Windows Defender fails to protect from spyware

Windows Defender fails to protect from spyware

Microsoft's free Windows Defender ships standard with Windows Vista and is available as a free download for Windows XP SP2. If it had presented itself as an anti-adware program, we'd be less hard on it, but Defender's Web site asserts that the software provides "Spyware protection for free," and in that claim it fails.

In tests performed by, Windows Defender did detect all ten of the active adware threats it was exposed to. It detected less than 50 percent of the 46,352 inactive adware samples we threw at it -- hardly admirable but middle of the road against other products. In disinfection tests, the program successfully removed 55 percent of adware files and Registry entries, missing PremiumSearch, (which messes with Internet Explorer's home page and favorites and produces pop-up ads) and Starware (which creates an IE search bar).

But with regard to spyware, the story is entirely different and somewhat by design. Microsoft says in its own product documentation that Windows Defender is not a replacement for full anti-virus protection -- in contrast to the company's subscription-based Windows OneCare antimalware suite -- and makes clear that Windows Defender won't block such virulent computer threats as password-stealing bots and Trojan horse programs, some of which can be classified as spyware. Sure enough, in our tests the program neither detected nor disinfected the ten active spyware threats we introduced. It did, however, detect 7 percent of the 6365 inactive password stealers we threw at it. It failed to detect any inactive rootkits.

Windows Defender did excel in behavior-based protection, which detects changes to key areas of the system without having to know anything about the actual threat. This type of protection is important in the case of a zero-day threat which runs rampant before security companies have a chance to patch their software. The program detected all additions to the 'Run' keys (HKCU and HKLM), all additions to the startup folder, all changes to the Internet Explorer Search and Start pages and changes to the Hosts file (which can redirect a URL to a malicious Web site).

Windows Defender is easy to understand and configure. There's little user interaction beyond the option of choosing a low, medium, or high level of security. Windows Defender was the only stand-alone antispyware program we tested that by default has a regularly scheduled scan (at 2 a.m. daily). In Vista, it is the only antispyware tool that integrates with Internet Explorer 7 Protected Mode to permit scanning of downloaded files before they are saved or executed. Warning: Telephone support for the program is expensive. After two free calls, you must pay US$35 per request. E-mail and Web-based support is free.

Windows Defender is certainly better than nothing. It combats adware and offers behavior-based protection that should block many threats that might try to make unwelcome changes to your system, but if a Trojan horse or other piece of malicious spyware slips past Defender's first line of defense, you'll need something else to clean up the mess.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Ryan Naraine

PC World
Show Comments


James Cook University - Master of Data Science Online Course

Learn more >


Victorinox Werks Professional Executive 17 Laptop Case

Learn more >

Sansai 6-Outlet Power Board + 4-Port USB Charging Station

Learn more >



Back To Business Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?