MalwareTeks Blog » Blog Archive » IE Defender Fraudware Authors Dispute Security Communities Classification of IE Defender


 02 Nov 2007 @ 11:27 PM 
 

IE Defender Fraudware Authors Dispute Security Communities Classification of IE Defender

 

Today someone posting as iedefender registered at CastleCops® and posted in the thread by the very same name. http://www.castlecops.com/p1017137-iedefender.html#1017137

Hello, we’re developers of IEDefender, our software is clean and is real antispyware. As we can see, people from your site send our exe to different antivirus and antispyware companies, trying to black PR our company. They’ve got answers, that our soft is clean, because IT IS CLEAN! We contacted Kaspersky, they also confirmed, there are no problems with our software, you can check our .exe with any popular antiviruses, there no problems! Stop sending your detractive mails and messages, in other case we would be forced to send all information to our lawyers and meet your representative in the court, where it would be very hard for you to prove, that our software is not real, because IT’S REAL ANTISPYWARE!

Give me a break. This craptacular “Rogue” Anti-Spyware application is fraudware. The IE Defender site is registered through ESTDomains, known as the registrar of record for several other fraudulent applications. Their website is hosted by InHoster also known for hosting several fraudulent applications and malware.

IE Defender finds it’s way onto your system via a fake video codec. Now IE Defender would like you to believe that this is because of some “Rogue” affiliate(s). Nice try fellas, that might work on someone else, a bit more naive then the folks you are currently engaging in a dialog.

Your software is detected as Malware, Fraudware, Risktool … etc, by Ad-Aware SE, Avira, Kaspersky, PrevX, Trojan Hunter, VBA32, WebWasher. More Anti-Virus, Anti-Spyware vendors will be detecting your Crapware very soon.

Then iedefender has the balls, to take a poke at RogueRemover by MalwareBytes. H’m, that’s interesting, just how many fraudulent security applications do you guys put out that are targeted by the very legit program, RogueRemover? Don’t even bother to answer that question. The answer would just be a lie. Just like all the lies you have told so far.

So, I have taken the liberty to put together a batch script to remove your malware and generally craptacular IE Defender “Rogue” Anti-Spyware application.

Download FixIEDef by ShadowPuterDude to the Desktop.

Direction for using FixIEDef can be found on the FixIEDef Web Page

Because of the speed at which new variants are released, FixIEDef may not have your particular variant added to the script. In that case, complete the steps in our Malware Cleaning Guide.

Start a new thread in the Malware Removal Forum of this site.

Attach the following logs:

  1. ISeeYouXp log
  2. HijackThis log
  3. Both Online AV scan logs

(You must Register before posting anywhere on this board. Registering is 100% FREE)

Download Mirrors for FixIEDef:
http://it-mate.co.uk/downloads/fixiedef/fixiedef.exe
http://hosts-file.net/download/fixiedef/fixiedef.exe
http://avant.it-mate.co.uk/?c=Download&f=Tools/FixIEDef
http://archives.mysteryfcm.co.uk/?f=Security/AntiMalware/Antispyware/F ixIEDef

EDIT: (03 November 2007) Added download mirrors

EDIT: (03 November 2007) Removed
[HKEY_CLASSES_ROOT\AppID\{0EEDB911-C5FA-486F-8334-57288578C627}]
 [HKEY_CLASSES_ROOT\CLSID\{0EEDB911-C5FA-486F-8334-57288578C627}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0EEDB911-C5FA-486F-8334-57 288578C627}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EEDB911-C5FA-486F-8334-57 288578C627}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer  \Browser Helper Objects\{0EEDB911-C5FA-486F-8334-57288578C627}]

Legit software, XunLei a Chinese P2P application, uses the same CLSID as the infection.

Share our articles with others by publishing them to:
  • Digg
  • Reddit
  • del.icio.us
  • Slashdot
  • StumbleUpon
  • Technorati
  • blogmarks
  • Furl
  • YahooMyWeb
  • Fark
Tags Tags: , , , ,
Categories: Uncategorized
Posted By: ShadowPuterDude
Last Edit: 25 Jan 2008 @ 08 25 PM
1,238 views
E-mailPermalink
 

Responses to this post » (11 Total)

 
  1. Security Cadets » IE Defender authors disputes the classification of IE Defender said...
    5:25 am - November 3rd, 2007

    [...] Coverage - MalwareTeks Share this with: These icons link to social bookmarking sites where readers can share and [...]

  2. IE Defender Defends Itself | Nellie2 said...
    2:51 pm - November 3rd, 2007

    [...] has posted about it in the MalwareTeks Blog and he has also developed a stand alone fix for IE Defender which is linked to in that blog [...]

  3. Eric said...
    10:00 am - November 6th, 2007

    Thanks
    this script worked great at getting rid of Idefender
    Again my greatest thanks

    Eric

  4. Jonathan said...
    2:42 pm - November 7th, 2007

    Also used the BAT file - worked beautifully! It’s nice to know someone is looking out for our backs! (AND is a lot faster in creating fixes and info than the commercial products.)

  5. Shane said...
    9:07 pm - November 7th, 2007

    What a hero. Man I hate Iedefender and all those other pcprivacy rogue spyware crap. Thanks again

  6. BP said...
    5:46 pm - November 8th, 2007

    Script worked great! Thanks a lot. I tryed Sophos, Spybot, Adware and SuperAnti Spyware on this thing and could not get it. I even ran a hijack this log and nothing.

    Nice work. Down with those iedefender Jerks!

  7. Scott McRae said...
    9:18 pm - November 29th, 2007

    You are a bad man. Spent hours today trying to beat this thing for a buddy on the phone. Finally came across your script. You nailed it my friend.

    Thank you, thank you, thank you.

  8. waltonloads08 said...
    11:24 pm - December 3rd, 2007

    thank you for kicking IEdefrauder’s ass for me!

  9. scottymcc said...
    3:36 am - December 10th, 2007

    Wasted two days on this piece of rubbish, almost had to waste money to buy a legit program.

    ShadowPuterDude - Thank you so much!

  10. Rick said...
    6:29 pm - January 25th, 2008

    Thanks a bunch! The latest Smitfraud didn’t qute do it, but FixIEDef certainly did the trick. I also went in and deleted the contents of the temp folders in each user profile as well as in the windows folder.

    That thread at castlecops is pure gold. The guy trying to defend his crapware is clearly writing from some place where the law can’t get to him; the quality of English used betrays the fact that it’s not his first language…he’s likely somewhere in eastern Europe. He can argue all he wishes about the legitimacy of IEDefender, but the machine that I removed it from had Norton (the user disabled it to download something Norton said he shouldn’t…sheesh). Looking through the logs, it’s clear that Norton detected it as high risk malware and tried to deal with it.

    Thanks again, ShadowPuterDude.

    Cheers!

  11. Jerry said...
    10:46 pm - April 13th, 2008

    Thank you for your free IE Defender removal tool. it worked great. IEDefender is really gone ! Once again THANK YOU, THANK YOU, THANK YOU !!!!!!!

 

Leave A Comment ...

 

 XHTML:
You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
\/ More Options ...
Change Theme...
  • Users » 9
  • Posts/Pages » 187
  • Comments » 116
Change Theme...
  • VoidVoid « Default
  • LifeLife
  • EarthEarth
  • WindWind
  • WaterWater
  • FireFire
  • LiteLight
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.