| Bleeping Computer | Welcome Guide Blogs Chat Help | RSS |
|
How to remove XP-ShieldPosted by Grinler on May 14, 2008 @ 03:05 PM · Views: 575
What this programs does: XP-Shield is a rogue anti-spyware program that is in the same family as AntiVirProtect and WinXProtector. When XP-Shield is installed, it will scan your computer and list a variety of security risks that can only be removed if you first purchase the software. What classifies this software as a rogue is that it deliberately lists legitimate Microsoft files as malware in order to scare you into purchasing the software. For example, it lists the C:\Windows\System32\dllcache\pdh.dll file as the Complexel Trojan, when in reality it is a legitimate Microsoft DLL file. Furthermore, when XP-Shield is running it will randomly display security alerts that are masquerading as Windows Security Center alerts stating that Windows has detected virus or spyware activity on your computer. It then proceeds to tell you that it found XP-Shield and that you should purchase it in order to protect yourself. These alerts, though, are being generated by the program itself and not Windows as it attempts to make you believe. This is just another example of the misleading tactics XP-Shield uses in order to have you purchase a license of the software. Below are various screen shots of XPShield program.
This guide will walk you through removing XP-Shield.
Threat Classification:
Advanced information: View XP-Shield files.
Tools Needed for this fix:
Symptoms that may be in a HijackThis Log: O4 - HKCU\..\Run: [XPShield] C:\PROGRA~1\XPShield\XP-SHI~1.EXE
Guide Updates: 05/14/08 - Initial guide creation.
Automated Removal Instructions for XP-Shield using Malwarebytes' Anti-Malware:
Your computer should now be free of the XPShield program. If your current anti-virus solution let this infection through, you may want to consider purchasing the PRO version of Malwarebytes' Anti-Malware to protect against these types of threats in the future. If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below: Preparation Guide For Use Before Posting A Hijackthis Log
Associated XP-Shield Files: c:\Program Files\XPShield
Associated XP-Shield Windows Registry Information: HKEY_CURRENT_USER\Software\XPShield
This is a self-help guide. Use at your own risk. BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum. If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.
|
|