How to remove System Protection Tools
Tuesday, May 29th, 2012 at 2:33 amHome » Rogue Antispyware » System Protection Tools
System Protection Tools description
System Protection Tools is as a rogue application. It is designed to resemble Windows Firewall. This way the scammers confuse people into paying for a useless program. If your “Windows Firewall” requires registering System Protection Tools, run a real antimalware program or use the manual removal guide provided beneath this article.
System Protection Tools is able to imitate system errors and antispyware scanner. Do not trust a single notification with System Protection Tools title on it.
Deleting System Protection Tools might be a pesky deal because the fraud may block regular security programs. Use registration code 0W000-000B0-00T00-E0020 to temporarily disable System Protection Tools and then remove the scam without hesitation.
System Protection Tools is a Rogue Antispyware software
How to manually remove System Protection Tools
To remove System Protection Tools spyware you must block System Protection Tools sites, stop and remove processes, unregister DLL files, search and delete all other System Protection Tools files and registry utility. Follow the System Protection Tools detection and removal instructions below.
The most typical software removal method is to remove System Protection Tools by using "Add or Remove Programs" service. However there may be hidden System Protection Tools files, running processes and registries in your computer, so System Protection Tools may recreate all other files after reboot.
System Protection Tools manual removal instructions
Stop and remove System Protection Tools processes:
tempdoc.exe
ScanDisk_.exe
runddlkey.exe
SICKBOY.exe
kernel32.exe
eb.exe
ANTIGEN.exe
cid.exe
SPa76.exe
Read more how to kill System Protection Tools processes
Locate and delete System Protection Tools registry entries:
HKEY_CURRENT_USER\Software\3
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\SPT.DocHostUIHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=7&q={searchTerms}"
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=7&q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "IIL" = 0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "ltHI" = 0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "ltTST"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PRS" = "http://127.0.0.1:27777/?inj=%ORIGINAL%"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "DisallowRun" = 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "0" = "msseces.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "1" = "MSASCui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "2" = "ekrn.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "3" = "egui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "4" = "avgnt.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "5" = "avcenter.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "6" = "avscan.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "7" = "avgfrw.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "8" = "avgui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "9" = "avgtray.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "10" = "avgscanx.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "11" = "avgcfgex.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "12" = "avgemc.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "13" = "avgchsvx.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "14" = "avgcmgr.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "15" = "avgwdsvc.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "System Protection Tools"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe
Read more how to delete System Protection Tools registry entries
Download RegistryBooster 2010 to scan errors caused by System Protection Tools
Search and unregister System Protection Tools DLL libraries:
mozcrt19.dll
sqlite3.dll
Read more how to unregister System Protection Tools DLL files
Detect and delete other System Protection Tools files:
%AppData%\Microsoft\Internet Explorer\Quick Launch\System Protection Tools.lnk
%AppData%\System Protection Tools\
%AppData%\System Protection Tools\cookies.sqlite
%AppData%\System Protection Tools\Instructions.ini
%AppData%\System Protection Tools\ScanDisk_.exe
%CommonAppData%\79b35\
%CommonAppData%\79b35\46.mof
%CommonAppData%\79b35\SPT.ico
%CommonAppData%\79b35\SPa76.exe
%CommonAppData%\79b35\mozcrt19.dll
%CommonAppData%\79b35\sqlite3.dll
%CommonAppData%\79b35\BackUp
%CommonAppData%\79b35\BackUp\Adobe Reader Speed Launch.lnk
%CommonAppData%\79b35\BackUp\Adobe Reader Synchronizer.lnk
%CommonAppData%\79b35\Quarantine Items\
%CommonAppData%\79b35\SPEOGYGUOT\
%CommonAppData%\79b35\SPEOGYGUOT\SPOUGJT.cfg
%CommonAppData%\79b35\TAMPSys\
%UserProfile%\Desktop\System Protection Tools.lnk
%UserProfile%\Recent\ANTIGEN.exe
%UserProfile%\Recent\cid.exe
%UserProfile%\Recent\ddv.tmp
%UserProfile%\Recent\eb.drv
%UserProfile%\Recent\eb.exe
%UserProfile%\Recent\exec.sys
%UserProfile%\Recent\fan.tmp
%UserProfile%\Recent\fix.sys
%UserProfile%\Recent\hymt.drv
%UserProfile%\Recent\hymt.sys
%UserProfile%\Recent\kernel32.drv
%UserProfile%\Recent\kernel32.exe
%UserProfile%\Recent\kernel32.tmp
%UserProfile%\Recent\PE.tmp
%UserProfile%\Recent\runddlkey.exe
%UserProfile%\Recent\SICKBOY.exe
%UserProfile%\Recent\SICKBOY.tmp
%UserProfile%\Recent\tempdoc.exe
%StartMenu%\System Protection Tools.lnk
%StartMenu%\Programs\System Protection Tools.lnk
We strongly recommend you to use spyware remover to track System Protection Tools and automaticaly remove System Protection Tools processes, registries and files as well as other spyware threats.


