Quick Defragmenter

Another variant of a fake Microsoft optimization program was observed lately called Quick Defragmenter, QuickDefragmenter or Quick Defrag virus and found out to keep on propagating itself through the Internet. Just like other programs of the same kind including HDD Defragmenter, Smart Defragmenter and System Defragmenter, this new one will post a number of errors detected as part of its ‘PC Performance and Stability Analysis Report’. To get mentioned irregularities out of the troubled computer, a message to buy the registered version of Quick Defragmenter will keep on flashing the computer screen.

Don’t mind this bogus and potentially unwanted application. As a matter of fact, Quick Defragmenter should be removed from the computer immediately before it can perform additional damages on the compromised PC. A very effective anti-malware program is necessary to remove a rogue program. Below, we have provided a couple of procedures that can easily take out Quick Defragmenter from a contracted computer.

Alias: QuickDefragmenter, Quick Defrag

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

Quick Defragmenter Removal Procedures

Manual Removal:
1. Stop Quick Defragmenter process by pressing Ctrl+Alt+Del. Windows Task Manager will open. Look for the following process:
(random characters).exe
winsp2up.exe

2. Update your installed anti-virus program.
3. Run a full system scan and clean/delete all detected infected file(s). A manual removal of virus-related files should also be performed.
4. Edit Windows registry and delete unwanted entries as described below. [how to edit registry]
5. Exit registry editor.
6. Remove Quick Defragmenter start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. System Configuration Utility will open. Go to Startup tab and uncheck the following Startup item(s):
(random characters).exe
winsp2up.exe

7. Click Apply and restart Windows.

Quick Defragmenter Removal Tool:
In order to completely remove the threat, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.

Using Portable SuperAntiSpyware:
To thoroughly remove the virus, it is best to do a separate scan of another security program so that other infected files not detected by anti-virus application can be remove as well. Click here to download and run SAS Portable Scanner.

Technical Details and Additional Information:

Malicious Files Added by Quick Defragmenter:
%UserProfile%\Start Menu\Programs\Quick Defragmenter
%Temp%\[random].bmp
%Temp%\[random].exe
%Temp%\winsp2up.exe
%Temp%\winsp2upd.dll

Quick Defragmenter Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]“
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “winsp2up.exe”

What to do next...