Home Malware Programs Rogue Anti-Spyware Programs IE Defender

IE Defender

Posted: October 25, 2007

Threat Metric

Threat Level: 10/10
Infected PCs: 166
First Seen: July 24, 2009
Last Seen: November 11, 2024
OS(es) Affected: Windows

ScreenshotIE Defender is a rogue anti-spyware program due to its deceptive and aggressive advertising practices. IE Defender and its marketing affiliates are distributing and installing IE Defender's anti-spyware program through a download which is bundled with a trojan triggered by a browser helper object (BHO). Many of these trojan bundled downloads are located in sites which offer a "video codec" to be able to view free adult entertainment videos.

After your PC is infected with the trojan bundled download, it keeps showing up a pop-up stating "NOTICE: Your system is infected and your computer performance is not at the highest level. Full system optimization will greatly increase your computer's performance and prevent data loss". When you click on the popup, it will direct your IE to IEDefender.com to download IE Defender's anti-spyware program.

In addition, the Trojan which came bundled from either IE Defender and/or its affiliates hijacks your search engines, such as Google, Yahoo and MSN, and displays a fake error message within your search results claiming that your system is infected and offering to buy the IE Defender program. Once you click on this fake error message you will be redirected to IE Defender's home site where you will be tricked into buying IE Defender's anti-spyware application.

ScreenshotScreenshotScreenshotScreenshotScreenshot

Aliases

TROJ_AGENT.AJH [TrendMicro]Trojan Horse [Symantec]Rootkit.Win32.Podnuha.bhw [Sunbelt]Mal/BHO-Fam [Sophos]Medium Risk Malware [Prevx1]Trj/Downloader.MDW [Panda]Win32/Rootkit.Podnuha.BHW [NOD32]Trojan:Win32/Boaxxe.H [Microsoft]Trojan.BHO.Gen [McAfee-GW-Edition]Generic.dx [McAfee]Rootkit.Win32.Podnuha [Ikarus]W32/Podnuha.BHW!tr.rkit [Fortinet]Win32/Kvol!generic [eTrust-Vet]Trojan.Siggen.644 [DrWeb]TrojWare.Win32.Rootkit.Podnuha.~K [Comodo]
More aliases (141)

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to IE Defender may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



iedefender.exe File name: iedefender.exe
Size: 1.37 MB (1372672 bytes)
MD5: 7debb3de3e5ca3835d3d0067529a2318
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
a3gpcodec.dll File name: a3gpcodec.dll
Size: 247.29 KB (247296 bytes)
MD5: d02194a30b6316498631a1350280f1ce
Detection count: 81
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
bidisplv.dll File name: bidisplv.dll
Size: 105.77 KB (105771 bytes)
MD5: 420b2da62c4f1df1a20ae37ca2fca1bd
Detection count: 80
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
VideoMP3.dll File name: VideoMP3.dll
Size: 218.11 KB (218112 bytes)
MD5: 5244d884fb31be263bf145c01c9f9918
Detection count: 74
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
bkfgnqhm.dll File name: bkfgnqhm.dll
Size: 110.59 KB (110592 bytes)
MD5: 9ceecf911241c9890541167edf53739f
Detection count: 70
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
advpac.dll File name: advpac.dll
Size: 84.99 KB (84992 bytes)
MD5: bcf3a381bbe26d9c1ec24bac8b18f567
Detection count: 65
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
ddccawv.dll File name: ddccawv.dll
Size: 36.35 KB (36352 bytes)
MD5: 39d36d9a908aa2073344c55fc40289fb
Detection count: 56
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
IntelVideo.dll File name: IntelVideo.dll
Size: 245.76 KB (245760 bytes)
MD5: 327e40b3ed4d28b6ee765fae9c6622af
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
blopenvtlv.dll File name: blopenvtlv.dll
Size: 249.85 KB (249856 bytes)
MD5: a7b78cdc5256e7bd5224357ff5e727a7
Detection count: 50
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
argosqaf.dll File name: argosqaf.dll
Size: 80.44 KB (80448 bytes)
MD5: 92905c5ce0362c7bb9dfdb4cb43fc17f
Detection count: 45
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
adspipe.dll File name: adspipe.dll
Size: 188.41 KB (188416 bytes)
MD5: 064b3b95808c2270d149126402edd78e
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
ddccy.dll File name: ddccy.dll
Size: 316.51 KB (316512 bytes)
MD5: ca4f88b58b55e7189676fcd14b377362
Detection count: 34
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
blopenvtok.dll File name: blopenvtok.dll
Size: 278.52 KB (278528 bytes)
MD5: d156c98b1cb9a5cf6aff715560ecdef7
Detection count: 33
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
byvsr.dll File name: byvsr.dll
Size: 328.28 KB (328288 bytes)
MD5: b9631b35cc20e7c501f9592e9a75d40b
Detection count: 30
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
ieDefender-setup[2].exe File name: ieDefender-setup[2].exe
Size: 2.74 MB (2743590 bytes)
MD5: ce7b1332dc2bfb7c24bfadf9c55faf74
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
dx50codec.dll File name: dx50codec.dll
Size: 248.83 KB (248832 bytes)
MD5: 1ee34dfe18c9e6a572ea35b908c89e64
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
C:\rogueware samples\folder\infested 11 11 2022\Rogues Spytrooper\9f6e9299ef5d26c3206ec736ccf00fe02ea180bff34eafc00da31245c2c781ff (2).exe File name: 9f6e9299ef5d26c3206ec736ccf00fe02ea180bff34eafc00da31245c2c781ff (2).exe
Size: 2.74 MB (2748728 bytes)
MD5: 4053d1bb2e6564b964df9e309698f889
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: C:\rogueware samples\folder\infested 11 11 2022\Rogues Spytrooper\9f6e9299ef5d26c3206ec736ccf00fe02ea180bff34eafc00da31245c2c781ff (2).exe
Group: Malware file
Last Updated: May 6, 2024
C:\rogueware samples\folder\infested 11 11 2022\XP Antispyware\iedefender-setup.exe File name: iedefender-setup.exe
Size: 2.58 MB (2582694 bytes)
MD5: 7a974fed8ffba2b4c36291a75f5f00c0
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: C:\rogueware samples\folder\infested 11 11 2022\XP Antispyware\iedefender-setup.exe
Group: Malware file
Last Updated: May 6, 2024

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{F4D76F01-7896-458a-890F-E1F05C46069F}File name without pathASKPBAR.DLLIntelVideo.dll

4 Comments

  • jorge says:

    como desinstalar iedefender

  • ghostrider01 says:

    jorge, If you think, that to follow the manual IE Defender Removal Instructions is too difficult for you, you should use a reliable anti-spyware program.

  • Jay X says:

    thanks guy, this was realy bugging the hell outa me. A friend sent me a link over messenger. THE JERK!! now i have this thing on..... anyway gonna go uninstall it... thanks again.

  • Warren says:

    Do these instructions work with Windows Vista Home Premimun?

Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.