Jump to content

Removal instructions for ContentProtector


Recommended Posts

  • Staff
What is ContentProtector?

The Malwarebytes research team has determined that ContentProtector is adware. These adware applications display advertisements not originating from the sites you are browsing.

How do I know if my computer is affected by ContentProtector?

You may see these warnings during install:

main.png

warning1.png

warning2.png

this entry in your list of installed programs:

warning4.png

and this icon in your startmenu:

icons.png

How did ContentProtector get on my computer?

Adware applications use different methods for distributing themselves. This particular one was bundled with other software.

How do I remove ContentProtector?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-{version}.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to:
    Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • Once the program has loaded, select Scan Now. Or select the Threat Scan from the Scan menu.
  • If an update is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of ContentProtector?
  • No, Malwarebytes' Anti-Malware removes ContentProtector completely.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the ContentProtector adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late.

 

protection1.png


Technical details for experts

Possible signs in FRST logs:
 
 ("Artex Management S. A.") C:\Program Files\ContentProtector\ContentProtector.exe
 ("Artex Management S. A.") C:\Program Files\ContentProtector\ContentProtectorUpdate.exe
 R2 ContentProtector; C:\Program Files\ContentProtector\ContentProtector.exe [709376 2016-02-16] ("Artex Management S. A.")
 R2 ContentProtectorUpdate; C:\Program Files\ContentProtector\ContentProtectorUpdate.exe [257792 2016-02-16] ("Artex Management S. A.")
 R1 ContentProtectorDrv; C:\WINDOWS\system32\drivers\ContentProtectorDrv.sys [58200 2016-02-16] ()
 C:\Program Files\ContentProtector
 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ContentProtector
 C:\WINDOWS\system32\Drivers\ContentProtectorDrv.sys

ContentProtector (HKLM\...\ContentProtector) (Version: 2.0 - Artex Management S. A.)
Alterations made by the installer:
File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files\ContentProtector
       Adds the file condefclean.exe"="2/16/2016 7:14 PM, 122112 bytes, A
       Adds the file condefupdatePS.dll"="2/16/2016 7:14 PM, 14080 bytes, A
       Adds the file ConProtSetup.exe"="7/19/2016 1:20 PM, 6322787 bytes, A
       Adds the file ContentProtector.exe"="2/16/2016 7:14 PM, 709376 bytes, A
       Adds the file ContentProtectorConrol.exe"="2/16/2016 7:14 PM, 278784 bytes, A
       Adds the file ContentProtectorUpdate.exe"="2/16/2016 7:14 PM, 257792 bytes, A
       Adds the file import_root_cert.exe"="2/16/2016 7:14 PM, 99584 bytes, A
       Adds the file libeay32.dll"="2/16/2016 7:14 PM, 2515200 bytes, A
       Adds the file nfregdrv.exe"="2/16/2016 7:14 PM, 144640 bytes, A
       Adds the file ssleay32.dll"="2/16/2016 7:14 PM, 483072 bytes, A
    Adds the folder C:\Program Files\ContentProtector\cert\SSL
       Adds the file cert.db"="7/19/2016 12:25 PM, 0 bytes, A
       Adds the file ContentProtector 2.cer"="7/19/2016 12:25 PM, 776 bytes, A
    Adds the folder C:\Program Files\ContentProtector\nss
       Adds the file certutil.exe"="2/16/2016 7:14 PM, 95488 bytes, A
       Adds the file mozcrt19.dll"="2/16/2016 7:14 PM, 718080 bytes, A
       Adds the file nspr4.dll"="2/16/2016 7:14 PM, 169216 bytes, A
       Adds the file nss3.dll"="2/16/2016 7:14 PM, 369920 bytes, A
       Adds the file plc4.dll"="2/16/2016 7:14 PM, 20224 bytes, A
       Adds the file plds4.dll"="2/16/2016 7:14 PM, 17152 bytes, A
       Adds the file smime3.dll"="2/16/2016 7:14 PM, 111872 bytes, A
       Adds the file softokn3.dll"="2/16/2016 7:14 PM, 378112 bytes, A
    Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ContentProtector
       Adds the file Settings.lnk"="7/19/2016 12:24 PM, 993 bytes, A
    In the existing folder C:\Windows\System32\drivers
       Adds the file ContentProtectorDrv.sys"="2/16/2016 7:13 PM, 58200 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{3E0DB45B-9FCC-4064-B48C-080BD03A99A4}]
       "LocalService"="REG_SZ", "ContentProtector"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{C81BED3B-31BD-491F-813D-78EFC2638CE1}]
       "LocalService"="REG_SZ", "ContentProtectorUpdate"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35F4BB37-03C5-41DE-85AF-7C301390C7EC}]
       "(Default)"="REG_SZ", "UpdaterIface Class"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35F4BB37-03C5-41DE-85AF-7C301390C7EC}\LocalServer32]
       "(Default)"="REG_SZ", ""C:\Program Files\ContentProtector\ContentProtectorUpdate.exe""
       "ServerExecutable"="REG_SZ", "C:\Program Files\ContentProtector\ContentProtectorUpdate.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35F4BB37-03C5-41DE-85AF-7C301390C7EC}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35F4BB37-03C5-41DE-85AF-7C301390C7EC}\TypeLib]
       "(Default)"="REG_SZ", "{D5397E85-8AF4-414B-90FC-9F4244CD46FA}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35F4BB37-03C5-41DE-85AF-7C301390C7EC}\Version]
       "(Default)"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7395C3-28B5-445E-AA7D-539B63514CAB}]
       "(Default)"="REG_SZ", "DefenderControl Class"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7395C3-28B5-445E-AA7D-539B63514CAB}\LocalServer32]
       "(Default)"="REG_SZ", ""C:\Program Files\ContentProtector\ContentProtector.exe""
       "ServerExecutable"="REG_SZ", "C:\Program Files\ContentProtector\ContentProtector.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7395C3-28B5-445E-AA7D-539B63514CAB}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7395C3-28B5-445E-AA7D-539B63514CAB}\TypeLib]
       "(Default)"="REG_SZ", "{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B7395C3-28B5-445E-AA7D-539B63514CAB}\Version]
       "(Default)"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B28F9114-243E-4046-B173-11825352D18A}]
       "(Default)"="REG_SZ", "IDefenderControl"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B28F9114-243E-4046-B173-11825352D18A}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B28F9114-243E-4046-B173-11825352D18A}\TypeLib]
       "(Default)"="REG_SZ", "{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B910D9A1-9F21-484A-8650-82250DABF38E}]
       "(Default)"="REG_SZ", "IUpdaterIface"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B910D9A1-9F21-484A-8650-82250DABF38E}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B910D9A1-9F21-484A-8650-82250DABF38E}\TypeLib]
       "(Default)"="REG_SZ", "{D5397E85-8AF4-414B-90FC-9F4244CD46FA}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}\1.0]
       "(Default)"="REG_SZ", "ContentDefenderLib"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}\1.0\0\win64]
       "(Default)"="REG_SZ", "C:\Program Files\ContentProtector\ContentProtector.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}\1.0\FLAGS]
       "(Default)"="REG_SZ", "0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}\1.0\HELPDIR]
       "(Default)"="REG_SZ", "C:\Program Files\ContentProtector"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5397E85-8AF4-414B-90FC-9F4244CD46FA}\1.0]
       "(Default)"="REG_SZ", "condefupdateLib"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5397E85-8AF4-414B-90FC-9F4244CD46FA}\1.0\0\win64]
       "(Default)"="REG_SZ", "C:\Program Files\ContentProtector\ContentProtectorUpdate.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5397E85-8AF4-414B-90FC-9F4244CD46FA}\1.0\FLAGS]
       "(Default)"="REG_SZ", "0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5397E85-8AF4-414B-90FC-9F4244CD46FA}\1.0\HELPDIR]
       "(Default)"="REG_SZ", "C:\Program Files\ContentProtector"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B28F9114-243E-4046-B173-11825352D18A}]
       "(Default)"="REG_SZ", "IDefenderControl"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B28F9114-243E-4046-B173-11825352D18A}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B28F9114-243E-4046-B173-11825352D18A}\TypeLib]
       "(Default)"="REG_SZ", "{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B910D9A1-9F21-484A-8650-82250DABF38E}]
       "(Default)"="REG_SZ", "IUpdaterIface"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B910D9A1-9F21-484A-8650-82250DABF38E}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B910D9A1-9F21-484A-8650-82250DABF38E}\TypeLib]
       "(Default)"="REG_SZ", "{D5397E85-8AF4-414B-90FC-9F4244CD46FA}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\ContentProtector]
       "campaignid"="REG_SZ", "0"
       "ff"="REG_SZ", "yes"
       "installed"="REG_SZ", "1"
       "siteid"="REG_SZ", "0"
       "sourceid"="REG_SZ", "1"
       "userid"="REG_SZ", "B155C458-9D41-4923-87C3-9A9033D8D6C2"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ContentProtector]
       "DisplayIcon"="REG_SZ", "C:\Program Files\ContentProtector\ConProtSetup.exe"
       "DisplayName"="REG_SZ", "ContentProtector"
       "DisplayVersion"="REG_SZ", "2.0"
       "EstimatedSize"="REG_DWORD", 6000
       "InstallDate"="REG_SZ", "20160719"
       "Publisher"="REG_SZ", "Artex Management S. A."
       "UninstallString"="REG_SZ", "C:\Program Files\ContentProtector\ConProtSetup.exe uninst=1"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentProtector]
       "DependOnService"="REG_MULTI_SZ, "RPCSS "
       "DisplayName"="REG_SZ", "ContentProtector"
       "ErrorControl"="REG_DWORD", 1
       "ImagePath"="REG_EXPAND_SZ, ""C:\Program Files\ContentProtector\ContentProtector.exe""
       "ObjectName"="REG_SZ", "LocalSystem"
       "Start"="REG_DWORD", 2
       "Type"="REG_DWORD", 16
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentProtectorDrv]
       "DisplayName"="REG_SZ", "ContentProtectorDrv"
       "ErrorControl"="REG_DWORD", 1
       "Group"="REG_SZ", "PNP_TDI"
       "ImagePath"="REG_EXPAND_SZ, "\??\C:\WINDOWS\system32\drivers\ContentProtectorDrv.sys"
       "Start"="REG_DWORD", 1
       "Tag"="REG_DWORD", 10
       "Type"="REG_DWORD", 1
       "WOW64"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ContentProtectorUpdate]
       "DependOnService"="REG_MULTI_SZ, "RPCSS "
       "DisplayName"="REG_SZ", "ContentProtectorUpdate"
       "ErrorControl"="REG_DWORD", 1
       "ImagePath"="REG_EXPAND_SZ, ""C:\Program Files\ContentProtector\ContentProtectorUpdate.exe""
       "ObjectName"="REG_SZ", "LocalSystem"
       "Start"="REG_DWORD", 2
       "Type"="REG_DWORD", 16
Malwarebytes Anti-Malware log:
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/19/2016
Scan Time: 1:34 PM
Logfile: mbamContentProtector.txt
Administrator: Yes

Version: 2.2.1.1039
Malware Database: v2016.07.19.04
Rootkit Database: v2016.05.27.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Enabled

OS: Windows 10
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 307227
Time Elapsed: 1 hr, 30 min, 59 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\ContentProtector.exe, 5636, Delete-on-Reboot, [ab3549dcf2a8d85e5c0014df27dcdc24]
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\ContentProtectorUpdate.exe, 2608, Delete-on-Reboot, [4a96c95c35650f2794ca8e65768d53ad]

Modules: 0
(No malicious items detected)

Registry Keys: 17
PUP.Optional.ContentDefender, HKLM\SOFTWARE\CLASSES\TYPELIB\{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}, Quarantined, [c020f82d1189290d3a984b4ccb37619f], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\CLASSES\INTERFACE\{B28F9114-243E-4046-B173-11825352D18A}, Quarantined, [c020f82d1189290d3a984b4ccb37619f], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B28F9114-243E-4046-B173-11825352D18A}, Quarantined, [c020f82d1189290d3a984b4ccb37619f], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B28F9114-243E-4046-B173-11825352D18A}, Quarantined, [c020f82d1189290d3a984b4ccb37619f], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}, Quarantined, [c020f82d1189290d3a984b4ccb37619f], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}, Quarantined, [c020f82d1189290d3a984b4ccb37619f], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\CLASSES\TYPELIB\{D5397E85-8AF4-414B-90FC-9F4244CD46FA}, Quarantined, [19c73ee73466c670d9fa62352cd65da3], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\CLASSES\INTERFACE\{B910D9A1-9F21-484A-8650-82250DABF38E}, Quarantined, [19c73ee73466c670d9fa62352cd65da3], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B910D9A1-9F21-484A-8650-82250DABF38E}, Quarantined, [19c73ee73466c670d9fa62352cd65da3], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B910D9A1-9F21-484A-8650-82250DABF38E}, Quarantined, [19c73ee73466c670d9fa62352cd65da3], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{D5397E85-8AF4-414B-90FC-9F4244CD46FA}, Quarantined, [19c73ee73466c670d9fa62352cd65da3], 
PUP.Optional.ContentDefender, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{D5397E85-8AF4-414B-90FC-9F4244CD46FA}, Quarantined, [19c73ee73466c670d9fa62352cd65da3], 
PUP.Optional.ContentProtector, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ContentProtector, Quarantined, [35ab4bda3e5ca78ffb70d0f502ffd828], 
PUP.Optional.ContentProtector, HKLM\SOFTWARE\CONTENTPROTECTOR, Quarantined, [0bd58d98b2e873c3669d8676a65d0df3], 
PUP.Optional.ContentProtector, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ContentProtector, Quarantined, [ab3549dcf2a8d85e5c0014df27dcdc24], 
PUP.Optional.ContentProtector, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ContentProtectorDrv, Quarantined, [fee28d98b8e2fe38f6678d66b54e916f], 
PUP.Optional.ContentProtector, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ContentProtectorUpdate, Quarantined, [4a96c95c35650f2794ca8e65768d53ad], 

Registry Values: 1
PUP.Optional.ContentProtector, HKLM\SOFTWARE\CONTENTPROTECTOR|campaignid, 0, Quarantined, [0bd58d98b2e873c3669d8676a65d0df3]

Registry Data: 0
(No malicious items detected)

Folders: 5
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector, Delete-on-Reboot, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\cert, Delete-on-Reboot, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\cert\SSL, Delete-on-Reboot, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ContentProtector, Quarantined, [5888c65f6d2d3bfb49db4681748ea35d], 

Files: 23
PUP.Optional.ContentProtector, C:\WINDOWS\SYSTEM32\drivers\ContentProtectorDrv.sys, Delete-on-Reboot, [8269e5b1101add0709780fd66e9df59d], 
PUP.Optional.ContentProtector, C:\Users\{username}\Desktop\ConProtSe.exe, Quarantined, [79674adbcbcf2f07a8c30eb76b9606fa], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\ConProtSetup.exe, Quarantined, [35ab4bda3e5ca78ffb70d0f502ffd828], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\ContentProtector.exe, Delete-on-Reboot, [ab3549dcf2a8d85e5c0014df27dcdc24], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\ContentProtectorUpdate.exe, Delete-on-Reboot, [4a96c95c35650f2794ca8e65768d53ad], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\condefclean.exe, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\condefupdatePS.dll, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\ContentProtectorConrol.exe, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\import_root_cert.exe, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\libeay32.dll, Delete-on-Reboot, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nfregdrv.exe, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\ssleay32.dll, Delete-on-Reboot, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\cert\SSL\cert.db, Delete-on-Reboot, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\cert\SSL\ContentProtector 2.cer, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss\certutil.exe, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss\mozcrt19.dll, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss\nspr4.dll, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss\nss3.dll, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss\plc4.dll, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss\plds4.dll, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss\smime3.dll, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\Program Files\ContentProtector\nss\softokn3.dll, Quarantined, [9749e63f702a41f59e85b71047bbd32d], 
PUP.Optional.ContentProtector, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ContentProtector\Settings.lnk, Quarantined, [5888c65f6d2d3bfb49db4681748ea35d], 

Physical Sectors: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites
  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.