Home Malware Programs Rogue Anti-Spyware Programs PC Defender Plus

PC Defender Plus

Posted: October 31, 2012

Threat Metric

Threat Level: 10/10
Infected PCs: 7
First Seen: October 31, 2012
Last Seen: April 18, 2018
OS(es) Affected: Windows

PC Defender Plus Screenshot 1PC Defender Plus is a rogue anti-malware scanner that pretends to detect threats while its alerts and scans always include fake system information. SpywareRemove.com malware research team has identified PC Defender Plus as an old but still threatening member of the WinPC Defender family of scamware, and, like other members of FakeRean, PC Defender Plus may act to block safe programs or make negative changes to your computer's security settings. PC Defender Plus's most notable symptoms include inaccurate system alerts and scans that always display fake infections. Rather than spending money on PC Defender Plus's nonfunctional security functions, you always should use real anti-malware software to remove PC Defender Plus, as a confirmed threat to your PC's well-being.

Why All the Dangers that PC Defender Plus Finds Don't Add Up to a Thing

PC Defender Plus is one of an older branch of still dangerous fake anti-malware programs from the FakeRean group, a collection of scamware products that include numerous brand names and different visual designs. PC Defender Plus's particular branch includes other members like Ultimate Defender, SystemDefender, IE Defender, XP Defender, Advanced XP Defender, WinDefender2008, PCTotalDefender, PC Defender 2008, Personal Defender 2009, WinDefender 2009, Perfect Defender 2009, Total Defender, Malware Defender 2009, WinPC Defender, PC Privacy Defender, Smart Defender Pro, Rogue.UltimateDefender, FraudTool.LastDefender.b and Security Defender Pro 2015.

PC Defender Plus promotes itself as a solid anti-malware product that's detecting malware on your computer almost continuously, but a combination of casual observation and common sense should be capable of telling you that any of PC Defender Plus's warnings are faked. While PC Defender Plus wants you to spend money to make its various pop-ups and automatic scans quiet down, SpywareRemove.com malware experts discourage this waste of money since PC Defender Plus doesn't have any features that are worth your money and can be removed without purchasing PC Defender Plus.

Enjoying the Opposite of a Defense Under PC Defender Plus's Computer Ministrations

While PC Defender Plus is unlikely to employ the sophisticated code-injection-related attacks that most recent members of its family have been found to use, SpywareRemove.com malware researchers confirm that PC Defender Plus can be a security risk due to the unwarranted system changes that PC Defender Plus makes via Registry alterations. PC Defender Plus also has a high chance of:

  • Modifying your browser's settings. This may make your browser vulnerable to web-based attacks.
  • Blocking other programs on your computer – even if there's no reason for them to be blocked. Default Windows security tools have the greatest chance of being blocked by PC Defender Plus, although prominent brands of AV programs may be targeted, too.

SpywareRemove.com malware analysts can't recommend a solution to a PC Defender Plus infection that's better than using anti-malware software to scan your computer and delete all of PC Defender Plus's various features, including any other malware that may be implicated in PC Defender Plus's presence on your system. If PC Defender Plus blocks your favored software, disabling PC Defender Plus (for instance, by booting Windows into Safe Mode) is a commendable workaround.

PC Defender Plus Screenshot 2PC Defender Plus Screenshot 3PC Defender Plus Screenshot 4PC Defender Plus Screenshot 5PC Defender Plus Screenshot 6PC Defender Plus Screenshot 7

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to PC Defender Plus may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner

Note: SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware tool to remove the malware threats. Learn more on SpyHunter. If you would like to uninstall SpyHunter for any reason, please follow these uninstall instructions. To learn more about our policies and practices, visit our EULA, Privacy Policy and Threat Assessment Criteria .

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%CommonAppData%\pcdfdata\support.ico File name: %CommonAppData%\pcdfdata\support.ico
Mime Type: unknown/ico
Group: Malware file
%CommonAppData%\pcdfdata\defs.bin File name: %CommonAppData%\pcdfdata\defs.bin
File type: Binary File
Mime Type: unknown/bin
Group: Malware file
%CommonAppData%\PC Defender Plus\PC Defender Plus.lnk File name: %CommonAppData%\PC Defender Plus\PC Defender Plus.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%CommonAppData%\pcdfdata\config.bin File name: %CommonAppData%\pcdfdata\config.bin
File type: Binary File
Mime Type: unknown/bin
Group: Malware file
%CommonAppData%\pcdfdata\app.ico File name: %CommonAppData%\pcdfdata\app.ico
Mime Type: unknown/ico
Group: Malware file
%CommonAppData%\pcdfdata\vl.bin File name: %CommonAppData%\pcdfdata\vl.bin
File type: Binary File
Mime Type: unknown/bin
Group: Malware file
%CommonAppData%\pcdfdata\uninst.ico File name: %CommonAppData%\pcdfdata\uninst.ico
Mime Type: unknown/ico
Group: Malware file
%CommonPrograms%\PC Defender Plus\Remove PC Defender Plus.lnk File name: %CommonPrograms%\PC Defender Plus\Remove PC Defender Plus.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%CommonPrograms%\PC Defender Plus\PC Defender Plus Help and Support.lnk File name: %CommonPrograms%\PC Defender Plus\PC Defender Plus Help and Support.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%CommonDesktopDir%\PC Defender Plus.lnk File name: %CommonDesktopDir%\PC Defender Plus.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\COMMAND\ISOLATEDCOMMAND = "%1" %*HKEY_CURRENT_USER\.EXE\CONTENT TYPE = application/x-mHKEY_CURRENT_USER\.EXE\SHELL\OPEN\COMMAND\ISOLATEDCOMMAND = "%1" %*HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\PCDFSVC = %ALLUSERSPROFILE%\Application Data\pcdfdata\[RANDOM CHARACTERS] /minHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\INSTALLLOCATION = %ALLUSERSPROFILE%\Application Data\pcdfdataHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\DISPLAYNAME = PC Defender PlusHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\DISPLAYICON = %ALLUSERSPROFILE%\Application Data\pcdfdata\[RANDOM CHARACTERS] ,0HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\UNINSTALLSTRING = %ALLUSERSPROFILE%\Application Data\pcdfdata\[RANDOM CHARACTERS] /toutHKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\COMMAND\HKEY_CURRENT_USER\SOFTWARE\CLASSES\.EXE\HKEY_CURRENT_USER\.EXE\SHELL\OPEN\COMMAND\HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\HKEY_CURRENT_USER\.EXE\SHELL\HKEY_CURRENT_USER\.EXE\SHELL\OPEN\HKEY_CURRENT_USER\SOFTWARE\CLASSES\.EXE\DEFAULTICON\HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\

Related Posts