MYDEFENS.EXE is FakwAV FakeScan

August 8, 2012 by NightWatcher
Filed under: Malware 
: Solved!

Fix it immediately:

The file MYDEFENS.EXE is a part of Fake Antiviral software.
You must delete the file MYDEFENS.EXE immediately!
Delete the file MYDEFENS.EXE without delay!
Kill the process MYDEFENS.EXE and remove MYDEFENS.EXE from the Windows startup.

Malware Analysis of MYDEFENS.EXE
Full path on a computer: %Program Files%\mydefender\mydefens.exe

Detected by UnHackMe:

Item Name: mydefens
Author:
Related File: %PROGRAM FILES%\MYDEFENDER\MYDEFENS.EXE
Type: Registry Run

Item Name: mydefender.exe
Author:
Related File: %PROGRAM FILES%\MYDEFENDER\MYDEFENDER.EXE
Type: Running Processes

Item Name: mydefen.exe
Author:
Related File: %PROGRAM FILES%\MYDEFENDER\MYDEFEN.EXE
Type: Running Processes

Removal Results: Success
Number of reboot: 1

MYDEFENS.EXE is known as:

FakwAV.FakeScan

MYDEFENS.EXE hash:

  • MD5: e3fd4d86283be9817e3465da34f3647e
The file is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center.
How to quickly detect MYDEFENS.EXE presence?

Registry:
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run\mydefens: “%Program Files%\mydefender\mydefens.exe”
Folders:
  • %Programs%\mydefender
  • %Program Files%\mydefender
Files:
  • %Programs%\mydefender\mydefender E??aAIAo.url
  • %Programs%\mydefender\mydefender.lnk
  • %Programs%\mydefender\Uninstall.lnk
  • %Profile%\version.dat
  • %Program Files%\mydefender\mydefen.exe
  • %Program Files%\mydefender\mydefender.dat
  • %Program Files%\mydefender\mydefender.exe
  • %Program Files%\mydefender\mydefens.exe
  • %SysDir%\uninstmdf.exe


Recommended: UnHackMe anti-rootkit and anti-malware

Premium software: RegRun Security Suite (Good choice for removal and protection)

Written by

Malware Hunter.

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.