Home / Spyware Encyclopedia / Fake Anti Spyware.Desktop Defender 2010
Recommendation to Automatically remove Fake Anti Spyware.Desktop Defender 2010

Our products can remove Fake Anti Spyware.Desktop Defender 2010, and thousands of other Virus and Spyware automatically and instantly.

 Fake Anti Spyware.Desktop Defender 2010Technical Details
Category Fake Anti Spyware
Discovered 8/8/2008 12:38:13 AM
Modified 1/19/2010 3:36:47 PM
Threat Level Critical
Category Description

These are programs which look like any legitimate program but usually download without users permission, entice users into buying them by showing fake results to improve users PC performance. They may also download spyware and other unwanted programs.
Notice

Summary
The following http urls were started:
NA
The hosts file was updated with the following url-to-ip mappings:
NA  
The following internet connection was established:
207.46.225.221 80
78.129.166.178 80
 

The following Files were created:

NameVersionPublisherSignature(MD5)File Size(in KB)
..\desktop defender 2010\desktop defender 2010.exe 
 4.1.0.5
Nexton Enterprises Ltd.
c40c2bfd196686098d45afc45463a788
22007808
..\desktop defender 2010\ieaddon.dll 
 2.1.9.0
Nexton Enterprises Ltd.
8e27fe88af301cce1eb6999d36ca7074
57344
..\desktop defender 2010\shellext.dll 
 1.9.4.0
Nexton Enterprises Ltd.
527d6f56ccc5288d744968b4f2134fd2
69632
..\desktop defender 2010\af.dll 
   
fe6a7b917aa160afc18c527147611a9c
49152
..\temp\kgcgbtj0etbt.exe 
 1.0.0.0
 
94844627fc9a068556bae8d028fd4bab
49152
..\desktop defender 2010\hjengine.dll 
   
768aaa22d9b36ac2c88d147b54bb1367
626688
..\desktop defender 2010\tdifw_drv_wlh.sys 
   
71f27699fb28e2493a3122a75dafe07c
23552
[SAMPLE]
   
575a876959a4fea5536bae7a34e8a087
3635757
..\temp\.tt6.tmp.exe 
   
575a876959a4fea5536bae7a34e8a087
3635757
..\lphc70tj0etbt.exe 
   
4b731e83c6c3b883c12479d2fcb19558
145920
[SAMPLE]
   
4b731e83c6c3b883c12479d2fcb19558
145920
..\desktop defender 2010\tdifw_drv_wxp.sys 
   
42decb1a9bf7e16506058c0eb3d4bdd0
55552
..\tdifw_drv.sys 
   
42decb1a9bf7e16506058c0eb3d4bdd0
55552


The following Registry Entries were created:

..\Software\Microsoft\Windows\CurrentVersion\Internet Settings\user agent\post platform\"desktop defender 2010"\"desktop defender 2010"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"desktop defender 2010"\"%pf%\desktop defender 2010\desktop defender 2010.exe"
..\Software\Microsoft\Windows\CurrentVersion\Uninstall\desktop defender 2010\(Default)
..\System\CurrentControlSet\Enum\root\legacy_tdifw_drv\(Default)
..\Software\desktop defender 2010\(Default)
..\System\CurrentControlSet\Services\tdifw_drv\(Default)
..\Software\Classes\Folder\shellex\ContextMenuHandlers\antivirus_contextscan\(Default)
..\Software\Classes\Drives\shellex\ContextMenuHandlers\antivirus_contextscan\(Default)
..\Software\Classes\Drive\shellex\ContextMenuHandlers\antivirus_contextscan\(Default)
..\Software\Classes\*\shellex\ContextMenuHandlers\antivirus_contextscan\(Default)
..\Software\Classes\Appid\IEAddon.DLL\"AppID"\"{C0E56AC2-9F72-436E-B6E7-AEC28AF9E4EB}"
..\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}\(Default)
..\Software\Classes\IEAddon.StatusBarPane.1\(Default)
..\Software\Classes\IEAddon.StatusBarPane\(Default)
..\Software\Classes\Appid\{C0E56AC2-9F72-436E-B6E7-AEC28AF9E4EB}\(Default)
..\Software\Classes\Typelib\{3ED0E410-5C8E-47B6-A75D-D10B886E903C}\(Default)
..\Software\Classes\Clsid\{CCB5551D-8594-4999-85F9-1E3EABCB95AC}\(Default)
..\Software\Classes\Clsid\{08EEC6AD-7486-487F-89B7-5A3716DDAE14}\(Default)
..\Software\Classes\Interface\{5B184B9D-B7BD-4FEA-8D1F-5E27182206A5}\(Default)
..\Software\Microsoft\SOFTWARE NOTIFIER\(Default)

The following images were captured:

NA
NA



Recommendation to Automatically remove Fake Anti Spyware.Desktop Defender 2010

Our products can remove Fake Anti Spyware.Desktop Defender 2010, and thousands of other Virus and Spyware automatically and instantly.

Search Threats
Customer Service Rating by LivePerson