Home Malware Programs Potentially Unwanted Programs (PUPs) Protectium

Protectium

Posted: January 19, 2015

Threat Metric

Threat Level: 1/10
Infected PCs: 260
First Seen: January 20, 2015
Last Seen: November 17, 2022
OS(es) Affected: Windows

Protectium is an application classified as adware that is created and developed by Pinwid Ltd. The Protectium adware installs a Chromium-based browser extension that is designed to deliver ads and alter search results via SimilarSites. Ad-supported applications such as Protectium are known to collect information about users such as their browsing habits and history in order to present relevant ads. Advertisements displayed by Protectium are quite annoying and although looking to be useful, they are not. Ads by Protectium are a simple redirect method that provide online traffic to third party websites.

Aliases

Pindi.8CC [AVG]Artemis!660E8B0A3CCD [McAfee]Artemis [McAfee-GW-Edition]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\Start Menu\Programs\Startup\Protectium.exe.lnk File name: Protectium.exe.lnk
Size: 1.94 KB (1949 bytes)
MD5: 3a4d3409edb0757f511f084b58100d16
Detection count: 9
File type: Shortcut
Mime Type: unknown/lnk
Path: %ALLUSERSPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: January 20, 2015
C:\Users\<username>\appdata\local\protectium\navigator\Protectium.exe File name: C:\Users\<username>\appdata\local\protectium\navigator\Protectium.exe
MD5: af60d9099288b19cd1f668eac484eab0
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Extensions.crx File name: Extensions.crx
Mime Type: unknown/crx
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathProtectium.lnkHKEY..\..\..\..{RegistryKeys}Software\Classes\ProtectiumHtmlSOFTWARE\Clients\StartMenuInternet\Protectium.exeSoftware\ProtectiumSOFTWARE\RegisteredApplications\Protectium.NSJA6BHDA3NCFCFMXW3QSCUYUQSOFTWARE\Wow6432Node\Clients\StartMenuInternet\Protectium.exeSOFTWARE\Wow6432Node\RegisteredApplications\Protectium.NSJA6BHDA3NCFCFMXW3QSCUYUQ

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Protectium%LOCALAPPDATA%\protectium
The following URL's were detected:
www.protectium.com
Loading...