Total Protect

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 13
First Seen: July 22, 2011
Last Seen: January 8, 2020
OS(es) Affected: Windows

Total Protect Image

An Overview of Total Protect

Total Protect is a fake security program that has several clones, some of which include Total Protect 2009, Antivirus 2009, and Total Defender. Our ESG malware researchers consider Total Protect a serious risk to any computer's security. Total Protect pretends to be a real security utility, but it is really a harmful collection of Trojans and malicious scripts. The aim of Total Protect is to take a computer user's money. If Total Protect is installed on your computer system, we strongly advise you to remove it immediately with a legitimate security tool.
 

How the Total Protect Scam Works

The goal of Total Protect is to steal your money. It does this by convincing you to pay for a useless "full version" of this program to help you keep your computer secure. Total Protect also makes computer users panic by deliberately causing a large number of problems on the infected computer system. Our ESG PC security analysts have identified the following as some of the effects of Total Protect on a computer system:

  • Total Protect consumes a large amount of memory and processing power. Because of this, computers infected with Total Protect tend to become slow, sluggish, and unresponsive.
  • Total Protect's harmful scripts can interfere with Windows' normal operations, resulting in general system instability and random crashes. Total Protect can also cause certain specific applications to crash or refuse to open.
  • Total Protect has been known to change a computer system's settings and to alter the settings for a number of the most popular Internet browsers.
  • The most obvious effect of Total Protect is its fake system scan and constant fake security alerts. Total Protect alters the Windows Registry so that it will start up when Windows is launched. When the computer user logs into his session, the first thing he/she will see is the Total Protect splash screen and interface. This "feature" cannot be disabled, and the window cannot be closed until Total Protect finishes running its fake system scan. Our ESG team of security experts recommends ignoring the results of this fake system scan and the numerous fake security alerts from this rogue security program.
     

    Removing Total Protect from Your Computer

    Total Protect makes harmful changes to your system settings which make its manual removal quite difficult. It is not enough to delete the program in the Control Panel, it is also necessary to undo its many changes to the Windows Registry and to delete its associated files. This is why our ESG team of malware researchers recommends using a legitimate anti-malware utility to remove Total Protect automatically. Total Protect may take measures to make its removal difficult. For these cases, it often helps to start up Windows in Safe Mode. To do this, press F8 during start-up.

    SpyHunter Detects & Remove Total Protect

    File System Details

    Total Protect may create the following file(s):
    # File Name MD5 Detections
    1. RtlDriver32.exe d48cc73e9ce582b169dca25ef2e7b57c 6
    2. RtlDriver32.exe 819c9c4313076bd487858c0bf439954a 2
    3. %Temp%\(RANDOM CHARACTERS).exe

    Registry Details

    Total Protect may create the following registry entry or registry entries:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:8992'
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "
    HKEY_CURRENT_USER\Software(RANDOM CHARACTERS)

Related Posts

Trending

Most Viewed

Loading...