PC Defender Plus
Posted: October 31, 2012
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Threat Level: | 10/10 |
---|---|
Infected PCs: | 7 |
First Seen: | October 31, 2012 |
---|---|
Last Seen: | April 18, 2018 |
OS(es) Affected: | Windows |
PC Defender Plus is a rogue anti-malware scanner that pretends to detect threats while its alerts and scans always include fake system information. SpywareRemove.com malware research team has identified PC Defender Plus as an old but still threatening member of the WinPC Defender family of scamware, and, like other members of FakeRean, PC Defender Plus may act to block safe programs or make negative changes to your computer's security settings. PC Defender Plus's most notable symptoms include inaccurate system alerts and scans that always display fake infections. Rather than spending money on PC Defender Plus's nonfunctional security functions, you always should use real anti-malware software to remove PC Defender Plus, as a confirmed threat to your PC's well-being.
Why All the Dangers that PC Defender Plus Finds Don't Add Up to a Thing
PC Defender Plus is one of an older branch of still dangerous fake anti-malware programs from the FakeRean group, a collection of scamware products that include numerous brand names and different visual designs. PC Defender Plus's particular branch includes other members like Ultimate Defender, SystemDefender, IE Defender, Advanced XP Defender, XP Defender, WinDefender2008, PCTotalDefender, PC Defender 2008, Personal Defender 2009, WinDefender 2009, Perfect Defender 2009, Total Defender, Malware Defender 2009, WinPC Defender, PC Privacy Defender, Smart Defender Pro, Rogue.UltimateDefender, FraudTool.LastDefender.b and Security Defender Pro 2015.
PC Defender Plus promotes itself as a solid anti-malware product that's detecting malware on your computer almost continuously, but a combination of casual observation and common sense should be capable of telling you that any of PC Defender Plus's warnings are faked. While PC Defender Plus wants you to spend money to make its various pop-ups and automatic scans quiet down, SpywareRemove.com malware experts discourage this waste of money since PC Defender Plus doesn't have any features that are worth your money and can be removed without purchasing PC Defender Plus.
Enjoying the Opposite of a Defense Under PC Defender Plus's Computer Ministrations
While PC Defender Plus is unlikely to employ the sophisticated code-injection-related attacks that most recent members of its family have been found to use, SpywareRemove.com malware researchers confirm that PC Defender Plus can be a security risk due to the unwarranted system changes that PC Defender Plus makes via Registry alterations. PC Defender Plus also has a high chance of:
- Modifying your browser's settings. This may make your browser vulnerable to web-based attacks.
- Blocking other programs on your computer – even if there's no reason for them to be blocked. Default Windows security tools have the greatest chance of being blocked by PC Defender Plus, although prominent brands of AV programs may be targeted, too.
SpywareRemove.com malware analysts can't recommend a solution to a PC Defender Plus infection that's better than using anti-malware software to scan your computer and delete all of PC Defender Plus's various features, including any other malware that may be implicated in PC Defender Plus's presence on your system. If PC Defender Plus blocks your favored software, disabling PC Defender Plus (for instance, by booting Windows into Safe Mode) is a commendable workaround.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%CommonAppData%\pcdfdata\support.ico
File name: %CommonAppData%\pcdfdata\support.icoMime Type: unknown/ico
Group: Malware file
%CommonAppData%\pcdfdata\defs.bin
File name: %CommonAppData%\pcdfdata\defs.binFile type: Binary File
Mime Type: unknown/bin
Group: Malware file
%CommonAppData%\PC Defender Plus\PC Defender Plus.lnk
File name: %CommonAppData%\PC Defender Plus\PC Defender Plus.lnkFile type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%CommonAppData%\pcdfdata\config.bin
File name: %CommonAppData%\pcdfdata\config.binFile type: Binary File
Mime Type: unknown/bin
Group: Malware file
%CommonAppData%\pcdfdata\app.ico
File name: %CommonAppData%\pcdfdata\app.icoMime Type: unknown/ico
Group: Malware file
%CommonAppData%\pcdfdata\vl.bin
File name: %CommonAppData%\pcdfdata\vl.binFile type: Binary File
Mime Type: unknown/bin
Group: Malware file
%CommonAppData%\pcdfdata\uninst.ico
File name: %CommonAppData%\pcdfdata\uninst.icoMime Type: unknown/ico
Group: Malware file
%CommonPrograms%\PC Defender Plus\Remove PC Defender Plus.lnk
File name: %CommonPrograms%\PC Defender Plus\Remove PC Defender Plus.lnkFile type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%CommonPrograms%\PC Defender Plus\PC Defender Plus Help and Support.lnk
File name: %CommonPrograms%\PC Defender Plus\PC Defender Plus Help and Support.lnkFile type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%CommonDesktopDir%\PC Defender Plus.lnk
File name: %CommonDesktopDir%\PC Defender Plus.lnkFile type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
Registry Modifications
HKEY..\..\{Value}HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\COMMAND\ISOLATEDCOMMAND = "%1" %*HKEY_CURRENT_USER\.EXE\CONTENT TYPE = application/x-mHKEY_CURRENT_USER\.EXE\SHELL\OPEN\COMMAND\ISOLATEDCOMMAND = "%1" %*HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\PCDFSVC = %ALLUSERSPROFILE%\Application Data\pcdfdata\[RANDOM CHARACTERS] /minHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\INSTALLLOCATION = %ALLUSERSPROFILE%\Application Data\pcdfdataHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\DISPLAYNAME = PC Defender PlusHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\DISPLAYICON = %ALLUSERSPROFILE%\Application Data\pcdfdata\[RANDOM CHARACTERS] ,0HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\UNINSTALLSTRING = %ALLUSERSPROFILE%\Application Data\pcdfdata\[RANDOM CHARACTERS] /toutHKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\COMMAND\HKEY_CURRENT_USER\SOFTWARE\CLASSES\.EXE\HKEY_CURRENT_USER\.EXE\SHELL\OPEN\COMMAND\HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\HKEY_CURRENT_USER\.EXE\SHELL\HKEY_CURRENT_USER\.EXE\SHELL\OPEN\HKEY_CURRENT_USER\SOFTWARE\CLASSES\.EXE\DEFAULTICON\HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.