Active Shield

It includes Elevated threats that are typically installed without adequate notice and consent, and may make unwanted changes to our system, such as reconfiguring our browser’s homepage and search settings. These threats may install advertising-related add-ons, including toolbars and search bars, or insert advertising-related components into the Winsock Layered Service Provider chain. These new add-ons and components may block or redirect our preferred network connections, and can negatively impact our computer’s performance and stability. Elevated threats may also collect, transmit, and share potentially sensitive data without adequate notice and consent.0

General information:

Malware Name: Active Shield
Malware Type: Adware
Company Name: Security Stronghold
Company URL: http://www.securitystronghold.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation.

Company Description:

Security Stronghold is a company that specializes in the protection of computers from malicious programs like trojans, spyware, adware, trackware, dialers, keyloggers and other viruses. Its products are intended both for corporate and home users. Its products will help us to turn our computer into Secure Stronghold.

Spyware Description:

It includes Elevated threats that are typically installed without adequate notice and consent, and may make unwanted changes to our system, such as reconfiguring our browser’s homepage and search settings. These threats may install advertising-related add-ons, including toolbars and search bars, or insert advertising-related components into the Winsock Layered Service Provider chain. These new add-ons and components may block or redirect our preferred network connections, and can negatively impact our computer’s performance and stability. Elevated threats may also collect, transmit, and share potentially sensitive data without adequate notice and consent.0

Characteristics/Symptoms:

    -> False positives work as good to purchase -> False scan results -> Uses inadequate scan/detection scheme -> Uses out of date ref database0

Additional information might be found here:

google Search at Google for Active Shield
bing Search at Bing for Active Shield
yahoo Search at Yahoo for Active Shield

Processes Running:

ActiveShield.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\Security Stronghold\SS Active Shield\Backups.dat 4 DAT File
C:\Program Files\Security Stronghold\SS Active Shield\Res\alert_exit.jpg 24323 JPEG Image
C:\Program Files\Security Stronghold\SS Active Shield\as_pad.xml 10186 XML Document

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\All Users\Start Menu\Programs\Active Shield
C:\Program Files\Security Stronghold\SS Active Shield\Res

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionUninstallActive Shield_is1 DisplayName
HKEY_LOCAL_MACHINE SOFTWARESecurity StrongholdActive Shield FilePath
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Active Shield_is1 UninstallString