User Protection - How to remove March 19, 2010 By gabriele Don’t expect that User Protection (also called as UserProtection) seeks to warn you about dangerous situation detected on your PC. In truth, User Protection is a rogue anti-spyware application, a total copy of Dr. Guard and Paladin Antivirus, so it only simulates scanning of malware actions and then announces hundreds of them trying to make people purchase its “full” version. It is obvious that this program is designed for the commercial reasons, so get rid of User Protection in the shortest period of time. In the beginning, User Protection rogue finds its way to the targeted computer through Trojans viruses. These minor threats come after they find some security vulnerabilities on the system and then download all the data of the badware. After sneaking inside the PC, User Protection begins to show up on misleading pop-up ads and security warnings every time computer boots up. Massages typically claim to find various cyber threats and malware with a reason to make users concerned about their PCs, for example: Dangerous! Antivirus detected some harmful programs on your PC! They may corrupt your information or send it to hackers. Antivirus is run in Demo Mode. Activate your Antivirus otherwise all the data will be lost or damaged! Antivirus Alert – Critical threat detected Warning: Network attack detected Network attack has been detected. Process is attempting to access your private data. Your computer is being attacked from a remote PC. Process is trying to steal your passwords listed below. It is highly recommended to block this threat now. User’s activity loggers detected! It’s strongly recommended to remove detected threats right now! Zlob.Porn.Ad adware has been detected. This adware module advertises websites with explicit content. Be advised of such content being possibly illegal. Please click the button below to locate and remove this threat now. This deceitful tactics of User Protection ends up with suggestions to purchase so called full version and people are simply redirected to make a payment for the license key of the scam. The most ironic fact is that User Protection tells the truth but keep in mind that the virus is the same UserProtection. Keep in mind that program is useless and has neither spyware detection nor removal engine. The solution after being contacted to User Protection is obvious – delete User Protection as soon as possible. Don’t waste your time because it will let more malware inside and make your computer totally damaged. Automatic Malware removal tools Download Spyhunter for Malware detection(Win) Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Download Combo Cleaner for Malware detection(Mac) Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy , Manual removal Processes: asr64_ldm.exe uninstall.exe Dll: drgext.dll drghook.dll Files: %Documents and Settings%\\[UserName]\\Desktop\\User Protection Support.lnk %Documents and Settings%\\[UserName]\\Desktop\\User Protection.lnk %Documents and Settings%\\[UserName]\\Start Menu\\Programs\\User Protection %Documents and Settings%\\[UserName]\\Start Menu\\Programs\\User Protection\\About.lnk %Documents and Settings%\\[UserName]\\Start Menu\\Programs\\User Protection\\Activate.lnk %Documents and Settings%\\[UserName]\\Start Menu\\Programs\\User Protection\\Buy.lnk %Documents and Settings%\\[UserName]\\Start Menu\\Programs\\User Protection\\User Protection Support.lnk c:\\Documents and Settings\\All Users\\Application Data\\fiosejgfse.dll c:\\Program Files\\User Protection c:\\Program Files\\User Protection\\about.ico c:\\Program Files\\User Protection\\activate.ico c:\\Program Files\\User Protection\\buy.ico c:\\Program Files\\User Protection\\help.ico c:\\Program Files\\User Protection\\scan.ico c:\\Program Files\\User Protection\\settings.ico c:\\Program Files\\User Protection\\splash.mp3 c:\\Program Files\\User Protection\\uninstall.exe c:\\Program Files\\User Protection\\update.ico c:\\Program Files\\User Protection\\usr.db c:\\Program Files\\User Protection\\usrext.dll c:\\Program Files\\User Protection\\usrhook.dll c:\\Program Files\\User Protection\\usrprot.exe c:\\Program Files\\User Protection\\virus.mp3 %UserProfile%\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\User Protection.lnk %UserProfile%\\Desktop\\User Protection Support.lnk %UserProfile%\\Desktop\\User Protection.lnk %UserProfile%\\Desktop\\usrprot.exe.txt %UserProfile%\\Local Settings\\Temp\\4otjesjty.mof %UserProfile%\\Local Settings\\Temp\\usr.dat %UserProfile%\\Local Settings\\Temp\\usrr.dat %UserProfile%\\Start Menu\\Programs\\User Protection %UserProfile%\\Start Menu\\Programs\\User Protection\\About.lnk %UserProfile%\\Start Menu\\Programs\\User Protection\\Activate.lnk %UserProfile%\\Start Menu\\Programs\\User Protection\\Buy.lnk %UserProfile%\\Start Menu\\Programs\\User Protection\\Scan.lnk %UserProfile%\\Start Menu\\Programs\\User Protection\\Settings.lnk %UserProfile%\\Start Menu\\Programs\\User Protection\\Update.lnk %UserProfile%\\Start Menu\\Programs\\User Protection\\User Protection Support.lnk %UserProfile%\\Start Menu\\Programs\\User Protection\\User Protection.lnk Registers: HKEY_CLASSES_ROOT\\*\\shellex\\ContextMenuHandlers\\SimpleShlExt HKEY_CLASSES_ROOT\\CLSID\\{5E2121EE-0300-11D4-8D3B-444553540000} HKEY_CLASSES_ROOT\\Folder\\shellex\\ContextMenuHandlers\\SimpleShlExt HKEY_LOCAL_MACHINE\\SOFTWARE\\User Protection HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\User Protection HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System “DisableTaskMgr” HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run “User Protection” HKEY_CLASSES_ROOT\\CLSID\\{5E2121EE-0300-11D4-8D3B-444553540000} HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved “{5E2121EE-0300-11D4-8D3B-444553540000}” HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System “DisableTaskMgr” = “1? HKEY_CLASSES_ROOT\\CLSID\\{5E2121EE-0300-11D4-8D3B-444553540000} HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\User Protection HKEY_LOCAL_MACHINE\\SOFTWARE\\User Protection HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \"User Protection\" HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved \"{5E2121EE-0300-11D4-8D3B-444553540000}\" User Protection facts Type: Rogue Anti-Spyware Download Spyhunter for Malware detection(Win) Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Download Combo Cleaner for Malware detection(Mac) Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy , TOC Leave a ReplyYour email address will not be published. Required fields are marked *Comment * Name * Email * Website