<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; Desktop</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/desktop/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Desktop Defender 2010 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/10/31/desktop-defender-2010-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/10/31/desktop-defender-2010-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 31 Oct 2009 16:50:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Defender]]></category>
		<category><![CDATA[Desktop]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=e0243e8e-991a-4f13-8107-8970e7bb814f</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the Desktop Defender 2010 adware. a-squared Anti-Malware detects this malware as Adware.Win32.DesktopDefender2010. Desktop Defender 2010 is a rogue scanner program, it shows misleading scan results and fake security alerts. If you download and install Windows PC Defender 2010, it will be automatically configured [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak of the Desktop Defender 2010 adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detects this malware as Adware.Win32.DesktopDefender2010.</p>
<p>Desktop Defender 2010 is a rogue scanner program, it shows misleading scan results and fake security alerts. If you download and install Windows PC Defender 2010, it will be automatically configured to start each time you log on into Windows. Once the program is running it will scan your computer and then displays fake infections, but will not allow you to remove them until you purchase it.</p>
<p>This rogue has some protection, one of them is the protection against virtual machine. When user try to run the Installer of this rogue on the virtual machine environment, the application will crash.</p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/DesktopDefender2010_InstallerCrash.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/DesktopDefender2010_VMProtection.png" alt="" /></p>
<p>And also protects himself from the unwanted applications, e.g. File Monitor and Registry Monitor from SysInternals.</p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/DesktopDefender2010_ToolsProtection.png" alt="" /></p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Desktop Defender 2010\msvcr71.dll</li>
<li>%ProgramFiles%\Desktop Defender 2010\pthreadVC2.dll</li>
<li>%ProgramFiles%\Desktop Defender 2010\shellext.dll</li>
<li>%ProgramFiles%\Desktop Defender 2010\siglsp.dll</li>
<li>%ProgramFiles%\Desktop Defender 2010\tdifw_drv_WLH.sys</li>
<li>%ProgramFiles%\Desktop Defender 2010\tdifw_drv_WXP.sys</li>
<li>%ProgramFiles%\Desktop Defender 2010\uninstall.exe</li>
<li>%ProgramFiles%\Desktop Defender 2010\AF.dll</li>
<li>%ProgramFiles%\Desktop Defender 2010\daily.cvd</li>
<li>%ProgramFiles%\Desktop Defender 2010\Desktop Defender 2010.exe</li>
<li>%ProgramFiles%\Desktop Defender 2010\guide.chm</li>
<li>%ProgramFiles%\Desktop Defender 2010\hjengine.dll</li>
<li>%ProgramFiles%\Desktop Defender 2010\IEAddon.dll</li>
<li>%ProgramFiles%\Desktop Defender 2010\MFC71.dll</li>
<li>%ProgramFiles%\Desktop Defender 2010\MFC71ENU.DLL</li>
<li>%ProgramFiles%\Desktop Defender 2010\msvcp71.dll</li>
<li>%SystemRoot%\system32\drivers\tdifw_drv.sys</li>
<li>%AllUsersProfile%\Desktop\Desktop Defender 2010.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Desktop Defender 2010.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Desktop Defender 2010\How to Activate Desktop Defender 2010.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Desktop Defender 2010\Activate Desktop Defender 2010.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Desktop Defender 2010\Desktop Defender 2010.lnk</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Desktop Defender 2010.lnk</li>
<li>%UserProfile%\Local Settings\Temp\kgn.exe</li>
<li>%UserProfile%\Local Settings\Temp\kilslmd.exex</li>
<li>%UserProfile%\Local Settings\Temp\kn.a.exe</li>
<li>%UserProfile%\Local Settings\Temp\.tt1.tmp</li>
<li>%UserProfile%\Local Settings\Temp\.tt1.tmp.exe</li>
<li>%UserProfile%\Local Settings\Temp\gedx_ae09.exe</li>
<li>%UserProfile%\Local Settings\Temp\nsq18.tmp\ext.dll</li>
<li>%UserProfile%\Local Settings\Temp\nsq18.tmp\System.dll</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\*\shellex\ContextMenuHandlers\antivirus_contextscan</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AppID\IEAddon.DLL</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\AppID\{C0E56AC2-9F72-436E-B6E7-AEC28AF9E4EB}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{08EEC6AD-7486-487F-89B7-5A3716DDAE14}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{08EEC6AD-7486-487F-89B7-5A3716DDAE14}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}\InprocServer32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}\ProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}\Programmable</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}\TypeLib</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}\VersionIndependentProgID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Drive\shellex\ContextMenuHandlers\antivirus_contextscan</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Folder\shellex\ContextMenuHandlers\antivirus_contextscan</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\IEAddon.StatusBarPane</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\IEAddon.StatusBarPane\CLSID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\IEAddon.StatusBarPane\CurVer</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\IEAddon.StatusBarPane.1</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\IEAddon.StatusBarPane.1\CLSID</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}\ProxyStubClsid</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}\ProxyStubClsid32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}\TypeLib</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}\1.0</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}\1.0\0</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}\1.0\0\win32</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}\1.0\FLAGS</li>
<li>HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}\1.0\HELPDIR</li>
<li>HKEY_LOCAL_MACHINE\software\Desktop Defender 2010</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Desktop Defender 2010</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdifw_drv</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run, &#8220;Desktop Defender 2010&#8243;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_3.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_5.png" alt="" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_1.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_6.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_7.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_8.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_9.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_10.png" alt="" width="400" /></p>
<p><img style="border: 1px solid black;" src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_11.png" alt="" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/10/Adware.Win32.DesktopDefender2010_12.png" alt="" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.DesktopDefender2010?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/10/14/windows-enterprise-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Enterprise Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/26/windows-system-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows System Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/advanced-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Advanced Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/total-pc-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Total PC Defender 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/10/21/alpha-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Alpha Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/10/31/desktop-defender-2010-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

