Home Malware Programs Adware Content Defender

Content Defender

Posted: August 26, 2015

Threat Metric

Ranking: 4,522
Threat Level: 2/10
Infected PCs: 72,451
First Seen: August 17, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Content Defender is a web browser extension that is cleverly advertised as a useful utility that can enhance your web browser's security. It does so by protecting you from accessing phishing websites and malicious web destinations. At least, this is what Content Defender's website says. In reality, though, the extension isn't capable of achieving much when it comes to online security. In fact, it doesn't pack any features that may protect you while browsing the web and, unfortunately, the only thing that this extension's installations may bring you are annoying ads that will accompany your web browsing journey.

The Content Defender extension is classified as adware, so its removal is strongly recommended. This software won't bring any useful features or tools to your computer, and the only thing that will notify you of its presence are the Content Defender ads flooding your web browser. Removing this extension is the only way to remove the ads that it spawns, so your best bet would be to download a potent anti-malware application and use its scanner to discover and remove all of Content Defender's components.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\windows\system32\drivers\condef.sys File name: condef.sys
Size: 56.11 KB (56112 bytes)
MD5: 2662a31ffc8565492a0492ae90ac52d7
Detection count: 234
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\condef.sys
Group: Malware file
Last Updated: May 18, 2023
C:\System Volume Information\_restore{02EF14A9-1484-4129-B0B2-B0A26FE0A77E}\RP29\A0016816.sys File name: A0016816.sys
Size: 56.36 KB (56368 bytes)
MD5: 14a2aef6aff5a438acace9c1d1b09ab8
Detection count: 61
File type: System file
Mime Type: unknown/sys
Path: C:\System Volume Information\_restore{02EF14A9-1484-4129-B0B2-B0A26FE0A77E}\RP29\A0016816.sys
Group: Malware file
Last Updated: May 8, 2022
C:\Users\<username>\AppData\Local\Temp\condefclean.exe File name: condefclean.exe
Size: 113.88 KB (113880 bytes)
MD5: ab32d5d764d252be947747807cf19b47
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\condefclean.exe
Group: Malware file
Last Updated: May 8, 2022
C:\WINDOWS\Temp\Временная папка 1 для ContentDefender.zip\driver\tdi__amd64.sys File name: tdi__amd64.sys
Size: 61.23 KB (61232 bytes)
MD5: 3c85a37a54db8567fb49454f1e843995
Detection count: 35
File type: System file
Mime Type: unknown/sys
Path: C:\WINDOWS\Temp\Временная папка 1 для ContentDefender.zip\driver\tdi__amd64.sys
Group: Malware file
Last Updated: May 8, 2022
%TEMP%\condefclean.exe File name: condefclean.exe
Size: 114.73 KB (114736 bytes)
MD5: fe116abb3e0da251e6a5e4bb4a9f06dc
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: February 23, 2016
%WINDIR%\TEMP\condefclean.exe File name: condefclean.exe
Size: 114.84 KB (114848 bytes)
MD5: 52f8a78bb360a1e22d47376dc4539c44
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\TEMP
Group: Malware file
Last Updated: February 23, 2016
C:\Users\<username>\Desktop\Windows.old\Program Files\Content Defender\condefclean.exe File name: condefclean.exe
Size: 115.76 KB (115760 bytes)
MD5: a7ca1302b699f7f3f489aba51074454c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\Windows.old\Program Files\Content Defender\condefclean.exe
Group: Malware file
Last Updated: July 11, 2023
%TEMP%\condefclean.exe File name: condefclean.exe
Size: 114.73 KB (114736 bytes)
MD5: 6fb26930ef0402a5009684c9da5cde01
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 1, 2020
%TEMP%\condefclean.exe File name: condefclean.exe
Size: 115.76 KB (115760 bytes)
MD5: afe94bbfc5c953e3c6f618096e988e5e
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: February 23, 2016

Registry Modifications

The following newly produced Registry Values are:

CLSID{35F4BB37-03C5-41DE-85AF-7C301390C7EC}{3E0DB45B-9FCC-4064-B48C-080BD03A99A4}{9B7395C3-28B5-445E-AA7D-539B63514CAB}{B28F9114-243E-4046-B173-11825352D18A}{B910D9A1-9F21-484A-8650-82250DABF38E}{C81BED3B-31BD-491F-813D-78EFC2638CE1}{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}{D5397E85-8AF4-414B-90FC-9F4244CD46FA}Regexp file mask%WINDIR%\system32\Drivers\contentdefenderdrv.sysHKEY..\..\..\..{RegistryKeys}SOFTWARE\ContentDefenderSYSTEM\ControlSet001\Enum\Root\LEGACY_CONTENTDEFENDERDRVSYSTEM\ControlSet001\services\ContentDefenderSYSTEM\ControlSet001\services\contentdefenderdrvSYSTEM\CurrentControlSet\Enum\Root\LEGACY_CONTENTDEFENDERDRVSYSTEM\CurrentControlSet\services\ContentDefenderSYSTEM\CurrentControlSet\services\contentdefenderdrvHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ContentDefender

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Content Defender%PROGRAMFILES%\Content Defender%PROGRAMFILES(x86)%\Content Defender
Loading...