Home Malware Programs Rogue Anti-Spyware Programs SaveDefense

SaveDefense

Posted: August 27, 2009

SaveDefense (also referred to as Save Defense) is a fake spyware remover hailing from the same family as SaveKeep, SaveSoldier, WiniFighter and WiniBlueSoft. Once installed, SaveDefense generates fictitious and sometimes grossly exaggerated scan results along with fabricated security alerts, all in order to fool you into thinking your PC is infected. You are then prompted to purchase and download the full version of SaveDefense to combat these imaginary threats.

File System Modifications

  • The following files were created in the system:
    # File Name File Size (bytes) File Hash
    1 SaveDefense N/A N/A
    2 SaveDefense.exe 666,112 fdab4220f9ca733dbbc10759f0890320
    3 SaveDefense.lnk N/A N/A
    4 SaveDefenseSvc.exe 37,376 a35a84dcceeee51256b12351a0ebf3d0
    5 setup[1].exe 803,272 385ff01599069d433ba9628975dfa4ce

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Software\SaveDefense

Additional Information on SaveDefense

  • The following paths were detected:
    # Path
    1 %AllUsersProfile%\Start Menu\Programs\SaveDefense
    2 %ProgramFiles%\SaveDefense Software\SaveDefense
Loading...