Home Malware Programs Rogue Anti-Spyware Programs Windows Defragger

Windows Defragger

Posted: March 18, 2011

Along with other known threats sharing Windows Defragger's code, Windows Defragger is a rogue system maintenance application that pretends to defrag and generally fix up your computer. In the process of faking this activity, Windows Defragger will display errors that require registration of the program to fix. These errors don't actually exist; Windows Defragger's makers just want to snatch up your money without giving you a functional product in exchange. If you spy Windows Defragger on your system, you should remove Windows Defragger since Windows Defragger can adversely affect PC security and change system settings without your permission.

This 'Defragger' Does a Lot of Things... But Not Defragging

Windows Defragger infections are placed on new computers by Trojans, as well as by malicious web domains that falsely warn you that your computer requires a security-related download. You may notice that Windows Defragger bears a strong resemblance to other known threats like Windows Diagnostic and Windows Tool. These rogue security applications all share code, but use different names to trick computer users into believing they're unrelated, legitimate products.

PCs infected by Windows Defragger have been reported to suffer from these highly negative symptoms:

  • Restricted access to various applications, especially Windows maintenance and anti-virus programs. Windows Defragger may alter your system settings to make Windows Defragger appear as though there are no files in program folders or otherwise prevent you from launching a program.
  • Desktop appearance changed without the user's consent. Windows Defragger can change your wallpaper and remove program shortcuts to increase your sense of alarm and to further prevent program access. These changes can persist eve after you've removed Windows Defragger itself.
  • Windows Defragger may also hijack your web browser to block you from seeing websites or redirects to malicious websites. Dangerous websites of the sorts advertised by Windows Defragger are likely to use your personal information in illegal ways or force you to download other malware.
  • Most obviously, Windows Defragger will fake scans for file fragmentation, outdated drivers, HDD reading or writing errors and other minor problems. Windows Defragger's scans will find problems in most areas every single time even if they're not really present. Windows Defragger may also create fake error messages from your taskbar and other areas to continue pushing the idea that there's something wrong with your computer.

Avoiding Victimization by the Great Windows Defragger Fraud

Although Windows Defragger will recommend over and over again that you register Windows Defragger to fix all problems, there are no problems to fix... except for Windows Defragger! Dispute any Windows Defragger-related charges with your credit card company to undo any damage you may have inadvertently caused yourself by giving away your credit card information.

Whether you've fallen for this rogue security program's scam or not, you need to delete Windows Defragger to get your computer back to a state of normalcy. Running a scan with verified anti-malware applications in Safe Mode will take care of Windows Defragger in nine cases out of ten, assuming you've kept your software updated for identifying the latest threats. Most Windows users are vulnerable to attack by Windows Defragger, including users of Windows 7, so don't think that an OS upgrade necessarily makes you immune.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AllUsersProfile%\Application Data\[RANDOM CHARACTERS]
    2 %AllUsersProfile%\Application Data\[RANDOM CHARACTERS].dll
    3 %AllUsersProfile%\Application Data\[RANDOM CHARACTERS].exe
    4 %AllUsersProfile%\Application Data\~[RANDOM CHARACTERS]

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"

Related Posts

Loading...