<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; Windows PC Defender</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/windows-pc-defender/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Windows PC Defender Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/09/23/windows-pc-defender-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/09/23/windows-pc-defender-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 12:18:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows PC Defender]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=b92734a8-bdfc-438b-b0e6-d565fea63ec2</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak for the Windows PC Defender adware. a-squared Anti-Malware detect this malware as Adware.Win32.WindowsPCDefender. Windows PC Defender is rogue security software that show false warning messages and show misleading scan results. The advertisement will state that you are infected and then prompt you to download [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak for the Windows PC Defender adware. <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a> detect this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPCDefender" target="_blank">Adware.Win32.WindowsPCDefender</a>.</p>
<p>Windows PC Defender is rogue security software that show false warning messages and show misleading scan results. The advertisement will state that you are infected and then prompt you to download Windows PC Defender to your computer. If you download and install Windows PC Defender, it will start automatically when your computer starts. The installer will also create numerous harmless files on your computer, usually at Recent folder, that are used to impersonate malware files. Once the program is running it will scan your computer and then display these files as infections, but will not allow you to remove them until you purchase the program.</p>
<p><strong>The main program will extract several files to (the name of the files and directory for this rogue are random):</strong></p>
<ul>
<li>%CommonAppData%\b0cf5\WPba6.exe</li>
<li>%CommonAppData%\WPCDSys\wpcd.cfg</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Windows PC Defender.lnk</li>
<li>%AppData%\Windows PC Defender\Instructions.ini</li>
<li>%UserProfile%\Cookies\index.dat</li>
<li>%UserProfile%\Cookies\virus demo@support.zonedialog[1].txt</li>
<li>%UserProfile%\Desktop\1587.mof</li>
<li>%UserProfile%\Desktop\Windows PC Defender.lnk</li>
<li>%UserProfile%\Desktop\WPCD.ico</li>
<li>%UserProfile%\Desktop\BackUp\HyperSnap-DX.lnk</li>
<li>%UserProfile%\Desktop\WPCDSys\vd952342.bd</li>
<li>%UserProfile%\Recent\ANTIGEN.tmp</li>
<li>%UserProfile%\Recent\cb.dll</li>
<li>%UserProfile%\Recent\cid.exe</li>
<li>%UserProfile%\Recent\cid.sys</li>
<li>%UserProfile%\Recent\CLSV.drv</li>
<li>%UserProfile%\Recent\exec.drv</li>
<li>%UserProfile%\Recent\fix.sys</li>
<li>%UserProfile%\Recent\grid.tmp</li>
<li>%UserProfile%\Recent\kernel32.tmp</li>
<li>%UserProfile%\Recent\PE.sys</li>
<li>%UserProfile%\Recent\PE.tmp</li>
<li>%UserProfile%\Recent\ppal.drv</li>
<li>%UserProfile%\Recent\SM.tmp</li>
<li>%UserProfile%\Recent\tjd.sys</li>
<li>%UserProfile%\Recent\tjd.tmp</li>
<li>%UserProfile%\Start Menu\Windows PC Defender.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows PC Defender.lnk</li>
</ul>
<p><strong>And create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\Windows PC Defender</li>
</ul>
<p><strong>This rogue also try to modify hosts file:</strong></p>
<ul>
<li>74.125.45.100 4-open-davinci.com</li>
<li>74.125.45.100 securitysoftwarepayments.com</li>
<li>74.125.45.100 privatesecuredpayments.com</li>
<li>74.125.45.100 secure.privatesecuredpayments.com</li>
<li>74.125.45.100 getantivirusplusnow.com</li>
<li>74.125.45.100 secure-plus-payments.com</li>
<li>74.125.45.100 www.getantivirusplusnow.com</li>
<li>74.125.45.100 www.secure-plus-payments.com</li>
<li>74.125.45.100 www.getavplusnow.com</li>
<li>74.125.45.100 www.securesoftwarebill.com</li>
<li>74.125.45.100 secure.paysecuresystem.com</li>
<li>74.125.45.100 paysoftbillsolution.com</li>
<li>206.53.61.77 google.ae</li>
<li>206.53.61.77 google.as</li>
<li>206.53.61.77 google.at</li>
<li>206.53.61.77 google.az</li>
<li>206.53.61.77 google.ba</li>
<li>206.53.61.77 google.be</li>
<li>206.53.61.77 google.bg</li>
<li>206.53.61.77 google.bs</li>
<li>206.53.61.77 google.ca</li>
<li>206.53.61.77 google.cd</li>
<li>206.53.61.77 google.com.gh</li>
<li>206.53.61.77 google.com.hk</li>
<li>206.53.61.77 google.com.jm</li>
<li>206.53.61.77 google.com.mx</li>
<li>206.53.61.77 google.com.my</li>
<li>206.53.61.77 google.com.na</li>
<li>206.53.61.77 google.com.nf</li>
<li>206.53.61.77 google.com.ng</li>
<li>206.53.61.77 google.ch</li>
<li>206.53.61.77 google.com.np</li>
<li>206.53.61.77 google.com.pr</li>
<li>206.53.61.77 google.com.qa</li>
<li>206.53.61.77 google.com.sg</li>
<li>206.53.61.77 google.com.tj</li>
<li>206.53.61.77 google.com.tw</li>
<li>206.53.61.77 google.dj</li>
<li>206.53.61.77 google.de</li>
<li>206.53.61.77 google.dk</li>
<li>206.53.61.77 google.dm</li>
<li>206.53.61.77 google.ee</li>
<li>206.53.61.77 google.fi</li>
<li>206.53.61.77 google.fm</li>
<li>206.53.61.77 google.fr</li>
<li>206.53.61.77 google.ge</li>
<li>206.53.61.77 google.gg</li>
<li>206.53.61.77 google.gm</li>
<li>206.53.61.77 google.gr</li>
<li>206.53.61.77 google.ht</li>
<li>206.53.61.77 google.ie</li>
<li>206.53.61.77 google.im</li>
<li>206.53.61.77 google.in</li>
<li>206.53.61.77 google.it</li>
<li>206.53.61.77 google.ki</li>
<li>206.53.61.77 google.la</li>
<li>206.53.61.77 google.li</li>
<li>206.53.61.77 google.lv</li>
<li>206.53.61.77 google.ma</li>
<li>206.53.61.77 google.ms</li>
<li>206.53.61.77 google.mu</li>
<li>206.53.61.77 google.mw</li>
<li>206.53.61.77 google.nl</li>
<li>206.53.61.77 google.no</li>
<li>206.53.61.77 google.nr</li>
<li>206.53.61.77 google.nu</li>
<li>206.53.61.77 google.pl</li>
<li>206.53.61.77 google.pn</li>
<li>206.53.61.77 google.pt</li>
<li>206.53.61.77 google.ro</li>
<li>206.53.61.77 google.ru</li>
<li>206.53.61.77 google.rw</li>
<li>206.53.61.77 google.sc</li>
<li>206.53.61.77 google.se</li>
<li>206.53.61.77 google.sh</li>
<li>206.53.61.77 google.si</li>
<li>206.53.61.77 google.sm</li>
<li>206.53.61.77 google.sn</li>
<li>206.53.61.77 google.st</li>
<li>206.53.61.77 google.tl</li>
<li>206.53.61.77 google.tm</li>
<li>206.53.61.77 google.tt</li>
<li>206.53.61.77 google.us</li>
<li>206.53.61.77 google.vu</li>
<li>206.53.61.77 google.ws</li>
<li>206.53.61.77 google.co.ck</li>
<li>206.53.61.77 google.co.id</li>
<li>206.53.61.77 google.co.il</li>
<li>206.53.61.77 google.co.in</li>
<li>206.53.61.77 google.co.jp</li>
<li>206.53.61.77 google.co.kr</li>
<li>206.53.61.77 google.co.ls</li>
<li>206.53.61.77 google.co.ma</li>
<li>206.53.61.77 google.co.nz</li>
<li>206.53.61.77 google.co.tz</li>
<li>206.53.61.77 google.co.ug</li>
<li>206.53.61.77 google.co.uk</li>
<li>206.53.61.77 google.co.za</li>
<li>206.53.61.77 google.co.zm</li>
<li>206.53.61.77 google.com</li>
<li>206.53.61.77 google.com.af</li>
<li>206.53.61.77 google.com.ag</li>
<li>206.53.61.77 google.com.ar</li>
<li>206.53.61.77 google.com.au</li>
<li>206.53.61.77 google.com.bn</li>
<li>206.53.61.77 google.com.br</li>
<li>206.53.61.77 google.com.by</li>
<li>206.53.61.77 google.com.bz</li>
<li>206.53.61.77 google.com.cu</li>
<li>206.53.61.77 google.com.ec</li>
<li>206.53.61.77 google.com.fj</li>
<li>206.53.61.77 www.google.ae</li>
<li>206.53.61.77 www.google.as</li>
<li>206.53.61.77 www.google.at</li>
<li>206.53.61.77 www.google.az</li>
<li>206.53.61.77 www.google.ba</li>
<li>206.53.61.77 www.google.be</li>
<li>206.53.61.77 www.google.bg</li>
<li>206.53.61.77 www.google.bs</li>
<li>206.53.61.77 www.google.ca</li>
<li>206.53.61.77 www.google.cd</li>
<li>206.53.61.77 www.google.com.gh</li>
<li>206.53.61.77 www.google.com.hk</li>
<li>206.53.61.77 www.google.com.jm</li>
<li>206.53.61.77 www.google.com.mx</li>
<li>206.53.61.77 www.google.com.my</li>
<li>206.53.61.77 www.google.com.na</li>
<li>206.53.61.77 www.google.com.nf</li>
<li>206.53.61.77 www.google.com.ng</li>
<li>206.53.61.77 www.google.ch</li>
<li>206.53.61.77 www.google.com.np</li>
<li>206.53.61.77 www.google.com.pr</li>
<li>206.53.61.77 www.google.com.qa</li>
<li>206.53.61.77 www.google.com.sg</li>
<li>206.53.61.77 www.google.com.tj</li>
<li>206.53.61.77 www.google.com.tw</li>
<li>206.53.61.77 www.google.dj</li>
<li>206.53.61.77 www.google.de</li>
<li>206.53.61.77 www.google.dk</li>
<li>206.53.61.77 www.google.dm</li>
<li>206.53.61.77 www.google.ee</li>
<li>206.53.61.77 www.google.fi</li>
<li>206.53.61.77 www.google.fm</li>
<li>206.53.61.77 www.google.fr</li>
<li>206.53.61.77 www.google.ge</li>
<li>206.53.61.77 www.google.gg</li>
<li>206.53.61.77 www.google.gm</li>
<li>206.53.61.77 www.google.gr</li>
<li>206.53.61.77 www.google.ht</li>
<li>206.53.61.77 www.google.ie</li>
<li>206.53.61.77 www.google.im</li>
<li>206.53.61.77 www.google.in</li>
<li>206.53.61.77 www.google.it</li>
<li>206.53.61.77 www.google.ki</li>
<li>206.53.61.77 www.google.la</li>
<li>206.53.61.77 www.google.li</li>
<li>206.53.61.77 www.google.lv</li>
<li>206.53.61.77 www.google.ma</li>
<li>206.53.61.77 www.google.ms</li>
<li>206.53.61.77 www.google.mu</li>
<li>206.53.61.77 www.google.mw</li>
<li>206.53.61.77 www.google.nl</li>
<li>206.53.61.77 www.google.no</li>
<li>206.53.61.77 www.google.nr</li>
<li>206.53.61.77 www.google.nu</li>
<li>206.53.61.77 www.google.pl</li>
<li>206.53.61.77 www.google.pn</li>
<li>206.53.61.77 www.google.pt</li>
<li>206.53.61.77 www.google.ro</li>
<li>206.53.61.77 www.google.ru</li>
<li>206.53.61.77 www.google.rw</li>
<li>206.53.61.77 www.google.sc</li>
<li>206.53.61.77 www.google.se</li>
<li>206.53.61.77 www.google.sh</li>
<li>206.53.61.77 www.google.si</li>
<li>206.53.61.77 www.google.sm</li>
<li>206.53.61.77 www.google.sn</li>
<li>206.53.61.77 www.google.st</li>
<li>206.53.61.77 www.google.tl</li>
<li>206.53.61.77 www.google.tm</li>
<li>206.53.61.77 www.google.tt</li>
<li>206.53.61.77 www.google.us</li>
<li>206.53.61.77 www.google.vu</li>
<li>206.53.61.77 www.google.ws</li>
<li>206.53.61.77 www.google.co.ck</li>
<li>206.53.61.77 www.google.co.id</li>
<li>206.53.61.77 www.google.co.il</li>
<li>206.53.61.77 www.google.co.in</li>
<li>206.53.61.77 www.google.co.jp</li>
<li>206.53.61.77 www.google.co.kr</li>
<li>206.53.61.77 www.google.co.ls</li>
<li>206.53.61.77 www.google.co.ma</li>
<li>206.53.61.77 www.google.co.nz</li>
<li>206.53.61.77 www.google.co.tz</li>
<li>206.53.61.77 www.google.co.ug</li>
<li>206.53.61.77 www.google.co.uk</li>
<li>206.53.61.77 www.google.co.za</li>
<li>206.53.61.77 www.google.co.zm</li>
<li>206.53.61.77 www.google.com</li>
<li>206.53.61.77 www.google.com.af</li>
<li>206.53.61.77 www.google.com.ag</li>
<li>206.53.61.77 www.google.com.ar</li>
<li>206.53.61.77 www.google.com.au</li>
<li>206.53.61.77 www.google.com.bn</li>
<li>206.53.61.77 www.google.com.br</li>
<li>206.53.61.77 www.google.com.by</li>
<li>206.53.61.77 www.google.com.bz</li>
<li>206.53.61.77 www.google.com.cu</li>
<li>206.53.61.77 www.google.com.ec</li>
<li>206.53.61.77 www.google.com.fj</li>
<li>206.53.61.77 google.com</li>
<li>206.53.61.77 www.google.com</li>
<li>206.53.61.77 bing.com</li>
<li>206.53.61.77 www.bing.com</li>
<li>206.53.61.77 search.yahoo.com</li>
<li>206.53.61.77 www.search.yahoo.com</li>
<li>206.53.61.77 search.live.com</li>
<li>206.53.61.77 search.msn.com</li>
</ul>
<p><strong>Malware screenshots:</strong></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPCDefender_1.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPCDefender_2.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPCDefender_3.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPCDefender_4.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPCDefender_5.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPCDefender_6.png" alt="" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPCDefender_7.png" alt="" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.WindowsPCDefender?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/25/additional-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Additional Guard Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/pc-live-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Live Guard Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/12/08/live-pc-care-adware-removal-instructions/" rel="bookmark" class="crp_title">Live PC Care Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/29/my-security-engine-adware-removal-instructions/" rel="bookmark" class="crp_title">My Security Engine Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/03/security-master-av-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Master AV Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/09/23/windows-pc-defender-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

