Home/ Spyware Encyclopedia / Fake Anti Spyware.WinDefender2008 | |  | Fake Anti Spyware.WinDefender2008 Technical Details |  |
|
| Category |
 |
Fake
Anti Spyware |
| Discovered |
|
7/11/2008
16:03:00 PM |
| Modified |
|
7/11/2008
16:39:00 PM |
| Threat
Level |
 |
Critical |
| Description |
 |
WinDefender2008
or Win Defender
2008, is a Fake
Anti Spyware program.
WinDefender 2008
displays the misleading
or fake scans result
notifying user computer
is infected. WinDefender
2008 displays the
misleading error
messages, system
popups, alert messages
to trick user to
buy the paid version
of WinDefender2008.
If user clicks on
the fake error messages,
it redirected to
win-defender.com
where it encouraged
purchasing WinDefender2008. |
| Summary |
 |
The
hosts file was updated
with the following
url-to-ip mappings
: n/a The
following http urls
were started :
win-defender.com
dl.filekicker.com
dl11.filekicker.net
Generated smtp
traffic : n/a
There was a new
connection established
with a remote IRC
Server : n/a
The Following
Hidden Entries Created
: n/a The
following internet
connection was established: |
| Processes |
|
WDefDemo.exe |
| Drivers |
|
N/A |
| Folders
created |
|
%PFDIR%\WinDefender
2008
%COMMON_PROGRAMS%\WinDefender
2008 Unregistered |
| Browsed
Sites |
|
Win-Defender.com |
| When
the Fake Anti Spyware
is executed, it
creates the following
files: |
| Name |
Version |
Publisher |
Signature
(MD5) |
File
Size (in Bytes) |
| ..\windefender
2008\fwhookdrv.sys |
|
|
50fa7aec76db8eb6f74cab4cf0ca8926 |
3840 |
| ..\windefender
2008\options.xml |
|
|
befdd5d43917b8c6ca13b5f0c08e1603 |
1002 |
| ..\windefender
2008\options.xml |
|
|
7def81b6f78420685947a66c50ecb45d |
1051 |
| ..\windefender
2008 \uninstall_sf_sf_.exe |
|
|
f7566e85f45d3628ba3516df00d3ff96 |
155648 |
| ..\windefender
2008\wdefdemo.exe |
1.0.0.1 |
|
3c7304d9b6a7ed52ede99ed66b16ef09 |
9773056 |
| ..\windefender
2008\wdefdemo.exe |
1.0.0.1 |
|
b7392339290b9f8a398e5927f5a42fcd |
9773056 |
| ..\desktop
\launch windefender
2008.lnk |
|
|
|
642 |
|
|
| When
the Fake Anti Spyware
is executed, it
creates the following
Registry entries: |
| • |
..\software\windefender
2008 |
| • |
..\software\microsoft\windows\currentversion\run\"windefender
2008" |
| • |
..\software\microsoft\windows\currentversion\uninstall\windefender
2008 |
|
Snapshot
 |
| Recommendation to remove Fake Anti Spyware.WinDefender2008 |  | Spyware Detector can remove Fake Anti Spyware.WinDefender2008, and thousands of other Spyware definitions, automatically and instantly. Click here to download Spyware Detector and scan for free. |
| |
|
| |
| |
|  |  | Personalized e-Mail support by our Research Team. You send an "Export Log" report to us, we then add new definition and you eliminate spyware found on YOUR PC in the next Live Update. So, not only do you benefit but the whole community enjoys the feedback.
|  |  | Speed up your computer and increase browsing performance by deleting Spyware & Adware |  |  | Enjoy continuous protection and security with frequent spyware definition updates so you never have to worry about new threats and outdated software. |  |  | Surf the web with confidence knowing your online activities aren't being tracked, and your confidential data is secure from prying eyes. |
|
|
| |  |  | | | |  |  |  | Submit a Threat Submit a threat to be reviewed by our research team
Submit a Threat |  |  |
|
|