PC Defender Plus virus. How to remove it effectively

andy | November 2, 2012

PC Defender Plus is not a real defender. Instead of actually protecting your PC it only imitates the traits of some security program for your computer. So, its presence on your system is really undesirable. When you detect this application on your PC please hurry up to delete it immediately. If you can’t get rid of PC Defender Plus then please follow these guidelines we’ve specifically elaborated to assist users in elimination of this scam. Believe us – we know that you should avoid this hoax by all means!

PC Defender Plus virus

Tricking and scaring users with a lot of deceitful information is the basic feature of PC Defender Plus hoax. Its infiltration is carried out in a hidden manner – thus users cannot really terminate this process easily (unlike with legitimate security applications). During the very installation procedure this virus amends your system and registry settings in such a manner that makes it possible for the virus program to be started automatically together with every system startup.

Fake scans of PC Defender Plus take place each time users turn their computers on. Immediately after the fake scan is over the hoax displays various fake security reports for the only purpose – to scare users tremendously with this faulty information. Please disregard all the information that was reported by this nasty malicious utility. Remember that hackers developed it specifically for the purpose of tricking users and bringing them to the point where they will be asked to buy its helpless and useless licensed version which is not able to assist in removal of real infections. So, be very careful, please! Do not ever commit the serious mistake associated with purchasing this hoax. Instead of doing this please follow the detailed malware removal guide that is means to assist users in extermination of this nasty and rogue antispyware utility.

Removal guide of PC Defender Plus virus:

  1. Run GridinSoft Trojan Killer:
    Click Win+R and type the direct link for the program’s downloading. http://trojan-killer.net/download.php

  2. If your PC is totally blocked and any attemps to launch the computer in such manner are in vain, use this method:
    take your USB flash drive / Memory Stick and download GridinSoft Trojan Killer installation file from this site http://trojan-killer.net/download.php and save it to your USB flash drive / Memory Stick. Get back to your infected PC and insert the USB Drive / Memory Stick into the respective USB slot.

  3. Install GridinSoft Trojan Killer. (If you have Win 7 you need to click the right mouse button on the icon, pick “Run as” and choose with administrator
    rights.If your PC is totally blocked and any attemps to launch the computer in such manner are in vain, use this method:
    take your USB flash drive / Memory Stick and download GridinSoft Trojan Killer installation file from this site http://trojan-killer.net/download.php and save it to your USB flash drive / Memory Stick. Get back to your infected PC and insert the USB Drive / Memory Stick into the respective USB slot, install and launch GridinSoft Trojan Killer.
  4. IMPORTANT!

    Don’t uncheck the Start Trojan Killer checkbox at the end of installation!
    Checkbox

    Manual removal guide of PC Defender Plus virus:

    Delete PC Defender Plus files:

    • %commonappdata%pcdfdatadefs.bin
    • %commonappdata%pcdfdatasupport.ico
    • %commonappdata%pcdfdataconfig.bin
    • %commonprograms%PC Defender PlusPC Defender Plus.lnk

    • %commondesktopdir%PC Defender Plus.lnk
    • %commonappdata%pcdfdataapp.ico
    • %commonprograms%PC Defender PlusRemove PC Defender Plus.lnk
    • %commonappdata%pcdfdatavl.bin
    • %commonprograms%PC Defender PlusPC Defender Plus Help and Support.lnk
    • %commonappdata%pcdfdatauninst.ico

    Delete PC Defender Plus registry entries:

    The following registry elements have been created:

    • HKEY_CURRENT_USER.EXESHELL
    • HKEY_CURRENT_USER.EXESHELLOPEN
    • HKEY_CURRENT_USER.EXESHELLOPENCOMMAND
    • HKEY_CURRENT_USER.EXESHELLRUNAS
    • HKEY_CURRENT_USER.EXESHELLRUNASCOMMAND
    • HKEY_CURRENT_USERSOFTWARECLASSES.EXE
    • HKEY_CURRENT_USERSOFTWARECLASSES.EXEDEFAULTICON
    • HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONUNINSTALLPCDFDATA

    The following registry elements have been changed:

    • HKEY_CURRENT_USER.EXECONTENT TYPE = application/x-m
    • HKEY_CURRENT_USER.EXESHELLOPENCOMMANDISOLATEDCOMMAND = “%1″ %*
    • HKEY_CURRENT_USER.EXESHELLRUNASCOMMANDISOLATEDCOMMAND = “%1″ %*
    • HKEY_CURRENT_USERSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUNPCDFSVC = %ALLUSERSPROFILE%Application Datapcdfdata[random] /min
    • HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONUNINSTALLPCDFDATADISPLAYICON = %ALLUSERSPROFILE%Application Datapcdfdata[random] ,0
    • HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONUNINSTALLPCDFDATADISPLAYNAME = PC Defender Plus
    • HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONUNINSTALLPCDFDATAINSTALLLOCATION = %ALLUSERSPROFILE%Application Datapcdfdata
    • HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONUNINSTALLPCDFDATAUNINSTALLSTRING = %ALLUSERSPROFILE%Application Datapcdfdata[random] /tout

No Comments

4 Trackbacks

Leave a comment

*