Severity scale  
  (96/100)

PC Defender. How to Remove? (Uninstall Guide)

removal by - -   Also known as PCDefender | Type: Rogue Antispyware
12
PC Defender (or PCDefender) is a fake spyware removal tool designed to gain the income by pushing PC users into paying for its "full" version. The program is known to be a successor of infamous PC Defender 2008 which has caused many troubles for the users worldwide, so there is no doubt that PCDefender MUST be avoided. However, you may have no awareness about this scam installed into your machine because Trojan horses are used for the infiltration.

When in the targeted computer, PC Defender starts seeking its dirty commercial goals. Its unregistered version creates fake registry entries and adds some corrupt files at first. Then, invasion is usually followed by triggering system tray notifications and other alerts telling about infections that are "detected" in the PC. Victims are usually suggested to scan their computers that additionally report multiple infections trying to make them scared. They are misleadingly informed that only the "licensed" version of PC Defender can fix everything.

In fact, the above mentioned PC Defender alerts and scanners are falsified and created not only to scare users but also to get them into paying for so called "full" version. In the same time the system may be absolutely clear of infections and the reported ones are usually the same created by PC Defender. The only parasite is this rogue, so if you take your PC security and privacy important, remove PC Defender with all of its files and registry entries ASAP.
Related files: qmgr1.dat, qmgr0.dat, hook.dll

PC Defender properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use. By downloading any of provided Anti-spyware software you agree with our Privacy Policy and Agreement of Use.
Do it now!
Download
Reimage - remover Happiness
Guarantee
Compatible with Microsoft Windows
What to do if failed?
If you failed to remove infection using Reimage Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall PC Defender. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Reimage is recommended to uninstall PC Defender. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

More information about this program can be found in Reimage review.
Not using OS X? Download a remover for Windows.
Press Mentions on Reimage
Alternate Software
Alternate Software
STOPzilla
Tested and Confirmed! STOPzilla removes PC Defender (2010-01-10 23:04:28)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes PC Defender (2010-01-10 23:04:28)
Plumbytes
We are testing Plumbytes's efficiency (2010-02-19 21:58)
Hitman Pro
STOPzilla
Tested and Confirmed! STOPzilla removes PC Defender (2010-01-10 23:04:28)
Malwarebytes Anti Malware
Tested and Confirmed! Malwarebytes Anti Malware removes PC Defender (2010-01-10 23:04:28)
Webroot SecureAnywhere AntiVirus
PC Defender screenshot
PC Defender snapshot

PC Defender manual removal

Kill processes:
Antispyware.exe
proccheck.exe
96222EB958BE7AE1F3D10F.exe
E99A03E2B966DDBBBF0A73.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "C:\WINDOWS\system32\userinit.exe,"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "C:\WINDOWS\system32\userinit.exe,"C:\Program Files\Def Group\PC Defender\Antispyware.exe""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Def Group\PC Defender\"" = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Def Group\"" = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender\"" = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\WINDOWS\Installer\{FC2ABC8E-3715-4A32-B8B5-559380F45282}\"" = ""
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" "0x00002001"
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\Def Group\PC Defender\"proccheck.exe" = "proccheck"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\VAS\"922RR651620485838S50SR09QS119674.rkr" = "1B 00 00 00 06 00 00 00 10 8D 5A 77 91 B0 CA 01"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"Mode" = "4"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"ScrollPos1280x1024(1).x" = "0"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"ScrollPos1280x1024(1).y" = "0"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"Sort" = "0"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"SortDir" = "1"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"Col" = "0xFFFFFFFF"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"ColInfo" = "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FD DF DF FD 0F 00 04 00 20 00 10 00 28 00 3C 00 00 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00 00 01 60 00 78 00 78 00 00 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00 FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\INF\"922EE651620485838F50FE09DF119674.exe" = "922EE651620485838F50FE09DF119674"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\system32\"REG.exe" = "Registry Console Tool"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\Def Group\PC Defender\"Antispyware.exe" = "PC Defender application main executable"
HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" = "0x00002001"
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\Def Group\PC Defender\"proccheck.exe" = "proccheck"
Unregister DLLs:
hook.dll

Delete files:
Perflib_Perfdata_a98.dat
PC Defender.lnk
clean.hiv
Antispyware.exe
hook.dll
proccheck.exe
14d256.msi
96222EB958BE7AE1F3D10F.exe
E99A03E2B966DDBBBF0A73.exe
922EE651620485838F50FE09DF119-1680527D.pf
ANTISPYWARE.EXE-19ABB532.pf
PROCCHECK.EXE-03906D86.pf
REG.EXE-0D2A95F7.pf
Delete directories:
C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender
C:\Program Files\Def Group
C:\Program Files\Def Group\PC Defender
C:\WINDOWS\Installer\{FC2ABC8E-3715-4A32-B8B5-559380F45282}

Geolocation of PC Defender

Map reveals the prevalence of PC Defender. Countries and regions that have been affected the most are: Philippines, Indonesia, India, Vietnam and Brazil.

Information updated:

Comments on PC Defender

Post a comment

Attention: Use this form only if you have additional information about a parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.

Home page Name



«

(All fields are required)