Windows Defender fails to protect from spyware

Windows Defender fails to protect from spyware

Microsoft's free Windows Defender ships standard with Windows Vista and is available as a free download for Windows XP SP2. If it had presented itself as an anti-adware program, we'd be less hard on it, but Defender's Web site asserts that the software provides "Spyware protection for free," and in that claim it fails.

In tests performed by, Windows Defender did detect all ten of the active adware threats it was exposed to. It detected less than 50 percent of the 46,352 inactive adware samples we threw at it -- hardly admirable but middle of the road against other products. In disinfection tests, the program successfully removed 55 percent of adware files and Registry entries, missing PremiumSearch, (which messes with Internet Explorer's home page and favorites and produces pop-up ads) and Starware (which creates an IE search bar).

But with regard to spyware, the story is entirely different and somewhat by design. Microsoft says in its own product documentation that Windows Defender is not a replacement for full anti-virus protection -- in contrast to the company's subscription-based Windows OneCare antimalware suite -- and makes clear that Windows Defender won't block such virulent computer threats as password-stealing bots and Trojan horse programs, some of which can be classified as spyware. Sure enough, in our tests the program neither detected nor disinfected the ten active spyware threats we introduced. It did, however, detect 7 percent of the 6365 inactive password stealers we threw at it. It failed to detect any inactive rootkits.

Windows Defender did excel in behavior-based protection, which detects changes to key areas of the system without having to know anything about the actual threat. This type of protection is important in the case of a zero-day threat which runs rampant before security companies have a chance to patch their software. The program detected all additions to the 'Run' keys (HKCU and HKLM), all additions to the startup folder, all changes to the Internet Explorer Search and Start pages and changes to the Hosts file (which can redirect a URL to a malicious Web site).

Windows Defender is easy to understand and configure. There's little user interaction beyond the option of choosing a low, medium, or high level of security. Windows Defender was the only stand-alone antispyware program we tested that by default has a regularly scheduled scan (at 2 a.m. daily). In Vista, it is the only antispyware tool that integrates with Internet Explorer 7 Protected Mode to permit scanning of downloaded files before they are saved or executed. Warning: Telephone support for the program is expensive. After two free calls, you must pay US$35 per request. E-mail and Web-based support is free.

Windows Defender is certainly better than nothing. It combats adware and offers behavior-based protection that should block many threats that might try to make unwelcome changes to your system, but if a Trojan horse or other piece of malicious spyware slips past Defender's first line of defense, you'll need something else to clean up the mess.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Ryan Naraine

PC World
Show Comments

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?