Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

ProtectU - is this antimalware or malware?


  • Please log in to reply
9 replies to this topic

#1 midimusicman79

midimusicman79

  • Members
  • 761 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:09:15 AM

Posted 10 June 2016 - 08:58 AM

Hi all!

 

While searching the Internet for new anti-malware tools to try, I stumbled upon ProtectU, which is featured at thewindowsclub.com, here: http://www.thewindowsclub.com/protectu-malware-detection-software

 

Upon installation, the app appeared in SysTray as a real-time process looking like a padlock, and had only one option to open up the GUI, which seemed legitimate and relatively simple.

 

There was an option to scan the system for malware, which already had been automatically run, however another scan was available on demand.

 

So I scanned my system, which went rather quickly, but as it found no malware, I thought that I could uninstall it, which albeit went successfully. So far so good, however;

 

Even after uninstallation, four processes belonging to the said app were still continously running, just like before the uninstallation.

 

And as such, I had to resort to system restore to get rid of it. Good riddance! Luckily I have the habit of backing up my registry with WR (AiO) and creating a restore point before trying new software - just in case. :wink:

 

Hence, my question is as follows: ProtectU - is this anti-malware or malware?

 

Thank you very much in advance!

 

Regards,

midimusicman79


Edited by midimusicman79, 11 June 2016 - 05:10 AM.

MS Win 10 Pro 64-bit, EAM Pro/EEK, MB 3 Free, WPP, SWB Free, CryptoPrevent Free, NVT OSA and Unchecky, WFW, FFQ with CanDef, uBO, Ghostery, Grammarly Free and HTTPS Ew. Acronis TI 2018, K. Sw. Upd. AM-tools: 9-lab RT BETA, AdwCleaner, Auslogics AM, aswMBR, Avira PCC, BD ART, catchme, Cezurity AV, CCE, CKS, ClamWin P., Crystal Sec., DDS, DWCI, EMCO MD, eScan MWAV, ESS/EOS, FGP, FMTB, FRST, F-SOS, FSS, FreeFixer, GMP, GMER, hP BETA, HJT, Inherit, JRT, K. avz4, KVRT, K. TDSSKiller, LSP-Fix, MB 3 Free, MBAR BETA, MA Stinger, NMC, NoBot, NPE, NSS, NVT MRF (NMRF), OTL, PCC, QD, RCS, RSIT, RKill, Rs, SC, SR, SAP, SVRT, SAS, SL, TMHC, TSA ART, UHM, Vba32 AR, VRS, WR (AiO), Xvirus PG, ZAM, ZHPC, ZHPD and Zoek. I have 23 Years of PC Experience. Bold = effective.


BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,672 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:15 AM

Posted 10 June 2016 - 09:38 AM

Might be an error in the uninstallation. ProtectU is an open-source project hosted on GitHub, so if it was indeed malicious, it would have been called out a long time ago.

https://protectuapp.github.io/web/

Feel free to go through the code (if you can read it) to see for yourself.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,734 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:03:15 AM

Posted 10 June 2016 - 11:07 AM

Sometimes software uninstall works more effectively if you first stop and disable the program's service (and associated processes in Task Manager) or perform the removal in safe mode so there are less processes which can interfere with the uninstallation.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#4 midimusicman79

midimusicman79
  • Topic Starter

  • Members
  • 761 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:09:15 AM

Posted 11 June 2016 - 07:51 AM

Hi, Aura & quietman7!

 

Thank you both for the prompt and clarifying replies! :)

 

When I uninstalled ProtectU yesterday, it gave the following message: "Some components could not be uninstalled. These can be removed manually."

 

Today as I reinstalled (in normal mode) and uninstalled the said app in safe mode, the message changed to: "The application ProtectU was successfully uninstalled."

 

IMO, given all the anti-malware tools (in my signature) that I have tried subsequently, this is a rather seldom experience, nevertheless just a heads-up. :wink:

 

Thank you very much for the help! :) The issue has been successfully resolved! :thumbup2:

 

Regards,

midimusicman79


MS Win 10 Pro 64-bit, EAM Pro/EEK, MB 3 Free, WPP, SWB Free, CryptoPrevent Free, NVT OSA and Unchecky, WFW, FFQ with CanDef, uBO, Ghostery, Grammarly Free and HTTPS Ew. Acronis TI 2018, K. Sw. Upd. AM-tools: 9-lab RT BETA, AdwCleaner, Auslogics AM, aswMBR, Avira PCC, BD ART, catchme, Cezurity AV, CCE, CKS, ClamWin P., Crystal Sec., DDS, DWCI, EMCO MD, eScan MWAV, ESS/EOS, FGP, FMTB, FRST, F-SOS, FSS, FreeFixer, GMP, GMER, hP BETA, HJT, Inherit, JRT, K. avz4, KVRT, K. TDSSKiller, LSP-Fix, MB 3 Free, MBAR BETA, MA Stinger, NMC, NoBot, NPE, NSS, NVT MRF (NMRF), OTL, PCC, QD, RCS, RSIT, RKill, Rs, SC, SR, SAP, SVRT, SAS, SL, TMHC, TSA ART, UHM, Vba32 AR, VRS, WR (AiO), Xvirus PG, ZAM, ZHPC, ZHPD and Zoek. I have 23 Years of PC Experience. Bold = effective.


#5 RolandJS

RolandJS

  • Members
  • 4,533 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Austin TX metro area
  • Local time:02:15 AM

Posted 11 June 2016 - 07:53 AM

I have protectU running in my desktop computer, giving it a few runs this week; will report on it later.


Edited by RolandJS, 11 June 2016 - 07:54 AM.

"Take care of thy backups and thy restores shall take care of thee."  -- Ben Franklin revisited.

http://collegecafe.fr.yuku.com/forums/45/Computer-Technologies/

Backup, backup, backup! -- Lady Fitzgerald (w7forums)

Clone or Image often! Backup... -- RockE (WSL)


#6 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,734 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:03:15 AM

Posted 11 June 2016 - 04:11 PM

A "Some components could not be uninstalled. These can be removed manually" message is not uncommon. Software installs itself in so many locations throughout the system and registry, even the uninstallers can't find everything.


.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#7 midimusicman79

midimusicman79
  • Topic Starter

  • Members
  • 761 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:09:15 AM

Posted 12 June 2016 - 06:29 AM

Hi, RolandJS & quietman7!

 

Thanks to both of you for the prompt and helpful replies! :)

 

@RolandJS:

That is nice; good luck! :thumbup2:

 

@quietman7:

Yes, I suppose that is why there are official uninstall / removal tools for Anti-Virus / Anti-Malware as well as stand-alone uninstaller tools, which all do a better job of uninstalling than in the normal fashion.

 

There are many stand-alone uninstaller tools out there; Do you have any recommendations?

 

Regards,

midimusicman79


MS Win 10 Pro 64-bit, EAM Pro/EEK, MB 3 Free, WPP, SWB Free, CryptoPrevent Free, NVT OSA and Unchecky, WFW, FFQ with CanDef, uBO, Ghostery, Grammarly Free and HTTPS Ew. Acronis TI 2018, K. Sw. Upd. AM-tools: 9-lab RT BETA, AdwCleaner, Auslogics AM, aswMBR, Avira PCC, BD ART, catchme, Cezurity AV, CCE, CKS, ClamWin P., Crystal Sec., DDS, DWCI, EMCO MD, eScan MWAV, ESS/EOS, FGP, FMTB, FRST, F-SOS, FSS, FreeFixer, GMP, GMER, hP BETA, HJT, Inherit, JRT, K. avz4, KVRT, K. TDSSKiller, LSP-Fix, MB 3 Free, MBAR BETA, MA Stinger, NMC, NoBot, NPE, NSS, NVT MRF (NMRF), OTL, PCC, QD, RCS, RSIT, RKill, Rs, SC, SR, SAP, SVRT, SAS, SL, TMHC, TSA ART, UHM, Vba32 AR, VRS, WR (AiO), Xvirus PG, ZAM, ZHPC, ZHPD and Zoek. I have 23 Years of PC Experience. Bold = effective.


#8 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,734 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:03:15 AM

Posted 12 June 2016 - 06:42 AM

I use Revo Uninstaller Portable and MyUninstaller.

If you use CCleaner there is an uninstaller under the under Tools button.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#9 midimusicman79

midimusicman79
  • Topic Starter

  • Members
  • 761 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:09:15 AM

Posted 12 June 2016 - 08:43 AM

Hi again, quietman7!

 

Thanks, I do use CCleaner Portable. :thumbup2:

 

Regards,

midimusicman79


Edited by midimusicman79, 12 June 2016 - 08:43 AM.

MS Win 10 Pro 64-bit, EAM Pro/EEK, MB 3 Free, WPP, SWB Free, CryptoPrevent Free, NVT OSA and Unchecky, WFW, FFQ with CanDef, uBO, Ghostery, Grammarly Free and HTTPS Ew. Acronis TI 2018, K. Sw. Upd. AM-tools: 9-lab RT BETA, AdwCleaner, Auslogics AM, aswMBR, Avira PCC, BD ART, catchme, Cezurity AV, CCE, CKS, ClamWin P., Crystal Sec., DDS, DWCI, EMCO MD, eScan MWAV, ESS/EOS, FGP, FMTB, FRST, F-SOS, FSS, FreeFixer, GMP, GMER, hP BETA, HJT, Inherit, JRT, K. avz4, KVRT, K. TDSSKiller, LSP-Fix, MB 3 Free, MBAR BETA, MA Stinger, NMC, NoBot, NPE, NSS, NVT MRF (NMRF), OTL, PCC, QD, RCS, RSIT, RKill, Rs, SC, SR, SAP, SVRT, SAS, SL, TMHC, TSA ART, UHM, Vba32 AR, VRS, WR (AiO), Xvirus PG, ZAM, ZHPC, ZHPD and Zoek. I have 23 Years of PC Experience. Bold = effective.


#10 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,734 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:03:15 AM

Posted 12 June 2016 - 03:35 PM

:thumbup2:
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users