Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 21 April 2011

Remove the Fake BitDefender 2011 (Uninstall Guide)

Posted on 15:14 by Unknown
BitDefender 2011 is a rogue anti-virus program that demands money to clean up non-existent infections in your computer. I think you all know the legitimate anti-virus software from BitDefender which is a well known company and obviously has nothing to do with the BitDefender 2011 scareware. It's an old but effective trick and I'm afraid that may fool casual users into installing this rogue anti-virus application. Previously, we wrote about the fake E-Set Antivirus 2011 and AVG Antivirus 2011; these are pretty much the same as BitDefender2011. Just like most other scareware, BitDefender 2011 is promoted through the use of Trojan horses and infected websites that redirect you to fake online virus scanners. Fake AV scanner reports tons of infections on your computer and prompts to install fake virus protection software. Once BitDefender 2011 is installed, it pretends to scan your computer for viruses, spyware, adware and reports even more non-existent threats. It is worth noting, that this rogue anti-virus software can not delete your files, so you shouldn't worry about that. If you have the fake BitDefender 2011 on your computer and need help removing it, please follow the removal instructions below.



While BitDefender 2011 is running, it displays fake security alerts in attempt to scare you into thinking that your computer is fried. For those of you who have already been hit by rogue anti-spyware software these fake alerts shouldn't be a surprise. Bit Defender 2011 displays some pretty basic stuff. The fake alert will state that your computer is infected with spyware, keyloggers and other badware. You may also see a fake security warning saying that you are using unlicensed software or that your sensitive information is being transferred to a remote server which belongs to cyber-criminals. Such offending warnings should be ignored as they do not make any sense. Here are some of the fake security alerts:



Another rather annoying thing about this infection is that BitDefender 2011 blocks legitimate malware removal tools. However, BitDefender 2011 Resident Shield blocks other legitimate programs too, i.e., Microsoft calculator or registry editor. It states that the program is infected and was terminated due to security reasons. Surprisingly, it doesn't block Task Manager, but there is a good reason for that. BitDefender 2011 created a new column in the Windows Task Manager that displays word "Infected" next to various active processes.

And probably last, but not least, BitDefender 2011 hijacks web browsers via the Image File Execution Options and displays fake security warnings Internet Explorer Emergency Mode (Internet Explorer) and Attention! Your web page requested has been canceled (Mozilla Firefox).





These fake alerts do not show up in safe mode and safe mode with networking though. So, you should restart your computer is safe mode with networking and download anti-malware application to remove the rogue AV if it blocks security-related websites in normal mode. Also, you can use the registration codes listed below to activate the fake BitDefender 2011 if you really can't do anything on your computer. Thanks to Steven K. from http://xylibox.blogspot.com for sharing these codes. Just click "License" from the left side menu and enter one of these codes:

DLE01-JGN91-KAH52-DPH063-XYL52
IGE19-CJA07-FDK41-CMI651-XYL62
HML20-HCF21-ABP27-KBG564-XYL12
PFI91-ENK07-KLC65-MCJ224-XYL81
JGA43-KGJ19-DHG29-MOM599-XYL52
DAO35-KGB74-CHC40-FLI616-XYL14
ENK13-PFD81-OFH29-HMF191-XYL63

Please note that even if these codes will do the trick, you still need to run a full system scan with anti-malware software. Do not purchase BitDefender 2011. There is no guarantee that your credit card details aren't going to be sold to other third parties. Clarifications and comments are welcome as usual. If you have questions, please leave a comment below. Good luck and be safe online!


BitDefender 2011 removal instructions (in Safe Mode with Networking):

1. Reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key. Login as the same user you were previously logged in with in the normal Windows mode. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm



2. Download free anti-malware software from the list below and run a full system scan.
  • MalwareBytes Anti-malware
  • SUPERAntispyware
  • Spybot S&D
  • Hitman Pro 3.5
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

3. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Alternate BitDefender 2011 removal instructions (Manual):

1. Go into C:\WINDOWS\system32 folder. Locate msiexecs.exe and delete it. Important! Do not delete msiexec.exe. See the image below.



2. Open the Windows Registry Editor. At the taskbar, click Start → Run. Type regedit and click OK or press Enter. (In Windows Vista/7 click the Start button in the lower-left corner of your screen. Type regedit into Start search box and press Enter).



3. Locate the HKEY_LOCAL_MACHINE entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe

In the righthand pane select Debugger = msiexecs.exe -sb and delete it if it exists.
Close the registry editor.



4. Open Internet Explorer and download free anti-malware software from the list below and run a full system scan.
  • MalwareBytes Anti-malware
  • SUPERAntispyware
  • Spybot S&D
  • Hitman Pro 3.5
NOTE: in some cases the rogue program may block anti-malware software. Before saving the selected program onto your computer, you may have to rename the installer to iexplore.exe or winlogon.exe With all of these tools, if running Windows 7 or Vista they MUST be run as administrator. Launch the program and follow the prompts. Don't forget to update the installed program before scanning.

4. New threats appear every day. In order to protect your PC from such (new) infections we strongly recommend you to use ESET Smart Security.


Associated BitDefender 2011 files and registry values:

Files:
  • C:\Program Files\BitDefender 2011\
  • C:\Program Files\BitDefender 2011\bitdefender.exe
  • C:\Documents and Settings\All Users\Start Menu\BitDefender 2011\
  • C:\Documents and Settings\All Users\Start Menu\BitDefender 2011\BitDefender 2011.lnk
  • %AllUsersProfile%\Start Menu\BitDefender 2011\Uninstall.lnk
  • %UserProfile%\Desktop\BitDefender 2011.lnk
  • C:\WINDOWS\system32\msiexecs.exe
Registry values:
  • HKEY_CURRENT_USER\Software\[SET OF RANDOM CHARACTERS]
  • HKEY_CURRENT_USER\Software\[SET OF RANDOM CHARACTERS]
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '0'
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "BitDefender 2011" = 'C:\Program Files\BitDefender 2011\bitdefender.exe'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe "Debugger" = 'msiexecs.exe -sb'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe "Debugger" = 'msiexecs.exe -sb'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe "Debugger" = 'msiexecs.exe -sb'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe "Debugger" = 'msiexecs.exe -sb'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safari.exe "Debugger" = 'msiexecs.exe -sb'
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "WinNT-EVI 21.04.2011"
BitDefender 2011 removal video:

Thanks to rogueamp for making this video.
Share the knowledge:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Rogue programs | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
    RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
  • Remove Rattlingsearchsystem.com (Uninstall Guide)
    Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
  • Remove TR/ATRAPS.Gen2, removal instructions
    Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • How to remove 'TidyNetwork' adware virus from your computer
    As internet users most of us have seen those irritating little pop-up windows that are advertising something that we normally have little or...
  • Remove Windows Attention Utility (Uninstall Guide)
    Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ►  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ▼  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ▼  April (15)
      • How to Remove Antivirus Center (Uninstall Guide)
      • "System plugin at address 0x00874324 got critical ...
      • Remove the Fake BitDefender 2011 (Uninstall Guide)
      • Remove the Fake Windows Security Alert (Uninstall ...
      • Windows Recovery, Windows Restore Malware Removal ...
      • Remove Facemoods (Uninstall Guide)
      • How to Remove Antivirus Clean 2011 (Uninstall Guide)
      • A - Z Threats & Risks
      • Remove Internet Protection (Uninstall Guide)
      • Remove Relevant Knowledge (Uninstall Guide)
      • Remove Fast Windows Antivirus 2011 (Uninstall Guide)
      • Remove Protection-soft24.com, Aviraprotect.com (Un...
      • How to Remove Antivirus Protection Trial (Uninstal...
      • Remove Critical Hard Disk Drive Error Warning (Uni...
      • How to Remove Antimalware Tool (Uninstall Guide)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile