Sign in / Sign up

How to Remove System Defender

text size: | Related software / service: Registry Editor

Problem

You may want to install Windows Defender, but then installed the Mal-ware named "System Defender instead, an you may get trouble when you try to remove it from your computer, this Recipe will help you remove System Defender from your PC.

Solution

  1. Launch Task Manager by pressing <Ctrl> + <Alt> + <Esc>, find and "End Process" these process:
    WS339.exe
    ppal.exe
    tjd.exe

    End Process related to System Defender
  2. Press <Win> + <F>, and find these files below one by one from "All files and folders":
    Search for files related to System Defender to remove it
  3. Select the file in search result and right click to delete them from your computer:
    c:\Documents and Settings\All Users\Application Data\117fc\WS339.exe
    c:\Documents and Settings\All Users\Application Data\117fc\WSD.ico
    c:\Documents and Settings\All Users\Application Data\WSDDSys\wsd.cfg
    %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\System Defender.lnk
    %UserProfile%\Application Data\System Defender\cookies.sqlite
    %UserProfile%\Application Data\System Defender\Instructions.ini
    %UserProfile%\Desktop\System Defender.lnk
    %UserProfile%\Desktop\xp_7a9be\68.mof
    %UserProfile%\Desktop\xp_7a9be\WSDDSys\vd952342.bd
    %UserProfile%\Recent\ANTIGEN.sys
    %UserProfile%\Recent\ANTIGEN.tmp
    %UserProfile%\Recent\ddv.tmp
    %UserProfile%\Recent\PE.drv
    %UserProfile%\Recent\PE.sys
    %UserProfile%\Recent\ppal.exe
    %UserProfile%\Recent\runddlkey.drv
    %UserProfile%\Recent\std.sys
    %UserProfile%\Recent\tjd.exe
    %UserProfile%\Recent\tjd.sys
    %UserProfile%\Start Menu\System Defender.lnk
    %UserProfile%\Start Menu\Programs\System Defender.lnk
    c:\Program Files\Mozilla Firefox\searchplugins\search.xml
    c:\Documents and Settings\All Users\Application Data\117fc
    c:\Documents and Settings\All Users\Application Data\WSDDSys
    %UserProfile%\Application Data\System Defender
    %UserProfile%\Desktop\xp_7a9be\
    %UserProfile%\Desktop\xp_7a9be\WSDDSys
    %UserProfile%\Desktop\xp_7a9be\mozcrt19.dll
    %UserProfile%\Desktop\xp_7a9be\sqlite3.dll
    %UserProfile%\Recent\ANTIGEN.dll
    %UserProfile%\Recent\cid.dll
    %UserProfile%\Recent\CLSV.dll
    %UserProfile%\Recent\PE.dll
    %UserProfile%\Recent\tempdoc.dll

    Delete files related to System Defender
  4. Launch Registry Editor by pressing <Win> + <R>, type in "regedit" and click on "OK" button:
    Launch Registry Editor to remove registry entries related to System Defender
  5. Expand the registry and delete these entries:
    HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
    HKEY_CLASSES_ROOT\xp_7a9be.DocHostUIHandler
    HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://search-gala.com/?&uid=220&q={searchTerms}”
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
    HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes “URL” = “http://search-gala.com/?&uid=220&q={searchTerms}”
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “System Defender”

    Delete System Defender registry entries to remove it from your computer
  6. Reboot your computer, the System Defender may be removed from your computer.  

Tips

See also

Vote for this tutorial

Authors

  Tfcra

Creative Commons License
All text shared under a Creative Commons License