate your computer through security exploits and alter your browser settings, you will discover your web-surfing activities becoming interrupted and redirected to the System-protector.org domain. Here your computer is subject to a fraudulent online scan that displays numerous false infection reports, as well as aggressive advertising schemes, all in order to persuade you to purchase and install System Protector.

File System Details

System-protector.org may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\shellex.dll
2. %UserProfile%\Application Data\lsascs.exe
3. %UserProfile%\Application Data\install.exe
4. %UserProfile%\Application Data\Microsoft\windll32.exe
5. %UserProfile%\Desktop\System Protector.lnk
6. %UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk
7. %UserProfile%\Application Data\SpyProtectorSC_Config.ini
8. %UserProfile%\Start Menu\Programs\System Protector\Support Page.url
9. %WINDOWS%\system32\spyprotector.cpl
10. %UserProfile%\Application Data\SpyProtectorSC_Base_new.dat
11. %UserProfile%\Start Menu\Programs\System Protector\Purchase License.url
12. %Program Files%\System Protector

Registry Details

System-protector.org may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System Protector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" => 1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System Protector

Trending

Most Viewed

Loading...