|
Free malware removal tool to remove SysProtector
|
|
Written by Administrator |
Saturday, 09 January 2010 17:35
|
|
SysProtector is a fake antivirus which installs itself on your system with or without your will. This fake Antivirus comes from WiniSoft family, they have just changed the name of the application, the file names but the rest is the same. Its purpose is to scare you by posting false scan results so that you spend money on buying a full version which by the way doesn't even exist. Do not purchase this bogus application. Remove SysProtector as soon as possible from your system. Beware of this scam.

To remove SysProtector
- Download and extract this removal tool for SysProtector
- Click on the delete button

SysProtector will be removed in 10s. Restart your computer when it's finished.
Folder
- %CommonPrograms%\SysProtector
- %Temp%\nsa2.tmp
- %ProgramFiles%\SysProtector Software
- %ProgramFiles%\SysProtector Software\SysProtector
Files
- %CommonDesktopDir%\SysProtector.lnk
- %CommonPrograms%\SysProtector\1 SysProtector.lnk
- %CommonPrograms%\SysProtector\2 Homepage.lnk
- %CommonPrograms%\SysProtector\3 Uninstall.lnk
- %Temp%\nsa2.tmp\nsProcess.dll
- %ProgramFiles%\SysProtector Software\SysProtector\SysProtector.exe
- %ProgramFiles%\SysProtector Software\SysProtector\uninstall.exe
- %System%\wbem\Performance\WmiApRpl_new.ini
Registry
Regisytry key created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SysProtector
- HKEY_LOCAL_MACHINE\SOFTWARE\SysProtector
- HKEY_CURRENT_USER\Software\SysProtector
Registry values created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SysProtector
- DisplayName = "SysProtector"
- UninstallString = ""%ProgramFiles%\SysProtector Software\SysProtector\uninstall.exe""
- NoModify = 0x00000001
- NoRepair = 0x00000001
- HKEY_LOCAL_MACHINE\SOFTWARE\SysProtector
- Lang = "English"
- Install_Dir = "%ProgramFiles%\SysProtector Software\SysProtector"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- SysProtector.exe = "%ProgramFiles%\SysProtector software\SysProtector\SysProtector.exe"
- HKEY_CURRENT_USER\Software\SysProtector
- CurrentVersion =
- "771eb5b6f272744584a5567cff88f8a7d17c6bcd7ae..."
- AgentsSettings = 0x00000001

|