Registry Defender Removal Guide

Threat Level:
8/10
Rate this Article:
Comments (0)
Article Views: 3051

Computer fraud is very popular nowadays and hackers become more and more aggressive in their ways to trick unsuspecting users. To make people believe that they are about to buy a legitimate and effective program, cyber criminals often use the reliable layout of security software. This is the case with one of their latest creations – Registry Defender. Do not be deceived by its reliable name – it will neither defend your system, not detect any present infections. On the contrary, in will put your system in real danger and will do everything possible to make you pay for a bogus program.

Registry Defender pretends to be a trustworthy AV application which is able to detect any system problems and infections. It tries to convince you that there are system errors and to do that displays many pop-up messages and warnings. It also makes a system scan, which says that you have to remove some infected files immediately. Although all of these messages are really frightening, do not be misled by their fake content. They have nothing to do with reality and are displayed only to scare you into buying a scam application.

Registry Defender will redirect you to some fake web page. If you have a closer look at that page, you will see that it has no detailed information about the security product and its creators. Moreover, the site will has only a form, which requires you to submit your personal and credit card details. Do not give your information, as this program will not give you even a registry key. It will only take your money and leave your computer in danger.

Download Remover for Registry Defender *
*SpyHunter scanner, published on this site, is intended to be used only as a detection tool. To use the removal functionality, you will need to purchase the full version of SpyHunter.

Registry Defender Screenshots:

Registry Defender

Registry Defender technical info for manual removal:

Files Modified/Created on the system:

# File Name File Size (Bytes) File Hash
1Chrome_Loader.exe2090277 bytesMD5: 90658655035c54d71a41e731b791cce6
21AB8.exe303211 bytesMD5: b7553dbc27115a1c9273493ae28d132c
3INSTALL.LOG19511 bytesMD5: e6743bbf541ba9916cb12517f72f3fa1
4escritorio.exe305845 bytesMD5: 0550f5a4c60537e200495bd01a1fd273
5Eset fix(1).exe1803474 bytesMD5: a1d08cf77b0d3366d52c18aebfb4e905
60318be33-62f8-a702-0e4c-b3fea26b9b45.dll2730496 bytesMD5: 54daea86968425ee7437eed17465101d
7questdns179.exe26112 bytesMD5: 3c5030716e0cfc56bb25ea1a5d9de23e
8ulbrnii.dll11264 bytesMD5: 9b0e51d090b978bcedff8f2b8ec2a55c
9p0906tqqzv.exe16384 bytesMD5: dbec012628545cbf21f8524375d474df
10GenDM.exe888832 bytesMD5: 7e5a0164275d00d65eb8a1f6b2ddd259
11oef.exe305152 bytesMD5: 49bc100ad6eef23f112ce7d754fce7c3
12RegDef2011.exe1198048 bytesMD5: 69dc05b8ef8ac9a4bcfe47ba0e61a74e
13DqSeoCbFrTc.exe458752 bytesMD5: 71fb1ee9ab2f56359249a1c4c9335b4c
14wscntfy.exe36864 bytesMD5: 1cd712a5faec6519bcc38cfc0a43f169
15ClipUserNetM.dll151552 bytesMD5: 15dc33b7a56949cbe29df63cc8117fb5
16Uninstall.exe410141 bytesMD5: 7e7f1f5cb6b79ee6403137f90f5bd63e
17trracert.exe57344 bytesMD5: 16bf529b01d4547a9ae36b00a68073ab
18RegistryDefender.exe1126400 bytesMD5: b3c66c0f4f53f4dd15d8e814c6535665
192895.exe389120 bytesMD5: dba4160733afc4e67aced4babc8af88d
20privacy.exe816640 bytesMD5: 9f17f66bda05c039331b775e32a6453f
21agente.exe176128 bytesMD5: 5820c0a140f9502d1e4ff17a40f51641
22eekum0qzb2.exe16384 bytesMD5: 5fd74d17d0ebfeae798120350ceebffe
23jml.exe364544 bytesMD5: 51925bb97ef917841f95334eaf64394f
24ek0igjo911.exe16384 bytesMD5: 6d5c50a827ea8092888caef1a2517545
25lsi.exe396288 bytesMD5: b2cf2b46b363e0e66bff49ea666ed572
26vhs.exe308224 bytesMD5: dc103b463216a7c226e24b06f29e1419
27Setup%20Registry%20Defender[1].exe
283A92.exe147456 bytesMD5: c703d2e55a5b5b5132c5a737ea98bfb5
29svchost.exe2435072 bytesMD5: 0f641dda991e2eda7b94d86ca52e52ef
30Lucifer.exe62464 bytesMD5: d811cd76c43e6a8cfb781ed94f83c456
31rd2010.exe1193408 bytesMD5: 71af7accf79edff874b19be6b718e972
32ivn.exe372224 bytesMD5: e42a03d4fdde7304377750b095c44e20
33remote.exe940544 bytesMD5: 473d4e19499a0c3a49a6b29618207516
34hhJj43j0mrE2fc.exe346880 bytesMD5: 46b5449d4b8d5611661088cd0c0cd0aa
35NUSB3w32.dll157184 bytesMD5: 4a0c63fba11b0a2917051f14fe66678a
36vdn.exe374784 bytesMD5: c49c9904027ea013f08b12822ede8085
37bqg.exe344064 bytesMD5: 7583beae74d202a63b6946c485f1829f
38RDAssistant.exe815792 bytesMD5: fb924bd37175d57189906345b86416fb
39CktPzrpm8100kw.exe362178 bytesMD5: 1ecf1452ffbfcdbf99e6c2b5e494ccb9
40ucms.exe157696 bytesMD5: 23d9a444e0b0e5af69a3904cb81060ea
41pm_proc1.exe515592 bytesMD5: 90879f9696947bebb4bcddcb906c84c2
42rutserv.exe4003328 bytesMD5: 8008e5a7f569e95bd2ebb05d347f481e
43user32.dll858112 bytesMD5: c4ce20b61b69f4fe226d74b46666bb84

Memory Processes Created:

# Process Name Process Filename Main module size
1Chrome_Loader.exeChrome_Loader.exe2090277 bytes
21AB8.exe1AB8.exe303211 bytes
3escritorio.exeescritorio.exe305845 bytes
4Eset fix(1).exeEset fix(1).exe1803474 bytes
5questdns179.exequestdns179.exe26112 bytes
6p0906tqqzv.exep0906tqqzv.exe16384 bytes
7GenDM.exeGenDM.exe888832 bytes
8oef.exeoef.exe305152 bytes
9RegDef2011.exeRegDef2011.exe1198048 bytes
10DqSeoCbFrTc.exeDqSeoCbFrTc.exe458752 bytes
11wscntfy.exewscntfy.exe36864 bytes
12Uninstall.exeUninstall.exe410141 bytes
13trracert.exetrracert.exe57344 bytes
14RegistryDefender.exeRegistryDefender.exe1126400 bytes
152895.exe2895.exe389120 bytes
16privacy.exeprivacy.exe816640 bytes
17agente.exeagente.exe176128 bytes
18eekum0qzb2.exeeekum0qzb2.exe16384 bytes
19jml.exejml.exe364544 bytes
20ek0igjo911.exeek0igjo911.exe16384 bytes
21lsi.exelsi.exe396288 bytes
22vhs.exevhs.exe308224 bytes
23Setup%20Registry%20Defender[1].exeSetup%20Registry%20Defender[1].exe
243A92.exe3A92.exe147456 bytes
25svchost.exesvchost.exe2435072 bytes
26Lucifer.exeLucifer.exe62464 bytes
27rd2010.exerd2010.exe1193408 bytes
28ivn.exeivn.exe372224 bytes
29remote.exeremote.exe940544 bytes
30hhJj43j0mrE2fc.exehhJj43j0mrE2fc.exe346880 bytes
31vdn.exevdn.exe374784 bytes
32bqg.exebqg.exe344064 bytes
33RDAssistant.exeRDAssistant.exe815792 bytes
34CktPzrpm8100kw.exeCktPzrpm8100kw.exe362178 bytes
35ucms.exeucms.exe157696 bytes
36pm_proc1.exepm_proc1.exe515592 bytes
37rutserv.exerutserv.exe4003328 bytes

Registry Modifications:

The following Registry Keys were created:

  • RUNNING PROGRAM\RegistryDefender.exe
  • RUNNING PROGRAM\rd2010.exe

Reply

Your email address will not be published.

Name
Website
Comment

Enter the numbers in the box to the right *