Windows Defender fails to protect from spyware

Windows Defender fails to protect from spyware

Microsoft's free Windows Defender ships standard with Windows Vista and is available as a free download for Windows XP SP2. If it had presented itself as an anti-adware program, we'd be less hard on it, but Defender's Web site asserts that the software provides "Spyware protection for free," and in that claim it fails.

In tests performed by, Windows Defender did detect all ten of the active adware threats it was exposed to. It detected less than 50 percent of the 46,352 inactive adware samples we threw at it -- hardly admirable but middle of the road against other products. In disinfection tests, the program successfully removed 55 percent of adware files and Registry entries, missing PremiumSearch, (which messes with Internet Explorer's home page and favorites and produces pop-up ads) and Starware (which creates an IE search bar).

But with regard to spyware, the story is entirely different and somewhat by design. Microsoft says in its own product documentation that Windows Defender is not a replacement for full anti-virus protection -- in contrast to the company's subscription-based Windows OneCare antimalware suite -- and makes clear that Windows Defender won't block such virulent computer threats as password-stealing bots and Trojan horse programs, some of which can be classified as spyware. Sure enough, in our tests the program neither detected nor disinfected the ten active spyware threats we introduced. It did, however, detect 7 percent of the 6365 inactive password stealers we threw at it. It failed to detect any inactive rootkits.

Windows Defender did excel in behavior-based protection, which detects changes to key areas of the system without having to know anything about the actual threat. This type of protection is important in the case of a zero-day threat which runs rampant before security companies have a chance to patch their software. The program detected all additions to the 'Run' keys (HKCU and HKLM), all additions to the startup folder, all changes to the Internet Explorer Search and Start pages and changes to the Hosts file (which can redirect a URL to a malicious Web site).

Windows Defender is easy to understand and configure. There's little user interaction beyond the option of choosing a low, medium, or high level of security. Windows Defender was the only stand-alone antispyware program we tested that by default has a regularly scheduled scan (at 2 a.m. daily). In Vista, it is the only antispyware tool that integrates with Internet Explorer 7 Protected Mode to permit scanning of downloaded files before they are saved or executed. Warning: Telephone support for the program is expensive. After two free calls, you must pay US$35 per request. E-mail and Web-based support is free.

Windows Defender is certainly better than nothing. It combats adware and offers behavior-based protection that should block many threats that might try to make unwelcome changes to your system, but if a Trojan horse or other piece of malicious spyware slips past Defender's first line of defense, you'll need something else to clean up the mess.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Ryan Naraine

PC World
Show Comments

Cool Tech

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Breitling Superocean Heritage Chronographe 44

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?