MYDEFENDER.EXE is FakwAV FakeScan

August 8, 2012 by NightWatcher
Filed under: Malware 
: Solved!

You should Download Removal Tool here...

The file MYDEFENDER.EXE is a part of Fake Antiviral software.
You must delete the file MYDEFENDER.EXE immediately!
Delete the file MYDEFENDER.EXE without delay!
Kill the process MYDEFENDER.EXE and remove MYDEFENDER.EXE from the Windows startup.

Malware Analysis of MYDEFENDER.EXE
Full path on a computer: %Program Files%\mydefender\mydefender.exe

Detected by UnHackMe:

Item Name: mydefens
Author:
Related File: %PROGRAM FILES%\MYDEFENDER\MYDEFENS.EXE
Type: Registry Run

Item Name: mydefender.exe
Author:
Related File: %PROGRAM FILES%\MYDEFENDER\MYDEFENDER.EXE
Type: Running Processes

Item Name: mydefen.exe
Author:
Related File: %PROGRAM FILES%\MYDEFENDER\MYDEFEN.EXE
Type: Running Processes

Removal Results: Success
Number of reboot: 1

MYDEFENDER.EXE is known as:

FakwAV.FakeScan

MYDEFENDER.EXE hash:

  • MD5: 76102857eaa994620843ff82444b0091
The file tries to download information from some web sites.
How to quickly detect MYDEFENDER.EXE presence?

Registry:
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run\mydefens: “%Program Files%\mydefender\mydefens.exe”
Folders:
  • %Programs%\mydefender
  • %Program Files%\mydefender
Files:
  • %Programs%\mydefender\mydefender E??aAIAo.url
  • %Programs%\mydefender\mydefender.lnk
  • %Programs%\mydefender\Uninstall.lnk
  • %Profile%\version.dat
  • %Program Files%\mydefender\mydefen.exe
  • %Program Files%\mydefender\mydefender.dat
  • %Program Files%\mydefender\mydefender.exe
  • %Program Files%\mydefender\mydefens.exe
  • %SysDir%\uninstmdf.exe


Recommended: UnHackMe anti-rootkit and anti-malware

Premium software: RegRun Security Suite (Good choice for removal and protection)

Written by

Malware Hunter.

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.