Antimalware Defender

Antimalware Defender is a rogue security tool extending from the same family as Virus Doctor. Antimalware Defender is typically distributed by sneaky Trojans but it can also be dropped by other malicious software. On execution, Antimalware Defender displays a bogus pop-up window that appears to be a Critical Windows update. The update reads as follows:

"Antimalware security update for Windows XP (KB961118)
Size: 433KB
This critical update will install System Security Update 2010.01.023 (Antimalware Defender Upgrade; KB648759)"

Antimalware Defender has a similar GUI to the legitimate Windows Defender application, but they are not related to each other at all. Antimalware Defender will also conduct a fake system scan that will report several infections, scaring the victim into purchasing the "full version" of Antimalware Defender. Antimalware Defender will also launch annoying pop-ups and security alerts to further incite the victim. Users should not even consider purchasing Antimalware Defender as it cannot detect or remove any type of computer malware.

File System Details

Antimalware Defender may create the following file(s):
# File Name Detections
1. c:\Program Files\Antimalware Defender\Antimalware Defender.dll
2. C:\Documents and Settings\\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.mkv
3. c:\WINDOWS\system32\ca84c702-c758-4421-974e-b02662e76d7c_6.avi
4. %UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.ico
5. %UserProfile%\Desktop\Antimalware Defender.lnk
6. %UserProfile%\Local Settings\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.mkv
7. C:\Documents and Settings\\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.ico
8. C:\Documents and Settings\\Start Menu\Programs\Startup\ca84c702-c758-4421-974e-b02662e76d7c_6.lnk
9. %UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.avi
10. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antimalware Defender.lnk
11. %UserProfile%\Local Settings\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.ico
12. %UserProfile%\Start Menu\Programs\Startup\ca84c702-c758-4421-974e-b02662e76d7c_6.lnk
13. C:\Documents and Settings\\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.avi
14. C:\Documents and Settings\\Start Menu\Programs\Antimalware Defender\Antimalware Defender.lnk
15. c:\WINDOWS\system32\ca84c702-c758-4421-974e-b02662e76d7c_6.ico
16. %UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.mkv
17. %UserProfile%\Local Settings\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.avi
18. %UserProfile%\Start Menu\Programs\Antimalware Defender\Antimalware Defender.lnk

Registry Details

Antimalware Defender may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ca84c702-c758-4421-974e-b02662e76d7c_6"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ca84c702-c758-4421-974e-b02662e76d7c}
HKEY_CLASSES_ROOT\CLSID\{ca84c702-c758-4421-974e-b02662e76d7c}

Trending

Most Viewed

Loading...