"System-Protector" malware/spyware/etc. - Diesel Forum - TheDieselStop.com
Ford Diesel Forum / Powerstroke Forum
Ford Diesel Forum / Powerstroke Forum
Go Back   Diesel Forum - TheDieselStop.com > Other Topics > Other Technical Questions

Other Technical Questions Discussion of other technical topics. Please see the sticky post at the top of the thread listing for specific rules. The rules for this forum are more restrictive than they have been in the past.

TheDieselstop.com is the premier Diesel Truck Forum on the internet. Registered Users do not see the above ads.
Reply
 
LinkBack Thread Tools Display Modes
Old 03-21-2009, 12:54 AM   #1 (permalink)
Senior Member
 
Join Date: Jan 2000
Location: Northern Montana
Posts: 1,547
My Photos: (0)
Feedback Score: 0 reviews
"System-Protector" malware/spyware/etc.

I've got a problem, a bad one. Something called "System Protector", it pops up with a yellow bar across the top of the screen, and is seriously screwing with my computer. Locks me out of task manager, won't let me run Spybot, etc. Does anybody know what it is/how to get rid of it, or know where to go for help? I honestly don't know where it came from, but I'm thinking it came off the wife's Gmail account (it's on her computer, luckily not mine.) Are there any good bulletin boards for stuff like this? Thanks!
Copper is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Advertisement
 
Old 03-21-2009, 02:34 AM   #2 (permalink)
Lifetime Supporting Member
 
johnm's Avatar
 
Join Date: Apr 1999
Location: Holly Hill, Florida, 32117
Posts: 3,849
My Photos: (148)
Feedback Score: 0 reviews
Go To Safe Mode And Run Those Programs. Should Getem

Jm
__________________
100% Disabled Viet Nam Veteran (Agent Orange and its' complications)
SOMETIMES I'M ALL CAPS...BECAUSE OF MY DIABETIC EYE DEGENERATION

Pic under name is record holder high mileage vehicle. 3469.6 MPG. Built by UNLV Mechanical Engineering students.

2009 Mitsubusi Outlander SE - (24 MPG in town)
2004 VW Golf TDI - (42 MPG in town)



click on or cut & paste for forum rules
http://www.thedieselstop.com/forums/...=rula#faq_rulz
johnm is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-24-2009, 12:41 PM   #3 (permalink)
Senior Member
 
WormDrowner's Avatar
 
Join Date: Nov 2002
Location: Houston, Texas
Posts: 686
My Photos: (1)
Feedback Score: 0 reviews
Send a message via ICQ to WormDrowner
It is likely a trojan downloader. You will need to go to a site like Symantec.com or McAfee.com and run an online scan. This should identify the specific virus. You should then follow their instructions carefully to ensure that all the virus is removed. I went through this with my father a year or so back and it was a bear to clean out.
__________________
"You can all go to Hell. I'm going to Texas." - Davy Crockett



1996 F-250 Supercab PSD with Edge Evolution, MBRP 4" exhaust, AFE Stage II Intake. Isspro Gauges.

1996 MB C220
WormDrowner is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-07-2009, 12:39 AM   #4 (permalink)
Senior Member
 
Join Date: Aug 2003
Location: Hernando Beach, FL
Posts: 1,119
My Photos: (0)
Feedback Score: 0 reviews
Malware

The local tech guy in the St Petersburg Times newspaper recommended going to www . malwarebytes. org and downloading their free malware scanner/killer. You will note that this is a non-profit website.

I and numerous others I know have used this and it has, so far, been excellent. The free program runs once, and then you have to manually update/run it when you want to scan. They also sell a program that loads and continually monitors your computer. But programs like this (and Norton) running in the background can slow down your computer a bit... or a lot.

I believe you must have a proper virus checker/firewall system installed, running, and updating automatically to protect yourself. I personally use Norton Internet Security (virus checker and firewall) in combination with a router firewall and Mozilla Firefox as a browser, but stuff has gotten past Norton, Firefox, and the firewall. Malwarebytes cleaned up the stuff that Norton missed.

Just as an aside, I also run two computers (laptop & desktop) with Ubuntu Linux operating system and have never had any virus software or firewalls and have never caught anything on these 2 computers. But you have to be a little 'techie' to run Linux.



Florida Ed
__________________
2011 Suzuki Burgman 650cc Rice Rocket Scooter 49 MPG, 120+ MPH, & 2009 Honda Shadow 750cc 51 MPG, 100+ MPH

2001 7.3 F-350 Dually Lariat CC LWB 4X2 Dark Green 4.10 4R100 5'ver Hauler (32' Montana 2 slides 10,500# - 2,000# tongue weight), 106 gal aux tank, 159K miles, nephews arguing over who will inherit it 'cause I'm gonna' drive it 'til I die. Bone stock.

2001 5.4 Gasser F-250 XLT Crewcab SWB 4X2 3.73 4R100 98K miles headed to 150K stock as the day it was made

Before these: '00 F-250 CC PSD, '97 F-250 CC PSD, '94 Ford F-150, '91 Ford E-250, '81 Ford E-150, '66 Ford F-100 (cars not included)
FloridaEd is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-08-2009, 03:29 PM   #5 (permalink)
Senior Member
 
Join Date: Jul 2001
Location: St. Louis, MO
Posts: 366
My Photos: (3)
Feedback Score: 0 reviews
I'll second the Malwarebytes, stuff. Load it onto a jump drive and run it off of there.
__________________
97 F-250 Crewcab,4X4, 4.10 gears, coolant filter, 203 deg. thermostat, coolant eye, Bilsteins, 255/85R16s.

00 Ural BC-65.

97 Honda Foreman.

"A little rebellion, now and then, is a good thing." Thomas Jefferson
pigdog is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-15-2009, 02:47 AM   #6 (permalink)
Junior Member
 
danrow55's Avatar
 
Join Date: Jul 2009
Posts: 8
My Photos: (0)
Feedback Score: 0 reviews
I use Cyberdefender for my anti-virus protection on my computer. It's also a fee software that scans for trojans, malwares and spywares. You have to upgrade to remove viruses, but the scanning software is free to download. We use this on all our copmuters - it works great.
danrow55 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-15-2009, 06:22 AM   #7 (permalink)
Senior Member
 
Join Date: Jan 2008
Posts: 373
My Photos: (0)
Feedback Score: 0 reviews
System Protector is a rogue anti-spyware application. It is advertised and installed without user's permission through the use of trojan viruses when browsing malicious websites. Usually, these trojan viruses display fake security alerts or similar notifications. System Protector is advertised as security scanner, but the truth is that this parasite only mimics normal anti-spyware programs. The main goal of SystemProtector is to frighten the user and trick money from him.

Once installed, System Protector is configured to start automatically and to scan the infected system. After the scan, System Protector states that user's computer is seriously infected and strongly suggests to purchase a full version of System Protector, because trial version can only detect infections, but is is unable to remove them. Of course, those infections are all fake. System Protector displays the same list of infections on all infected computers. This parasite also has built-in utility that blocks security-related websites. It is highly recommended to remove System Protector from the system as soon as possible, because removal delay can only worsen the situation.

FORUM:
Discuss System Protector in
spyware removal forum

Related files: install.exe, lsascs.exe, shellex.dll, Windll32.exe, SpyProtectorSC_Base_new.dat, SpyProtectorSC_Config.ini, System Protector.lnk, Purchase License.url, Support Page.url, spyprotector.cpl

System Protector properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

System Protector snapshot:
System Protector removal

Automatic System Protector removal:
remover for System Protector
System Protector manual removal:
Kill processes:
install.exe lsascs.exe windll32.exe
HELP:
how to kill malicious processes

Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System "DisableTaskMgr" => 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\Cont extMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D6 3-2EAA-4694-8ABA-EC209C630D83}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shel lex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\App Paths\lsascs.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run "System Protector"
HELP:
how to remove registry entries

Unregister DLLs:
shellex.dll
HELP:
how to unregister malicious DLLs

Delete files:
install.exe lsascs.exe shellex.dll windll32.exe SpyProtectorSC_Base_new.dat SpyProtectorSC_Config.ini System Protector.lnk Purchase License.url Support Page.url spyprotector.cpl
HELP:
how to remove harmful files

Delete directories:
C:\Program Files\System Protector
Other programs to remove System Protector:
• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download
__________________
02 SWB CC 4x4 auto, AIS, DPTunerF5, FTVB, 4" Banks Monster SS Exhaust, HPOXover, AirDog, Amsoil ByPass, Centramatics
blackout is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 07-15-2009, 08:34 PM   #8 (permalink)
Lifetime Supporting Member
Lifetime Supporting Member
 
Join Date: Apr 1999
Location: Westchester, New York
Posts: 602
My Photos: (0)
Feedback Score: 0 reviews
download spyware Doctor and run it to identify and clean them. Then use a GOOD A/V & spyware program such as Vipre from sunbelt software. If you were running McAfee, you might as well have been running nothing at all. I have cleaned 2 machines of this recently and both had McAfee (Useless) . This virus locks out the admin rights also and will not let you load any programs. You will need to use SAFE mode to get the maching back to normal. There are also 2 lines in the registry in the HKLM MICROSOFT SOFTWARE RUN that will look bad. they are .EXE files. delete them .
__________________
2008 F-450 Lariat loaded on order 7/3/07 delivered 9/13/2007 Pueblo Gold and all the goodies except Nav radio and moonroof and Fisher 8'6" X-blade

2005
F-350 Lariat LOADED CC SRW LB 6.0 SOLD
Med. Wedgewood Blue
All Options except moon roof
8'6" Fisher X-blade SS
2003 PSD 6.0 Lariat CC SB SOLD
All options but the moon roof
Scottb NY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Advertisement
 
Reply

  Diesel Forum - TheDieselStop.com > Other Topics > Other Technical Questions


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


» Featured Product
» Log in
User Name:

Password:

Not a member yet?
Register Now!

» Auto Insurance
» Wheel & Tire Center

Powered by vBadvanced CMPS v3.2.2

All times are GMT -5. The time now is 09:47 AM.



Powered by vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2