Jump to content

Recommended Posts

What is PCProtect?

The Malwarebytes research team has determined that PCProtect is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.
More information can be found on our Malwarebytes Labs blog.

How do I know if I am infected with PCProtect?

This is how the main screen of the system optimizer looks:

main.png

You will find these icons in your taskbar, your startmenu, and on your desktop:

icons.png

and see these warnings during install:

warning1.png

warning2.png/img]

and these screens during "operations":

warning5.png

warning6.png

You may see this entry in your list of installed programs:

warning4.png

How did PCProtect get on my computer?

These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their website:

website.png

How do I remove PCProtect?

Our program Malwarebytes can detect and remove this potentially unwanted application.

  • Please download Malwarebytes to your desktop.
  • Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  • Then click Finish.
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.

Is there anything else I need to do to get rid of PCProtect?

  • No, Malwarebytes removes PCProtect completely.

How would the full version of Malwarebytes help protect me?

We hope our application and this guide have helped you eradicate this system optimizer.

As you can see below the full version of Malwarebytes would have protected you against the PCProtect installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.

 

protection1.png


Technical details for experts

You may see these entries in FRST logs:

 

(Protected Antivirus Limited -> PCProtect) C:\Program Files (x86)\PCProtect\PCProtect.exe
(Protected Antivirus Limited -> PCProtect) C:\Program Files (x86)\PCProtect\SecurityService.exe
R2 SecurityService; C:\Program Files (x86)\PCProtect\SecurityService.exe [4980480 2019-03-06] (Protected Antivirus Limited -> PCProtect)
R1 webshieldfilter; C:\Windows\System32\drivers\webshieldfilter.sys [87904 2019-03-05] (Protected Antivirus Limited -> Windows (R) Win 7 DDK provider)
C:\Users\{username}\Documents\PCProtect
C:\ProgramData\SecuritySuite
C:\Users\{username}\AppData\Roaming\PCProtect
C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PCProtect.lnk
(Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\webshieldfilter.sys
C:\Program Files (x86)\PCProtect
C:\Users\{username}\Desktop\PCProtect.lnk

PCProtect (HKLM-x32\...\PCProtect) (Version: 4.13.39 - PCProtect)
(The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\PCProtect\SSLEAY32.dll
(The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\PCProtect\LIBEAY32.dll

Alterations made by the installer:
 

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\PCProtect
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file install.name"="3/18/2019 9:07 AM, 46 bytes, A
       Adds the file installoptions.jdat"="3/18/2019 9:08 AM, 325 bytes, A
       Adds the file lib_SCAPI.dll"="3/6/2019 2:06 PM, 28592 bytes, A
       Adds the file libeay32.dll"="3/5/2019 6:00 PM, 1445888 bytes, A
       Adds the file Microsoft.VC90.CRT.manifest"="7/17/2017 7:35 PM, 524 bytes, A
       Adds the file msvcm90.dll"="3/6/2019 2:07 PM, 245232 bytes, A
       Adds the file msvcp120.dll"="7/17/2017 7:35 PM, 455328 bytes, A
       Adds the file msvcp90.dll"="7/17/2017 7:35 PM, 568832 bytes, A
       Adds the file msvcr120.dll"="7/17/2017 7:35 PM, 970912 bytes, A
       Adds the file msvcr90.dll"="7/17/2017 7:35 PM, 655872 bytes, A
       Adds the file nfapi.dll"="3/6/2019 2:07 PM, 166600 bytes, A
       Adds the file PasswordExtension.Win.exe"="3/6/2019 2:07 PM, 2439128 bytes, A
       Adds the file PasswordExtension.Win.exe.config"="3/6/2019 2:04 PM, 774 bytes, A
       Adds the file PCProtect.exe"="3/6/2019 2:07 PM, 10061720 bytes, A
       Adds the file PCProtect.exe.config"="3/6/2019 2:03 PM, 1397 bytes, A
       Adds the file ProtocolFilters.dll"="3/6/2019 2:07 PM, 385448 bytes, A
       Adds the file SCAPI.dll"="3/6/2019 2:07 PM, 94080 bytes, A
       Adds the file SecurityService.exe"="3/6/2019 2:07 PM, 4980480 bytes, A
       Adds the file SecurityService.exe.config"="3/6/2019 2:04 PM, 1426 bytes, A
       Adds the file ShellBrowser.dll"="10/26/2015 1:38 PM, 884576 bytes, A
       Adds the file ssleay32.dll"="3/5/2019 6:00 PM, 352256 bytes, A
       Adds the file System.Data.SQLite.dll"="3/6/2019 2:07 PM, 386864 bytes, A
       Adds the file uninst.exe"="3/18/2019 9:07 AM, 160439 bytes, A
       Adds the file Update.Win.exe"="3/6/2019 2:07 PM, 5071400 bytes, A
       Adds the file Update.Win.exe.config"="3/6/2019 2:04 PM, 1538 bytes, A
       Adds the file vccorlib120.dll"="7/17/2017 7:35 PM, 247984 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\bins
       Adds the file subinacl.exe"="4/19/2017 5:49 PM, 298112 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\data
       Adds the file account.jdat"="3/18/2019 9:14 AM, 1477 bytes, A
       Adds the file addon.jdat"="3/18/2019 9:08 AM, 1384 bytes, A
       Adds the file avconfig.jdat"="3/18/2019 9:12 AM, 1784 bytes, A
       Adds the file avlic.jdat"="3/18/2019 9:11 AM, 3640 bytes, A
       Adds the file certs.jdat"="3/18/2019 9:08 AM, 3067 bytes, A
       Adds the file details.jdat"="3/18/2019 9:14 AM, 224 bytes, A
       Adds the file gcld"="3/18/2019 8:58 AM, 32768 bytes, A
       Adds the file idpro.jdat"="3/18/2019 9:08 AM, 1756 bytes, A
       Adds the file prefs.jdat"="3/18/2019 9:18 AM, 1281 bytes, A
       Adds the file sdet.jdat"="3/18/2019 9:14 AM, 883 bytes, A
       Adds the file sf_notify.dict"="3/18/2019 9:08 AM, 3072 bytes, A
       Adds the file ui.jdat"="3/18/2019 9:14 AM, 2342 bytes, A
       Adds the file updates.jdat"="3/18/2019 9:08 AM, 44 bytes, A
       Adds the file vpn_locations.jdat"="3/18/2019 9:08 AM, 13620 bytes, A
       Adds the file wwwcache.dict"="3/18/2019 9:17 AM, 11264 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\data\pfdata\SSL
       Adds the file cert.db"="3/18/2019 9:08 AM, 0 bytes, A
       Adds the file PCProtect Malicious URL Protection CA 2.cer"="3/18/2019 9:08 AM, 818 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\driver\amd64
       Adds the file devcon.exe"="5/24/2016 3:59 PM, 89728 bytes, A
       Adds the file OemWin2k.inf"="5/24/2016 3:59 PM, 7288 bytes, A
       Adds the file tap0901.cat"="5/24/2016 3:59 PM, 8889 bytes, A
       Adds the file tap0901.map"="5/24/2016 3:59 PM, 14875 bytes, A
       Adds the file tap0901.pdb"="5/24/2016 3:59 PM, 404480 bytes, A
       Adds the file tap0901.sys"="5/24/2016 3:59 PM, 39040 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\driver\i386
       Adds the file devcon.exe"="5/24/2016 3:59 PM, 63616 bytes, A
       Adds the file OemWin2k.inf"="5/24/2016 3:59 PM, 7271 bytes, A
       Adds the file tap0901.cat"="5/24/2016 3:59 PM, 8853 bytes, A
       Adds the file tap0901.map"="5/24/2016 3:59 PM, 15920 bytes, A
       Adds the file tap0901.pdb"="5/24/2016 3:59 PM, 429056 bytes, A
       Adds the file tap0901.sys"="5/24/2016 3:59 PM, 33664 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\json
    Adds the folder C:\Program Files (x86)\PCProtect\locale
       Adds the file da_DK.mo"="3/5/2019 6:00 PM, 276798 bytes, A
       Adds the file de_DE.mo"="3/5/2019 6:00 PM, 291612 bytes, A
       Adds the file es_ES.mo"="3/5/2019 6:00 PM, 289348 bytes, A
       Adds the file fr_FR.mo"="3/5/2019 6:00 PM, 301341 bytes, A
       Adds the file it_IT.mo"="3/5/2019 6:00 PM, 287968 bytes, A
       Adds the file nl_NL.mo"="3/5/2019 6:00 PM, 280826 bytes, A
       Adds the file nn_NO.mo"="3/5/2019 6:00 PM, 276004 bytes, A
       Adds the file pl_PL.mo"="3/5/2019 6:00 PM, 302035 bytes, A
       Adds the file pt_PT.mo"="3/5/2019 6:00 PM, 290268 bytes, A
       Adds the file sv_SE.mo"="3/5/2019 6:00 PM, 277390 bytes, A
       Adds the file tr_TR.mo"="3/5/2019 6:00 PM, 291151 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\logs
       Adds the file main.log"="3/18/2019 9:14 AM, 273628 bytes, A
       Adds the file savapi.log"="3/18/2019 9:13 AM, 198 bytes, A
       Adds the file security_service.log"="3/18/2019 9:14 AM, 7481 bytes, A
       Adds the file service_install.log"="3/18/2019 9:07 AM, 164 bytes, A
       Adds the file service-1552896751.logc"="3/18/2019 9:12 AM, 0 bytes, A
       Adds the file threat.log"="3/18/2019 9:13 AM, 3033 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\Manifest
       Adds the file chrome-manifest.json"="3/18/2019 9:12 AM, 681 bytes, A
       Adds the file firefox-manifest.json"="3/18/2019 9:12 AM, 502 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\ovpn
       Adds the file libcrypto-1_1.dll"="3/5/2019 6:00 PM, 2651896 bytes, A
       Adds the file liblzo2-2.dll"="3/5/2019 6:00 PM, 174960 bytes, A
       Adds the file libpkcs11-helper-1.dll"="3/5/2019 6:00 PM, 115192 bytes, A
       Adds the file libssl-1_1.dll"="3/5/2019 6:00 PM, 589648 bytes, A
       Adds the file openssl.exe"="3/5/2019 6:00 PM, 932624 bytes, A
       Adds the file openvpn.exe"="3/5/2019 6:00 PM, 886400 bytes, A
       Adds the file openvpn_down.bat"="9/15/2017 5:51 PM, 475 bytes, A
       Adds the file openvpn_up.bat"="10/2/2017 4:59 PM, 784 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\ovpn\xp
       Adds the file libeay32.dll"="3/5/2019 6:00 PM, 2273256 bytes, A
       Adds the file liblzo2-2.dll"="3/5/2019 6:00 PM, 175312 bytes, A
       Adds the file libpkcs11-helper-1.dll"="3/5/2019 6:00 PM, 115488 bytes, A
       Adds the file openvpn.exe"="3/5/2019 6:00 PM, 739808 bytes, A
       Adds the file ssleay32.dll"="3/5/2019 6:00 PM, 582272 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\queues
       Adds the file 5ajp2uqh.tae.queue"="3/18/2019 9:12 AM, 0 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI
       Adds the file aebb.dll"="3/18/2019 9:12 AM, 72056 bytes, A
       Adds the file aecore.dll"="3/18/2019 9:12 AM, 278952 bytes, A
       Adds the file aecrypto.dll"="3/18/2019 9:12 AM, 141800 bytes, A
       Adds the file aedroid.dll"="3/18/2019 9:12 AM, 2805800 bytes, A
       Adds the file aedroid_gwf.dat"="3/18/2019 9:12 AM, 4371320 bytes, A
       Adds the file aeemu.dll"="3/18/2019 9:12 AM, 421160 bytes, A
       Adds the file aeexp.dll"="3/18/2019 9:12 AM, 403624 bytes, A
       Adds the file aeexp_gwf.dat"="3/18/2019 9:12 AM, 60496 bytes, A
       Adds the file aegen.dll"="3/18/2019 9:12 AM, 712088 bytes, A
       Adds the file aehelp.dll"="3/18/2019 9:12 AM, 295576 bytes, A
       Adds the file aeheur.dll"="3/18/2019 9:12 AM, 10757160 bytes, A
       Adds the file aeheur_agen.dat"="3/18/2019 9:12 AM, 1546392 bytes, A
       Adds the file aeheur_gwf.dat"="3/18/2019 9:12 AM, 912 bytes, A
       Adds the file aeheur_mv.dat"="3/18/2019 9:12 AM, 3119184 bytes, A
       Adds the file aelibinf.dll"="3/18/2019 9:12 AM, 80376 bytes, A
       Adds the file aelibinf_db.dat"="3/18/2019 9:12 AM, 88632 bytes, A
       Adds the file aelidb.dat"="3/18/2019 9:12 AM, 88248 bytes, A
       Adds the file aemobile.dll"="3/18/2019 9:12 AM, 362072 bytes, A
       Adds the file aemvdb.dat"="7/2/2015 5:52 PM, 1793 bytes, A
       Adds the file aeoffice.dll"="3/18/2019 9:12 AM, 786896 bytes, A
       Adds the file aeoffice_gwf.dat"="3/18/2019 9:12 AM, 31528 bytes, A
       Adds the file aepack.dll"="3/18/2019 9:12 AM, 856632 bytes, A
       Adds the file aerdl.dll"="3/18/2019 9:12 AM, 1263912 bytes, A
       Adds the file aesbx.dll"="3/18/2019 9:12 AM, 1667056 bytes, A
       Adds the file aescn.dll"="3/18/2019 9:12 AM, 163488 bytes, A
       Adds the file aescript.dll"="3/18/2019 9:12 AM, 1097680 bytes, A
       Adds the file aeset.dat"="3/18/2019 9:12 AM, 3272 bytes, A
       Adds the file aevdf.dat"="3/18/2019 7:00 AM, 5484 bytes, A
       Adds the file aevdf.dll"="3/18/2019 9:12 AM, 154264 bytes, A
       Adds the file apcfile.dll"="3/9/2018 5:18 PM, 1698744 bytes, A
       Adds the file apchash.dll"="1/12/2018 5:46 PM, 133264 bytes, A
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file avupdate.exe"="7/27/2017 6:32 PM, 1967224 bytes, A
       Adds the file avupdate.log"="3/18/2019 9:12 AM, 1910 bytes, A
       Adds the file avupdate_msg.avr"="7/27/2017 6:32 PM, 6392 bytes, A
       Adds the file avupdate-savapilib-engine.conf"="3/13/2018 6:02 PM, 439 bytes, A
       Adds the file cacert.crt"="3/9/2018 5:18 PM, 6065 bytes, A
       Adds the file HBEDV.KEY"="3/18/2019 9:12 AM, 1024 bytes, A
       Adds the file local000.vdf"="3/18/2019 9:12 AM, 72323584 bytes, A
       Adds the file msvcp120.dll"="2/2/2017 5:55 PM, 455328 bytes, A
       Adds the file msvcr120.dll"="2/2/2017 5:55 PM, 970912 bytes, A
       Adds the file productname.dat"="3/13/2018 5:51 PM, 17 bytes, A
       Adds the file savapi.dll"="3/9/2018 5:18 PM, 1804680 bytes, A
       Adds the file savapiclient.dll"="3/9/2018 5:18 PM, 126032 bytes, A
       Adds the file vdfupd.dll"="3/28/2014 12:47 PM, 102480 bytes, A
       Adds the file xbv00000.vdf"="3/18/2019 7:00 AM, 43855208 bytes, A
       Adds the file xbv00255.vdf"="3/18/2019 7:00 AM, 2408 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\idx
       Adds the file master.idx"="3/18/2019 9:11 AM, 56 bytes, A
       Adds the file module-vdf.info"="3/18/2019 9:12 AM, 141867 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\names_cache
       Adds the file AV-malware-names-3940-FApvl4"="3/18/2019 9:12 AM, 71275356 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access
       Adds the file on-access-drivers-install.cmd"="2/19/2018 7:38 PM, 5831 bytes, A
       Adds the file on-access-drivers-uninstall.cmd"="2/19/2018 7:38 PM, 7356 bytes, A
       Adds the file README"="3/13/2018 6:02 PM, 386 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\utils
       Adds the file on-access-drivers-final.cmd"="1/12/2018 5:27 PM, 2385 bytes, A
       Adds the file on-access-drivers-post.cmd"="3/7/2018 7:26 PM, 3835 bytes, A
       Adds the file on-access-drivers-pre.cmd"="1/12/2018 5:27 PM, 4641 bytes, A
       Adds the file sd_inst.exe"="1/12/2018 5:46 PM, 90368 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\win32\vista
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file avgntflt.inf"="2/13/2018 6:58 PM, 2463 bytes, A
       Adds the file avgntflt.sys"="2/13/2018 6:58 PM, 130912 bytes, A
       Adds the file avipbb.inf"="2/13/2018 6:58 PM, 1962 bytes, A
       Adds the file avipbb.sys"="2/13/2018 6:58 PM, 156088 bytes, A
       Adds the file avkmgr.inf"="2/13/2018 6:58 PM, 1888 bytes, A
       Adds the file avkmgr.sys"="2/13/2018 6:58 PM, 35840 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\win32\win7
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file avgntflt.cat"="2/13/2018 6:58 PM, 679 bytes, A
       Adds the file avgntflt.inf"="2/13/2018 6:58 PM, 2463 bytes, A
       Adds the file avgntflt.sys"="2/13/2018 6:58 PM, 130912 bytes, A
       Adds the file avipbb.cat"="2/13/2018 6:58 PM, 7940 bytes, A
       Adds the file avipbb.inf"="2/13/2018 6:58 PM, 1962 bytes, A
       Adds the file avipbb.sys"="2/13/2018 6:58 PM, 156088 bytes, A
       Adds the file avkmgr.cat"="2/13/2018 6:58 PM, 714 bytes, A
       Adds the file avkmgr.inf"="2/13/2018 6:58 PM, 1888 bytes, A
       Adds the file avkmgr.sys"="2/13/2018 6:58 PM, 35840 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\win32\win8
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file avgntflt.cat"="2/13/2018 6:58 PM, 9565 bytes, A
       Adds the file avgntflt.inf"="2/13/2018 6:58 PM, 2536 bytes, A
       Adds the file avgntflt.sys"="2/13/2018 6:58 PM, 147576 bytes, A
       Adds the file avipbb.cat"="2/13/2018 6:58 PM, 9648 bytes, A
       Adds the file avipbb.inf"="2/13/2018 6:58 PM, 2051 bytes, A
       Adds the file avipbb.sys"="2/13/2018 6:58 PM, 168776 bytes, A
       Adds the file avkmgr.cat"="2/13/2018 6:58 PM, 9567 bytes, A
       Adds the file avkmgr.inf"="2/13/2018 6:58 PM, 1888 bytes, A
       Adds the file avkmgr.sys"="2/13/2018 6:58 PM, 53256 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\win32\xp
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file avgntflt.inf"="2/13/2018 6:58 PM, 2463 bytes, A
       Adds the file avgntflt.sys"="2/13/2018 6:58 PM, 130912 bytes, A
       Adds the file avipbb.inf"="2/13/2018 6:58 PM, 1962 bytes, A
       Adds the file avipbb.sys"="2/13/2018 6:58 PM, 156088 bytes, A
       Adds the file avkmgr.inf"="2/13/2018 6:58 PM, 1888 bytes, A
       Adds the file avkmgr.sys"="2/13/2018 6:58 PM, 35840 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\win64\vista
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file avgntflt.cat"="3/6/2018 5:35 PM, 7831 bytes, A
       Adds the file avgntflt.inf"="3/6/2018 5:35 PM, 2536 bytes, A
       Adds the file avgntflt.sys"="3/6/2018 5:35 PM, 196344 bytes, A
       Adds the file avipbb.cat"="3/6/2018 5:35 PM, 7940 bytes, A
       Adds the file avipbb.inf"="3/6/2018 5:35 PM, 2052 bytes, A
       Adds the file avipbb.sys"="3/6/2018 5:35 PM, 153552 bytes, A
       Adds the file avkmgr.cat"="3/6/2018 5:35 PM, 7829 bytes, A
       Adds the file avkmgr.inf"="3/6/2018 5:35 PM, 2000 bytes, A
       Adds the file avkmgr.sys"="3/6/2018 5:35 PM, 35328 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\win64\win7
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file avgntflt.cat"="2/13/2018 6:58 PM, 7831 bytes, A
       Adds the file avgntflt.inf"="2/13/2018 6:58 PM, 2536 bytes, A
       Adds the file avgntflt.sys"="2/13/2018 6:58 PM, 196344 bytes, A
       Adds the file avipbb.cat"="2/13/2018 6:58 PM, 7940 bytes, A
       Adds the file avipbb.inf"="2/13/2018 6:58 PM, 2052 bytes, A
       Adds the file avipbb.sys"="2/13/2018 6:58 PM, 153552 bytes, A
       Adds the file avkmgr.cat"="2/13/2018 6:58 PM, 7829 bytes, A
       Adds the file avkmgr.inf"="2/13/2018 6:58 PM, 2000 bytes, A
       Adds the file avkmgr.sys"="2/13/2018 6:58 PM, 35328 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\win64\win8
       Adds the file avgio.dll"="3/7/2018 7:26 PM, 61872 bytes, A
       Adds the file avgntflt.cat"="2/13/2018 6:58 PM, 9573 bytes, A
       Adds the file avgntflt.inf"="2/13/2018 6:58 PM, 2536 bytes, A
       Adds the file avgntflt.sys"="2/13/2018 6:58 PM, 178840 bytes, A
       Adds the file avipbb.cat"="2/13/2018 6:58 PM, 9656 bytes, A
       Adds the file avipbb.inf"="2/13/2018 6:58 PM, 2052 bytes, A
       Adds the file avipbb.sys"="2/13/2018 6:58 PM, 169864 bytes, A
       Adds the file avkmgr.cat"="2/13/2018 6:58 PM, 9574 bytes, A
       Adds the file avkmgr.inf"="2/13/2018 6:58 PM, 2000 bytes, A
       Adds the file avkmgr.sys"="2/13/2018 6:58 PM, 44488 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\on_access\win64\xp
       Adds the file avgio.dll"="3/13/2018 3:54 PM, 61872 bytes, A
       Adds the file avgntflt.inf"="3/13/2018 2:57 PM, 2400 bytes, A
       Adds the file avgntflt.sys"="3/13/2018 2:57 PM, 187592 bytes, A
       Adds the file avipbb.inf"="3/13/2018 2:57 PM, 1912 bytes, A
       Adds the file avipbb.sys"="3/13/2018 2:57 PM, 144832 bytes, A
       Adds the file avkmgr.inf"="3/13/2018 2:57 PM, 1937 bytes, A
       Adds the file avkmgr.sys"="3/13/2018 2:57 PM, 27424 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\SAVAPI\tmp
    Adds the folder C:\Program Files (x86)\PCProtect\startup
       Adds the file startup.json"="3/18/2019 9:13 AM, 2 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\tdi\amd64
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 75944 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\tdi\i386
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 70016 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\wfp\windows10\amd64
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 98944 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\wfp\windows10\i386
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 87416 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\wfp\windows7\amd64
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 87904 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\wfp\windows7\i386
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 75376 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\wfp\windows8
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\wfp\windows8\amd64
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 89520 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\urldrv\wfp\windows8\i386
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 78184 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\x64
       Adds the file SQLite.Interop.dll"="3/6/2019 2:07 PM, 1462488 bytes, A
    Adds the folder C:\Program Files (x86)\PCProtect\x86
       Adds the file SQLite.Interop.dll"="3/6/2019 2:07 PM, 1036976 bytes, A
    Adds the folder C:\ProgramData\SecuritySuite\Quarantine
    In the existing folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
       Adds the file PCProtect.lnk"="3/18/2019 9:08 AM, 1040 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\PCProtect
       Adds the file vdf_1552896517.zip"="3/18/2019 9:11 AM, 74487828 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\PCProtect\3.0.0
       Adds the file avira32redist.zip"="3/18/2019 9:08 AM, 16538155 bytes, A
    In the existing folder C:\Users\{username}\Desktop
       Adds the file PCProtect.lnk"="3/18/2019 9:07 AM, 1019 bytes, A
    In the existing folder C:\Windows\System32\drivers
       Adds the file webshieldfilter.sys"="3/5/2019 6:00 PM, 87904 bytes, A
    In the existing folder C:\Windows\System32\NDF
       Adds the file eventlog.etl"="3/18/2019 9:10 AM, 0 bytes

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\NativeMessagingHosts\com.pcprotect.passwordvaultassistant]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\PCProtect\Manifest\firefox-manifest.json"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PCProtect]
       "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\PCProtect\uninst.exe"
       "DisplayName"="REG_SZ", "PCProtect"
       "DisplayVersion"="REG_SZ", "4.13.39"
       "HelpLink"="REG_SZ", "http://support.pcprotect.com"
       "InstallLocation"="REG_SZ", "C:\Program Files (x86)\PCProtect"
       "MajorVersion"="REG_SZ", "4"
       "MinorVersion"="REG_SZ", "13"
       "Publisher"="REG_SZ", "PCProtect"
       "UninstallString"="REG_SZ", "C:\Program Files (x86)\PCProtect\uninst.exe"
       "URLInfoAbout"="REG_SZ", "http://www.pcprotect.com"
       "VersionMajor"="REG_SZ", "4"
       "VersionMinor"="REG_SZ", "13"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SecurityService]
       "DelayedAutostart"="REG_DWORD", 0
       "Description"="REG_SZ", "Responsible for managing PC security"
       "DisplayName"="REG_SZ", "PC Security Management Service"
       "ErrorControl"="REG_DWORD", 1
       "ImagePath"="REG_EXPAND_SZ, ""C:\Program Files (x86)\PCProtect\SecurityService.exe""
       "ObjectName"="REG_SZ", "LocalSystem"
       "Start"="REG_DWORD", 2
       "Type"="REG_DWORD", 16
       "WOW64"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SecurityService\Security]
       "Security"="REG_BINARY, ........0................p.................... .............................................
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\webshieldfilter]
       "DisplayName"="REG_SZ", "webshieldfilter"
       "ErrorControl"="REG_DWORD", 1
       "Group"="REG_SZ", "PNP_TDI"
       "ImagePath"="REG_EXPAND_SZ, "system32\drivers\webshieldfilter.sys"
       "Start"="REG_DWORD", 1
       "Tag"="REG_DWORD", 9
       "Type"="REG_DWORD", 1
       "WOW64"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\webshieldfilter\Enum]
       "0"="REG_SZ", "Root\LEGACY_WEBSHIELDFILTER\0000"
       "Count"="REG_DWORD", 1
       "NextInstance"="REG_DWORD", 1
    [HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{d79b57ed-727c-4ab8-ba67-e7c6fd30fac1}\LocalServer32]
       "(Default)"="REG_SZ", "C:\Program Files (x86)\PCProtect\PCProtect.exe"
    [HKEY_CURRENT_USER\Software\SSProtect\SecuritySuite]
       "AutoLogin"="REG_DWORD", 1
       "Install"="REG_DWORD", 1552896480

Malwarebytes log:
 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 3/18/19
Scan Time: 11:00 AM
Log File: b0f901a2-4964-11e9-8294-00ffdcc6fdfc.json

-Software Information-
Version: 3.7.1.2839
Components Version: 1.0.538
Update Package Version: 1.0.9728
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {computername}\{username}

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 235366
Threats Detected: 29
Threats Quarantined: 29
Time Elapsed: 4 min, 4 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 2
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\PCProtect.exe, Quarantined, [653], [503746],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\SECURITYSERVICE.EXE, Quarantined, [653], [503747],1.0.9728

Module: 8
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\PCProtect.exe, Quarantined, [653], [503746],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\SECURITYSERVICE.EXE, Quarantined, [653], [503747],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\PROTOCOLFILTERS.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\SCAPI.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\NFAPI.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\X86\SQLITE.INTEROP.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\X86\SQLITE.INTEROP.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\LIB_SCAPI.DLL, Quarantined, [653], [652430],1.0.9728

Registry Key: 2
PUP.Optional.PCProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SECURITYSERVICE, Quarantined, [653], [503747],1.0.9728
PUP.Optional.PCProtect, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCProtect, Quarantined, [653], [503746],1.0.9728

Registry Value: 1
PUP.Optional.PCProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SECURITYSERVICE|IMAGEPATH, Quarantined, [653], [503747],1.0.9728

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 16
PUP.Optional.PCProtect, C:\Windows\System32\drivers\webshieldfilter.sys, Quarantined, [653], [652430],0.0.0
PUP.Optional.PCProtect, C:\USERS\{username}\DESKTOP\PCPROTECT.LNK, Quarantined, [653], [354599],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\PasswordExtension.Win.exe, Quarantined, [653], [503746],1.0.9728
PUP.Optional.PCProtect, C:\USERS\{username}\APPDATA\ROAMING\Microsoft\Windows\Start Menu\Programs\PCProtect.lnk, Quarantined, [653], [503746],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\PCProtect.exe, Quarantined, [653], [503746],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\SECURITYSERVICE.EXE, Quarantined, [653], [503747],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\uninst.exe, Quarantined, [653], [503746],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\Update.Win.exe, Quarantined, [653], [503746],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\PROTOCOLFILTERS.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\SCAPI.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\NFAPI.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\X86\SQLITE.INTEROP.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\LIB_SCAPI.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\MSVCM90.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\PROGRAM FILES (X86)\PCPROTECT\SYSTEM.DATA.SQLITE.DLL, Quarantined, [653], [652430],1.0.9728
PUP.Optional.PCProtect, C:\USERS\{username}\DESKTOP\PCPROTECT_SETUP.EXE, Quarantined, [653], [652430],1.0.9728

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

As mentioned before the full version of Malwarebytes could have protected your computer against this threat.
We use different ways of protecting your computer(s):

  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention

Save yourself the hassle and get protected.

Share this post


Link to post
Share on other sites
Sign in to follow this  

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.