Advanced Defender

Advanced Defender is an added malware and a variant of Personal Protector. Both originate from a family of rogue programs. An evaluation made on Advanced Defender shows that it is lack of virus scanning components and therefore all of its generated scans are purely for promotional purposes. It will alert computer users of identified threats that do not actually exist on computer. This rogue program will first sneak into computer as a Trojan that is capable of redirecting Internet browser to scam web sites. These sites may secretly download and execute the fake anti-virus program onto visitor’s PC. The Trojan gets intensify in the presence of harmful software called Advanced Defender.

Fake programs like Advanced Defender is being promoted on its own swindle websites and can be carried-out by Trojan infection. Other ways to acquire this is by visiting malicious web sites that can download and install it on computer without your consent. Removing this unwanted application may not be feasible via Add/Remove of Windows because it does not contain an uninstall component when installed. An anti-malware or removal tool is necessary to completely remove Advanced Defender virus.

Screen Shot Image:

Advanced Defender Image

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Show More Details

Malware Behavior
Advanced Defender’s presence on the computer will cause severe disturbance coming from excessive pop-up alerts and browser redirection. It also precludes users from executing any installed software. Opening or running any programs will exhibit a warning stating virus infection on the executable file. The alert will contain this full message:

“Cmd.exe is infected with worm Lsas.Blaster.Keyloger. This worm is trying to send your credit card details using to connect to remote host.”

This fake alert generated by Advanced Defender is fictitious. It attempts to trick victims about current security status of the system.

Added Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "advanceddefender" 
HKEY_LOCAL_MACHINE\SOFTWARE\Advanced Defender
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Defender
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = "1"
Associated Files and Folders:
%UserProfile%\Desktop\Advanced Defender.lnk
%UserProfile%\Start Menu\Programs\Advanced Defender\Advanced Defender.lnk
C:\Documents and Settings\All Users\Microsoft PData\track.wid
C:\Program Files\Advanced Defender\advanceddefender.exe
C:\Program Files\Advanced Defender\base.wdb
C:\Program Files\Advanced Defender\baseadd.wdb
C:\Program Files\Advanced Defender\conf.wcf
C:\Program Files\Advanced Defender\quarant.wdb
C:\WINDOWS\certofsystem.exe
C:\WINDOWS\explorers.exe
C:\WINDOWS\microsoftdefend.dll
C:\WINDOWS\regp.exe
C:\WINDOWS\secureit.com
C:\WINDOWS\spoos.exe
C:\WINDOWS\system32\winscent.exe 

How to Remove Advanced Defender

Manual Removal Procedure

1. Kill any running process that belongs to Advanced Defender.
- Press Ctrl+Alt+Del on your keyboard.
- When Windows Task Manager appears, look for the following files and click End Task.
algadvanceddefender.exe

2. Delete all registry entries that belong to this malware.
- Press [Windows Key]+R on your keyboard.
- In the 'Open' dialog box, type regedit. This will open registry editor.
- Find and delete the following:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "advanceddefender"
- Close registry editor. Changes made will be save automatically.

3. Scan the computer with antivirus program.
- Connect to Internet and open your antivirus software. Please Update to obtain the latest database and necessary files.
- Restart the computer in Safe Mode.
- Just before Windows logo begins to load press F8 on your keyboard.
- On Windows Advanced Boot Options, select Safe Mode and press Enter.

4. Delete all files dropped by Advanced Defender.
- While still in Safe Mode, search and delete malicious files. Please refer to 'Associated Files and Folders.'

Automatic Removal of Advanced Defender

In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.