Monday, September 13, 2010

IronDefender Removal GuideIronDefender Removal Guide

IronDefender Removal Guide
IronDefender is a fake antivirus program that disguises itself a legitimate antivirus program. IronDefender cannot detect any malware and also remove any malware from the computer. After IronDefender installs itself into the computer, it will start automatically when Windows boot. Then, IronDefender will scan the computer and scares the user that the computer is infected by malwares. IronDefender will ask the user to register IronDefender by purchasing the full version of IronDefender to eliminate the malwares. Don't believe all of them as it is a lie.

IronDefender produce fake features like "Full Scan", "System Scan", "Scan Basic Locations", "Scan Removable Media", "Scan Folder", "Realtime protection" and "Tools". All of the features do not really protect the computer but just show the fake functions only.

IronDefender should be removed immediately!

IronDefender Removal Guide
Kill Process
(How to kill a process effectively?)
F0E84.exe
vur4.exe
[random].exe

Delete Registry
HKEY_CURRENT_USER\Software\IronDefender
HKEY_LOCAL_MACHINE\SOFTWARE\IronDefender
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IronDefender
HKEY_CURRENT_USER\Software "Install_Dir" = "C:\Program Files\FDFCA"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "vur4.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "F0E84.exe"

Remove Folders and Files
%ALLUSERSPROFILE%\Start Menu\Programs\IronDefender.lnk
%ProgramFiles%\FDFCA\
%ProgramFiles%\FDFCA\F0E84.exe
%ProgramFiles%\FDFCA\Uninstall.exe
%SystemRoot%\[random].exe
%SystemRoot%\[random].bin
%SystemRoot%\[random].dll
%SystemRoot%\[random].cpl
%SystemRoot%\system32\[random].exe
%SystemRoot%\system32\[random].bin
%SystemRoot%\system32\[random].dll
%SystemRoot%\system32\[random].cpl
%UserProfile%\Desktop\hash
%UserProfile%\Desktop\IronDefender.lnk
%UserProfile%\Local Settings\Temp\[random].exe

No comments:

Post a Comment