| Bleeping Computer | Welcome Guide Blogs Chat Help Search RSS |
|
Remove ArmorDefender (Uninstall Guide)Posted by Grinler on January 19, 2010 @ 03:31 PM · Views: 2,146
What this infection does: ArmorDefender is a rogue anti-virus program from the Wini family of rogues. It is still installed through the use of Trojans that masquerade as Flash updates required to watch an online video. When the Trojan is run it will download and install ArmorDefender and configure it to start automatically when Windows starts. The Trojan will also create numerous harmless files in the C:\Windows and C:\Windows\System32 folders that have random names. These files will then be detected as infections by ArmorDefender when it scans your computer, but ArmorDefender will state it cannot remove these files unless you first purchase the program. This method of create faking infection files on your computer and then detecting them as malware is just a tactic where the developers are trying to convince you that you have a security problem in the hopes that you will then purchase the program.
While the Trojan is running, it will also display numerous security alerts on your computer. These security alerts will contain messages stating that your computer is under attack or that an active malware has been detected. The Trojan will also display a fake Windows Security Center window that suggests that you purchase ArmorDefender to protect your computer. Just like the scan results, these fake security alerts should be ignored. As you can see, the purpose of this rogue is to trick you into thinking there is a security problem on your computer so that you will be convinced to purchase the program. If you have already purchased this program, then we suggest that you contact your credit card company and dispute the charges stating that the program was a scam. Finally, to remove this malware please use the removal guide below.
Threat Classification:
Advanced information: View ArmorDefender files.
Entries for this program found in the Add or Remove Programs control panel: ArmorDefender
Tools Needed for this fix:
Symptoms that may be in a HijackThis Log: O4 - HKLM\..\Run: [ArmorDefender] C:\Program Files\ArmorDefender Software\ArmorDefender\ArmorDefender.exe -min
Guide Updates: 01/19/10 - Initial guide creation.
Automated Removal Instructions for ArmorDefender using Malwarebytes' Anti-Malware:
Your computer should now be free of the ArmorDefender program. If your current anti-virus solution let this infection through, you may want to consider purchasing the PRO version of Malwarebytes' Anti-Malware to protect against these types of threats in the future. If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below: Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help
Associated ArmorDefender Files: c:\Program Files\ArmorDefender Software
Associated ArmorDefender Windows Registry Information: HKEY_CURRENT_USER\Software\ArmorDefender
This is a self-help guide. Use at your own risk. BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can ask for malware removal assistance in our Virus, Trojan, Spyware, and Malware Removal Logs forum. If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.
|
|