Unlimited Defender is a scam scanner that shows random names assigned to no system address or to system addresses that contain harmless but useful content. Scanner is not merely the thing the program simulates to mislead user into believing they are infected and need to order extended treatment from the security solution to which they belong. Another predestination of the scan is to convince users of the need to download and install the fake security solution. To avoid further confusion of the reader, it needs to be clarified there are two types of scan from the misleading program, the online scan and resident scan. Both cases provide fake results, of course, where the former lures users to activate the counterfeit and the latter is only meant to engage users into the scam by means of downloading and installing the counterfeit.
  • Full name: Unlimited Defender, UnlimitedDefender, Unlimited-Defender
  • Version: 2012
  • Type: Rogue anti-spyware
  • Origin: Russian Federation, Ukraine

Signs of being infected with Unlimited Defender

Unlimited Defender protects itself from interruption. It has annoying habit of terminating other software, especially if it is busy itself to popup its alerts and fake scan windows. The ploy is typical for contemporary malware.
The outline of the program GUI reminds that of Unlimited Defender adware, as well as a host of other fake security tools which use elements of Windows logo in their graphics. The above explains why the most popular signs of the adware identification are its front window, which is a big popups that attracts user’s attention as such, and alerts that state the program (name is usually hushed up) has failed due to virus (random virus name mentioned).
Unlimited Defender automatical removal:

Manual Removal of Unlimited Defender:

The steps below will guide your through Unlimited Defender removal steps. It is critical to complete the adware removal, for deleting executables only does not eradicate the adware popups and startup routines.

Remove Unlimited Defender files and dll’s:

%Documents and Settings%\[UserName]\Local Settings\Temp\[RANDOM CHARACTERS]
%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe
%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS]
%Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]

Unregister Unlimited Defender registry values:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = ‘1’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = ‘1’
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exee” -a “%Program Files%\Internet Explorer\iexplore.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe” -a “%Program Files%\Mozilla Firefox\firefox.exe”‘
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe” -a “%Program Files%\Mozilla Firefox\firefox.exe” -safe-mode’
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe” -a “%1” %*’
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = ‘”%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe” -a “%1” %*’
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%Documents and Settings%\[UserName]\Local Settings\Application Data\[RANDOM CHARACTERS].exe” -a “%1” %*’
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation “TLDUpdates”

