SaveDefender is another representative of Winisoft family which already has more than 20 “exponents” of rogue applications. As its predecessors, SaveDefender uses backdoor Trojans and misleading online antimalware scanners in order to get into your computer. Once installed, parasite will be configured to start automatically every time you login in Windows. SaveDefender creates numerous files with random names in order to detect infected items. But in reality this files won’t carry any danger to your computer, they are shown to you in order to scare you and push into purchasing licensed version for about a 50$. While running, SaveDefender will bother you with annoying pop-ups, exaggerated scan results and fake security alerts informing that your computer is seriously infected and you must buy full version in order to remove all threats and protect your data and privacy. Last but not least, by using too many system recourses while “working” in background SaveDefender can noticeably slow down your computer. As you see SaveDefender is mostly unwanted application on your computer, we advise you to remove SaveDefender as soon as possible.
Type: Rogue Anti-Spyware
Malware Author: Unknown
Threat Level: Critical
Screenshot:

How to remove SaveDefender manually:
It's possible to remove SaveDefender manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.
The files to be deleted:
c:\Documents and Settings\All Users\Desktop\SaveDefender.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SaveDefender
c:\Documents and Settings\All Users\Start Menu\Programs\SaveDefender\1 SaveDefender.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SaveDefender\2 Homepage.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\SaveDefender\3 Uninstall.lnk
%Temp%\ri2aqoym.exe
c:\Program Files\SaveDefender Software
c:\Program Files\SaveDefender Software\SaveDefender
c:\Program Files\SaveDefender Software\SaveDefender\SaveDefender.exe
c:\Program Files\SaveDefender Software\SaveDefender\uninstall.exe
c:\WINDOWS\101919py365z.ocx
c:\WINDOWS\10203hack9z5l284.ocx
c:\WINDOWS\10ez5parse20909.bin
c:\WINDOWS\system32\13542spazbot13c9.cpl
c:\WINDOWS\system32\13598viruz5b9.ocx
c:\WINDOWS\system32\14397szambot506.exe
Remove registry entries:
HKEY_CURRENT_USER\Software\SaveDefender
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SaveDefender
HKEY_LOCAL_MACHINE\SOFTWARE\SaveDefender
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVEDEFENDERSVC
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SaveDefenderSvc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ri2aqoym.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "SaveDefender"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SaveDefender
HKEY_LOCAL_MACHINE\SOFTWARE\SaveDefender
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVEDEFENDERSVC
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SaveDefenderSvc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ri2aqoym.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "SaveDefender"
Please be careful because manual removal of SaveDefender may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So we strongly recommend you to use automatical removal tool.
No comments:
Post a Comment