Home Malware Programs Rogue Anti-Spyware Programs Defense Center

Defense Center

Posted: June 14, 2010

Threat Metric

Threat Level: 10/10
Infected PCs: 1,134
First Seen: June 17, 2010
Last Seen: February 18, 2023
OS(es) Affected: Windows

ScreenshotDefense Center (aka DefenseCenter) is a rogue antispyware program designed to pilfer money from unwary computer users. Defense Center employs a browser hijacker to redirect users to a fake scan page which produces bogus results claiming the PC is infected with malware. The system will then be bombarded by pop-up alerts urging the purchase of Defense Center to remove the so-called threats. Do not fall for this trickery. It is a blatant scam to get you to spend money. Remove Defense Center using a reliable antispyware program.

ScreenshotScreenshotScreenshotScreenshot

Aliases

Trojan.FakeAV!gen39 [Symantec]W32/FakeAlert.HX.gen!Eldorado [F-Prot]FakeAlert-SecurityTool.i [McAfee]Trojan-Downloader.Win32.Mufanom [Ikarus]Trojan.Win32.Hiloti.gen.f (v) [Sunbelt]Mal/Hiloti-D [Sophos]Trojan-Downloader.Win32.Mufanom.aafz [Kaspersky]Win32:Hilot [Avast]W32/Hiloti.I.gen!Eldorado [F-Prot]a variant of Win32/Cimag.DC [NOD32]Hiloti.gen.e [McAfee]Trojan.Packed.21137 [DrWeb]a variant of Win32/Kryptik.HQD [NOD32]VirTool.Win32.Obfuscator.ah!e (v) [Sunbelt]SecurityToolFraud!Gen4 [Symantec]
More aliases (86)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Defense Center\defcnt.exe File name: defcnt.exe
Size: 1.66 MB (1661952 bytes)
MD5: 11ea668acbcde94ce69dbd3b9ee578ca
Detection count: 251
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Defense Center
Group: Malware file
Last Updated: June 17, 2010
%PROGRAMFILES%\Defense Center\defcnt.exe File name: defcnt.exe
Size: 1.66 MB (1661952 bytes)
MD5: a95737643a2fe963f07d942e36fc341a
Detection count: 201
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Defense Center
Group: Malware file
Last Updated: October 27, 2010
%APPDATA%\Defense Center\defcnt.exe File name: defcnt.exe
Size: 1.66 MB (1661952 bytes)
MD5: 2735a9e7bdd45c3818dbad953d96a941
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Defense Center
Group: Malware file
Last Updated: June 17, 2010
%APPDATA%\Defense Center\defcnt.exe File name: defcnt.exe
Size: 1.66 MB (1661952 bytes)
MD5: bc4995c1afc9fa0c70b1c91c73de66d3
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Defense Center
Group: Malware file
Last Updated: June 17, 2010
%PROGRAMFILES%\Defense Center\defcnt.exe File name: defcnt.exe
Size: 1.66 MB (1661952 bytes)
MD5: 221fdf14fd5bad8d2240c2095fdadedd
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Defense Center
Group: Malware file
Last Updated: June 17, 2010
%PROGRAMFILES%\Defense Center\defcnt.exe File name: defcnt.exe
Size: 1.66 MB (1661952 bytes)
MD5: 82e1fab67f596ef433e692f95835abd5
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Defense Center
Group: Malware file
Last Updated: June 17, 2010
%PROGRAMFILES%\Defense Center\defcnt.exe File name: defcnt.exe
Size: 1.66 MB (1661952 bytes)
MD5: 8b353f4f257ff79532f9d71dcfa46fcd
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Defense Center
Group: Malware file
Last Updated: June 17, 2010
%PROGRAMFILES%\Defense Center\defcnt.exe File name: defcnt.exe
Size: 1.66 MB (1661952 bytes)
MD5: d4c39e90c195c2352e101fcf0bc1d27b
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Defense Center
Group: Malware file
Last Updated: June 17, 2010
%TEMP%\mschrt20ex.dll File name: mschrt20ex.dll
Size: 301.56 KB (301568 bytes)
MD5: 57b453403e62b43ae880b9e280825923
Detection count: 15
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: June 29, 2010
%TEMP%\esentutl64.exe File name: esentutl64.exe
Size: 418.3 KB (418304 bytes)
MD5: e16da8bb88cae88fe72f8969a43e745b
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 29, 2010
%TEMP%\Bf3.exe File name: Bf3.exe
Size: 169.47 KB (169472 bytes)
MD5: d1a06ac9249d9c2554358d0fb5b4d965
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 29, 2010
%WINDIR%\system32\sshnas21.dll File name: sshnas21.dll
Size: 216.06 KB (216064 bytes)
MD5: 70bd4a85f5a25e0f46900e213884e565
Detection count: 10
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: June 29, 2010
%TEMP%\wscsvc32.exe File name: wscsvc32.exe
Size: 220.16 KB (220160 bytes)
MD5: 657bd95834e67585b275cd8be7af0e99
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 29, 2010

Registry Modifications

The following newly produced Registry Values are:

File name without pathDefense Center.lnk

Additional Information

The following directories were created:
%APPDATA%\Defense Center%ProgramFiles%\Defense Center

Related Posts

5 Comments

  • discodan says:

    Hi I am a noob at this I can not get my pc to boot up in safe mode to perform these tasks... can you tell me any other ways to do this?

  • Ron Hahn says:

    It didn't let me delete defext.dll and %Program Files%\Protection Center

  • Ron Hahn says:

    It said %Program Files%\Protection Center is protected and can't be removed.

  • Andy B says:

    Only problem with this process is that task manager has been disabled. Even if you use the run - taskmgr command it simply puts up a message saying "task manager is disabled by your administrator".

    Any thoughts?

  • ioj says:

    it wont let me open the task manager

    HELP

Loading...