



Today someone posting as iedefender registered at CastleCops® and posted in the thread by the very same name. http://www.castlecops.com/p1017137-iedefender.html#1017137
Hello, we’re developers of IEDefender, our software is clean and is real antispyware. As we can see, people from your site send our exe to different antivirus and antispyware companies, trying to black PR our company. They’ve got answers, that our soft is clean, because IT IS CLEAN! We contacted Kaspersky, they also confirmed, there are no problems with our software, you can check our .exe with any popular antiviruses, there no problems! Stop sending your detractive mails and messages, in other case we would be forced to send all information to our lawyers and meet your representative in the court, where it would be very hard for you to prove, that our software is not real, because IT’S REAL ANTISPYWARE!
Give me a break. This craptacular “Rogue” Anti-Spyware application is fraudware. The IE Defender site is registered through ESTDomains, known as the registrar of record for several other fraudulent applications. Their website is hosted by InHoster also known for hosting several fraudulent applications and malware.
IE Defender finds it’s way onto your system via a fake video codec. Now IE Defender would like you to believe that this is because of some “Rogue” affiliate(s). Nice try fellas, that might work on someone else, a bit more naive then the folks you are currently engaging in a dialog.
Your software is detected as Malware, Fraudware, Risktool … etc, by Ad-Aware SE, Avira, Kaspersky, PrevX, Trojan Hunter, VBA32, WebWasher. More Anti-Virus, Anti-Spyware vendors will be detecting your Crapware very soon.
Then iedefender has the balls, to take a poke at RogueRemover by MalwareBytes. H’m, that’s interesting, just how many fraudulent security applications do you guys put out that are targeted by the very legit program, RogueRemover? Don’t even bother to answer that question. The answer would just be a lie. Just like all the lies you have told so far.
So, I have taken the liberty to put together a batch script to remove your malware and generally craptacular IE Defender “Rogue” Anti-Spyware application.
Download FixIEDef by ShadowPuterDude to the Desktop.
Direction for using FixIEDef can be found on the FixIEDef Web Page
Because of the speed at which new variants are released, FixIEDef may not have your particular variant added to the script. In that case, complete the steps in our Malware Cleaning Guide.
Start a new thread in the Malware Removal Forum of this site.
Attach the following logs:
(You must Register before posting anywhere on this board. Registering is 100% FREE)
Download Mirrors for FixIEDef:
http://it-mate.co.uk/downloads/fixiedef/fixiedef.exe
http://hosts-file.net/download/fixiedef/fixiedef.exe
http://avant.it-mate.co.uk/?c=Download&f=Tools/FixIEDef
http://archives.mysteryfcm.co.uk/?f=Security/AntiMalware/Antispyware/F ixIEDef
EDIT: (03 November 2007) Added download mirrors
EDIT: (03 November 2007) Removed
[HKEY_CLASSES_ROOT\AppID\{0EEDB911-C5FA-486F-8334-57288578C627}]
[HKEY_CLASSES_ROOT\CLSID\{0EEDB911-C5FA-486F-8334-57288578C627}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0EEDB911-C5FA-486F-8334-57 288578C627}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EEDB911-C5FA-486F-8334-57 288578C627}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects\{0EEDB911-C5FA-486F-8334-57288578C627}]
Legit software, XunLei a Chinese P2P application, uses the same CLSID as the infection.










More Options ...

Categories
Tag Cloud
Blog RSS
Comments RSS

Void « Default
Life
Earth
Wind
Water
Fire
Light 
5:25 am - November 3rd, 2007
[...] Coverage - MalwareTeks Share this with: These icons link to social bookmarking sites where readers can share and [...]
2:51 pm - November 3rd, 2007
[...] has posted about it in the MalwareTeks Blog and he has also developed a stand alone fix for IE Defender which is linked to in that blog [...]
10:00 am - November 6th, 2007
Thanks
this script worked great at getting rid of Idefender
Again my greatest thanks
Eric
2:42 pm - November 7th, 2007
Also used the BAT file - worked beautifully! It’s nice to know someone is looking out for our backs! (AND is a lot faster in creating fixes and info than the commercial products.)
9:07 pm - November 7th, 2007
What a hero. Man I hate Iedefender and all those other pcprivacy rogue spyware crap. Thanks again
5:46 pm - November 8th, 2007
Script worked great! Thanks a lot. I tryed Sophos, Spybot, Adware and SuperAnti Spyware on this thing and could not get it. I even ran a hijack this log and nothing.
Nice work. Down with those iedefender Jerks!
9:18 pm - November 29th, 2007
You are a bad man. Spent hours today trying to beat this thing for a buddy on the phone. Finally came across your script. You nailed it my friend.
Thank you, thank you, thank you.
11:24 pm - December 3rd, 2007
thank you for kicking IEdefrauder’s ass for me!
3:36 am - December 10th, 2007
Wasted two days on this piece of rubbish, almost had to waste money to buy a legit program.
ShadowPuterDude - Thank you so much!
6:29 pm - January 25th, 2008
Thanks a bunch! The latest Smitfraud didn’t qute do it, but FixIEDef certainly did the trick. I also went in and deleted the contents of the temp folders in each user profile as well as in the windows folder.
That thread at castlecops is pure gold. The guy trying to defend his crapware is clearly writing from some place where the law can’t get to him; the quality of English used betrays the fact that it’s not his first language…he’s likely somewhere in eastern Europe. He can argue all he wishes about the legitimacy of IEDefender, but the machine that I removed it from had Norton (the user disabled it to download something Norton said he shouldn’t…sheesh). Looking through the logs, it’s clear that Norton detected it as high risk malware and tried to deal with it.
Thanks again, ShadowPuterDude.
Cheers!
10:46 pm - April 13th, 2008
Thank you for your free IE Defender removal tool. it worked great. IEDefender is really gone ! Once again THANK YOU, THANK YOU, THANK YOU !!!!!!!