SystemDefender

SystemDefender Description

ScreenshotDo not be tricked into thinking that SystemDefender is some kind of Windows product. SystemDefender is malware that pretends to be security software, in order to scare you into paying money for nothing.

Signs of Infection with SystemDefender

SystemDefender preys on PC users by making itself look like a Microsoft product or a Windows component. Accordingly, the first sign you'll see of an infection will likely be a fake update window that is produced by a Trojan. The Trojan that promotes SystemDefender is hidden in unrelated, harmless-looking downloads, or in fake Windows updates on third-party sites. Once the Trojan has found its way in, SystemDefender will alert you that you need to download an anti-malware update for Windows. If you agree to the update, as most people would, then you are allowing SystemDefender to download.

When SystemDefender becomes active, SystemDefender can't be ignored. The SystemDefender interface will frequently appear, and SystemDefender will use it to run fake scans of your computer. In order to make the scan results believable, SystemDefender creates some junk files for itself to detect later. That way, if you go looking for the malware files that SystemDefender claims to find, you will find some of them, although they are empty. After each scan, SystemDefender will warn you that to remove these "threats", you need to upgrade to the licensed or registered version of SystemDefender. SystemDefender will try to take you to the SystemDefender website, where you can pay for the malware by credit card. No matter what SystemDefender may tell you, paying that money will not get you anything.

SystemDefender will also try to get you to go to SystemDefender's payment site by showing frequent phony security alerts. These alerts will say some really scary things about threats to your computer, but you can disregard all of that as scare tactics. Likewise, SystemDefender will show error messages when you try to use other programs and SystemDefender will prevent them from running, on the basis that they are malicious or infected. The real reason that SystemDefender disables other programs is to prevent you from deleting SystemDefender, and to that end, SystemDefender will disable Task Manager and the Control Panel.

SystemDefender means to leave you feeling as if you have no way out of the bind SystemDefender has you in, other than by paying the money SystemDefender demands. So, don't think that SystemDefender will let you look for help online. SystemDefender will redirect you to malicious websites by interfering with your computer's settings. In the worst cases of SystemDefender infection, users may be unable to access the Internet at all, or may find that their computers become unstable and crash.

Malware Related to SystemDefender

SystemDefender comes from a family of fake security programs that imitate Windows Defender, which is a real, useful Microsoft product. The malware in SystemDefender's family uses the Windows name, logos, fonts, and styling in SystemDefender's interfaces and alerts in order to convince people that SystemDefender is a real Microsoft software. Some of these other fake security applications are Internet Defender, Security Defender, and Antimalware Defender, although this is by no means a complete list. The malware in this family is all part of a scam which can be traced back to Russia, and it is likely that new names for the same scam will crop up. SystemDefender appeared in March 2011.

Aliases: Adware Generic2.PZW [AVG], not-a-virus:AdWare.Win32.Agent.iv [Kaspersky], Suspicious file [Panda], Adware Generic2.PZX [AVG], Adware/Agent [Fortinet], Win32/Adware.Agent.NFR, Generic.Dropper.xCodec [Prevx1], not-a-virus:AdWare.Win32.Agent.iw [Kaspersky], W32/Agent.CHZW, Adware/Agent.iw, Backdoor.UltimateDefender.BO, Adware.UltimateDefender.1376256, SystemDefender [Symantec], Ultimate SecuritySuite [Sunbelt] and High Risk Fraudulent Security Program [Prevx1].

Technical Information

Screenshots & Other Imagery

Tip: Turn your sound ON and watch the video in Full Screen mode to fully experience how SystemDefender infects a computer.

SystemDefender Video

File System Details

SystemDefender creates the following file(s):
# File Name Size MD5 Detection Count
1 %WINDIR%msmhost.dll 184,320 1ff9614951c642d41b44f852cfc43cf0 2
2 %WINDIR%msmdev.dll 225,280 2781ca3ebc80c1195fe80d9593106e86 2
3 SystemDefender.exe 1,376,256 441d594812bde8509a922c179ea04fa5 0
4 SystemDefender_Installer[1].exe 96,328 5c8e056f2a4e362555be28986351a5df 0
More files

Registry Details

SystemDefender creates the following registry entry or registry entries:
Cookies
system-defender

More Details on SystemDefender

The following cookies were found:
  • system-defender

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.