|
Free malware removal tool to remove SysDefenders
|
|
Écrit par Administrator |
Mardi, 12 Janvier 2010 14:36
|
|
There are no translations available.
SysDefenders is a fake antivirus which installs itself on your system without your will. This fake Antivirus comes from WiniSoft family, they have just changed the name of the application, the file names but the rest is the same. Its purpose is to scare you by posting false scan results so that you spend money on buying a full version which by the way doesn't even exist. Do not purchase this bogus application. Remove SysDefenders as soon as possible from your system. Beware of this scam.

To remove SysDefenders
- Download and extract this removal tool for SysDefenders
- Click on the delete button

SysDefenders will be removed in 10s. Restart your computer when it's finished.
Folder
- %CommonPrograms%\SysDefenders
- %Temp%\nsa2.tmp
- %ProgramFiles%\SysDefenders Software
- %ProgramFiles%\SysDefenders Software\SysDefenders
Files
- %CommonDesktopDir%\SysDefenders.lnk
- %CommonPrograms%\SysDefenders\1 SysDefenders.lnk
- %CommonPrograms%\SysDefenders\2 Homepage.lnk
- %CommonPrograms%\SysDefenders\3 Uninstall.lnk
- %Temp%\nsa2.tmp\nsProcess.dll
- %Temp%\[random].exe
- %ProgramFiles%\SysDefenders Software\SysDefenders\SysDefenders.exe
- %ProgramFiles%\SysDefenders Software\SysDefenders\uninstall.exe
- %System%\wbem\Performance\WmiApRpl_new.ini
Registry
Regisytry key created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SysDefenders
- HKEY_LOCAL_MACHINE\SOFTWARE\SysDefenders
- HKEY_CURRENT_USER\Software\SysDefenders
Registry values created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SysDefenders
- DisplayName = "SysDefenders"
- UninstallString = ""%ProgramFiles%\SysDefenders Software\SysDefenders\uninstall.exe""
- NoModify = 0x00000001
- NoRepair = 0x00000001
- HKEY_LOCAL_MACHINE\SOFTWARE\SysDefenders
- Lang = "English"
- Install_Dir = "%ProgramFiles%\SysDefenders Software\SysDefenders"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- SysDefenders = "%ProgramFiles%\SysDefenders software\SysDefenders\SysDefenders.exe"
- [random].exe = "%Temp%\[random].exe"
- HKEY_CURRENT_USER\Software\SysDefenders
- CurrentVersion =
- "771eb5b6f272744584a5567cff88f8a7d17c6bcd7ae..."
- AgentsSettings = 0x00000001

|