XP Smart Defender

By Domesticus in Rogue Anti-Spyware Program

XP Smart Defender is a fake anti-spyware program designed by cybercrooks. XP Smart Defender has no capabilities of detecting and uninstalling any type of security threats. The main purpose of XP Smart Defender is to deceive unaware computer users and pilfer money from them. XP Smart Defender attempts to dupe PC users into thinking their computers are infected with various malware infections. Then, XP Smart Defender strives to induce victims to spend money on the bogus security tool that is allegedly able to repair any malware infections. XP Smart Defender is distributed via Trojans or malicious downloads and enters the corrupted machine secretly without a PC owner's knowledge. When installed, XP Smart Defender launches a supposed system scan and pretends to check the computer for possible malware threats and other security issues. Falsified malware reports produced by XP Smart Defender are used to intimidate victims into thinking their computers are corrupted.

XP Smart Defender urges victims to buy the full version of scareware, which, in reality, does not exist. XP Smart Defender also shows fraudulent pop-up warning messages that claim your computer is infected and in danger. To bypass the detection and removal, XP Smart Defender may disable legitimate security programs from functioning. Do not rely on anything XP Smart Defender states or displays because all information pertaining to this malicious software is inaccurate. ESG's malware researchers highly recommend you use a reputable anti-malware program to remove XP Smart Defender as soon as possible. Do not ever spend money on XP Smart Defender.

File System Details

XP Smart Defender may create the following file(s):
# File Name Detections
1. %CommonAppData%\pcdfdata\[RANDOM].exe
2. %CommonAppData%\pcdfdata\vl.bin
3. %CommonAppData%\pcdfdata\support.ico
4. %CommonPrograms%\XP Smart Defender\XP Smart Defender.lnk
5. %CommonAppData%\pcdfdata\uninst.ico
6. %CommonAppData%\pcdfdata\config.bin
7. %CommonPrograms%\XP Smart Defender\XP Smart Defender Help and Support.lnk
8. %CommonAppData%\pcdfdata\defs.bin
9. %CommonAppData%\pcdfdata\app.ico
10. %CommonDesktopDir%\XP Smart Defender.lnk

Registry Details

XP Smart Defender may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Classes\.exe\ [RANDOM_2]
HKEY_CURRENT_USER\Software\Classes\.exe\shell
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command = ""%CommonAppData%\pcdfdata\[RANDOM].exe" /ex "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command = '"%1" %*'
HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = 'application/x-m'
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = '%1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run pcdfsvc = "%CommonAppData%\pcdfdata\[RANDOM].exe /min"
HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'

Messages

The following messages associated with XP Smart Defender were found:

System Security Alert!
Unknown program is scanning your system registry right now! Identify the theft detected!
System Security Alert!
Vulnerabilities found
Background scan for security breaches has been finished. Serious problems have been detected. Safeguard your system against exploits, malware and viruses right now by activating Proactive Defence.
XP Smart Defender Firewall Alert
Iexplore.exe is infected with Trojan.JS.Fraud.ba. Private data can be stolen by third parties, including credit card details and passwords.
Windows recommends activate XP Smart Defender

Related Posts

Trending

Most Viewed

Loading...