Protection Shield Pro

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: December 2, 2011
Last Seen: February 18, 2022
OS(es) Affected: Windows

ScreenshotProtection Shield Pro is a fake anti-virus program. Malware applications like Protection Shield Pro are known as rogue security programs. Rogue security programs are characterized by their ability to mimic legitimate security programs. In reality, Protection Shield Pro causes a large number of problems in the operating system where Protection Shield Pro is installed. The main goal of Protection Shield Pro is to convince a computer user that the computer is infected with a large amount of Trojans and other malware. Then, Protection Shield Pro attempts to convince the user to purchase a fake "full version" of Protection Shield Pro to remove these nonexistent Trojans. You can be sure that the problems that are present on the infected computer are caused by Protection Shield Pro itself. This is why ESG team of PC security analysts recommends ignoring all of Protection Shield Pro's security alerts and removing this fake anti-virus with a real anti-malware application.
 

Other Malware Infections Associated with Protection Shield Pro

Protection Shield Pro is part of a large family of rogue anti-virus programs. All of the fake security applications in this family are essentially the same, with different skins and names that help them bypass anti-malware programs. Some clones of Protection Shield Pro include MS Removal Tool, Essential Cleaner, Personal Shield Pro, and System Tool 2011. The names of Protection Shield Pro's clones may include the year 2011 or 2012, as is the case of the last of the previous examples. Protection Shield Pro and its clones are also associated closely with Trojans designed to download and install rogue security programs into an infected computer. Two of the main Trojans that perform this function are the Zlob Trojan and the Fake Microsoft Security Essentials Alert Trojan.
 

Dealing with Protection Shield Pro

Protection Shield Pro displays constant fake security alerts and can severely decrease your computer's performance. To remove Protection Shield Pro from your computer, ESG PC security researchers advise using an up-to-date anti-malware program. Protection Shield Pro may include elements that disable your security programs or prevent you from visiting websites associated with computer security. To solve this problem, ESG PC security analysts recommend starting up Windows in Safe Mode, or starting up from an external source. This will prevent Protection Shield Pro from starting up along with Windows and affecting your computer system.

File System Details

Protection Shield Pro may create the following file(s):
# File Name Detections
1. %Documents and Settings%\[UserName]\Local Settings\Application Data\{RANDOM CHARACTERS}.exe
2. %Temp%\[RANDOM ALPHA NUMERIC].exe
3. %Temp%\[RANDOM ALPHA NUMERIC]
4. %Program Files%\Protection Shield Pro
5. %Documents and Settings%\All Users\Application Data\{RANDOM CHARACTERS}
6. %Program Files%\Protection Shield Pro\Protection Shield Pro.lnk
7. %Temp% refers to C:\Windows\Temp\

Registry Details

Protection Shield Pro may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = '127.0.0.1:33554'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run "[RANDOM ALPHA NUMERIC].exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\RunOnce "[RANDOM ALPHA NUMERIC]"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "[RANDOM ALPHA NUMERIC]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "
HKEY_CURRENT_USER\Software\{RANDOM CHARACTERS}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'

Trending

Most Viewed

Loading...