|
Free malware removal tool to remove Personal Protector
|
|
Written by Administrator |
Friday, 20 November 2009 06:55
|
|
Personal Protector is a fake antivirus which installs itself on your system without your will. Its purpose is to scare you by posting false scan results so that you spend money on buying a full version which by the way doesn't even exist. Do not purchase this bogus application. Remove it as soon as possible from your system. Beware of this scam.

To remove Personal Protector
- Download and extract this free removal tool for Personal Protector
- Click on the delete button

Personal Protector will be removed in10s.
- BlockProtector.exe
- BlockProtectorSvc.exe
- [RANDOM CHARACTERS].exe
- [RANDOM CHARACTERS].tmp.exe
- %AllUsersProfile%\Microsoft PData
- %Programs%\Personal Protector
- %ProgramFiles%\Personal Protector
- %ProgramFiles%\Personal Protector\q
- %DesktopDir%\Personal Protector.lnk
- %Programs%\Personal Protector\Personal Protector.lnk
- %ProgramFiles%\Personal Protector\base.wdb
- %ProgramFiles%\Personal Protector\baseadd.wdb
- %ProgramFiles%\Personal Protector\conf.wcf
- %ProgramFiles%\Personal Protector\personalprotector.exe
- %ProgramFiles%\Personal Protector\quarant.wdb
- %ProgramFiles%\Personal Protector\queue.wdb
- %ProgramFiles%\Personal Protector\un.exe
- %Windir%\certofsystem.exe
- %Windir%\explorers.exe
- %Windir%\microsoftdefend.dll
- %Windir%\regp.exe
- %Windir%\secureit.com
- %Windir%\spoos.exe
- %System%\winscent.exe
Registry keys created by the malware
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3554F5B3-D7C5-4D8D-B3E9-BA93120C0F53}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3554F5B3-D7C5-4D8D-B3E9-BA93120C0F53}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{567B1AAB-C750-4B2C-997E-887FC5DC1140}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{567B1AAB-C750-4B2C-997E-887FC5DC1140}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Protector
- HKEY_LOCAL_MACHINE\SOFTWARE\Personal Protector
- HKEY_LOCAL_MACHINE\SOFTWARE\Personal Protector\Soft
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
Registry values created by the malware
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3554F5B3-D7C5-4D8D-B3E9-BA93120C0F53}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3554F5B3-D7C5-4D8D-B3E9-BA93120C0F53}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{567B1AAB-C750-4B2C-997E-887FC5DC1140}\InprocServer32
- (Default) = "%AllUsersProfile%\Microsoft PData\inetprovider.dll"
- ThreadingModel = "Apartment"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- personalprotector = "%ProgramFiles%\personal protector\personalprotector.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
- InternetProvider = "{567B1AAB-C750-4B2C-997E-887FC5DC1140}"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Protector
- DisplayName = "Personal Protector"
- UninstallString = "%ProgramFiles%\Personal Protector\un.exe"
- InstallDate = "999788981"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

|