PC Defender Plus rogue removal instructions.

PC Defender Plus is new fake anti-virus program that actively bombards the average PC users. Many of our customers are currently complaining of this badware which is causing their PCs to act up. So right away we want to get it straight to all those who found this post that PC Defender Plus is a rogue security client developped to rip you off. No one is 100% safe, almost every Internet surfer is exposed to the intrusion of this cyber beast.PC Defender Plus virus

This is because the downloader for this scareware tends to hide on different web resources, even some decent ones that got compromised by hackers. There are several apparent symptoms you can tell the presence of this virus on your computer by. These are annoying popup ads. Such as you see below:PC Defender Plus Firewall  Fake Alert
and scan reports; browser usage problems. To be short all is done to make you believe that you PC suffers from real security bugs.

You are slightly bringing to the point when you should fill out your payment details for purchasing your copy of PC Defender Plus allegedly able to cure your PC. In the meanwhile, along with the side effects we have listed, you will see your computer get much slower as before. What do you do about this mess? To tell the truth PC Defender Plus removal is not an easy task, but not impossible. You will reach success on condition of careful following all steps shown in the section below.

Removal guide of PC Defender Plus virus:

  1. Run GridinSoft Trojan Killer:
    Click Win+R and type the direct link for the program’s downloading. direct link for the program’s downloading
    If your PC is totally blocked and any attemps to launch the computer in such manner are in vain, use this method:
    take your USB flash drive / Memory Stick and download GridinSoft Trojan Killer installation file from this site http://trojan-killer.net/download.php and save it to your USB flash drive / Memory Stick. Get back to your infected PC and insert the USB Drive / Memory Stick into the respective USB slot.
  2. Install GridinSoft Trojan Killer. (If you have Win 7 you need to click the right mouse button on the icon, pick “Run as” and choose with administrator
    rights.If your PC is totally blocked and any attemps to launch the computer in such manner are in vain, use this method:
    take your USB flash drive / Memory Stick and download GridinSoft Trojan Killer installation file from this site http://trojan-killer.net/download.php and save it to your USB flash drive / Memory Stick. Get back to your infected PC and insert the USB Drive / Memory Stick into the respective USB slot, install and launch GridinSoft Trojan Killer.
  3. IMPORTANT!

    Don’t uncheck the Start Trojan Killer checkbox at the end of installation!
    Checkbox

    Manual removal guide of PC Defender Plus virus:

    Delete PC Defender Plus files:

    • %commonappdata%\pcdfdata\defs.bin
    • %commonappdata%\pcdfdata\support.ico
    • %commonappdata%\pcdfdata\config.bin
    • %commonprograms%\PC Defender Plus\PC Defender Plus.lnk

    • %commondesktopdir%\PC Defender Plus.lnk
    • %commonappdata%\pcdfdata\app.ico
    • %commonprograms%\PC Defender Plus\Remove PC Defender Plus.lnk
    • %commonappdata%\pcdfdata\vl.bin
    • %commonprograms%\PC Defender Plus\PC Defender Plus Help and Support.lnk
    • %commonappdata%\pcdfdata\uninst.ico

    Delete PC Defender Plus registry entries:

    The following registry elements have been created:

    • HKEY_CURRENT_USER\.EXE\SHELL\
    • HKEY_CURRENT_USER\.EXE\SHELL\OPEN\
    • HKEY_CURRENT_USER\.EXE\SHELL\OPEN\COMMAND\
    • HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\
    • HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\COMMAND\
    • HKEY_CURRENT_USER\SOFTWARE\CLASSES\.EXE\
    • HKEY_CURRENT_USER\SOFTWARE\CLASSES\.EXE\DEFAULTICON\
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\

    The following registry elements have been changed:

    • HKEY_CURRENT_USER\.EXE\CONTENT TYPE = application/x-m
    • HKEY_CURRENT_USER\.EXE\SHELL\OPEN\COMMAND\ISOLATEDCOMMAND = “%1” %*
    • HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\COMMAND\ISOLATEDCOMMAND = “%1” %*
    • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\PCDFSVC = %ALLUSERSPROFILE%\Application Data\pcdfdata\[random] /min
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\DISPLAYICON = %ALLUSERSPROFILE%\Application Data\pcdfdata\[random] ,0
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\DISPLAYNAME = PC Defender Plus
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\INSTALLLOCATION = %ALLUSERSPROFILE%\Application Data\pcdfdata
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\UNINSTALLSTRING = %ALLUSERSPROFILE%\Application Data\pcdfdata\[random] /tout

Leave a Comment

*