We received the file SPROTECTOR.DLL and detected that SPROTECTOR.DLL is not good.
SPROTECTOR.DLL is Adware. You should remove the file SPROTECTOR.DLL.
Kill the process SPROTECTOR.DLL and remove SPROTECTOR.DLL from Windows.
Malware Analysis of SPROTECTOR.DLL
Full path on a computer: %Program Files%\VaudiX\sprotector.dll
Detected by UnHackMe:
SPROTECTOR.DLL
Default location: %Program Files%\VaudiX\sprotector.dll
Removal Results: Success
Number of reboot: 1
SPROTECTOR.DLL is known as:
Adware.SProtector, ADW_SPROTECT, Win32:SProtector-A [PUP], Adware.BGuard.B (B), Adware.BGuard.11, a variant of Win32.SProtector.A
SPROTECTOR.DLL hash:
- MD5: d59fb8a196cc8ad8e8bde0c437070cc6
The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.
How to quickly detect SPROTECTOR.DLL presence?
Registry:
- HKLM\Software\Classes\CLSID\{8E22D34A-B54A-CE43-F969-3152012AEF23}\InprocServer32\: “%Common Appdata%\SearchNewTab\r.dll”
- HKLM\Software\Classes\CLSID\{A686A7F0-E68B-0F1D-9A33-286570998B02}\InprocServer32\: “%Common Appdata%\VuaaUdix\aSEuth4C1.dll”
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1\UninstallString: “”%Program Files%\Optimizer Pro\unins000.exe”"
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\OptimizerPro\UninstallString: “C:\DOCUME~1\ALLUSE~1\APPLIC~1\INSTAL~1\OPTIMI~1\Setup.exe /remove /q0″
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SP_8187691c\UninstallString: “”%Program Files%\VaudiX\uninstall.exe” /FULLPATH=”%Program Files%\VaudiX”"
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SP_b0285714\UninstallString: “”%Program Files%\WebSearch\uninstall.exe” /FULLPATH=”%Program Files%\WebSearch”"
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{681002C6-5019-81A2-7871-A43754F71E56}\UninstallString: “”regsvr32.exe” /s /n /i:”ExecuteCommands;UninstallCommands” “%Common Appdata%\VuaaUdix\0f5UBEyma.dll”"
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6BC806A1-CC1D-D9FE-2202-20A27E7661A0}\UninstallString: “C:\DOCUME~1\ALLUSE~1\APPLIC~1\INSTAL~1\{58498~1\Setup.exe /remove /q0″
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}\UninstallString: “”regsvr32.exe” /s /n /i:”ExecuteCommands;UninstallCommands” “%Common Appdata%\SearchNewTab\k.dll”"
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Optimizer Pro: “%Program Files%\Optimizer Pro\OptProLauncher.exe”
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs: “c:\progra~1\vaudix\sprote~1.dll c:\progra~1\websea~1\sprote~1.dll”
Folders:
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\4-hqettgs@eu-fqec.co.uk
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\4-hqettgs@eu-fqec.co.uk\content
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\tgti.m8m@qo-xxooxk.co.uk
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\tgti.m8m@qo-xxooxk.co.uk\content
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\searchplugins
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\inhijklbadahameeeaiacbhkdbhnailk
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\inhijklbadahameeeaiacbhkdbhnailk\1.3
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn\1.0
- %Common Appdata%\BetterSoft
- %Common Appdata%\BetterSoft\OptimizerPro
- %Common Appdata%\InstallMate
- %Common Appdata%\InstallMate\OptimizerPro
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}
- %Common Appdata%\SearchNewTab
- %Common Appdata%\StarApp
- %Common Appdata%\StarApp\Setup
- %Common Appdata%\VuaaUdix
- %Common Startmenu%\Programs\Optimizer Pro
- %Program Files%\Optimizer Pro
- %Program Files%\VaudiX
- %Program Files%\WebSearch
Files:
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\4-hqettgs@eu-fqec.co.uk\bootstrap.js
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\4-hqettgs@eu-fqec.co.uk\chrome.manifest
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\4-hqettgs@eu-fqec.co.uk\content\bg.js
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\4-hqettgs@eu-fqec.co.uk\install.rdf
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\tgti.m8m@qo-xxooxk.co.uk\bootstrap.js
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\tgti.m8m@qo-xxooxk.co.uk\chrome.manifest
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\tgti.m8m@qo-xxooxk.co.uk\content\bg.js
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\extensions\staged\tgti.m8m@qo-xxooxk.co.uk\install.rdf
- %Appdata%\Mozilla\Firefox\Profiles\profile.default\searchplugins\WebSearch.xml
- %Desktop%\Optimizer Pro.lnk
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\inhijklbadahameeeaiacbhkdbhnailk\1.3\67hdCklt2d.js
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\inhijklbadahameeeaiacbhkdbhnailk\1.3\background.html
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\inhijklbadahameeeaiacbhkdbhnailk\1.3\content.js
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\inhijklbadahameeeaiacbhkdbhnailk\1.3\lsdb.js
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\inhijklbadahameeeaiacbhkdbhnailk\1.3\manifest.json
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\inhijklbadahameeeaiacbhkdbhnailk\1.3\sqlite.js
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn\1.0\background.html
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn\1.0\content.js
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn\1.0\lsdb.js
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn\1.0\manifest.json
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn\1.0\newtab.html
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn\1.0\sqlite.js
- %Local Appdata%\Google\Chrome\User Data\Default\Extensions\iofkbndbipkjmabaopipefbgfhkmjpgn\1.0\xb.js
- %Common Appdata%\BetterSoft\OptimizerPro\1173230912.ini
- %Common Appdata%\BetterSoft\OptimizerPro\OptimizerPro.exe
- %Common Appdata%\InstallMate\OptimizerPro\Custom.dll
- %Common Appdata%\InstallMate\OptimizerPro\Readme.txt
- %Common Appdata%\InstallMate\OptimizerPro\Setup.dat
- %Common Appdata%\InstallMate\OptimizerPro\Setup.exe
- %Common Appdata%\InstallMate\OptimizerPro\Setup.ico
- %Common Appdata%\InstallMate\OptimizerPro\TsuDll.dll
- %Common Appdata%\InstallMate\OptimizerPro\_Setup.dll
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}\20130809152349.log
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}\Custom.dll
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}\Readme.txt
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}\Setup.dat
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}\Setup.exe
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}\Setup.ico
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}\TsuDll.dll
- %Common Appdata%\InstallMate\{584989FA-5D5B-4875-AA9E-157983AAAB0C}\_Setup.dll
- %Common Appdata%\SearchNewTab\k.dll
- %Common Appdata%\SearchNewTab\r.dll
- %Common Appdata%\SearchNewTab\r.tlb
- %Common Appdata%\SearchNewTab\settings.ini
- %Common Appdata%\VuaaUdix\0f5UBEyma.dll
- %Common Appdata%\VuaaUdix\aSEuth4C1.dll
- %Common Appdata%\VuaaUdix\aSEuth4C1.tlb
- %Common Appdata%\VuaaUdix\settings.ini
- %Common Startmenu%\Programs\Optimizer Pro\Help.lnk
- %Common Startmenu%\Programs\Optimizer Pro\Optimizer Pro on the Web.lnk
- %Common Startmenu%\Programs\Optimizer Pro\Optimizer Pro.lnk
- %Common Startmenu%\Programs\Optimizer Pro\Uninstall Optimizer Pro.lnk
- %Program Files%\Optimizer Pro\English.ini
- %Program Files%\Optimizer Pro\file_id.diz
- %Program Files%\Optimizer Pro\HomePage.url
- %Program Files%\Optimizer Pro\OptimizerPro.chm
- %Program Files%\Optimizer Pro\OptimizerPro.exe
- %Program Files%\Optimizer Pro\OptProGuard.exe
- %Program Files%\Optimizer Pro\OptProLauncher.exe
- %Program Files%\Optimizer Pro\OptProReminder.exe
- %Program Files%\Optimizer Pro\OptProSchedule.exe
- %Program Files%\Optimizer Pro\OptProSmartScan.exe
- %Program Files%\Optimizer Pro\OptProStart.exe
- %Program Files%\Optimizer Pro\OptProUninstaller.exe
- %Program Files%\Optimizer Pro\scan.gif
- %Program Files%\Optimizer Pro\sqlite3.dll
- %Program Files%\Optimizer Pro\unins000.dat
- %Program Files%\Optimizer Pro\unins000.exe
- %Program Files%\Optimizer Pro\unins000.msg
- %Program Files%\VaudiX\sprotector.dll
- %Program Files%\VaudiX\uninstall.exe
- %Program Files%\WebSearch\sprotector.dll
- %Program Files%\WebSearch\uninstall.exe
- %WinDir%\Tasks\schedule!1173230912.job