SaveDefense
SaveDefense Description
SaveDefense (also known as Save Defense)is a rogue anti-spyware application sponsored through the use of affiliated trojans and browser hijackers, much like its predecessors SaveSoldier, SaveKeep, WiniBlueSoft and WiniFighter. Once active, SaveDefense will begin generating fake system scans that display fictitious and overly exaggerated infection results, along with fake security alerts, in order to trick the user into believing that the computer is infected. The user is then prompted to purchase and download the commercial version of SaveDefense in order to combat these threats.
Type: Rogue AntiSpyware Programs
Automatic Detection of SaveDefense
SaveDefense Technical Report
As new SaveDefense details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following SaveDefense files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| SaveDefenseSvc.exe | 37376 | a35a84dcceeee51256b12351a0ebf3d0 |
| SaveDefense.exe | 666112 | fdab4220f9ca733dbbc10759f0890320 |
| setup[1].exe | 803272 | 385ff01599069d433ba9628975dfa4ce |
SaveDefense has typically the following processes in memory:
- SaveDefense.exe
- SaveDefenseSvc.exe
SaveDefense created the following directories, files, paths:
- %ProgramFiles%\SaveDefense Software\SaveDefense
- %AllUsersProfile%\Start Menu\Programs\SaveDefense
SaveDefense creates the following registry entries:
- Software\SaveDefense
Important Article Disclaimer


English 

SaveDefense 










