Mar 19

Threat Description:

User Protection is rogue anti-spyware maintaining the renegade rip-off activities of its precursors known as Paladin Antivirus and Dr. Guard. User Protection usually appears on one’s computer unexpectedly and needs no particular ‘invitation’ to get on board. This backdoor infiltration is an outcome of trojan-generated unsolicited trespassing, so you may not notice when and how it User Protection installs on your PC. The malicious software in question is more than aggressive when it comes to the direct fulfillment of its objectives. It jacks up your OS and compels your workstation to display lots of popup ads that scanners of doubtful trustworthiness. Those adware items may stun you with the information they report. They state that you’ve got some serious security risks on your computer. According to User Protection, these ‘serious’ issues need to be taken care of in the shortest possible time, or else the consequences will make you regret much to have done nothing to prevent them. The sole fact that User Protection is rogue anti-spyware, none of its warning messages can be taken for granted, nor should you follow its recommendations. What does User Protection recommend? It prompts you to register its licensed copy and this is stated to be of great help to you. We say – anything User Protection tells you is scam. It just wants to swindle you out of some money and provide no help in return. User Protection can’t detect and remove computer threats so please stay away from it. User Protection uninstall tips are below this article, go ahead and try them.

Determine if your system is infected with User Protection and related threats:

User Protection Screenshot:

User Protection

How to remove this threat manually:

User Protection manual uninstall procedure:

Get rid of the related corrupt files:

  • %Documents and Settings%\[UserName]\Desktop\User Protection Support.lnk
  • %Documents and Settings%\[UserName]\Desktop\User Protection.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection\About.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection\Activate.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection\Buy.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection\User Protection Support.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection\User Protection.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection\Scan.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection\Settings.lnk
  • %Documents and Settings%\[UserName]\Start Menu\Programs\User Protection\Update.lnk
  • %Documents and Settings%\[UserName]\Application Data\Microsoft\Internet Explorer\Quick Launch\User Protection.lnk
  • %Program Files%\User Protection
  • %Program Files%\User Protection\about.ico
  • %Program Files%\User Protection\activate.ico
  • %Program Files%\User Protection\buy.ico
  • %Program Files%\User Protection\drg.db
  • %Program Files%\User Protection\drgext.dll
  • %Program Files%\User Protection\drghook.dll
  • %Program Files%\User Protection\help.ico
  • %Program Files%\User Protection\scan.ico
  • %Program Files%\User Protection\settings.ico
  • %Program Files%\User Protection\splash.mp3
  • %Program Files%\User Protection\uninstall.exe
  • %Program Files%\User Protection\update.ico
  • %Program Files%\User Protection\virus.mp3
  • %Temp%\asr64_ldm.exe

Delete the associated registry entries:

  • HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\SimpleShlExt
  • HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
  • HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\User Protection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\User Protection
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “User Protection”
  • HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved “{5E2121EE-0300-11D4-8D3B-444553540000}”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = “1″

Please note that User Protection manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download User Protection Removal Tool

Leave a Reply