Alfa Defender Pro

By ESGI Advisor in Rogue Anti-Spyware Program

Alfa Defender Pro Image

Alfa Defender Pro is a new member of a huge family of rogue security programs that have infected computers all over the world. Alfa Defender Pro is distributed by a professional-looking website that is part of a large ring of websites distributing fake security programs. Rogue security programs that are closely related to Alfa Defender Pro include Ultimate Defender, Bogema Security, Albinos Defender, Ultimate Guard, and many others. These are distributed through similar websites that include Bogemasecurity.com, Albinosdefender.com, Ultimate-guard.com, and other similar domains. Alfa Defender Pro and its clones are dangerous malware threats that pass themselves off as legitimate security applications. ESG malware researchers recommend removing Alfa Defender Pro from your computer with a trustworthy security program. If removed on time, Alfa Defender Pro will not leave any lasting damage on your computer system.
 

The Misleading Marketing Campaign Behind Alfa Defender Pro

Most rogue security programs are distributed by Trojans. Alfa Defender Pro is no different, and an Alfa Defender Pro infection will often include the presence of the Zlob Trojan or Fake Microsoft Security Essentials Alert Trojan. However, Alfa Defender Pro is also distributed by social engineering. Social engineering is a term computer researchers use for tactics that deal directly with how people behave, rather than solely working with computer systems. To manipulate unwary buyers, there is a large-scale marketing campaign behind Alfa Defender Pro and its clones. This Internet marketing campaign, which includes blogs, fake reviews, fake comments, and a highly stylized website, is made to give Alfa Defender Pro the appearance of a real security program. Unwary computer users often mistake Alfa Defender Pro and its clones for real security programs, directly downloading them onto their computers. Once downloaded and installed, Alfa Defender Pro is left free to wreak havoc on the infected computer system.

If you are receiving messages, alerts, or notifications from Alfa Defender Pro, this is a sign that your computer has been infected. Other symptoms include decreased performance, blocked access to the Internet, and blocked access to executable files. Our ESG security researchers recommend using a legitimate anti-malware application to remove an Alfa Defender Pro infection from your computer. In many cases, Alfa Defender Pro can block your legitimate security programs from running correctly. In these cases, starting Windows in Safe Mode is always helpful; to do this, press the F8 key while Windows is starting up.

File System Details

Alfa Defender Pro may create the following file(s):
# File Name Detections
1. %Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe
2. %Documents and Settings%\[UserName]\Local Settings\Temp\[RANDOM CHARACTERS]
3. %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]

Registry Details

Alfa Defender Pro may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe" -a "%Program Files%\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exee" -a "%Program Files%\Internet Explorer\iexplore.exe"'
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe" -a "%Program Files%\Mozilla Firefox\firefox.exe" -safe-mo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe" -a "%1" %*'

Trending

Most Viewed

Loading...