<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; ProtectionCenter</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/protectioncenter/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Protection Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 23:07:41 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[ProtectionCenter]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=938</guid>
		<description><![CDATA[The Emsisoft malware research team has discoverd a new outbreak of the Protection Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.ProtectionCenter. Protection Center is a rogue security program. This is a new variant from Data Protection, Digital Protection, Your Protection, User Protection,  Dr. Guard , and PaladinAntivirus. This rogue application tries to trick you [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has          discoverd a new outbreak           of the <strong>Protection Center </strong>adware.   <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                    Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ProtectionCenter" target="_blank">Adware.Win32.ProtectionCenter</a></strong>.</p>
<p><strong>Protection Center </strong>is a rogue security program. This   is   a new variant from <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataProtection" target="_blank">Data Protection</a></strong>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataProtection" target="_blank"><strong>Digital Protection</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.YourProtection" target="_blank"><strong>Your Protection</strong></a>, <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UserProtection" target="_blank">User Protection</a></strong>,  <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DrGuard" target="_blank"><strong>Dr. Guard </strong></a>, and <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PaladinAntivirus" target="_blank">PaladinAntivirus</a>.</strong> This  rogue       application      tries to trick you  by displaying  false         positive/misleading  scan     results  report, which  says that your          computer is infected with      viruses or  trojan, but you  will  not    be     able  to delete them before you      purchase. This rogue also found bundled with <a href="http://blog.emsisoft.com/2010/06/08/youve-got-twit-err-problems/" target="_blank"><strong>TDSS rootkit</strong></a>.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Protection Center\cntprot.exe</li>
<li>%ProgramFiles%\Protection Center\help.ico</li>
<li>%ProgramFiles%\Protection Center\scan.ico</li>
<li>%ProgramFiles%\Protection Center\settings.ico</li>
<li>%ProgramFiles%\Protection Center\splash.mp3</li>
<li>%ProgramFiles%\Protection Center\Uninstall.exe</li>
<li>%ProgramFiles%\Protection Center\update.ico</li>
<li>%ProgramFiles%\Protection Center\virus.mp3</li>
<li>%ProgramFiles%\Protection Center\about.ico</li>
<li>%ProgramFiles%\Protection Center\activate.ico</li>
<li>%ProgramFiles%\Protection Center\buy.ico</li>
<li>%ProgramFiles%\Protection Center\cnt.db</li>
<li>%ProgramFiles%\Protection Center\cntext.dll</li>
<li>%ProgramFiles%\Protection Center\cnthook.dll</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Protection Center.lnk</li>
<li>%UserProfile%\Desktop\Protection Center.lnk</li>
<li>%UserProfile%\Desktop\Protection Center Support.lnk</li>
<li>%UserProfile%\Local Settings\Temp\4otjesjty.mof</li>
<li>%UserProfile%\Local Settings\Temp\451d.tmp</li>
<li>%UserProfile%\Local Settings\Temp\3722.tmp</li>
<li>%UserProfile%\Local Settings\Temp\7461.tmp</li>
<li>%UserProfile%\Local Settings\Temp\cnt.dat</li>
<li>%UserProfile%\Local Settings\Temp\cntr.dat</li>
<li>%UserProfile%\Local Settings\Temp\dhdhtrdhdrtr5y</li>
<li>%UserProfile%\Local Settings\Temp\2bf7.tmp</li>
<li>%UserProfile%\Local Settings\Temp\4f4e.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Protection Center Support.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Protection Center.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Scan.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Settings.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Update.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\About.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Activate.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Protection Center\Buy.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Protection Center</li>
<li>HKEY_LOCAL_MACHINE\software\Protection Center</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, &#8220;Protection Center&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.ProtectionCenter_1.png"><img class="alignnone size-medium wp-image-939" title="Adware.Win32.ProtectionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/06/Adware.Win32.ProtectionCenter_1-400x296.png" alt="" width="400" height="296" /></a></p>
<p><strong>How to remove the infection of Protection</strong><strong> Center </strong><strong>(Adware.Win32.</strong><strong>Protection</strong><strong>Center)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                   Anti-Malware</a></strong>. Run a full scan on all drives and      move     all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/06/17/defense-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Defense Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/user-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">User Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/09/30/anvi-adware-removal-instructions/" rel="bookmark" class="crp_title">AnVi Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/15/data-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/16/digital-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Digital Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

