Type: Rogue Anti-Spyware
Malware Author: Unknown
Threat Level: Critical
Screenshot:

How to remove Spyware Protect 2009 manually:
It's possible to remove System Protector manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.
The files to be deleted:
%UserProfile%\Application Data\install.exe
%UserProfile%\Application Data\lsascs.exe
%UserProfile%\Application Data\shellex.dll
%UserProfile%\Application Data\Microsoft\windll32.exe
%UserProfile%\Application Data\SpyProtectorSC_Base_new.dat
%UserProfile%\Application Data\SpyProtectorSC_Config.ini
%UserProfile%\Desktop\System Protector.lnk
%UserProfile%\Start Menu\Programs\System Protector\Purchase License.url
%UserProfile%\Start Menu\Programs\System Protector\Support Page.url
%UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk
C:\Program Files\System Protector
C:\WINDOWS\system32\spyprotector.cpl
Remove registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" => 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System Protector"
Please be careful because manual removal of System Protector may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.
No comments:
Post a Comment