Remove “Google has detected??¦” web page
. Removal instructions
“Google has detectedâ?¦” web page is a fake notification generated by rogue anti-spyware called System Protector. Mainly, it states that user’s computer is not properly protected and suggests to buy a full version of System Protector. “Google has detectedâ?¦” fake web page reads:
“Google has detected that you are using the unregistered copy of System Protector. System Protector is recommended by Google for the best Web surfer safety level. Register Now and get the max level secure browsing!”
Firstly, Google usually doesn’t promote any software, especially on the Google search web page. Secondly, if user clicks on “Register Now and get the max level secure browsing!” link, he will automatically download System Protector. It is highly recommended to ignore such disinformation and to remove “Google has detectedâ?¦” infection from the system.
Related files: spyprotector.cpl, System Protector.lnk, Support Page.url, Purchase License.url, SpyProtectorSC_Config.ini, SpyProtectorSC_Base_new.dat
“Google has detected??¦” web page properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background
“Google has detected??¦” web page snapshot:
Automatic “Google has detected??¦” web page removal:
(2012-03-20 20:59:28)
(2012-03-20 20:59:28)
(2012-03-20 20:59:28)
“Google has detected??¦” web page manual removal:
Kill processes:
install.exe lsascs.exe windll32.exe
how to kill malicious processes
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System ???DisableTaskMgr??? => 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Pathssascs.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ???System Protector???
how to unregister malicious DLLs
Delete files:
SpyProtectorSC_Base_new.dat SpyProtectorSC_Config.ini Purchase License.url Support Page.url System Protector.lnk spyprotector.cpl
how to remove harmful files
Delete directories:
C:\Program Files\System Protector
Information updated: 2012-03-20 18:22:13