How to Disable a Windows Update Virus
Antimalware Defender is a rogue antimalware program that generates pop-ups designed to resemble the Windows Critical Update pop-ups. The pop-ups state "Antimalware security update for Windows XP (KB961118) Size: 433KB This critical update will install System Security Update 2010.01.023." Antimalware Defender then generates pop-ups telling you that your computer is infected with viruses and giving you instructions to remove the viruses. These instructions, of course, include communicating your credit card information to a remote hacker.
Instructions
-
Delete Registry Values
-
1
Click "Start," type "regedit" into the "Search" box and press "Enter." The Registry Editor opens.
-
2
Delete the following registry values from the left pane of the Registry Editor. To delete a registry value, right-click the registry value and select "Delete." Only delete the registry values listed. Deleting the wrong registry values can cause serious systemwide errors.
HKEY_CLASSES_ROOT\CLSID\{ca84c702-c758-4421-974e-b02662e76d7c}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ca84c702-c758-4421-974e-b02662e76d7c}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "ca84c702-c758-4421-974e-b02662e76d7c_6"
-
-
3
Close the Registry Editor.
Unregister DLLs
-
4
Click "Start," type "cmd" into the "Search" box and press "Enter." The Command Prompt opens.
-
5
Type "regsvr32 /u Antimalware Defender.dll" (without the quotation marks) into the Command Prompt and press "Enter."
-
6
Close the Command Prompt.
Delete Files and Directories
-
7
Click "Start," and click the "Search" box.
-
8
Search for and delete the following files and directories. To delete a file or directory, right-click the file or directory and select "Delete."
ca84c702-c758-4421-974e-b02662e76d7c_6.avi
ca84c702-c758-4421-974e-b02662e76d7c_6.ico
ca84c702-c758-4421-974e-b02662e76d7c_6.mkv
Antimalware Defender.lnk
ca84c702-c758-4421-974e-b02662e76d7c_6.lnk
c:\\Program Files\\Antimalware Defender Antimalware Defender.dll
C:\Documents and Settings\All Users\Start Menu\Programs\Antimalware Defender
C:\WINDOWS\system32\ca84c702-c758-4421-974e-b02662e76d7c_6.avi
C:\WINDOWS\system32\ca84c702-c758-4421-974e-b02662e76d7c_6.ico
%UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.avi
%UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.ico
%UserProfile%\Application Data\ca84c702-c758-4421-974e-b02662e76d7c_6.mkv
-
9
Restart your computer.
-
1
References
- Photo Credit credit cards image by Aleksandr Lobanov from Fotolia.com