DProtect

DProtect

Known Adware

by DProtect Lab

What is DProtect?

DProtect is software application developed by DProtect Lab. It is most commonly found on computers running Windows 7 with nearly 58.93% of installations running this operating system. DProtect's installer is typically 1.00 MB in size and installs around 5 files.

DProtect is most popular in the United States with 15.25% of installations residing in this country.

When using a computer that is connected to the internet, DProtect is known to create 2 firewall exceptions to allow inbound and outbound connectivity.

About DProtect?

DProtect is an adware web browser extension designed to display popup and banner ads while potentially modifying the user's web browser search and home page settings. Additionally, the program may monitor user behavior and inject rival advertisements or new ones. During installation, the publisher may offer changes to the Internet Browser settings which can be reconfigured by the user at any time from the options dialog available on the Internet Browser. These changes may include modifications to the homepage, default search engine, and the page displayed when opening a new tab.

Multiple virus scanners have detected malware in DProtect.

eGdpSvc.exe (MD5: d0f52960ae4f2b30008f7ce7f115095d) has been flagged by 22 scanners:
Scanner Software Result
Agnitum Outpost Trojan.Agent!L6TZXmBj5Uc
AhnLab-V3 Trojan/Win32.Staser
Avira AntiVir TR/Crypt.cfi.56
Antiy-AVL Trojan/Win32.Generic
Bkav FE HW32.CDB.Df4d
Commtouch SDK W32/Trojan.UHBK-2914
Comodo Security UnclassifiedMalware
Dr.Web Trojan.Siggen5.54287
Fortinet FortiGate W32/STASER.A!tr
IKARUS anti.virus Trojan.Win32.Staser
K7 AntiVirus Trojan
K7GW Trojan
Kaspersky Trojan.Win32.Staser.rrj
Kingsoft AntiVirus Win32.Troj.Undef.(kcloud)
Malwarebytes PUP.Optional.DProtect.A
McAfee RDN/Generic.dx!crf
McAfee-GW-Edition RDN/Generic.dx!crf
Panda Antivirus Trj/CI.A
Sophos Mal/VMProtBad-A
Trend Micro TROJ_FRS.BMA000IR13
TrendMicro-HouseCall TROJ_FRS.BMA000IR13
VIPRE Antivirus Trojan.Win32.Generic!BT
DProtectSvc.exe (MD5: 957c9c20b7df85c3f8d08e53f4720ba1) has been flagged by 29 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.Staser
avast! Win32:Staser-A [Trj]
AVG MalSign.Generic
Baidu-International Adware.Win32.ElexInstall
CAT-QuickHeal Trojan.Staser.fv
Comodo Security UnclassifiedMalware
Dr.Web Adware.Mutabaha.28
ESET-NOD32 a variant of Win32/ELEX.T
Fortinet FortiGate W32/Staser.FV!tr
IKARUS anti.virus Trojan.Win32.Staser
K7 AntiVirus Trojan
K7GW Trojan ( 00454f271 )
Malwarebytes Trojan.Staser
McAfee Adware-Bprotect
Panda Antivirus Generic Malware
Sophos Mal/Generic-S
Symantec Download.Adware
Trend Micro ADW_BPROTECT
VIPRE Antivirus Elex Installer (fs)
ViRobot Trojan.Win32.S.Agent.345152
Agnitum Outpost Trojan.Agent!L6TZXmBj5Uc
AhnLab-V3 Trojan/Win32.Staser
Avira AntiVir TR/Crypt.cfi.56
Bkav FE HW32.CDB.Df4d
Commtouch SDK W32/Trojan.UHBK-2914
Kaspersky Trojan.Win32.Staser.rrj
Kingsoft AntiVirus Win32.Troj.Undef.(kcloud)
McAfee-GW-Edition RDN/Generic.dx!crf
TrendMicro-HouseCall TROJ_FRS.BMA000IR13

Software Behaviors

Services:
  • DProtectSvc.exe runs as a service named 'DPService' (DPService) "DProtect Service".
  • eGdpSvc.exe runs as a service named 'eSafe Service' (eSafeSvc) "System eSafe update service".
Firewall:
  • eGdpSvc.exe is added as a firewall exception for 'C:\Documents and Settings\All Users\Datos de programa\eSafe\eGdpSvc.exe'.
  • DProtectSvc.exe is added as a firewall exception for 'C:\Documents and Settings\user\Application Data\DProtect\DProtectSvc.exe'.

Software Details

URL:
Support:
Installation path:
C:\Documents and Settings\user\Application data\dprotect
Uninstaller:
C:\Documents and Settings\user\Application Data\DProtect\DPUninstall.exe -silence
Size:
1.00 MB
Language:
English

DProtect Executable Details

Primary executable:
DProtectSvc.exe
Name:
DProtect
Path:
C:\Documents and Settings\user\Application data\dprotect\DProtectSvc.exe
MD5:
957c9c20b7df85c3f8d08e53f4720ba1
SHA-1:
SHA-256:
Files installed by DProtect
File Type Filename MD5
EXE
d0f52960ae4f2b30008f7ce7f115095d
DLL
5dd25706efaf888499dafc6a0c9d6aa3
DLL
0f161b35c28e4c45e721731f087e1595
EXE
957c9c20b7df85c3f8d08e53f4720ba1
EXE
21881efc326a0243d2b84ee778fecca7