Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Information Stealer
- Rootkit
- Cloaked Malware
- Worm
File Behavior
PROTECT.DLL has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Uses rootkit techniques to conceal its presence, interrogation or removal
- Uses low level functions to hide itself from the user and from system/security processes
- Found on infected systems and resists interrogation by security products
- This Process is a file infector which modifies program files to include a copy of the infection
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Creates new file extentions so that Internet Explorer will automatically open and potentially execute additional file types
- Creates a Toolbar Extension for Internet Explorer
- Creation and Registers a Browser Helper Object in Internet Explorer
- Registers a Dynamic Link Library File
PROTECT.DLL has been the subject of the following behavior:
- Created as a process on disk
- Registered as a Dynamic Link Library File
- Deleted as a process from disk
- Added as a Registry auto start to load Program on Boot up
- Added as a Link in the Start Menu
- The process is hooked into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Executed as a Process
- Deleted as a Link in the Start Menu
Country Of Origin
The filename PROTECT.DLL was first seen on May 9 2007 in the following geographical regions of the Webroot community:
- Spain on May 9 2007
- The United States on May 9 2007
- Czech Republic on Dec 8 2007
- Ukraine on Mar 13 2008
- Denmark on May 7 2008
- Germany on Sep 16 2008
- Canada on Jan 16 2009
- France on Feb 10 2012
File Name Aliases
PROTECT.DLL can also use the following file names:
- NER73C5788B.DLL
- VBRA199.DLL
- MSB.DLL
- AUTOCHK.DLL
- CHKDISK.DLL
- PROTECT (n).DLL
- MS.DLL
- 60836855.DLL
- 28816173.DLL
- 18839891.DLL
Filesizes
The following file size has been seen:
- 2,044,328 bytes
- 68,096 bytes
- 4,584,296 bytes
- 22,016 bytes
- 107,008 bytes
- 18,425,736 bytes
- 23,552 bytes
- 49,152 bytes
- 21,504 bytes
File Type
The filename PROTECT.DLL is used by multiple object types including Dynamic Link LIbraries,objects.
File Activity
One or more files with the name PROTECT.DLL creates, deletes, copies or moves the following files and folders:
- Deletes c:\documents and settings\user\start menu\programs\startup\ChkDisk.lnk
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.