Wednesday, February 23, 2011

Remove Internet Defender – Get Rid of InternetDefender Fake Update

Installer of the adware poses Internet Defender as update for Windows XP. Remarkably, even if the adware attempts to infect Vista or another Windows version other than XP, the message remains the same.
The text of the message prompting to install the tricky program may read as follows:
“Size: 433KB
This critical update will install System Security Update 2010.01.023 (Antimalware Defender Upgrade; KB648759)”.
If you provide your agreement on installation of the rogue, the trojan will promptly complete its installation. If not, it will attempt to bypass installation agreement procedure and install the counterfeit utility exploiting Windows vulnerabilities. This may cause serious system malfunctioning and even induce system crash.  
Behaviors of the adware are not less annoying than trojan’s impact. It says innocent and even critical importance files are infected or infections themselves.  In the meantime, it corrupts legit files and causes system freezes.
Get rid of  Internet Defender as a clone of SecurityDefender adware. Click here to launch free scan  and  Internet Defender removal process, as well as to dispose of other security and privacy threats.

Internet Defender screenshots:


Internet Defender removal solution:




Internet Defender manual removal info:
Delete infected files and processes:
c:\Documents and Settings\All Users\Application Data\56a10a26-dc02-40f3-a4da-8fa92d06b357_.mkv
c:\Documents and Settings\All Users\Application Data\56a10a26-dc02-40f3-a4da-8fa92d06b357_33.avi
c:\Documents and Settings\All Users\Application Data\56a10a26-dc02-40f3-a4da-8fa92d06b357_33.ico
c:\Documents and Settings\All Users\Start Menu\Programs\Startup\56a10a26-dc02-40f3-a4da-8fa92d06b357_33.lnk
c:\Program Files\Internet Defender
c:\Program Files\Internet Defender\Internet Defender.dll
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Defender.lnk
%UserProfile%\Desktop\Internet Defender.lnk
%UserProfile%\Start Menu\Programs\Startup\56a10a26-dc02-40f3-a4da-8fa92d06b357_33.lnk
%Temp%\.dll

Delete infected registry entries:
HKEY_CLASSES_ROOT\CLSID\{56a10a26-dc02-40f1-a4da-8fa92d06b357}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56a10a26-dc02-40f1-a4da-8fa92d06b357}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “56a10a26-dc02-40f3-a4da-8fa92d06b357_33″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “56a10a26-dc02-40f3-a4da-8fa92d06b357_33″

No comments: