A Very Important Message about anti-spyware software:
It is very sad to mention that this sector of Computing Security is a jungle. Not like others, anti-virus or firewalls. There are many bad or fake anti-spyware softwares out here that actually hi-jack your web browsers for one to try to force purchase to get your PC back. This is a must website to view before purchasing any anti-spyware software ! Note that there are legal liabilities for professionals in reporting bad software and this is a compliant website and very known at forums and groups:
Title: The Spyware Warrior List of Rogue/Suspect Anti-Spyware Products & Web Sites
Description: Bad, False, Fake products
URL: http://www.spywarewarrior.com/rogue_anti-spyware.htm
Ultimate Defender
Date Published:
Tuesday, March 7, 2006
http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453097665
Characteristics:
Category: Rogue Security Software
Description
Vendor Description
UDefender is one of the most popular and effective products against spyware and adware on the market. It is a strong shield for you home PC. Powerful system of detection and removal will clean your PC from already installed spyware and unique intellectual Real Time Protection system will let you surf internet safely and privately. Say NO! to spyware today.
Category
Rogue Security Software: Security software that uses deceptive means for installation and purpose. Once installed, the rogue software usually uses scare tactics to inform the user that spyware or malware is installed on their system. The rogue security software then claims to offer remediation in exchange of payment. These applications can come bundled with other malware that serve other purposes. This software usually comes in the form of Anti-spyware, or Anti-virus applications.
Reasons For Retention
During testing, Ultimate Defender reported the presence of a Trojan name Win32.Beovens.C on a clean system. None of the major commercial antivirus or antispyware products detected the presence of malware. Ultimate Defender (purposely) did not disclose the location of the Win32.Beovens.C object, making it impossible to verify its claim. However, Ultimate Defend
er will try to get the user to buy the full product to remove the threat (that is non existent) Currently Ultimate Defender is reporting a McAfee file (mcinfo.exe) as being infected by Win32.BotNet.94C4D. Scanning done by major AV and AS vendors report nothing wrong with this file (full scans are clean). Plus continual hounding to register/purchase Ultimate Defender to clean this "critical" infection.
Removal
Detections:
true
Executable Files:
true
Autorun References:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run ultimate defender
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run ultimate defender
Registry Items:
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run ultimate defender
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ultimate defender
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ultimate defender displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ultimate defender uninstallstring
HKEY_LOCAL_MACHINE\software\ultimate defender
HKEY_LOCAL_MACHINE\software\ultimate defender _islocal
HKEY_LOCAL_MACHINE\software\ultimate defender code
HKEY_LOCAL_MACHINE\software\ultimate defender email
HKEY_LOCAL_MACHINE\software\ultimate defender id
HKEY_LOCAL_MACHINE\software\ultimate defender info
HKEY_LOCAL_MACHINE\software\ultimate defender lis
HKEY_LOCAL_MACHINE\software\ultimate defender pstatus
HKEY_LOCAL_MACHINE\software\ultimate defender version
HKEY_LOCAL_MACHINE\software\ultimate defender\updates
HKEY_LOCAL_MACHINE\software\ultimate defender\updates check
HKEY_LOCAL_MACHINE\software\ultimate defender\updates download
HKEY_LOCAL_MACHINE\software\ultimate defender\updates reinstall
HKEY_CURRENT_USER\software\ultimate defender
HKEY_CURRENT_USER\software\ultimate defender hide
HKEY_CURRENT_USER\software\ultimate defender lastrun
HKEY_CURRENT_USER\software\ultimate defender remind
HKEY_CURRENT_USER\software\ultimate defender remind_at
HKEY_CURRENT_USER\software\ultimate defender state
HKEY_CURRENT_USER\software\ultimate defender totaldetected
HKEY_CURRENT_USER\software\ultimate defender totalruns
HKEY_CURRENT_USER\software\ultimate defender\erase
HKEY_CURRENT_USER\software\ultimate defender\scan
HKEY_CURRENT_USER\software\ultimate defender\scan options
HKEY_CURRENT_USER\software\ultimate defender\scan\whitelist
HKEY_CURRENT_USER\software\ultimate defender\scan\whitelist adware.win32.rdata
HKEY_CURRENT_USER\software\ultimate defender\scan\whitelist winpcap
HKEY_CURRENT_USER\software\ultimate defender\scripts\variables
HKEY_CURRENT_USER\software\ultimate defender\scripts\variables %content-length%
HKEY_CURRENT_USER\software\ultimate defender\scripts\variables %content-md5%
HKEY_CURRENT_USER\software\ultimate defender\scripts\variables %t%
HKEY_CURRENT_USER\software\ultimate defender\scripts\variables %wmid%
HKEY_CURRENT_USER\software\ultimate defender\settings
HKEY_CURRENT_USER\software\ultimate defender\settings hotkey
HKEY_CURRENT_USER\software\ultimate defender\settings hotkeyurgenthiddencleaning
HKEY_CURRENT_USER\software\ultimate defender\settings options
HKEY_CURRENT_USER\software\ultimate defender\settings proxyaddress
HKEY_CURRENT_USER\software\ultimate defender\settings proxyport
HKEY_CURRENT_USER\software\ultimate defender\settings rectwindow
HKEY_CURRENT_USER\software\ultimate defender\settings scheduleoptions
HKEY_CURRENT_USER\software\ultimate defender\settings scheduletime
HKEY_CURRENT_USER\software\ultimate defender\settings tipday
HKEY_CURRENT_USER\software\ultimate defender\settings tipn
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\application restrictions
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\application restrictions options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\browser helper objects
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\browser helper objects options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\disable regedit policy
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\disable regedit policy options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\ie reset web settings
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\ie reset web settings options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer 3rd party cookies
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer 3rd party cookies options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer explorer bars
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer explorer bars options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer extensions
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer extensions options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer menu extension
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer menu extension options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer plugins
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer plugins options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer restrictions
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer restrictions options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer security settings
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer security settings options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer security zones
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer security zones options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer shellbrowser
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer shellbrowser options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer toolbars
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer toolbars options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer trusted sites
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer trusted sites options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer urls
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer urls options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer webbrowser
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\internet explorer webbrowser options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\startup files
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\startup files options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\startup registry files
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\startup registry files options
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\url search hooks
HKEY_CURRENT_USER\software\ultimate defender\shield\application agent checkpoints\url search hooks options
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\dialup connection
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\dialup connection options
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\internet proxy server
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\internet proxy server options
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\internet trusted sites
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\internet trusted sites options
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\name server protection
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\name server protection options
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\tcpip parameters
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\tcpip parameters options
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\winsock layered service providers
HKEY_CURRENT_USER\software\ultimate defender\shield\internet agents checkpoints\winsock layered service providers options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\active desktop
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\active desktop options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\active desktop\items
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\appinit dlls
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\appinit dlls options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\approved shell extensions
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\approved shell extensions options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\context menu handler
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\context menu handler options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\control.ini policy
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\control.ini policy options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\explorer trojan
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\explorer trojan options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\ini file mapping
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\ini file mapping options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\shared taskscheduler
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\shared taskscheduler options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\shell service object delay load
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\shell service object delay load options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\user shell folders
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\user shell folders options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows directory trojans
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows directory trojans options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows extensions
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows extensions options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows hosts file
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows hosts file options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows password protection
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows password protection options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows protocols
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows protocols options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows restrict anonymous
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows restrict anonymous options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows services
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows services options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows shell execute hooks
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows shell execute hooks options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows update service
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\windows update service options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\winlogon shell
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\winlogon shell options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\winlogon userinit
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\winlogon userinit options
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\wow boot shell
HKEY_CURRENT_USER\software\ultimate defender\shield\system agent checkpoints\wow boot shell options
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run ultimate defender
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run ultimate defender
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run ultimate defender
Files:
%program_files%\ultimate defender\uninstall.exe
%program_files%\ultimate defender\app.exe
%program_files%\ultimate defender\extensions.pkg
%program_files%\ultimate defender\ultimatedefender.exe
udefender_installer.exe
%program_files%\ultimate defender\iesafe.exe
%program_files%\ultimate defender\program.info
%program_files%\ultimate defender\udefender.pkg
%program_files%\ultimate defender\ultimatedefender.db
udefender_setup.exe
ultimate defender.lnk
ultimate defender.pkg
ultimatedefender.db
ultimatedefender.exe
uninstall ultimate defender.lnk
uninstall.exe
update.exe
%common_programs%\ultimate defender\ultimate defender uninstall.lnk
%common_programs%\ultimate defender\ultimate defender.lnk
%common_startmenu%\ultimate defender\register ultimate defender.lnk
%common_startmenu%\ultimate defender\start ultimate defender.lnk
%common_startmenu%\ultimate defender\uninstall ultimate defender.lnk
%desktopdirectory%\ultimate defender.lnk
%desktopdirectory%\ultimate defender.pkg
%profile%\start menu\ultimate defender\register ultimate defender.lnk
%profile%\start menu\ultimate defender\start ultimate defender.lnk
%profile%\start menu\ultimate defender\uninstall ultimate defender.lnk
%program_files%\ultimate defender\_uninstall.log
_uninstall.log
app.exe
extensions.pkg
iesafe.exe
program.info
register ultimate defender.lnk
start ultimate defender.lnk
udefender.pkg
%program_files%\ultimate defender\update.exe
udefender_installer.exe
%program_files%\ultimate defender\app.exe
%program_files%\ultimate defender\ultimatedefender.exe
udefender_setup.exe
%program_files%\ultimate defender\uninstall.exe
%program_files%\ultimate defender\iesafe.exe
%program_files%\ultimate defender\update.exe
Directories:
%common_programs%\ultimate defender
%common_startmenu%\ultimate defender
%profile%\application data\ultimate defender
%profile%\application data\ultimate defender\logs
%profile%\start menu\ultimate defender
%program_files%\ultimate defender
File Analysis http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453097665
Copyright © 2007 CA