Archive for January, 2010

Jan 20

ProtectDefender Adware Removal Instructions

The Emsi Software malware research team has discoverd a new outbreak of the ProtectDefender adware. a-squared Anti-Malware detects this malware as Adware.Win32.ProtectDefender.

ProtectDefender, come from hxxp://www.protectdefender.com, is a rogue security program. This is a new variant from Winiguard/Winisoft family. The author of ProtectDefender also made ArmorDefender, DefendAPc, SysDefenders, InSysSecure, SysProtector, APcDefender, PcProtectar, PcsProtector, GreatDefender, APCProtect, ProtectPcs, SysDefence, TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, REAnti, KeepCop, SecureKeeper, LinkSafeness, AntiAid, SystemFighter, SystemVeteran, BlockProtector, BlockKeeper, BlockScanner, BlockWatcher, SoftStronghold, ShieldSafeness, SoftVeteran, SoftSoldierSoftCop, TrustFighter, TrustSoldier, SafeFighter, SecureVeteran, etc. To further convince victims, ProtectDefender will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.

Create new files:

  • %ProgramFiles%\ProtectDefender Software\ProtectDefender\always_skip.xml
  • %ProgramFiles%\ProtectDefender Software\ProtectDefender\ProtectDefender.exe
  • %ProgramFiles%\ProtectDefender Software\ProtectDefender\Uninstall.exe
  • %ProgramFiles%\ProtectDefender Software\ProtectDefender\always_delete.xml
  • %ProgramFiles%\ProtectDefender Software\ProtectDefender\quarantine\quarantine.xml
  • %UserProfile%\Cookies\userdemo@protectdefender[2].txt
  • %UserProfile%\Desktop\ProtectDefender.lnk
  • %UserProfile%\Start Menu\Programs\ProtectDefender.lnk

Create new registry entries:

  • HKEY_LOCAL_MACHINE\software\ProtectDefender
  • HKEY_CURRENT_USER\software\ProtectDefender
  • HKEY_CURRENT_USER\software\ProtectDefender\agents
  • HKEY_CURRENT_USER\software\ProtectDefender\general
  • HKEY_CURRENT_USER\software\ProtectDefender\realtime
  • HKEY_CURRENT_USER\software\ProtectDefender\scanner
  • HKEY_CURRENT_USER\software\ProtectDefender\tasks
  • HKEY_CURRENT_USER\software\ProtectDefender\tasks\0
  • HKEY_CURRENT_USER\software\ProtectDefender\tasks\1
  • HKEY_CURRENT_USER\software\ProtectDefender\updates
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ProtectDefender
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “ProtectDefender”
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “ProtectDefender”

Screenshots:

How to remove the infection of ProtectDefender (Adware.Win32.ProtectDefender)?

To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

Jan 19

ArmorDefender Adware Removal Instructions

The Emsi Software malware research team has discoverd a new outbreak of the ArmorDefender adware. a-squared Anti-Malware detects this malware as Adware.Win32.ArmorDefender.

ArmorDefender, come from hxxp://www.armordefender.com, is a rogue security program. This is a new variant from Winiguard/Winisoft family, with a new GUI. The author of ArmorDefender also made DefendAPc, SysDefenders, InSysSecure, SysProtector, APcDefender, PcProtectar, PcsProtector, GreatDefender, APCProtect, ProtectPcs, SysDefence, TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, REAnti, KeepCop, SecureKeeper, LinkSafeness, AntiAid, SystemFighter, SystemVeteran, BlockProtector, BlockKeeper, BlockScanner, BlockWatcher, SoftStronghold, ShieldSafeness, SoftVeteran, SoftSoldierSoftCop, TrustFighter, TrustSoldier, SafeFighter, SecureVeteran, etc. To further convince victims, ArmorDefender will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.

Create new files:

  • %ProgramFiles%\ArmorDefender Software\ArmorDefender\Uninstall.exe
  • %ProgramFiles%\ArmorDefender Software\ArmorDefender\ArmorDefender.exe
  • %SystemRoot%\system32\kus4.tmp.exe
  • %UserProfile%\Cookies\userdemo@armordefender[1].txt
  • %UserProfile%\Desktop\ArmorDefender.lnk
  • %UserProfile%\Local Settings\Temp\vow3.tmp.exe
  • %UserProfile%\Local Settings\Temp\kus4.tmp.exe
  • %UserProfile%\Start Menu\Programs\ArmorDefender.lnk

Create new registry entries:

  • HKEY_LOCAL_MACHINE\software\ArmorDefender
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\ArmorDefender
  • HKEY_CURRENT_USER\software\ArmorDefender
  • HKEY_CURRENT_USER\software\ArmorDefender\agents
  • HKEY_CURRENT_USER\software\ArmorDefender\general
  • HKEY_CURRENT_USER\software\ArmorDefender\realtime
  • HKEY_CURRENT_USER\software\ArmorDefender\scanner
  • HKEY_CURRENT_USER\software\ArmorDefender\tasks
  • HKEY_CURRENT_USER\software\ArmorDefender\tasks\0
  • HKEY_CURRENT_USER\software\ArmorDefender\tasks\1
  • HKEY_CURRENT_USER\software\ArmorDefender\updates
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “ArmorDefender”
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “ArmorDefender”

Screenshots:

How to remove the infection of ArmorDefender (Adware.Win32.ArmorDefender)?

To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

Jan 18

Win Security 360 Adware Removal Instructions

The Emsi Software malware research team has discoverd a new outbreak of the Win Security 360 adware. a-squared Anti-Malware detects this malware as Adware.Win32.WinSecurity360.

Win Security 360 is a rogue security program. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you purchase.

Create new files:

  • %ProgramFiles%\WinSecurity360\Win Security 360.url
  • %ProgramFiles%\WinSecurity360\Win Security 360 Help.url
  • %ProgramFiles%\WinSecurity360\WinSecurity360.exe
  • %ProgramFiles%\WinSecurity360\sk.lst
  • %UserProfile%\Application Data\WinSecurity360\vlc.dat
  • %UserProfile%\Application Data\WinSecurity360\WinSecurity360.ini
  • %UserProfile%\Application Data\WinSecurity360\rmd.dat
  • %UserProfile%\Desktop\Win Security 360.lnk
  • %UserProfile%\Start Menu\Programs\Startup\Win Security 360.lnk
  • %UserProfile%\Start Menu\Programs\Win Security 360\Website.lnk
  • %UserProfile%\Start Menu\Programs\Win Security 360\Win Security 360.lnk
  • %UserProfile%\Start Menu\Programs\Win Security 360\Win Security 360 Help.lnk

Create new registry entry:

  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\App Paths\WinSecurity360

Screenshots:

How to remove the infection of Win Security 360 (Adware.Win32.WinSecurity360)?

To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

Jan 18

DefendAPc Adware Removal Instructions

The Emsi Software malware research team has discoverd a new outbreak of the DefendAPc adware. a-squared Anti-Malware detects this malware as Adware.Win32.DefendAPc.

DefendAPc, come from hxxp://www.defendapc.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of DefendAPc also made SysDefenders, InSysSecure, SysProtector, APcDefender, PcProtectar, PcsProtector, GreatDefender, APCProtect, ProtectPcs, SysDefence, TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, REAnti, KeepCop, SecureKeeper, LinkSafeness, AntiAid, SystemFighter, SystemVeteran, BlockProtector, BlockKeeper, BlockScanner, BlockWatcher, SoftStronghold, ShieldSafeness, SoftVeteran, SoftSoldierSoftCop, TrustFighter, TrustSoldier, SafeFighter, SecureVeteran, etc. To further convince victims, DefendAPc will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.

Create new files:

  • %ProgramFiles%\DefendAPc Software\DefendAPc\always_delete.xml
  • %ProgramFiles%\DefendAPc Software\DefendAPc\always_skip.xml
  • %ProgramFiles%\DefendAPc Software\DefendAPc\DefendAPc.exe
  • %ProgramFiles%\DefendAPc Software\DefendAPc\main_config.xml
  • %ProgramFiles%\DefendAPc Software\DefendAPc\uninstall.exe
  • %ProgramFiles%\DefendAPc Software\DefendAPc\quarantine\quarantine.xml
  • %SystemRoot%\System32\spool\PRTPROCS\W32X86\00004e7f.tmp
  • %AllUsersProfile%\Desktop\DefendAPc.lnk
  • %AllUsersProfile%\Start Menu\Programs\DefendAPc\2 Homepage.lnk
  • %AllUsersProfile%\Start Menu\Programs\DefendAPc\3 Uninstall.lnk
  • %AllUsersProfile%\Start Menu\Programs\DefendAPc\1 DefendAPc.lnk
  • %UserProfile%\Cookies\userdemo@defendapc[1].txt

Create new registry entries:

  • HKEY_LOCAL_MACHINE\software\DefendAPc
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\DefendAPc
  • HKEY_CURRENT_USER\software\DefendAPc
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “DefendAPc”
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “DefendAPc”

Screenshots:

How to remove the infection of DefendAPc (Adware.Win32.DefendAPc)?

To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

Jan 12

SysDefenders Adware Removal Instructions

The Emsi Software malware research team has discoverd a new outbreak of the SysDefenders adware. a-squared Anti-Malware detects this malware as Adware.Win32.SysDefenders.

SysDefenders, come from hxxp://www.sysdefenders.com, is a rogue scanner program, it shows a fake security center window, shows misleading scan results and fake security alerts. The author of SysDefenders also made InSysSecure, SysProtector, APcDefender, PcProtectar, PcsProtector, GreatDefender, APCProtect, ProtectPcs, SysDefence, TheDefend, GuardPcs, IGuardPc, SiteAdware, AntiTroy, AntiKeep, AntiAdd, RESpyWare, REAnti, KeepCop, SecureKeeper, LinkSafeness, AntiAid, SystemFighter, SystemVeteran, BlockProtector, BlockKeeper, BlockScanner, BlockWatcher, SoftStronghold, ShieldSafeness, SoftVeteran, SoftSoldierSoftCop, TrustFighter, TrustSoldier, SafeFighter, SecureVeteran, etc. To further convince victims, SysDefenders will also create numerous junk files with random names on your computer that will be detected as malware when the program scans your computer, but will not allow you to remove them until you purchase it.

Create new files and folders:

  • %ProgramFiles%\SysDefenders Software\SysDefenders\main_config.xml
  • %ProgramFiles%\SysDefenders Software\SysDefenders\SysDefenders.exe
  • %ProgramFiles%\SysDefenders Software\SysDefenders\uninstall.exe
  • %AllUsersProfile%\Desktop\SysDefenders.lnk
  • %AllUsersProfile%\Start Menu\Programs\SysDefenders\1 SysDefenders.lnk
  • %AllUsersProfile%\Start Menu\Programs\SysDefenders\2 Homepage.lnk
  • %AllUsersProfile%\Start Menu\Programs\SysDefenders\3 Uninstall.lnk
  • %UserProfile%\Cookies\userdemo@sysdefenders[1].txt

Create new registry entries:

  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\SysDefenders
  • HKEY_LOCAL_MACHINE\software\SysDefenders
  • HKEY_CURRENT_USER\software\SysDefenders
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, “SysDefenders”
  • HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run, “SysDefenders”

Screenshots:

How to remove the infection of SysDefenders (Adware.Win32.SysDefenders)?

To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.