AdvancedSystemProtector.exe
Advanced System Protector by Systweak Inc (Signed)
Warning 4 antivirus scanners has detected malware in various versions of AdvancedSystemProtector.exe.
Overview
There are 6 versions of advancedsystemprotector.exe in the wild, the latest version being 2.1.1000.10158. advancedsystemprotector.exe is run as a standard windows process with the logged in user's account privileges. By adding a startup entry to the run registry key, the file will be executed when the user logs into Windows. In addition the the run registry key, it also creates a scheduled job to be executed by the Windows Task Scheduler up user login, this is typically done in order to bypass a User Account Control (UAC) prompt. The average file size is about 5.95 MB. The file is a digitally signed and issued to Systweak Inc by VeriSign. Some variations of the file have been seen to be installed with the program Advanced System Protector from Systweak Inc. The executable is a .NET framework assembly utilizing the CLR. During the process's lifecycle, the typical CPU resource utilization is less than 0.01%, the average private memory consumption is about 78.63 MB. Addionally, typically read and write I/O disk operations is about 97.12 KB per minute for reads and 53.35 KB per minute for writes.
What is advancedsystemprotector.exe?
advancedsystemprotector.exe is the core UI and partial engine of Advanced System Protector, an antivirus product. Advanced System Protector is a software application designed to find and remove malware infections and also provides protection shields against virus and spyware threats.
About advancedsystemprotector.exe (from Systweak Inc)
“Advanced System Protector is an effective solution to find and remove malware infections present on your PC. It also provides protection shields against malware threats.”
Details |
File name: | advancedsystemprotector.exe |
Publisher: | Systweak |
Product name: | Advanced System Protector |
Typical file path: | C:\Program Files\advanced system protector\advancedsystemprotector.exe |
Certificate |
Issued to: | Systweak Inc |
Authority (CA): | VeriSign |
Expiration date: | Sunday, March 10, 2013 |
Programs installed in
(Note, the programs listed below are for all versions of Advanced System Protector.)
“Advanced System Protector is a solution to detect and remove the malicious programs intruding your computer. It offers protection against deceptive applications that affect start-up programs, cookies,...”
Behaviors
(Note, the behaviors below are for all versions of advancedsystemprotector.exe, select a unique version for details.)
Scheduled tasks
- The job 'Advanced System Protector_startup' runs on logon in the path '\Advanced System Protector_startup'
- Entry path '\Advanced System Protector_startup'
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Advanced System Protector' → "C:\Program Files\Advanced System Protector\advancedsystemprotector.exe" autolaunch
- 'Advanced System Protector_startup' → "C:\Program Files\Advanced System Protector\AdvancedSystemProtector.exe" autolaunch
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
- Login entry path '\Advanced System Protector_startup'
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Advanced System Protector' → "C:\Program Files\Advanced System Protector\advancedsystemprotector.exe" autolaunch
Malware detections
Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engine | Engine version | Detection | File version |
Clam AntiVirus |
0.97.3.0 |
PUA.Win32.Packer.NetExecutable-1 |
2.1.1.77 |
Comodo Internet Security |
16507 |
UnclassifiedMalware |
2.1.1000.9467 |
ESET NOD32 |
7.8498 |
a variant of MSIL/AdvancedSystemProtector.A |
2.1.1000.9467 |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.F47V0627 |
2.1.1000.9467 |
All file variations of advancedsystemprotector.exe
Distribution by Windows OS
OS version | distribution |
Microsoft Windows XP |
25.00% |
|
Windows 7 Home Premium |
25.00% |
|
Windows 7 Ultimate N |
18.75% |
|
Windows 7 Professional |
12.50% |
|
Windows 7 Ultimate |
6.25% |
|
Windows Vista Home Premium |
6.25% |
|
Windows 8 Pro |
6.25% |
|
Distribution by country
Japan installs about 16.00% of Advanced System Protector.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Lenovo |
44.44% |
|
Acer |
22.22% |
|
Samsung |
22.22% |
|
Hewlett-Packard |
11.11% |
|