Additional Details
Rogue:W32/UltimateDefender is a detection for the UltimateDefender family of rogue antivirus.
As with most rogues, UltimateDefender is a misleading application that may give fake or exaggerated scanning results to scare the user into buying a license in order to remove the detected the "infection".
Installation
This rogueware is either downloaded manually or it may be bundled with other potentially unwanted software.
When the file is executed, it will display an installer wizard as shown below:
After user clicks the 'Continue' button, the installation files will be downloaded and silently installed into the system:
The UltimateDefender rogueware family will typically install component files in:
- C:\Program Files\Ultimate Defender
Activity
Upon successful installation, UltimateDefender will automatically scan the system, and then display scanning results that may be misleading or false:
The program will also constantly prompt annoying messages, in order to scare the users into believing the system is infected. The user is directed to register and buy a license in order to allow the program to 'removed the detected infection(s)'.
Registry
UltimateDefender adds the following registry key:
- HKEY_ALL_USERS\Software\Ultimate Defender
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Ultimate Defender"="C:\Program Files\Ultimate Defender\ultimatedefender.exe"
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
"Ultimate Defender"="C:\Program Files\Ultimate Defender\Uninstall.exe"