<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; PCDefender</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/pcdefender/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PC Defender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 22:58:42 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[PCDefender]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=727</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak of the PC Defender adware. a-squared Anti-Malware detects this malware as Adware.Win32.PCDefender. PC Defender is a rogue security program. This rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsi Software</strong> malware research team has    discoverd a new outbreak           of the <strong>PC Defender</strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared              Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCDefender" target="_blank">Adware.Win32.PCDefender</a></strong>.</p>
<p><strong>PC Defender </strong>is a rogue security program.   This rogue  application      tries to trick you  by displaying  false   positive/misleading  scan     results  report, which  says that your    computer is infected with      viruses or  trojan, but you  will not be   able  to delete them before you      purchase.</p>
<p>This program has a funny thing. It will displays fake blue screen on the victim machine. The blue screen will look like this:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_1.png"><img class="alignnone size-medium wp-image-728" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_1-400x203.png" alt="" width="400" height="203" /></a></p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Def Group\PC Defender\Antispyware.exe</li>
<li>%ProgramFiles%\Def Group\PC Defender\hook.dll</li>
<li>%ProgramFiles%\Def Group\PC Defender\proccheck.exe</li>
<li>%AllUsersProfile%\Desktop\PC Defender.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\PC Defender\PC Defender.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Def Group</li>
<li>HKEY_CURRENT_USER\software\Def Group\Antispyware</li>
<li>HKEY_CURRENT_USER\software\Def Group\Antispyware\Found</li>
</ul>
<p><strong>Modify registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon<br />
Old: Userinit = C:\WINDOWS\system32\userinit.exe,<br />
New: Userinit = C:\WINDOWS\system32\userinit.exe,&#8221;C:\Program Files\Def Group\PC Defender\Antispyware.exe&#8221;</li>
</ul>
<p>Screenshots:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_2.png"><img class="alignnone size-medium wp-image-729" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_2-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_3.png"><img class="alignnone size-medium wp-image-730" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_3-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_4.png"><img class="alignnone size-medium wp-image-731" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_4-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_5.png"><img class="alignnone size-medium wp-image-732" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_5-400x329.png" alt="" width="400" height="329" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_6.png"><img class="alignnone size-medium wp-image-733" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_6-400x307.png" alt="" width="400" height="307" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_7.png"><img class="alignnone size-medium wp-image-734" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_7-400x288.png" alt="" width="400" height="288" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_8.png"><img class="alignnone size-medium wp-image-735" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_8-400x288.png" alt="" width="400" height="288" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_9.png"><img class="alignnone size-medium wp-image-736" title="Adware.Win32.PCDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2010/02/Adware.Win32.PCDefender_9-400x239.png" alt="" width="400" height="239" /></a></p>
<p><strong>How to remove the infection of PC Defender</strong><strong> </strong><strong>(Adware.Win32.PCDefender</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">a-squared             Anti-Malware</a></strong>. Run a full scan on all drives and move    all detected          items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/02/09/advanced-defender-adware-removal-instructions/" rel="bookmark" class="crp_title">Advanced Defender Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/total-pc-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Total PC Defender 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/12/10/privacyguard-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">PrivacyGuard 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/14/fakesecurityessentials-adware-removal-instructions/" rel="bookmark" class="crp_title">FakeSecurityEssentials Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2010/02/24/pc-defender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

