• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove User Protection (Uninstall instructions)

Myantispyware team March 19, 2010    

User Protection is a rogue antispyware program from the same family of rogues as Dr. Guard, Paladin Antivirus and Malware Defender. The program is distributed through the use of trojans. Once the trojan infects your computer, it will add itself to the startup programs to run whenever you start Windows, and then performs several actions. First, shows many fake security alerts that inform, for example, that computer is infected, or that detected the attack from the Internet. Second, downloads and installs on your computer User Protection.

When User Protection is installed and started, it will first step register itself in the Windows registry to run automatically every time when Windows starts, Then it will ask you to uninstall legitimate antivirus and antispyware tools (Malwarebytes’ Anti-Malware, AVG, etc), to protect itself from uninstalling. After that, User Protection will run an imitation of system scan and detect numerous infections that will not be fixed unless you first purchase the software. Nothing new here, this is a scam. Like other rogue antispyware applications, the rogue is unable to detect or remove any infections and nor will be protect you from legitimate future threats. So you can safely ignore the false scan results.

While User Protection is running, you will be shown nag screens and fake security warnings from Windows task bar. A few samples:

Danger!
Harmful viruses detected on your computer. Click on the
message to scan your computer for security threats for free.

Warning! Network attack detected!
Network intrusion detected!
Your computer is being attacked from a remote PC.

Danger!
Unauthorized person tries to steal your passwords and private
information. Click on the message to prevent identity theft.

Danger!
A security threat detected on your computer.
TrojanASPX.JS.Win32. It strongly recommended to remove
this threat right now. Click on the message to remove it.

Warning! Adware detected!
Adware module detected on your PC!

Warning! Keylogger detected!
Keylogger activity detected on your PC!

Of course, all of these alerts and warnings are a fake and like false scan results should be ignored! As you can see, User Protection is a scam, that created with one purpose to scare your into purchasing so-called “full” version of the program. Most importantly, do not purchase it!

Last but not least, the same trojan that installs User Protection will also download and install onto your computer a variant of TDSS trojan. The trojan may redirect search results in Google, Yahoo, MSN, block the ability to run various antivirus and antispyware programs and much more.

If you find that your computer is infected with the rogue, then be quick and take effort to remove it immediately. Follow the removal guide below to remove User Protection and any associated malware from your computer for free.

Symptoms in a HijackThis Log

O4 – HKCU\..\Run: [diskperfxp.exe] C:\DOCUME~1\comp\LOCALS~1\Temp\diskperfxp.exe
O4 – HKCU\..\Run: [User Protection] “C:\Program Files\User Protection\usrprot.exe” -noscan

More screen shoots of User Protection



Use the following instructions to remove User Protection (Uninstall instructions)

Step 1. Remove TDSS trojan-rootkit

Download TDSSKiller from here and unzip to your desktop.

Open TDSSKiller folder. Right click to tdsskiller and select rename. Type a new name (123myapp, for example). Press Enter. Double click the TDSSKiller icon to start scanning Windows registry for TDSS trojan. If it is found, the you will see a screen similar to the one below.


TDSSKiller

Type delete and press Enter. Once TDSSKiller has finished removing rootkit TDSS, you will see a windows as shown below.


TDSSKiller

Type Y and press Enter. Your computer will be rebooted.

Step 2. Remove User Protection and any associated malware.

Download MalwareBytes Anti-malware (MBAM). Once downloaded, close all programs and windows on your computer.

Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MalwareBytes Anti-malware onto your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to “Update Malwarebytes’ Anti-Malware” and Launch “Malwarebytes’ Anti-Malware”. Then click Finish.

MalwareBytes Anti-malware will now automatically start and you will see a message stating that you should update the program before performing a scan. If an update is found, it will download and install the latest version.

As MalwareBytes Anti-malware will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main menu. You will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Make sure the “Perform quick scan” option is selected and then click on the Scan button to start scanning your computer for User Protection infection. This procedure can take some time, so please be patient.

When the scan is finished a message box will appear that it has completed scanning successfully. Click OK. Now click “Show Results”. You will see a list of infected items similar as shown below.
Note: list of infected items may be different than what is shown in the image below.


Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove User Protection. MalwareBytes Anti-malware will now remove all of associated User Protection files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.

User Protection creates the following files and folders

C:\Program Files\User Protection
%UserProfile%\Start Menu\Programs\User Protection
C:\Program Files\User Protection\usrhook.dll
C:\Program Files\User Protection\usrprot.exe
%UserProfile%\Local Settings\temp\diskperfxp.exe
C:\Documents and Settings\All Users\Desktop\spam001.exe
C:\Documents and Settings\All Users\Desktop\spam003.exe
C:\Documents and Settings\All Users\Desktop\troj000.exe
C:\Program Files\User Protection\about.ico
C:\Program Files\User Protection\activate.ico
C:\Program Files\User Protection\buy.ico
C:\Program Files\User Protection\help.ico
C:\Program Files\User Protection\scan.ico
C:\Program Files\User Protection\settings.ico
C:\Program Files\User Protection\splash.mp3
C:\Program Files\User Protection\uninstall.exe
C:\Program Files\User Protection\update.ico
C:\Program Files\User Protection\usr.db
C:\Program Files\User Protection\usrext.dll
C:\Program Files\User Protection\virus.mp3
%UserProfile%\Start Menu\Programs\User Protection\About.lnk
%UserProfile%\Start Menu\Programs\User Protection\Activate.lnk
%UserProfile%\Start Menu\Programs\User Protection\Buy.lnk
%UserProfile%\Start Menu\Programs\User Protection\Scan.lnk
%UserProfile%\Start Menu\Programs\User Protection\Settings.lnk
%UserProfile%\Start Menu\Programs\User Protection\Update.lnk
%UserProfile%\Start Menu\Programs\User Protection\User Protection Support.lnk
%UserProfile%\Start Menu\Programs\User Protection\User Protection.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\User Protection.lnk
%UserProfile%\Desktop\User Protection Support.lnk
%UserProfile%\Desktop\User Protection.lnk
C:\Documents and Settings\All Users\Desktop\nudetube.com.lnk
C:\Documents and Settings\All Users\Desktop\pornotube.com.lnk
C:\Documents and Settings\All Users\Desktop\youporn.com.lnk

User Protection creates the following registry keys and values

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\user protection
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\diskperfxp.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr

Malware removal Rogue Anti Spyware

 Previous Post

How to remove ave.exe malware

Next Post 

How to remove XP Smart Security 2010 (Uninstall guide)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

74 Comments

  1. Patrik
    ― April 12, 2010 - 8:01 am  Reply

    Joshua, it means that your computer is free from TDSS trojan. Now you can download and run Malwarebytes Anti-malware.

  2. ieqa
    ― April 12, 2010 - 8:28 am  Reply

    thanx…i’ve solved the problem..seriously this thing make me sick..once again thanx a lot..

    sharing is caring..

  3. Hailey
    ― April 12, 2010 - 1:32 pm  Reply

    Thanks so much!

  4. Sid
    ― April 16, 2010 - 9:33 pm  Reply

    What about windows 7 64-bit. My son somehow got this thing and the TDSSKiller app says it doesn’t support 64 bit when I run it. Any suggestions?

  5. Patrik
    ― April 17, 2010 - 10:20 am  Reply

    Sid, skip TDSSKiller step.

  6. Noelle
    ― April 22, 2010 - 3:40 pm  Reply

    Ok so I followed all the steps, but after Malware is done and Im clearing all the viruses off after the scan. Microsoft comes up and says thats the malware program is not working properly and shuts it down. I also still have the .lnk
    %UserProfile%\Desktop\User Protection Support.lnk
    %UserProfile%\Desktop\User Protection.lnk
    C:\Documents and Settings\All Users\Desktop\nudetube.com.lnk
    C:\Documents and Settings\All Users\Desktop\pornotube.com.lnk
    C:\Documents and Settings\All Users\Desktop\youporn.com.lnk
    icons on my desktop how should i remove those?

  7. Noelle
    ― April 22, 2010 - 3:47 pm  Reply

    Ok I tried again, I got all excited showed all the things you said it would load on my computer in quarantine. I did what you said made sure all ready to delete.
    Then I get this message.
    Microsoft Windows
    Malwarebytes anti maleware has stopped working.
    A problem cause the program to stop working correctly windows will closethe program and notify you if a solution is available 🙁

  8. Patrik
    ― April 23, 2010 - 10:33 am  Reply

    Noelle, open a new topic in our Spyware removal forum. I will check your PC.

  9. Nathanb
    ― April 26, 2010 - 12:41 am  Reply

    I’ve ran the program and it worked before, but this time it keeps telling me that it can’t remove everything and it needs to restart windows. When it does, the pop ups come right back up. I just can’t seem to get rid of the files :/

  10. Patrik
    ― April 27, 2010 - 8:25 am  Reply

    Nathanb, try update Malwarebytes and perform a resh scan.

  11. moudias
    ― May 8, 2010 - 9:30 am  Reply

    Help me please.I am doing the scan but when i press ok the program closing and i cant press”see the results”.What can i do?

  12. Patrik
    ― May 9, 2010 - 7:03 am  Reply

    moudias, please start a new topic in our Spyware removal forum. I will check your PC.

  13. Dominic
    ― May 13, 2010 - 7:36 am  Reply

    thank u very veryyyyy! much antispyware and you patrick when i see this dialog box i feel nervous i try to search a website that help me to prevent this malware…patrick and antipsyware moreeeeee powerrrr god bless. ur the best.to

  14. dulaman
    ― October 25, 2010 - 3:18 pm  Reply

    Thanks, it works, but only in safe mode.

« Previous 1 2 3

Leave a Reply to Noelle Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide
How to remove browser hijacker virus (Chrome, Firefox, IE, Edge)
adwcleaner
AdwCleaner – Review, How to use, Comments
How to reset Mozilla Firefox (Updated Apr. 2018)
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]

Recent Guides

How to remove ave.exe malware
How to remove Vista Antimalware 2010 (Uninstall instructions)
How to remove Vista Defender Pro (Removal guide)
How to remove Security Guard (Removal instructions)
How to remove Vista Smart Security 2010 (Removal guide)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.