1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Rogue:W32/UltimateDefender

Name : Rogue:W32/UltimateDefender
Aliases : UltimateDefender (Symantec)
Program:Win32/UltimateDefender (Microsoft)
Category:Riskware
Type:Rogue
Platform:W32
Author:Nous-Tech Solutions Ltd.
Website:http://www.udefender.com

Summary

Dishonest antivirus or antispyware software which tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected with fake viruses.

Details


File System Changes
Creates these files:

  •  C:\.protected
  •  C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender Uninstall.lnk
  •  C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender.lnk
  •  C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
  •  C:\Documents and Settings\Analyst\Application Data\Ultimate Defender\logs\1212632851.log
  •  C:\Documents and Settings\Analyst\Start Menu\Programs\Startup\.protected
  •  C:\Program Files\Ultimate Defender\program.info
  •  C:\Program Files\Ultimate Defender\UltimateDefender.db
  •  C:\Program Files\Ultimate Defender\UltimateDefender.exe
  •  C:\Program Files\Ultimate Defender\UltimateDefender.pkg
  •  C:\Program Files\Ultimate Defender\Uninstall.exe
  •  C:\WINDOWS\.protected
  •  C:\WINDOWS\system32\drivers\etc\.protected


Create these directories:

  •  C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender
  •  C:\Documents and Settings\Analyst\Application Data\Ultimate Defender
  •  C:\Documents and Settings\Analyst\Application Data\Ultimate Defender\logs
  •  C:\Program Files\Ultimate Defender



Registry Modifications
Sets these values:

  •  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  •  Ultimate Defender=[Path_to_UltimateDefender.exe]


Creates these keys:

  •  HKCU\Software\Ultimate Defender HKLM\SOFTWARE\Ultimate Defender
  •  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultimate Defender


Additional Details

Rogue:W32/UltimateDefender is a detection for the UltimateDefender family of rogue antivirus.

As with most rogues, UltimateDefender is a misleading application that may give fake or exaggerated scanning results to scare the user into buying a license in order to remove the detected the "infection".


Installation

This rogueware is either downloaded manually or it may be bundled with other potentially unwanted software.

When the file is executed, it will display an installer wizard as shown below:

Installation Wizard

After user clicks the 'Continue' button, the installation files will be downloaded and silently installed into the system:

Installing...

The UltimateDefender rogueware family will typically install component files in:
  •  C:\Program Files\Ultimate Defender


Activity

Upon successful installation, UltimateDefender will automatically scan the system, and then display scanning results that may be misleading or false:

UltimateDefender

The program will also constantly prompt annoying messages, in order to scare the users into believing the system is infected. The user is directed to register and buy a license in order to allow the program to 'removed the detected infection(s)'.


Registry

UltimateDefender adds the following registry key:
  •  HKEY_ALL_USERS\Software\Ultimate Defender
  •  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
        "Ultimate Defender"="C:\Program Files\Ultimate Defender\ultimatedefender.exe"
  •  HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
        "Ultimate Defender"="C:\Program Files\Ultimate Defender\Uninstall.exe"