Home Malware Programs Rogue Anti-Spyware Programs Security Defender

Security Defender

Posted: February 4, 2011

Threat Metric

Threat Level: 10/10
Infected PCs: 4,907
First Seen: February 11, 2011
Last Seen: May 20, 2023
OS(es) Affected: Windows

ScreenshotJust the latest spawn in a large brood of fake antivirus scanners, Security Defender has numerous connections to earlier forms of rogue malware and should be removed at the earliest opportunity. Like other rogues, it operates by way of a simple graphical shell that pretends to alert the user to serious computer errors. However, these are all false, specifically created to be a scam.

A Biography of the Newest Member of the Nasty Rogue Family

Security Defender, despite being the 2011 model of the same old scam, shares the limitations of these rogues. Most importantly, it's completely unable of detecting or removing true threats to your computer's stability or security. Like many kinds of malware, it has its origins in the Russian Federation. Although it may look a little different from others, more polished and modern, its methodology is identical. This is good for the user, because it means that removing Security Defender is an already solved puzzle!

Identifying the Traitor in Your Ranks

Sometimes it can be difficult to tell whether you have a malware infection on your computer. Security Defender is happily a standout rogue that makes identification very easy. In fact, it can't wait to advertise its presence! It will run itself automatically rather than requiring a prompt, and will immediately detect many nonexistent threats. Despite these messages, Security Defender is physically incapable of actually scanning your computer, let alone removing serious threats, even in its supposed 'full' version.

Another ironic trait that makes Security Defender a snap to identify is its rather morbidly enthusiastic marketing. This is a rogue that truly relies on you not knowing what it is to get the sale! It will engage in tactics such as creating popups or modifying your browser settings with a proxy server for redirection. Whatever foul tactics Security Defender takes always ends at the same goal, towards a purchase form for itself.

The Worst Security Defender Has to Offer to Your System

Security Defender's aggressive attempts to protect itself from being deleted are both its most blatant and its most dangerous behavior. To this end, it may automatically shut down any process it considers a threat to its own predatory well-being, including various genuine anti-malware scanner programs.

The Achilles Heels in Security Defender

Even in the face of such aggression, there's no reason to give in to this rogue invader. Security Defender has several weak points that make it easy to remove. Because it requires a web browser to scam you out of your money in the first place, Security Defender won't block the processes for Internet Explorer or Firefox.

However, it's usually more efficient to boot into Safe Mode. To access the menu for Safe Mode, simply hit F8 while starting your computer and this will prevent Security Defender from starting up in the first place. If your Internet connection is for some reason cut off or crippled by this rogue, there are two ways to regain it. The first is to use 'Safe Mode with Networking.' The second works in any mode - just disable proxy servers in your LAN Settings under the Connections tab of Internet Options (found in the Control Panel).

While in Safe Mode, removing Security Defender and any other infections should be your top concern, since this nasty little guy will hinder all other operations as long as it's on your hard drive. Some professional anti-malware scanners may have difficulty recognizing and cleansing the PC from Security Defender. It can also be removed in a hands-on fashion - searching for all its files and folders as well as registry entries, and deleting them one at a time. With this last method, you should take care that all components of Security Defender are truly deleted. Make sure that there aren't any malware-based processes running during your deletion sweep! If done properly, your system should be free of this highly disruptive pest, allowing you to go about your life with renewed freedom.

Security Defender Screenshot 2Security Defender Screenshot 3Security Defender Screenshot 4Security Defender Screenshot 5Security Defender Screenshot 6Security Defender Screenshot 7Security Defender Screenshot 8Security Defender Screenshot 9Security Defender Screenshot 10Security Defender Screenshot 11Security Defender Screenshot 12Security Defender Screenshot 13Security Defender Screenshot 14

Aliases

TR/Workir.agk [AntiVir]Trojan.Win32.Workir [Ikarus]Trojan.Win32.Scar.g.1 (v) [Sunbelt]BackDoor.Lat [DrWeb]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\03e5c2ca-9a05-418d-b277-d7db924dcb95_46.avi File name: 03e5c2ca-9a05-418d-b277-d7db924dcb95_46.avi
Size: 43.74 KB (43741 bytes)
MD5: 50451521c2528c39278d3a85250c1200
Detection count: 440
Mime Type: unknown/avi
Path: %APPDATA%
Group: Malware file
Last Updated: December 15, 2011
%ALLUSERSPROFILE%\13cbb1a7-243b-4c2d-a4f0-957e7ace64dd_34.avi File name: 13cbb1a7-243b-4c2d-a4f0-957e7ace64dd_34.avi
Size: 1.83 MB (1830400 bytes)
MD5: 601ddf36f1f78f6835c5179101d0b778
Detection count: 356
Mime Type: unknown/avi
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: December 15, 2011
%ALLUSERSPROFILE%\b31a8294-09b7-4487-974a-deb2578a502e_34.avi File name: b31a8294-09b7-4487-974a-deb2578a502e_34.avi
Size: 1.78 MB (1784832 bytes)
MD5: 558cdbe9ac8039dfbc29ec2181b99e2d
Detection count: 262
Mime Type: unknown/avi
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: December 15, 2011
%APPDATA%\2283880F-EF87-4aac-8EBD-C9BCC8494AF5_47.avi File name: 2283880F-EF87-4aac-8EBD-C9BCC8494AF5_47.avi
Size: 80.61 KB (80610 bytes)
MD5: 370aa0648b6deff8a7a499843d6f0307
Detection count: 166
Mime Type: unknown/avi
Path: %APPDATA%
Group: Malware file
Last Updated: December 15, 2011
%APPDATA%\2283880F-EF87-4aac-8EBD-C9BCC8494AF5_47.avi File name: 2283880F-EF87-4aac-8EBD-C9BCC8494AF5_47.avi
Size: 80.61 KB (80613 bytes)
MD5: feef20400b0fa5cc8493961acf7809eb
Detection count: 166
Mime Type: unknown/avi
Path: %APPDATA%
Group: Malware file
Last Updated: December 15, 2011
%ProgramFiles%\Security Defender\Security Defender.dll File name: Security Defender.dll
Size: 1.09 MB (1090048 bytes)
MD5: 1c75d2463adfdd2d1a462a096dec92fe
Detection count: 83
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ProgramFiles%\Security Defender
Group: Malware file
Last Updated: February 11, 2011
%ALLUSERSPROFILE%\Application Data\d09cfb1c-9bb8-4ad1-a467-d105a674c81a_.mkv File name: d09cfb1c-9bb8-4ad1-a467-d105a674c81a_.mkv
Size: 868B (868 bytes)
MD5: 92c4bc9e861f77ac4d5975a6dbb332aa
Detection count: 81
Mime Type: unknown/mkv
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: February 11, 2011

Registry Modifications

The following newly produced Registry Values are:

File name without pathSecurity Defender.lnkRegexp file mask%APPDATA%\[RANDOM CHARACTERS]-[RANDOM CHARACTERS]-[RANDOM CHARACTERS]-[RANDOM CHARACTERS]-[RANDOM CHARACTERS].avi%LOCALAPPDATA%\App\[RANDOM CHARACTERS].dll%WINDIR%\system32\[RANDOM CHARACTERS]-[RANDOM CHARACTERS]-[RANDOM CHARACTERS]-[RANDOM CHARACTERS]-[RANDOM CHARACTERS].avi

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\pcdfdata%ProgramFiles%\Security Defender
The following messages's were detected:
# Message
1Security Defender Firewall Alert
Iexplore.exe is infected with Trojan.JS.Fraud.ba. Private data can be stolen by third parties, including credit card details and passwords.
Windows recommends activate Security Defender
2System Security Alert!
Unknown program is scanning your system registry right now! Identify the theft detected!
3System Security Alert!
Vulnerabilities found
Background scan for security breaches has been finished. Serious problems have been detected. Safeguard your system against exploits, malware and viruses right now by activating Proactive Defence.

Related Posts

29 Comments

  • Glory Ncube says:

    I downloaded security defender onto my computer and paid for it and I was wondering if anyone knows how I can contact them for the refund as I have just found out that it is not good

    Thanks

  • stephanie says:

    somehow this security defender got into my computer and now i cant ge it removed help!!!!plzzzz its driving me nuts

  • alexander canon says:

    THANK YOU FOR YOUR SUPPORT

  • Karen Tindell says:

    Will someone PLEASE HELP ME WITH removing this disasterious and annoying Security Defender from my computer? It is driving me insane.

    Thank you
    Sincerely Karen

  • Rhonda625 says:

    Thank you for the info on removing this - I couldn't find all the processes you mentioned, but I'll keep working on it.

    Don't ever get Security Defender on your computer!

  • Pat says:

    I got as far as -- Run - entered regedit, found the HKEY_LOCAL_Machine, but not the softwarre/securirtyDefender, as a result when I right clicked could not highlight delete. So frustruated with this security Defender!!!! can anyone help

  • Cate Huggiins says:

    Security Defender Should be shut down!!!! It is a nuisance. My husband will spend days getting rid of this boil on the web. Does anyone have any suggestions?

  • sharontracy says:

    please tell me how i can get security defender out of this comperter i down load it until i knew i had to pay then i stop and now want it gone how do i do that helpppppp please

  • Sydney D. says:

    ITS DRIVING ME CRAZY PLEASE HELP ME?

  • Jerelle says:

    I cannot get this Security defender off my computer.

  • Joanne says:

    Can any one please tell me exactly which files or folders you need to delete from the registry? Thanks Joanne

  • Joe says:

    I followed the instructions and everything worked until i went to actually delete the file in the last step and it said i "needed permission" to delete it. I quarantined the file in Kaspersky anti virus. will this work or should i find out how to go about actually deleting it??

  • Jerry Sullivan says:

    I havebeen fight this security defender invasion for two days. I finally relented and am going to cancel my credit card payment.

  • Clara says:

    security defebder us insane I can't remove it PLEASE help!

  • kelsey says:

    PLEASE HELP ME GET THIS STUPID THING OFF MY COMPUTER PLEASE!!!!!

  • Betty Russell says:

    Security Defender appeared in my computer and took over every screen. I downloaded the latest Malwarebytes (free from the internet). I then ran the malwarebytes system and there was no more Security Defender. I had technicicans tell me, take it in to a computer repair. NOT! My register was scanned along with my C and D Drives and it was gone. Good luck All!!

  • danielle says:

    These directions plus the ones on Microsoft\'s website are very helpful with removing this stupid thing. I also purchased Prevx, an official Microsoft malware scanner/removal software to keep this from happening again. It took me 3 hours to fix my mistake, but I can rest peacefully knowing my laptop is much safer.

  • KESSEM GRIMES says:

    TAKE THIS SECURITY OFF MY COMPUTER

  • ian parkin says:

    Would you please remove security Defender it keeps getting in my way.

  • Debra says:

    I thought I got rid of this stupid security defender but after running a stopzilla and malware bytes, every time i long on, it keeps popping back. any suggestions? I want this stupid thing gone like yesterday

  • king says:

    We should start a class action law suit ! on Rogues the maker !

  • Allen Stark says:

    One of the worst yet to try and get off. I had to have my computer cleaned by a reputable tech. It came through a trusted friend's email.

  • Austin says:

    i hate the stupid security defender pop ups i have done the steps and they still pop up how do i get rid of these stupid things

  • shannon says:

    I already have security defender , its working this mess keeps popping up please help me

  • Nikki Cabrera says:

    can you please help me get this security defender off my laptop its getting in my way!

  • Jim McKay says:

    I'm trying to get this annoying program and no matter what I do it interupts my work every 5 mins. I didn't ask for this garbage and I want my name and computer off your list PRONTO

  • rohied says:

    can please help me take this piece of shit security defender out of my laptop.its driving me crazy

  • Angel says:

    THIS CRAP "SECURITY DEFENDER" GOT IN MY CUMPUTER!!!!!!!!! WHAT THE HELL!!!!!!!!!! GET IT OOOOOOOOOOOOOFF!!!!!!!

  • marilyn says:

    have run malwarebytes (free version) several times, but Security Defender seems to keep coming back - any suggestions?

Loading...