Behavior The program must be manually installed
The program reports false or exaggerated system security threats on the computer.
Installation When the program is executed, it creates the following files:
C:\Documents and Settings\Administrator\Start Menu\Programs\[DOUBLE-BYTE CHARACTERS].lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\[DOUBLE-BYTE CHARACTERS].lnk
C:\Program Files\ProtectOn\partner.ini
C:\Program Files\ProtectOn\ProtectOn.exe
C:\Program Files\ProtectOn\ProtectOnMtr.exe
C:\Program Files\ProtectOn\ProtectOnuck.exe
C:\Program Files\ProtectOn\Uninstall.exe
Next, the program creates the following registry entry/ies so that it executes whenever Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"ProtectOn" = "C:\Program Files\ProtectOn\ProtectOn.exe /run1"
The program also creates the following registry entries so that it can be uninstalled:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProtectOn\"DisplayName" = "[DOUBLE-BYTE CHARACTERS]"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProtectOn\"UninstallString" = "C:\Program Files\ProtectOn\Uninstall.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProtectOn\"DisplayIcon" = "C:\Program Files\ProtectOn\Uninstall.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProtectOn\"DisplayVersion" = "1.000"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProtectOn\"INSTDATE" = "20111215"
The program creates the following registry entries to register itself:
- HKEY_LOCAL_MACHINE\SOFTWARE\ProtectOn\pid = "pron116"
- HKEY_LOCAL_MACHINE\SOFTWARE\ProtectOn\"Version" = "1.000"
- HKEY_LOCAL_MACHINE\SOFTWARE\ProtectOn\"UpdateVersion" = "1.000"
- HKEY_LOCAL_MACHINE\SOFTWARE\ProtectOn\"Install_Dir" = "C:\Program Files\ProtectOn"
- HKEY_LOCAL_MACHINE\SOFTWARE\ProtectOn\"Environment" = "11111111111111"