Home Malware Programs Rogue Anti-Spyware Programs Protection Center

Protection Center

Posted: June 2, 2010

Threat Metric

Threat Level: 10/10
Infected PCs: 300
First Seen: June 8, 2010
Last Seen: September 12, 2022
OS(es) Affected: Windows

ScreenshotProtection Center (or ProtectionCenter) is a rogue anti-spyware program designed to con users into purchasing a useless product. Protection Center uses a Trojan to hijack the browser and redirect users to a fake scan page which produces bogus results claiming the PC is infected with malware. The system will be bombarded by popups with fake security alerts urging the user to purchase ProtectionCenter to remove all the alleged threats. The fake security alerts list imaginary threats like Exploit.Win32. Remove Protection Center and any other threat associated to this blatant scam immediately.

Aliases

Mal/TDSSPack-Q [Sophos]Trj/CI.A [Panda]a variant of Win32/Kryptik.EOU [NOD32]Trojan:Win32/FakeCog [Microsoft]Heuristic.LooksLike.Trojan.Dropper.Q [McAfee-GW-Edition]Generic FakeAlert.b [McAfee]Trojan.Win32.Tdss.beea [Kaspersky]W32/FakeAlert.B!tr [Fortinet]Win32.GenHeur.Krypt [eSafe]Trojan.Packed.20389 [DrWeb]Heur.Suspicious [Comodo]Downloader.Zlob.ASMF [AVG]Win32:Jifas-FY [Avast]W32/TDSS.C.gen!Eldorado [Authentium]TR/TDss.beea.58 [AntiVir]
More aliases (32)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



cntext.dll File name: cntext.dll
Size: 48.64 KB (48640 bytes)
MD5: 7e9e79f68cd3d92cb11f4b59ffd11901
Detection count: 62
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: June 11, 2010
asd7.tmp.exe File name: asd7.tmp.exe
Size: 93.18 KB (93184 bytes)
MD5: ffa989047471e02b2539162cafe03ff1
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 11, 2010
%APPDATA%\Protection Center\cntprot.exe File name: cntprot.exe
Size: 1.67 MB (1673728 bytes)
MD5: 1662de7cba76994908e47e8c912148ab
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Protection Center
Group: Malware file
Last Updated: October 27, 2010
cnthook.dll File name: cnthook.dll
Size: 28.16 KB (28160 bytes)
MD5: 99c68fc1f688fce5162e3296c058df60
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 15, 2020
mscdexnt.exe File name: mscdexnt.exe
Size: 417.28 KB (417280 bytes)
MD5: 373223cfa506d708fb694fed4db971bb
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2020

Registry Modifications

The following newly produced Registry Values are:

File name without pathyouporn.com.lnk

Additional Information

The following directories were created:
%ProgramFiles%\Protection Center
The following messages's were detected:
# Message
1Danger!
Unauthorized person tries to steal your passwords and private information. Click on the message to prevent identity theft.

Warning! Virus threat detected!
Virus activity detected!
Email-Worm.BAT adware has been detected. This adware module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click the button below to locate and remove this threat now.

Danger!
Harmful viruses detected on your computer. Click on the message to scan your comp

Related Posts

Loading...