Security Defender

By JubileeX in Rogue Anti-Spyware Program | 2,241 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (6 votes, average: 4.00 out of 5)
Loading ... Loading ...
More... More

Security Defender Description

Image Screenshot

[+] Click Image to Enlarge

Security Defender is a rogue anti-virus application and a scam. What’s particularly nasty about this one is that it impersonates Microsoft’s Windows Defender, which is legitimate anti-virus software.

Security Defender’s Scare Tactics

Leaving the infection process aside for the moment, because it can vary, there is a standard set of symptoms that you will see on a computer infected with Security Defender. First of all, it will alter the registry so that it runs every time Windows starts. Security Defender will pop-up with its bogus user interface, which is a complete ripoff of Windows Defender and uses the Windows Defender logo (which looks like a rampart, or a part of a castle wall), as well as the Windows logo, and Windows styling with fonts and icons. All of this is without permission, of course, because the people who created Security Defender are criminals. This screen will always show that threats have been detected on the system, along with a reminder to “activate” your copy of the Security Defender software. If you look at the list of threats which Security Defender claims to have detected, they are either harmless ordinary files or made-up names; but Security Defender will tell you that you have to activate it in order to be able to remove them.

Also, completely typical for a rogue anti-virus application, Security Defender will cause frequent pop-up alerts, which warn you of impending danger to your computer, which can only be averted by paying for your copy of Security Defender and somehow giving it its full functionality. The common error messages you’ll see with an infection of Security Defender will warn that there is a firewall alert and that the registry has been altered, or that some kind of unidentified malware has been found on the computer. Sometimes, Security Defender will claim that Internet Explorer is infected with a Trojan, which doesn’t even make sense. Of course, as always, these alerts will prompt you to pay for Security Defender in order to secure your PC. If you follow the prompts that Security Defender gives you, you will be led to a website where you can pay money for the malware, but absolutely nothing will change. Security Defender can’t gain functionality that doesn’t exist.

There have been reports of Security Defender preventing some programs from running. In particular, Security Defender may disable legitimate anti-virus applications. It is also possible that Security Defender may cause your web browser to redirect you to hazardous websites when you try to surf the web. There are claims that the security code D13F-3B7D-B3C5-BD84 can be entered into Security Defender, which will cause it to leave you alone for a while; but please note that this is not going to solve the problem; it can only temporarily disable Security Defender so that you can remove the malware.

How Security Defender Spreads on the Web and a PC

Security Defender seems to spread in two different ways. It is promoted by malicious websites that claim to offer free virus scans, and which actually cause Security Defender to download to your computer. Security Defender may also spread by way of a Trojan, which infects your system without your knowledge, and which typically is hidden in a downloaded file. This Trojan is reputedly capable of creating alerts which look as if they are reminders for software updates –- and if you follow the prompts in its alerts in order to download these “updates,” you download Security Defender.

Security Defender’s Additional Particularities

The scam that Security Defender is a part of is not anything new. It’s just a new, renamed version of Antimalware Defender, and, like its predecessor, it comes from Russia. The difference is, Security Defender is a name that showed up after about the first week of February 2011.

Type: Rogue AntiSpyware Programs

How Can You Detect Security Defender?

‘How Security Defender Infects Your Computer’ Video

Security Defender Removal Details

Security Defender has typically the following processes in memory:

  • %Temp%\[RANDOM CHARACTERS].dll
  • c:\Program Files\Security Defender\Security Defender.dll

Security Defender creates the following files in the system:

  • c:\Documents and Settings\All Users\Application Data\56a10a26-dc02-40f3-a4da-8fa92d06b357_.mkv
  • %UserProfile%\Desktop\Security Defender.lnk
  • c:\Documents and Settings\All Users\Application Data\56a10a26-dc02-40f3-a4da-8fa92d06b357_33.ico
  • c:\Documents and Settings\All Users\Start Menu\Programs\Startup\56a10a26-dc02-40f3-a4da-8fa92d06b357_33.lnk
  • %UserProfile%\Start Menu\Programs\Startup\56a10a26-dc02-40f3-a4da-8fa92d06b357_33.lnk
  • c:\Program Files\Security Defender
  • c:\Documents and Settings\All Users\Application Data\56a10a26-dc02-40f3-a4da-8fa92d06b357_33.avi
  • %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Security Defender.lnk

Security Defender creates the following registry entries:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “56a10a26-dc02-40f3-a4da-8fa92d06b357_33″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “56a10a26-dc02-40f3-a4da-8fa92d06b357_33″
  • HKEY_CLASSES_ROOT\CLSID\{56a10a26-dc02-40f1-a4da-8fa92d06b357}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56a10a26-dc02-40f1-a4da-8fa92d06b357}

Important Article Disclaimer

ESG Support Center

This entry was last updated on 11/30/11 and posted on 02/4/11. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.