Remove PC Defender. Description and removal instructions

 
Title: PC Defender
Also known as: PCDefender
Type: Spyware
Severity scale:PC Defender severity is 96  (96 / 100)
 
PC Defender (or PCDefender) is a fake spyware removal tool designed to gain the income by pushing PC users into paying for its “full” version. The program is known to be a successor of infamous PC Defender 2008 which has caused many troubles for the users worldwide, so there is no doubt that PCDefender MUST be avoided. However, you may have no awareness about this scam installed into your machine because Trojan horses are used for the infiltration.

When in the targeted computer, PC Defender starts seeking its dirty commercial goals. Its unregistered version creates fake registry entries and adds some corrupt files at first. Then, invasion is usually followed by triggering system tray notifications and other alerts telling about infections that are “detected” in the PC. Victims are usually suggested to scan their computers that additionally report multiple infections trying to make them scared. They are misleadingly informed that only the “licensed” version of PC Defender can fix everything.

In fact, the above mentioned PC Defender alerts and scanners are falsified and created not only to scare users but also to get them into paying for so called “full” version. In the same time the system may be absolutely clear of infections and the reported ones are usually the same created by PC Defender. The only parasite is this rogue, so if you take your PC security and privacy important, remove PC Defender with all of its files and registry entries ASAP.



Related files: ieocx.dll, bhs.bat, qmgr1.dat, qmgr0.dat, Perflib_Perfdata_a98.dat, PC Defender.lnk, clean.hiv, antispyware.exe, hook.dll, proccheck.exe, 14d256.msi, 96222EB958BE7AE1F3D10F.exe, E99A03E2B966DDBBBF0A73.exe, 922EE651620485838F50FE09DF119-1680527D.pf, ANTISPYWARE.EXE-19ABB532.pf, PROCCHECK.EXE-03906D86.pf, REG.EXE-0D2A95F7.pf

PC Defender properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Stays resident in background

PC Defender snapshot:
PC Defender removal

Automatic PC Defender removal:

remover for PC Defender

PC Defender manual removal:

Kill processes:
Antispyware.exe proccheck.exe 96222EB958BE7AE1F3D10F.exe E99A03E2B966DDBBBF0A73.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "C:\WINDOWS\system32\userinit.exe,"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "C:\WINDOWS\system32\userinit.exe,"C:\Program Files\Def Group\PC Defender\Antispyware.exe""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Def Group\PC Defender\"" = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Def Group\"" = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender\"" = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\WINDOWS\Installer\{FC2ABC8E-3715-4A32-B8B5-559380F45282}\"" = ""
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" "0x00002001"
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\Def Group\PC Defender\"proccheck.exe" = "proccheck"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\VAS\"922RR651620485838S50SR09QS119674.rkr" = "1B 00 00 00 06 00 00 00 10 8D 5A 77 91 B0 CA 01"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"Mode" = "4"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"ScrollPos1280x1024(1).x" = "0"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"ScrollPos1280x1024(1).y" = "0"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"Sort" = "0"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"SortDir" = "1"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"Col" = "0xFFFFFFFF"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\Bags\16\Shell\"ColInfo" = "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FD DF DF FD 0F 00 04 00 20 00 10 00 28 00 3C 00 00 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00 00 01 60 00 78 00 78 00 00 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00 FF FF FF FF 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\INF\"922EE651620485838F50FE09DF119674.exe" = "922EE651620485838F50FE09DF119674"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\system32\"REG.exe" = "Registry Console Tool"
HKEY_USERS\S-1-5-21-1172441840-534431857-1906119351-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\Def Group\PC Defender\"Antispyware.exe" = "PC Defender application main executable"
HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" = "0x00002001"
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Program Files\Def Group\PC Defender\"proccheck.exe" = "proccheck"
Unregister DLLs:
hook.dll

Delete files:
Perflib_Perfdata_a98.dat PC Defender.lnk clean.hiv Antispyware.exe hook.dll proccheck.exe 14d256.msi 96222EB958BE7AE1F3D10F.exe E99A03E2B966DDBBBF0A73.exe 922EE651620485838F50FE09DF119-1680527D.pf ANTISPYWARE.EXE-19ABB532.pf PROCCHECK.EXE-03906D86.pf REG.EXE-0D2A95F7.pf
Delete directories:
C:\Documents and Settings\All Users\Start Menu\Programs\PC Defender
C:\Program Files\Def Group
C:\Program Files\Def Group\PC Defender
C:\WINDOWS\Installer\{FC2ABC8E-3715-4A32-B8B5-559380F45282}

Other programs to remove PC Defender:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 10/01/10
Information updated: 19/02/10

Additional resources related to PC Defender:

Attention: If you know or you have a website or page about PC Defender removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about PC Defender parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites:
Related discussions: