Rogue:W32/UltimateDefender

Classification

Category :

Riskware

Type :

Rogue

Summary

Dishonest antivirus or antispyware software which tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected with fake viruses.

Removal

Based on the settings of your F-Secure security product, it may block the file from running, move it to the quarantine where it cannot spread or cause harm, or ask you to select an action.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

Rogue:W32/UltimateDefender is a detection for the UltimateDefender family of rogue antivirus.

As with most rogues, UltimateDefender is a misleading application that may give fake or exaggerated scanning results to scare the user into buying a license in order to remove the detected the "infection".

Installation

This rogueware is either downloaded manually or it may be bundled with other potentially unwanted software.

When the file is executed, it will display an installer wizard as shown below:

After user clicks the 'Continue' button, the installation files will be downloaded and silently installed into the system:

The UltimateDefender rogueware family will typically install component files in:

  • C:\Program Files\Ultimate Defender

Activity

Upon successful installation, UltimateDefender will automatically scan the system, and then display scanning results that may be misleading or false:

The program will also constantly prompt annoying messages, in order to scare the users into believing the system is infected. The user is directed to register and buy a license in order to allow the program to 'removed the detected infection(s)'.

Registry

UltimateDefender adds the following registry key:

  • HKEY_ALL_USERS\Software\Ultimate Defender
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Ultimate Defender"="C:\Program Files\Ultimate Defender\ultimatedefender.exe"
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall "Ultimate Defender"="C:\Program Files\Ultimate Defender\Uninstall.exe"

File System Changes

Creates these files:

  • C:\.protected
  • C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender Uninstall.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender\Ultimate Defender.lnk
  • C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
  • C:\Documents and Settings\Analyst\Application Data\Ultimate Defender\logs\1212632851.log
  • C:\Documents and Settings\Analyst\Start Menu\Programs\Startup\.protected
  • C:\Program Files\Ultimate Defender\program.info
  • C:\Program Files\Ultimate Defender\UltimateDefender.db
  • C:\Program Files\Ultimate Defender\UltimateDefender.exe
  • C:\Program Files\Ultimate Defender\UltimateDefender.pkg
  • C:\Program Files\Ultimate Defender\Uninstall.exe
  • C:\WINDOWS\.protected
  • C:\WINDOWS\system32\drivers\etc\.protected

Create these directories:

  • C:\Documents and Settings\All Users\Start Menu\Programs\Ultimate Defender
  • C:\Documents and Settings\Analyst\Application Data\Ultimate Defender
  • C:\Documents and Settings\Analyst\Application Data\Ultimate Defender\logs
  • C:\Program Files\Ultimate Defender

Registry Modifications

Sets these values:

  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  • Ultimate Defender=[Path_to_UltimateDefender.exe]

Creates these keys:

  • HKCU\Software\Ultimate Defender HKLM\SOFTWARE\Ultimate Defender
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultimate Defender