Malware Defender 2009 (Removal Instructions)

Malware Defender 2009 is a rogue security software, it is a false anti-spyware application that is generally installed in the user’s computer by dangerous trojans (such as Zlob and false video codecs), but it can also be installed manually by the victim.

Once your computer is infected with this parasite, it will immediately displays security warnings, alerts and system scans stating that your computer is heavily infected. These warnings are all false and are only displayed to make you think your computer is truly infected and that it is necessary to buy the full version of the software to remove the so-called infections.

Malware Defender 2009 Screenshot

Make sure to not fall in this scam, if your computer is infected with Malware Defender 2009, it is recommended to remove it immediately and to scan your system with a real security software.

Symptoms of infection

  • The process reged.exe is running in your system
  • The process malwaredef.exe is running in your system
  • The process spoolsystem.exe is running in your system
  • The process sysexplorer.exe is running in your system
  • The process wcenter.exe is running in your system
  • Slow computer performance
  • Repeated security warnings, alerts and system scans
  • Web sites that suddenly are shown on your desktop

Malicious web sites and urls:

1
2
3
easywinscanner17.com (209.249.222.48)
malwaredefender2009.com (67.43.237.75)
gomaldef09.com (67.43.237.77)

When the program is executed, it creates the following files:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
%ProgramFiles%\Malware Defender 2009
%ProgramFiles%\Malware Defender 2009\conf.cfg
%ProgramFiles%\Malware Defender 2009\malwaredef.exe
%ProgramFiles%\Malware Defender 2009\mbase.vdb
%ProgramFiles%\Malware Defender 2009\quarantine.vdb
%ProgramFiles%\Malware Defender 2009\queue.vdb
%ProgramFiles%\Malware Defender 2009\uninstall.exe
%ProgramFiles%\Malware Defender 2009\vbase.vdb
%ProgramFiles%\Malware Defender 2009\quarantine
C:\WINDOWS\reged.exe
C:\WINDOWS\spoolsystem.exe
C:\WINDOWS\sys.com
C:\WINDOWS\syscert.exe
C:\WINDOWS\sysexplorer.exe
C:\WINDOWS\vmreg.dll
C:\WINDOWS\system32\wcenter.exe
%AllUsers%\Application Data\Microsoft\Media Index\Drivers
%AllUsers%\Application Data\Microsoft\win.exe
%AllUsers%\Application Data\Microsoft\Media Index\svchos.exe
%AllUsers%\Application Data\Microsoft\Media Index\t.id
%AllUsers%\Application Data\Microsoft\Media Index\Drivers\c.cgm
%AllUsers%\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll
%AllUsers%\Application Data\Microsoft\Media Index\Drivers\vwkemjwebr.dll
%AllUsers%\Application Data\Microsoft\Network\install.exe

The program creates the following registry entries:

1
2
3
4
HKLM\SOFTWARE\Malware Defender 2009
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malware Defender 2009
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\updater
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\malwaredef

How to remove Malware Defender 2009 (manual removal) ?

  • Kill the running process malwaredef.exe
  • Kill the running process reged.exe
  • Kill the running process wcenter.exe
  • Kill the running process sysexplorer.exe
  • Kill the running process spoolsystem.exe
  • Unregister all the Malware Defender 2009 DLLs
  • Delete all the Malware Defender 2009 files
  • Delete all the Malware Defender 2009 registry entries

How to remove Malware Defender 2009 (automatic removal) ?

Random Posts

Previous Posts