Security Defense

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 3
First Seen: September 15, 2011
Last Seen: July 21, 2021
OS(es) Affected: Windows

Security Defense is a rogue anti-spyware program. Rogue anti-spyware programs are a kind of malware infection specifically designed to prey on inexperienced computer users. Security Defense is part of a scam which consists of convincing a computer user to buy a non-functional anti-spyware application. Some rogue security programs that are extremely similar to Security Defense include Security Protection and Data Recovery. If Security Defense is installed on your computer, you may become a victim of a computer scam. You should disregard all notifications, messages and warning from Security Defense and use a legitimate anti-malware program to remove Security Defense permanently. ESG malware analysts consider that Security Defense poses a significant security risk that should be dealt with immediately.
 

Understanding the Security Defense Scam

As was mentioned before, Security Defense is part of a long-running scam. The Security Defense scam consists in convincing a computer user that Security Defense is a legitimate anti-malware application and then, confusing that user into buying a useless "full version" of this fake security program. Security Defense perpetrates this scam in a way that is practically identical to the most common rogue security programs that are circulating today.

  1. First, Security Defense is installed onto a computer through deceptive means. There are several ways Security Defense accomplishes this: Security Defense can be installed with the help of a Trojan (such as Vundo, Zlob, of the Fake Microsoft Security Essentials Alert Trojans), Security Defense may be disguised as a system update or video codec or a computer user may simply be convinced to download Security Defense because of misleading marketing.
  2. Once Security Defense is installed, Security Defense makes several harmful changes to your computer settings and to the Windows Registry. These changes allow Security Defense to be launched when Windows starts up and allow Security Defense to alter your computer's normal operation significantly.
  3. The presence of Security Defense on the infected computer then causes a large number of adverse effects. The victim will usually be bombarded with a barrage of fake system alerts, warnings and security notifications. The computer will also run slowly, crash frequently and refuse to open certain files. To protect itself, Security Defense may also block legitimate anti-virus programs and access to the Internet.
  4. Inexperienced computer users may be fooled into thinking that all of these problems are caused by a number of different virus infections. Even though they are caused by Security Defense itself, the computer user is still prompted to buy a "full version" of Security Defense to fix these problems.

File System Details

Security Defense may create the following file(s):
# File Name Detections
1. %Documents and Settings%\[UserName]\Local Settings\Application Data\defender.exe

Registry Details

Security Defense may create the following registry entry or registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Security Defense

Trending

Most Viewed

Loading...