AV Defender

By Domesticus in Rogue Anti-Virus Program | 93 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Translate To:     Español  |   Português
More... More

AV Defender Description

AV Defender is a rogue anti-virus application that uses scare tactics to coerce users into paying for it. On entering a system, AV Defender will simulate a fake system scan that will produce a fake report of numerous malware detections. AV Defender will also display fake pop-up warnings and security alerts to further alarm the targeted victim and then advise him/her to purchase its non-existent full version. AV Defender is a useless application that can neither detect nor remove computer malware.

Type: Rogue Anti-Virus Program

How Can You Detect AV Defender?

AV Defender Removal Details

AV Defender has typically the following processes in memory:

  • c:\WINDOWS\microsoftdefend.dll
  • c:\WINDOWS\spoos.exe
  • c:\WINDOWS\explorers.exe
  • c:\WINDOWS\secureit.com
  • c:\Program Files\AV Defender\advanceddefender.exe
  • c:\WINDOWS\certofsystem.exe
  • c:\WINDOWS\regp.exe
  • c:\WINDOWS\system32\winscent.exe

AV Defender creates the following files in the system:

  • %UserProfile%\Desktop\AV Defender.lnk
  • c:\Program Files\AV Defender
  • c:\Program Files\AV Defender\conf.wcf
  • c:\Documents and Settings\All Users\Microsoft PData\track.wid
  • %UserProfile%\Start Menu\Programs\AV Defender\AV Defender.lnk
  • c:\Program Files\AV Defender\baseadd.wdb
  • c:\Program Files\AV Defender\q
  • c:\Documents and Settings\All Users\Microsoft PData
  • %UserProfile%\Start Menu\Programs\AV Defender
  • c:\Program Files\AV Defender\base.wdb
  • c:\Program Files\AV Defender\quarant.wdb

AV Defender creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = “1″
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AV Defender
  • HKEY_LOCAL_MACHINE\SOFTWARE\AV Defender
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “avdefender”

Important Article Disclaimer

ESG Support Center

This entry was last updated on 08/3/10 and posted on 07/5/10. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | Sitemap | RSS Feed | Privacy Policy | End User License Agreement | Additional Terms and Conditions Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.