pcdfdata – the place where PC Defender Plus virus dwells

1 Star2 Stars3 Stars4 Stars5 Stars (100 votes, average: 5.00 out of 5)
loadingLoading...

Today PC Defender Plus malware utility actively attacks quite a large number of computers all over the world. This fake antipspyware utility has been recently launched into the world wide web specifically for the purpose of tricking and deceiving users with its many fake security alerts, warnings, popups and notifications. This rogue is surely the master of scaring users tremendously. First of all, it comes to a random system without user’s permission, knowledge or approval. The installation process of this hoax is hidden from user’s attention, thus nobody can actually terminate its infiltration procedure. Upon successful entry into the infected computer this hoax in addition modifies the system settings of it specifically for the purpose of launching itself automatically together with every system startup. As a result of the above-mentioned perversions, users encounter the GUI of this hoax once then launch their PCs to do something important for them. Hence, instead of doing what they need to do, they have to face the annoying practice of PC Defender Plus virus permanently. Without any doubt, its numerous fake and untrue security alerts are really annoying. Furthermore, the PC infected with PC Defender Plus hoax experiences the tremendous system slowdown.


PC Defender Plus virus

pcdfdata” is the name of the folder where PC Defender scam nests. Its location is as follows – %commonappdata%\pcdfdata. Of course, “%commonappdata%” probably means nothing to you if you are not very well IT literate. For your information please consider this instruction below.

%CommonAppData% stands for the Application Data folder in the All Users profile. For Windows XP, Vista, NT, 2000 and 2003 it has the location C:\Documents and Settings\All Users\Application Data\, and for Windows Vista/Seven it is C:\ProgramData.

Thus, the locations of files associated with PC Defender Plus virus are as follows:

  • C:\Documents and Settings\All Users\Application Data\pcdfdata – For Windows XP
  • C:\ProgramData\pcdfdata – for Windows Vista and Windows Seven

Users who search for “pcdfdata” folder location probably attempt to get rid of this malicious utility manually. However, this is a time-consuming process that requires additional skills of a more IT-professional nature. We recommend you to remove PC Defender Plus scam automatically with the help of GridinSoft Trojan Killer as described below. By the way, one of the most severe processes of PC Defender Plus malware is named “pcdfsvc”. This one can be terminated effectively if you carefully follow the guidelines stipulated below.

Removal guide of PC Defender Plus virus:

  1. Run GridinSoft Trojan Killer:
    Click Win+R and type the direct link for the program’s downloading. https://trojan-killer.net/download.php
  2. Run GridinSoft Trojan Killer
    If your PC is totally blocked and any attemps to launch the computer in such manner are in vain, use this method:
    take your USB flash drive / Memory Stick and download GridinSoft Trojan Killer installation file from this site https://trojan-killer.net/download.php and save it to your USB flash drive / Memory Stick. Get back to your infected PC and insert the USB Drive / Memory Stick into the respective USB slot.

  3. Install GridinSoft Trojan Killer. (If you have Win 7 you need to click the right mouse button on the icon, pick “Run as” and choose with administrator
    rights.If your PC is totally blocked and any attemps to launch the computer in such manner are in vain, use this method:
    take your USB flash drive / Memory Stick and download GridinSoft Trojan Killer installation file from this site https://trojan-killer.net/download.php and save it to your USB flash drive / Memory Stick. Get back to your infected PC and insert the USB Drive / Memory Stick into the respective USB slot, install and launch GridinSoft Trojan Killer.
  4. IMPORTANT!

    Don’t uncheck the Start Trojan Killer checkbox at the end of installation!
    Checkbox

    Manual removal guide of PC Defender Plus virus:

    Delete PC Defender Plus files:

    • %commonappdata%\pcdfdata\defs.bin
    • %commonappdata%\pcdfdata\support.ico
    • %commonappdata%\pcdfdata\config.bin
    • %commonprograms%\PC Defender Plus\PC Defender Plus.lnk

    • %commondesktopdir%\PC Defender Plus.lnk
    • %commonappdata%\pcdfdata\app.ico
    • %commonprograms%\PC Defender Plus\Remove PC Defender Plus.lnk
    • %commonappdata%\pcdfdata\vl.bin
    • %commonprograms%\PC Defender Plus\PC Defender Plus Help and Support.lnk
    • %commonappdata%\pcdfdata\uninst.ico

    Delete PC Defender Plus registry entries:

    The following registry elements have been created:

    • HKEY_CURRENT_USER\.EXE\SHELL\
    • HKEY_CURRENT_USER\.EXE\SHELL\OPEN\
    • HKEY_CURRENT_USER\.EXE\SHELL\OPEN\COMMAND\
    • HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\
    • HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\COMMAND\
    • HKEY_CURRENT_USER\SOFTWARE\CLASSES\.EXE\
    • HKEY_CURRENT_USER\SOFTWARE\CLASSES\.EXE\DEFAULTICON\
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\

    The following registry elements have been changed:

    • HKEY_CURRENT_USER\.EXE\CONTENT TYPE = application/x-m
    • HKEY_CURRENT_USER\.EXE\SHELL\OPEN\COMMAND\ISOLATEDCOMMAND = “%1” %*
    • HKEY_CURRENT_USER\.EXE\SHELL\RUNAS\COMMAND\ISOLATEDCOMMAND = “%1” %*
    • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\PCDFSVC = %ALLUSERSPROFILE%\Application Data\pcdfdata\[random] /min
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\DISPLAYICON = %ALLUSERSPROFILE%\Application Data\pcdfdata\[random] ,0
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\DISPLAYNAME = PC Defender Plus
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\INSTALLLOCATION = %ALLUSERSPROFILE%\Application Data\pcdfdata
    • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PCDFDATA\UNINSTALLSTRING = %ALLUSERSPROFILE%\Application Data\pcdfdata\[random] /tout

Leave a Comment

*