Home Rogue Websites Defender-review.com

Defender-review.com

Posted: November 13, 2008

Defender-review.com is another con artist site that is associated with Personal Defender 2009 shenanigan schemes. When you become redirected to the Defender-review.com site, a pop up will be displayed claiming that Trojan-Spy.Win32.Banker.aiw has infected your PC.

Avoid the rogue Defender-review.com site if you can and do NOT click on anything if you are redirected there and most importantly do NOT purchase their useless program. Remove the infected as soon as possible with a reliable anti-spyware software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 duzakwq.dll
    2 gtawclv.dll
    3 icmntr.exe
    4 ictun.exe
    5 icun.exe
    6 isfmm.exe
    7 isfmntr.exe
    8 isfun.exe
    9 msmsgs.exe
    10 nvctrl.exe
    11 Online Security Guide.url
    12 pmmon.exe
    13 Security Troubleshooting.url
    14 spwoqbmv.exe
    15 VideoAccessCodecInstall.exe
    16 xbaqktfv.exe
    17 zafhemm.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IExplorer Security Plug-inInternet Explorer Secure Bar

Additional Information on Defender-review.com

  • The following domains were detected:
    # Domain
    1 Defender-review.com
Loading...