Apr 2, 2009

Remove System Protector - SystemProtector Removal Information

System Protector is new rogue antispyware application which was designed with one purpose – to steal money. Parasite is promoted through the use of Trojan horses that will display fake system warnings on your computer. If you click on that warnings Trojan will secretly download and install System Protector onto your board. Once installed, System Protector will configure itself to run automatically every time you turn on your computer, also it will perform full system scan and list you variety of infections that cannot be removed until you first purchase licensed version. But you must remember that licensed version of System Protector differs nothing from trial one, and have nothing to do with removing any types of infections. In fact System Protector is the only serious infection on your computer and we recommend you to remove it as soon as possible manually or using automatic removal tool.

Type: Rogue Anti-Spyware
Malware Author: Unknown
Threat Level: Critical
Screenshot:



How to remove Spyware Protect 2009 manually:
It's possible to remove System Protector manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

%UserProfile%\Application Data\install.exe
%UserProfile%\Application Data\lsascs.exe
%UserProfile%\Application Data\shellex.dll
%UserProfile%\Application Data\Microsoft\windll32.exe
%UserProfile%\Application Data\SpyProtectorSC_Base_new.dat
%UserProfile%\Application Data\SpyProtectorSC_Config.ini
%UserProfile%\Desktop\System Protector.lnk
%UserProfile%\Start Menu\Programs\System Protector\Purchase License.url
%UserProfile%\Start Menu\Programs\System Protector\Support Page.url
%UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk
C:\Program Files\System Protector
C:\WINDOWS\system32\spyprotector.cpl


Remove registry entries:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" => 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System Protector"


Please be careful because manual removal of System Protector may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

No comments:

/