Home Malware Programs Adware Content Defender

Content Defender

Posted: August 26, 2015

Threat Metric

Ranking: 7,021
Threat Level: 2/10
Infected PCs: 72,846
First Seen: August 17, 2015
Last Seen: March 6, 2025
OS(es) Affected: Windows

Content Defender is a web browser extension that is cleverly advertised as a useful utility that can enhance your web browser's security. It does so by protecting you from accessing phishing websites and malicious web destinations. At least, this is what Content Defender's website says. In reality, though, the extension isn't capable of achieving much when it comes to online security. In fact, it doesn't pack any features that may protect you while browsing the web and, unfortunately, the only thing that this extension's installations may bring you are annoying ads that will accompany your web browsing journey.

The Content Defender extension is classified as adware, so its removal is strongly recommended. This software won't bring any useful features or tools to your computer, and the only thing that will notify you of its presence are the Content Defender ads flooding your web browser. Removing this extension is the only way to remove the ads that it spawns, so your best bet would be to download a potent anti-malware application and use its scanner to discover and remove all of Content Defender's components.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\System Volume Information\_restore{02EF14A9-1484-4129-B0B2-B0A26FE0A77E}\RP29\A0016816.sys File name: A0016816.sys
Size: 56.36 KB (56368 bytes)
MD5: 14a2aef6aff5a438acace9c1d1b09ab8
Detection count: 61
File type: System file
Mime Type: unknown/sys
Path: C:\System Volume Information\_restore{02EF14A9-1484-4129-B0B2-B0A26FE0A77E}\RP29\A0016816.sys
Group: Malware file
Last Updated: May 8, 2022
C:\WINDOWS\Temp\Временная папка 1 для ContentDefender.zip\driver\tdi__amd64.sys File name: tdi__amd64.sys
Size: 61.23 KB (61232 bytes)
MD5: 3c85a37a54db8567fb49454f1e843995
Detection count: 35
File type: System file
Mime Type: unknown/sys
Path: C:\WINDOWS\Temp\Временная папка 1 для ContentDefender.zip\driver\tdi__amd64.sys
Group: Malware file
Last Updated: May 8, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{35F4BB37-03C5-41DE-85AF-7C301390C7EC}{3E0DB45B-9FCC-4064-B48C-080BD03A99A4}{9B7395C3-28B5-445E-AA7D-539B63514CAB}{B28F9114-243E-4046-B173-11825352D18A}{B910D9A1-9F21-484A-8650-82250DABF38E}{C81BED3B-31BD-491F-813D-78EFC2638CE1}{CCA2A357-CCB4-41C9-B6F5-4F202B8CDC82}{D5397E85-8AF4-414B-90FC-9F4244CD46FA}Regexp file mask%WINDIR%\system32\Drivers\contentdefenderdrv.sysHKEY..\..\..\..{RegistryKeys}SOFTWARE\ContentDefenderSYSTEM\ControlSet001\Enum\Root\LEGACY_CONTENTDEFENDERDRVSYSTEM\ControlSet001\services\ContentDefenderSYSTEM\ControlSet001\services\contentdefenderdrvSYSTEM\CurrentControlSet\Enum\Root\LEGACY_CONTENTDEFENDERDRVSYSTEM\CurrentControlSet\services\ContentDefenderSYSTEM\CurrentControlSet\services\contentdefenderdrvHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ContentDefender

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Content Defender%PROGRAMFILES%\Content Defender%PROGRAMFILES(x86)%\Content Defender
Loading...