webprotect.dll - Dangerous

webprotect.dll

Manual removal instructions:

Antivirus Report of webprotect.dll:
webprotect.dll Malware
webprotect.dllDangerous
webprotect.dllHigh Risk
webprotect.dll
We suggest you to remove WebProtect.dll from your computer as soon as possible.
WebProtect.dll is Trojan/Backdoor.
Kill the file WebProtect.dll and remove WebProtect.dll from Windows startup.

File: tcp.exe

Classification:
Code:
Antivirus Version Last Update Result
Avast 4.8.1335.0 2009.08.04 Win32:Trojan-gen {Other}
AVG 8.5.0.406 2009.08.04 Generic14.BSZ
BitDefender 7.2 2009.08.04 Trojan.Generic.2165133
Comodo 1860 2009.08.04 UnclassifiedMalware
DrWeb 5.0.0.12182 2009.08.04 Trojan.DownLoader.origin
F-Secure 8.0.14470.0 2009.08.04 Trojan-Downloader.Win32.VB.pqp
Kaspersky 7.0.0.125 2009.08.04 Trojan-Downloader.Win32.VB.pqp
Microsoft 1.4903 2009.08.04 -
NOD32 4306 2009.08.04 Win32/Delf.OPF
Symantec 1.4.4.12 2009.08.04 Downloader
Additional information
File size: 42496 bytes
MD5 : 7172dcb661566cb503b8ded5b7b57785
SHA1 : 9bbdbc23b0a92fd5f3c6d6d8ed59876d684f7f6c

Installation
When the program is executed, it creates the following registry subkeys and values:

----------------------------------
Keys added:24
----------------------------------
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\Implemented Categories
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\InprocServer32
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\ProgID
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\Programmable
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\TypeLib
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\VERSION
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}\ProxyStubClsid
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}\ProxyStubClsid32
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}\TypeLib
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0\0
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0\0\win32
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0\FLAGS
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0\HELPDIR
HKLM\SOFTWARE\Classes\WebProtect.ProtectCenter
HKLM\SOFTWARE\Classes\WebProtect.ProtectCenter\Clsid
HKLM\SOFTWARE\Microsoft\ESENT\Process\tcp
HKLM\SOFTWARE\Microsoft\ESENT\Process\tcp\DEBUG
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1D0A2B8-4275-42B1-9522-43B7166EF344}
HKLM\SOFTWARE\Microsoft\DownloadManager

----------------------------------
Values added:20
----------------------------------
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\VERSION\: "1.0"
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\TypeLib\: "{68A50108-6530-47C0-A9A5-30DC8B1199D0}"
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\ProgID\: "WebProtect.ProtectCenter"
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\InprocServer32\: "C:\WINDOWS\system32\WebProtect.dll"
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\InprocServer32\ThreadingModel: "Apartment"
HKLM\SOFTWARE\Classes\CLSID\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\: "WebProtect.ProtectCenter"
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}\TypeLib\: "{68A50108-6530-47C0-A9A5-30DC8B1199D0}"
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}\TypeLib\Version: "1.0"
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}\ProxyStubClsid32\: "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}\ProxyStubClsid\: "{00020424-0000-0000-C000-000000000046}"
HKLM\SOFTWARE\Classes\Interface\{1EEEC86D-FB26-40BC-BCDC-5652D1728A48}\: "ProtectCenter"
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0\0\win32\: "C:\WINDOWS\system32\WebProtect.dll"
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0\HELPDIR\: "C:\WINDOWS\system32"
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0\FLAGS\: "0"
HKLM\SOFTWARE\Classes\TypeLib\{68A50108-6530-47C0-A9A5-30DC8B1199D0}\1.0\: "WebProtect"
HKLM\SOFTWARE\Classes\WebProtect.ProtectCenter\Clsid\: "{B1D0A2B8-4275-42B1-9522-43B7166EF344}"
HKLM\SOFTWARE\Classes\WebProtect.ProtectCenter\: "WebProtect.ProtectCenter"
HKLM\SOFTWARE\Microsoft\ESENT\Process\tcp\DEBUG\Trace Level: ""
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\NoExplorer: 0x00000001
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1D0A2B8-4275-42B1-9522-43B7166EF344}\: "IoO??±??»?¤"

----------------------------------
Values modified:2
----------------------------------
HKLM\SOFTWARE\Classes\HTTP\shell\open\command\: ""C:\Program Files\Internet Explorer\iexplore.exe" -nohome"
HKLM\SOFTWARE\Classes\HTTP\shell\open\command\: ""C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome"

----------------------------------
Files added:1
----------------------------------
C:\WINDOWS\system32\WebProtect.dll

----------------------------------
Files [attributes?] modified:0
----------------------------------

----------------------------------
Folders added:0
----------------------------------

----------------------------------
Folders deleted:0
----------------------------------

----------------------------------
Total changes:47
----------------------------------

-------------------------------------------------------------------------------------
Detected by RegRun Reanimator:

Item Name: {B1D0A2B8-4275-42B1-9522-43B7166EF344}
Author: Lenovo (Beijing) Limited
Related File: C:\WINDOWS\system32\WebProtect.dll
Type: Browser Helper Objects

Removal Results: Success
Number of reboot: 1
-------------------------------------------------------------------------------------
WebProtect.dll

Code:
Antivirus Version Last Update Result
Avast 4.8.1335.0 2009.08.06 -
AVG 8.5.0.406 2009.08.06 -
BitDefender 7.2 2009.08.06 -
Comodo 1887 2009.08.06 -
DrWeb 5.0.0.12182 2009.08.06 -
F-Secure 8.0.14470.0 2009.08.06 Trojan-Downloader.Win32.VB.pqp
Kaspersky 7.0.0.125 2009.08.06 Trojan-Downloader.Win32.VB.pqp
Microsoft 1.4903 2009.08.06 -
NOD32 4312 2009.08.06 Win32/BHO.NRT
Symantec 1.4.4.12 2009.08.06 Trojan Horse

Additional information
File size: 14336 bytes
MD5 : a29f60d69968e52843cbba7f7c10ab8c
SHA1 : ba6a3e614c54a97cadc6e7221ff357ebc3412ef1
-------------------------------------------------------------------------------------

Recommended software:
UnHackMe anti-rootkit and anti-malware
http://www.unhackme.com
RegRun Security Suite (Good choice for removal and protection)

Remove webprotect.dll now!

Reviewed by:

by

webprotect.dll Dangerous Rating: 5 out of 5

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial of UnHackMe.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.