Mar 24, 2009

Remove MalwareDefender 2009 - Malware Defender 2009 Removal Instructions

MalwareDefender 2009 is latest rogue antispyware application from same developers as Spyware Guard 2009 and System Guard 2009. Malware Defender 2009 is promoted through the use of Trojan horses (usually Vundo Trojan) that display fake security alerts and annoying pop-ups in order to convince you that your computer is infected and you must download and install MalwareDefender 2009 in order to remove all threats. Once installed MalwareDefender 2009 will perform full system scan and list you variety of threats that cannot be removed with trial version, that’s why you must purchase licensed version. But remember, Malware Defender 2009 have nothing to do with removing any types of infections. Remove it as soon as possible manually or using automatic removal tool.

Type: Rogue Anti-Spyware
Malware Author: Unknown
Threat Level: Critical
Screenshot:



How to remove MalwareDefender 2009 manually:
It's possible to remove MalwareDefender 2009 manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.

The files to be deleted:

c:\Program Files\Malware Defender 2009
c:\Program Files\Malware Defender 2009\conf.cfg
c:\Program Files\Malware Defender 2009\malwaredef.exe
c:\Program Files\Malware Defender 2009\mbase.vdb
c:\Program Files\Malware Defender 2009\quarantine.vdb
c:\Program Files\Malware Defender 2009\queue.vdb
c:\Program Files\Malware Defender 2009\uninstall.exe
c:\Program Files\Malware Defender 2009\vbase.vdb
c:\Program Files\Malware Defender 2009\quarantine
c:\WINDOWS\reged.exe
c:\WINDOWS\spoolsystem.exe
c:\WINDOWS\sys.com
c:\WINDOWS\syscert.exe
c:\WINDOWS\sysexplorer.exe
c:\WINDOWS\vmreg.dll
c:\WINDOWS\system32\wcenter.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers
c:\Documents and Settings\All Users\Application Data\Microsoft\win.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\svchos.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\t.id
c:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\c.cgm
c:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\vifwnhzqoe.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\Network\install.exe
%UserProfile%\Desktop\Malware Defender 2009.lnk
%UserProfile%\Start Menu\Programs\Malware Defender 2009
%UserProfile%\Start Menu\Programs\Malware Defender 2009\Malware Defender 2009.lnk
%UserProfile%\Start Menu\Programs\Malware Defender 2009\Uninstall.lnk


Remove registry entries:

HKEY_CLASSES_ROOT\CLSID\{3F0691F1-70E6-44A9-938A-1DC356674878}
HKEY_CLASSES_ROOT\CLSID\{8B2C743A-D44A-4A93-8233-ABEE8BF8ED62}
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defender 2009
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malware Defender 2009
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "updater"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "malwaredef"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "DriversLoad"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "HardwareDrivers"


Please be careful because manual removal of MalwareDefender 2009 may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.

No comments:

/