Emsisoft Malware-Info
Name: Adware.Win32.WindowsEnterpriseDefender
Risklevel: Low Risk
Description:
It is a rogue security program that shows false warning messages. It also shows misleading scan results.
Removal instructions for Adware WindowsEnterpriseDefender:
To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware WindowsEnterpriseDefender.
Run a full scan on all drives and move all detected items to the quarantine.
More details about this danger:
Characteristics:
- Show fake warning messages.
- It also shows misleading scan results.
Installation: Installed through EXE
Process: WindowsEDefender.exe
Screenshots:
Used folders:
- C:\WINDOWS\system32\drivers\etc\
- C:\WINDOWS\system32\WBEM\Logs\
- C:\Documents and Settings\All Users\Application Data\e5d1\
- C:\Documents and Settings\All Users\Application Data\e5d1\BackUp\
- C:\Documents and Settings\All Users\Application Data\e5d1\WEDDSys\
- C:\Documents and Settings\All Users\Application Data\WEDDSys\
- C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\
- C:\Documents and Settings\[USER]\Application Data\Windows Enterprise Defender\
- C:\Documents and Settings\[USER]\Cookies\
- C:\Documents and Settings\[USER]\Desktop\
- C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\
- C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\
- C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009092820091005\
- C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009101220091013\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\
- C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\
- C:\Documents and Settings\[USER]\Start Menu\
- C:\Documents and Settings\[USER]\Start Menu\Programs\
Used files:
- C:\WINDOWS\system32\drivers\etc\hosts
[1228 Bytes] File - C:\WINDOWS\system32\WBEM\Logs\mofcomp.log
[10912 Bytes] LOG File - C:\WINDOWS\system32\WBEM\Logs\wbemprox.log
[451 Bytes] LOG File - C:\Documents and Settings\All Users\Application Data\e5d1\47.mof
[352 Bytes] MOF File - C:\Documents and Settings\All Users\Application Data\e5d1\unins000.dat
[4809 Bytes] DAT File - C:\Documents and Settings\All Users\Application Data\e5d1\WED.ico
[4286 Bytes] ICO File - C:\Documents and Settings\All Users\Application Data\e5d1\WindowsEDefender.exe
[2142720 Bytes] EXE File - C:\Documents and Settings\All Users\Application Data\e5d1\BackUp\HyperSnap-DX.lnk
[650 Bytes] LNK File - C:\Documents and Settings\All Users\Application Data\e5d1\WEDDSys\vd952342.bd
[11382 Bytes] BD File - C:\Documents and Settings\All Users\Application Data\WEDDSys\wed.cfg
[1473 Bytes] CFG File - C:\Documents and Settings\[USER]\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Enterprise Defender.lnk
[1810 Bytes] LNK File - C:\Documents and Settings\[USER]\Application Data\Windows Enterprise Defender\Instructions.ini
[1342 Bytes] INI File - C:\Documents and Settings\[USER]\Cookies\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Cookies\virus demo@windowsenterprisedefender[2].txt
[717 Bytes] TXT File - C:\Documents and Settings\[USER]\Desktop\Windows Enterprise Defender.lnk
[1792 Bytes] LNK File - C:\Documents and Settings\[USER]\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
[16384 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009092820091005\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\History\History.IE5\MSHist012009101220091013\index.dat
[32768 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\index.dat
[81920 Bytes] DAT File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\activate[1].htm
[2 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\avard1[1].gif
[4551 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\avard5[1].gif
[6757 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\calibri[1].htm
[6341 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\closelabel[1].gif
[979 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\install-report[1].htm
[2 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\lightbox[1].js
[18451 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\selector[1].gif
[509 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\0H2HIRKN\threat[1].jpg
[3156 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\avard4[1].gif
[4189 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\builder[1].js
[4770 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\diagram[1].jpg
[27454 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\effects[1].js
[38986 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\get_order_info[1].htm
[0 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\image[1].jpg
[31945 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\lightbox[1].css
[1642 Bytes] CSS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\6XSRQLQP\menu_bg[1].gif
[159 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\avard2[1].gif
[6466 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\button1[1].png
[9764 Bytes] PNG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\menu_ative[1].gif
[938 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\monitor[1].jpg
[1952 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\scriptaculous[1].js
[2654 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\SoftServiceReport[1].htm
[2 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\style[1].css
[12863 Bytes] CSS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\SRIDQBO7\top_logo[1].jpg
[21639 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\avard3[1].gif
[6180 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\avard6[1].gif
[4677 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\bottom_logo[1].jpg
[28212 Bytes] JPG File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\button2[1].gif
[2734 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\get_product_domains[1].htm
[35 Bytes] HTM File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\java[1].js
[563 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\loading[1].gif
[2767 Bytes] GIF File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\prototype[1].js
[126132 Bytes] JS File - C:\Documents and Settings\[USER]\Local Settings\Temporary Internet Files\Content.IE5\YNQ1M5MT\windowsenterprisedefender[1].htm
[6341 Bytes] HTM File - C:\Documents and Settings\[USER]\Start Menu\Windows Enterprise Defender.lnk
[1792 Bytes] LNK File - C:\Documents and Settings\[USER]\Start Menu\Programs\Windows Enterprise Defender.lnk
[1798 Bytes] LNK File
Additional information might be found here:
Search
at Google for
Adware WindowsEnterpriseDefender
Search at Bing for
Adware WindowsEnterpriseDefender
Search
at Yahoo for
Adware WindowsEnterpriseDefender
How can I protect myself from Adware WindowsEnterpriseDefender?
Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers.
This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.
Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!
Only $40 for the security of your computer.
Buy Emsisoft Anti-Malware online:
Trust only on the best protection software!
Spring Offer!
Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get
a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.
Only a few days left! Order here
























