Im-Infected / Popups / Your PC is not Protected – Pop up
Im-Infected / Popups / Your PC is not Protected – Pop up

Your PC is not Protected – Pop up

July 8th, 2009 No Comment

“Your PC is not Protected” is a pop-up alert coming from Windows task bar to fake computer users about its legitimacy. Seems to be an alert from Windows but its is not. Actually it originates from a Trojan that infected the computer prior to promoting rogue application. This alert was issued by rogue program AntivirusBEST and full message says:

Your PC is not protected.
Security center reports that ‘AntivirusBEST’ is inactive. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the suggested actions. Your system might be at risk now.”

If you execute or follow the link, it may lead to acquisition of the endorsed security product by opening a new browser window that points to payment processing page. Aside from the infection, this fraudulent actions will also steal credit card information once it was used in the transaction.

Type Popup
Sub-Type FakeAV
Aliases  
OS Affected Windows
Detected By MalwareBytes

What ”Your PC is not Protected” Does?

Po-pup will ascend from Windows task-bar and state that computer is infected with viruses.

Your-PC-is-not-protected-system-alert

It will create Windows Registry entries:

  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Current Version\Ext\Stats\{44b2c9f5-608d-46de-82e1-26c5bcb85193}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Explorer\Browser Helper Objects\{44b2c9f5-608d-46de-82e1-26c5bcb85193}
  • HKEY_CLASSES_ROOT\qwprotect.qwprotectbho
  • HKEY_CLASSES_ROOT\Interface\{296a8a7f-b5ac-4789-9b33-f32c2f9a6abd}
  • HKEY_CLASSES_ROOT\CLSID\{44b2c9f5-608d-46de-82e1-26c5bcb85193}
  • HKEY_CLASSES_ROOT\qwprotect.qwprotectbho.1
  • HKEY_CLASSES_ROOT\AppID\{296a8a7f-b5ac-4789-9b33-f32c2f9a6abd}
  • HKEY_CLASSES_ROOT\AppID\QWProtect.dll
  • HKEY_CLASSES_ROOT\TypeLib\{684a7904-2593-4bbe-a90e-cdaf2ac606ae}

The threat will drop the following malicious files:

  • c:\Documents and Settings\All Users\Application Data\AB\QWProtect.dll
  • c:\documents and settings\All Users\Application Data\AB\ABEST.CAB
  • c:\documents and settings\All Users\Start Menu\Programs\AntiVirusBEST
  • c:\Documents and Settings\All Users\Application Data\AB\abest.exe
  • c:\Documents and Settings\All Users\Application Data\AB\Installer.exe
  • c:\documents and settings\All Users\Application Data\AB\svchost.exe
  • c:\documents and settings\all users\start menu\Programs\antivirusbest\AntivirusBEST.lnk
  • c:\documents and settings\all users\start menu\Programs\antivirusbest\Uninstall.lnk
  • c:\documents and settings\all users\Desktop\AntivirusBEST.lnk
  • c:\Documents and Settings\All Users\Application Data\AB\

How to Remove ”Your PC is not Protected” Manually

1. Restart your computer in SafeMode
- After Power-On the computer, just before Windows start, press F8
- From the selections, Select SafeMode

2. Remove Registry entry/entries that the threat added. You MUST BACKUP YOUR REGISTRY FIRST.
- Click Start > Run
- Type in the field, regedit
- Navigate and look for the registry entries mentioned above and delete if necessary

3. Delete malicious files that the threat added:
- Base on the given location above, browse and delete the file
- If no location is given, click Start>Search> and search for the file.
- If cannot be deleted, press Ctrl+Alt+Del to access Task Manager, see if the file is running in the process. If it is, select the file and click End Process. Perform file delete again.

How to Easily Remove “Your PC is not Protected”

1. Print this procedure as we need to close all programs running later.
2. Download AntiMalware Application here and save it to your Desktop.
3. Close all open applications.
4. Double-Click on the downloaded mbam-setup.exe to start the installation. If unable to execute, infections on computer is preventing it from running, rename the file mbam-setup.exe to anything (like myfile.exe)
5. Run the installation on the default settings. No changes are necessary.
6. Just before completing the installation, make sure that the following are marked check.
- Update the program
- Launch the program

7. The tool will run and update itself after installation. Close it after the update.

8. Restart your computer in SafeMode
- After Power-On the computer, just before Windows start, press F8
- From the selections, Select SafeMode

9. Click on the icon and start to Perform Full Scan to begin scanning your computer for Malware related files.
10. After scanning, a message will appear stating that the scan is completed successfully. Click OK.
11. Click Show Results and detected threats will be displayed.
12. Make sure that all threats are marked check, then click Remove Selected to begin removal of the malicious files.
13. Exit MBAM and restart your computer.

14. Malware and all its files are now removed from your computer. To guard your computer from this threat and avoid future infections, you may want real-time protection from AntiMalware Apps.

Categories: Popups Tags:

Your PC is not Protected – Pop up Discussions

  1. No comments yet.