Malware Defender 2009: what it is and how to remove it

Malware Defender 2009 is a rogue anti-spyware application. It is very similar to System Guard 2009 and Spyware Guard 2009, so we can assume that these applications were created by the same group of scammers.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If wcenter.exe returns after removal, a full scan can find the entry that brings it back.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Malware Defender 2009 yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Malware Defender 2009: screenshot
Malware Defender 2009 as our 2021 report showed it.

Malware Defender 2009: summary

Detection namesNo Microsoft detection name is known
DistributionNot recorded in the old report
DamageNot recorded in the old report
NameMalware Defender 2009
TypeRogue antivirus
SymptomsAn unknown process in Task Manager
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 4 more facts
Files and processeswcenter.exe and C:\Windows\System32\wcenter.exe.
EvidenceOne write-up by a security site; details still limited
First seen26 April 2021
Facts checked7 October 2026

From our report of Apr 2021 · not reviewed since

What Malware Defender 2009 is

Malware Defender 2009 is a rogue anti-spyware application.

It is very similar to System Guard 2009 and Spyware Guard 2009, so we can assume that these applications were created by the same group of scammers. MalwareDefender 2009 is usually promoted along with trojan viruses, such as Vundo or similar.

These trojans display fake security alerts and pop-up windows about various security threats and suggest to download Malware Defender 2009 in order to remove those infections or protect the system from further possible infections. Once installed and active, MalwareDefender2009 is configured to load automatically when user starts his computer.

The rogue performs fake system scan and displays various malware infections that can't be removed until user purchases the full version of Malware Defender 2009. However, all those infections are actually fake. They were made up in order to frighten the user, hopping that he will buy worthless spyware remover.

Along with Malware Defender 2009 comes another infection called C:\Windows\System32\wcenter.exe. This trojan may also displays a fake Windows Security Center window with various security problems. It is already obvious that Malware Defender 2009 should be removed as soon as possible after detection. Otherwise it can cause more damage and even decrease system performance.

Is Malware Defender 2009 a real security program?

Traces of Malware Defender 2009 you can check

  • Path: C:\Windows\System32\wcenter.exe.
  • File: wcenter.exe

How to remove Malware Defender 2009

Nothing it reports is real.

These steps remove it and undo a payment if you made one.

  1. Step 1: Do not pay, and undo a payment if you made one

    Nothing that Malware Defender 2009 says it found needs fixing by it. Close its windows and do not enter card details.

    If you bought it, contact your bank or card issuer about a dispute and cancel any renewal, keeping the receipt e-mail as evidence. Uninstalling it from Windows 11 or Windows 10 removes the program but leaves the subscription running.

    Full procedure with screenshots: What to do after paying a scammer

  2. Step 2: Uninstall programs you did not mean to install

    Malware Defender 2009 rarely comes alone: it is usually installed by, or together with, a free program. In Windows 11 open Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and sort by install date.

    Uninstall every entry from the day the trouble began that you did not install on purpose, for example a download manager, a converter or a browser you never chose.

    Keep drivers and entries from Microsoft, Intel, AMD, NVIDIA or your PC's maker unless you are sure.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  3. Step 3: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  4. Step 4: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after Malware Defender 2009, its publisher or created on the day the problem started.

    Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  5. Step 5: Scan the PC, then run the offline scan

    A scan finds the parts of Malware Defender 2009 that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Access your website securely from any location

When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.

If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.

Recover files after data-affecting malware attacks

While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.

More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.

Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.

Questions about Malware Defender 2009

Is wcenter.exe a virus?

The name wcenter.exe is not enough to say. Malware often uses technical-sounding names, and harmless updaters often use odd ones. Check three things:

  • the folder the file runs from
  • the Digital Signatures tab in its properties
  • the program that starts it (Startup apps, Task Scheduler or services)

A signed file from a company whose product you use is almost certainly fine. An unsigned file in a user folder that no installed program explains should be removed, and the PC scanned with Microsoft Defender in offline mode.

Can I end wcenter.exe in Task Manager?

Ending an unknown process is safe in the sense that Windows will warn you before you close anything critical, and a restart brings back whatever Windows needs. Ending wcenter.exe will not remove it, though: if a task or startup entry launches it, it returns at the next sign-in.

Use ending the process as a test. If something important stops working, it belonged to a program you use. If nothing changes and it comes back by itself, find and disable its starter, delete the file and scan the PC.

How do I know Malware Defender 2009 is fake?

Three things give it away. It appears as an unfamiliar process called wcenter.exe in Task Manager, a window from a program rather than from Windows Security. It pushes you to act quickly by calling, paying or downloading.

And the threats it reports never show up when you run a scan in the real Windows Security app. Microsoft does not put phone numbers in warnings or charge for removing threats through pop-ups. Close the window, do not call, and follow the steps to find and uninstall the program behind it.

Someone called offering a refund for Malware Defender 2009. Is it genuine?

Almost certainly not. Refund calls are a well-known second stage of scareware and tech support scams. The caller says you are owed money, asks you to install a remote access program to "process" it, then opens your online banking, makes it look as if too much was refunded and asks you to send the difference back.

Hang up. Real refunds go back to the card or PayPal account you paid with, through your bank or the payment provider, and never need remote access or a gift card.

What could the caller do while connected to my PC?

Anything you could do. Callers working with fake alerts like Malware Defender 2009 typically show you Windows logs as "proof", install their own remote tool for later, and steer you to online banking or a gift card purchase. Some add a password to Windows or lock the PC if you refuse to pay.

Remove every remote access program you did not install yourself, check Settings > Accounts > Other users for new accounts, and change important passwords from a clean device. If you cannot be sure what was changed, a reset of Windows is the safe choice.

Did Malware Defender 2009 steal my information?

Not by itself, as far as reports show. Programs that display an unfamiliar process called wcenter.exe in Task Manager are built to scare people into paying or calling; they rarely take data on their own.

The risk comes from what you did in response: typing card details into the program, or letting a caller connect to your PC. If you did neither, uninstalling the program is enough. If you did either, treat that information as exposed:

  • block the card
  • change passwords from another device
  • remove any remote-access tool that was installed

Do I need to reinstall Windows to get rid of Malware Defender 2009?

Usually not. A thorough clean-up is enough when the offline scan finds nothing afterwards and you do not see an unfamiliar process called wcenter.exe in Task Manager again. A reset is the safer choice if an attacker had remote control, if security tools were switched off, or if detections come back after every clean-up.

Windows 11 can reset itself without a USB stick under Settings > System > Recovery > Reset this PC. Copy documents and photos out first and scan the copies. A reset does not change passwords or undo stolen data, so the account steps still apply.

Is my card safe after buying Malware Defender 2009?

Treat it as exposed. The order page belongs to the seller of Malware Defender 2009, and you cannot know how the number is stored or shared. Ask your bank for a replacement card, which is usually free, and dispute the original charge as a misrepresented product.

Until the new card arrives, check your account daily for small or foreign transactions. If the bank offers alerts for every card payment, turn them on. Keep the receipt and screenshots, because they support the dispute.

Will Fortect remove Malware Defender 2009?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Malware Defender 2009, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove "Unauthorized Access Detected" virus

“Unauthorised Access Detected” scam strikes again “Unauthorised Access Detected” virus operates as a tech support scam which scares users with fake claims that their computers might have been disabledRogue Anti-SpywareHigh riskJulie Splinters ·

Remove Systemcare-antivirus.org

Systemcare-antivirus.org is a fraudulent website that should always be avoided. You may run into it with and even without your knowledge because it has been promoted with a help ofRogue Anti-SpywareHigh riskUgnius Kiguolis ·

Remove Windows Antivirus 2008

Windows Antivirus 2008 – a fake security tool showing false-positive scan results Windows Antivirus 2008 is a corrupt security tool that is promoted as useful anti-spyware software. It manipulates the nameRogue Anti-SpywareMedium riskLucia Danes ·

Remove Personal Security

Personal Security - a fake anti-malware tool that will scam you out of your money Personal Security is a misleading anti-spyware application that displays fake security alerts/pop-ups and reports falseRogue Anti-SpywareMedium riskUgnius Kiguolis ·

Questions and experiences: Malware Defender 2009

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year