Home > Threats > Ultimate Defender

What is Ultimate Defender

Posted on 6 July 2007 under Rogue Programs

1. What is Ultimate Defender?

Ultimate Defender - useless fake anti-spyware application which is ascribable to spyware. Ultimate Defender generates undue or even non-existent computer security warnings, which can be removed only if the licensed program version is purchased. The alerts are shown every time "Windows" are started in the taskbar area. The main intention of Ultimate Defender is to mislead user and persuade him to pay for assumed infections removal.

2. Ultimate Defender screen shot:

Ultimate Defender

3. How to remove Ultimate Defender:

  1. Internet connection might be disabled or Internet browser might be blocked by Ultimate Defender, so it won't be possible to download any files to infected computer. In this case please download all files required for Ultimate Defender removal to another computer and then transfer them on the infected one using CD/DVD or USB flash drive.
  2. To remove Ultimate Defender download Spyware Doctor and install the program (for the installation guide click here). Before installation, make sure all other programs and windows are closed.
  3. After the installation, computer scan should be started automatically. If so, please move to the next step. If not, click "Status" on the left side menu and press "Scan Now" button to run computer scanner as shown in the picture below:

  4. After the scan has been completed and scan results have been generated, press "Fix Checked" button to remove Ultimate Defender.

  5. Restart the computer to complete Ultimate Defender removal procedure.

4. Ultimate Defender files:

ddesupport.dll, msdde.dll, msole.dll
avp.exe, mgrs.exe, UltimateDefender.exe

5. Hijackthis entries:

O2 Entries:
O2 - BHO: MSVPS System - {100B21CD-3B97-44FB-B1C0-EA6249E482E8} - C:\WINDOWS\ddesupport.dll
O4 Entries:
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\UltimateDefender.exe" hide
O21 Entries:
O21 - SSODL: msdde - {7725C992-B6C9-42AC-ACF9-A00D6AA45166} - C:\WINDOWS\msdde.dll
O21 - SSODL: msole - {80047F31-5F13-47A4-ACFB-CC64BCCDDE75} - C:\WINDOWS\msole.dll