| Bleeping Computer | Welcome Guide Blogs Chat Help Search RSS |
|
Remove ProtectSoldier (Uninstall Guide)Posted by Grinler on January 21, 2010 @ 11:05 AM · Views: 1,466
What this programs does: ProtectSoldier is a rogue anti-virus program from the Wini family of rogues. It is still installed through the use of Trojans that masquerade as Flash updates required to watch an online video. When the Trojan is run it will download and install ProtectSoldier and configure it to start automatically when Windows starts. The Trojan will also create numerous harmless files in the C:\Windows and C:\Windows\System32 folders that have random names. These files will then be detected as infections by ProtectSoldier when it scans your computer, but ProtectSoldier will state it cannot remove these files unless you first purchase the program. This method of create faking infection files on your computer and then detecting them as malware is just a tactic where the developers are trying to convince you that you have a security problem in the hopes that you will then purchase the program.
While the Trojan is running, it will also display numerous security alerts on your computer. These security alerts will contain messages stating that your computer is under attack or that an active malware has been detected. The text of one of these alerts is:
The Trojan will also display a fake Windows Security Center window that suggests that you purchase ProtectSoldier to protect your computer. Just like the scan results, these fake security alerts should be ignored. As you can see, the purpose of this rogue is to trick you into thinking there is a security problem on your computer so that you will be convinced to purchase the program. If you have already purchased this program, then we suggest that you contact your credit card company and dispute the charges stating that the program was a scam. Finally, to remove this malware please use the removal guide below.
Threat Classification:
Advanced information: View ProtectSoldier files.
Entries for this program found in the Add or Remove Programs control panel: ProtectSoldier
Tools Needed for this fix:
Symptoms that may be in a HijackThis Log: O4 - HKLM\..\Run: [ProtectSoldier] C:\Program Files\ProtectSoldier Software\ProtectSoldier\ProtectSoldier.exe -min
Guide Updates: 01/21/10 - Initial guide creation.
Automated Removal Instructions for ProtectSoldier using Malwarebytes' Anti-Malware:
Your computer should now be free of the ProtectSoldier program. If your current anti-virus solution let this infection through, you may want to consider purchasing the PRO version of Malwarebytes' Anti-Malware to protect against these types of threats in the future. If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below: Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help
Associated ProtectSoldier Files: %UserProfile%\Desktop\ProtectSoldier.lnk
Associated ProtectSoldier Windows Registry Information: HKEY_CURRENT_USER\Software\ProtectSoldier
This is a self-help guide. Use at your own risk. BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can ask for malware removal assistance in our Virus, Trojan, Spyware, and Malware Removal Logs forum. If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.
|
|