Registry Modification Makes Windows Defender an ‘Adware Killer’
Microsoft is offering a new opportunity for enterprise users to block potentially unwanted applications or PUAs. However, through a simple registry change, the adware blocker can also be unlocked on consumer systems in Windows Defender.
Heise.de discovered this following an announcement on Microsoft’s Technet blog about the pua blocker. The pua protection is only accessible to enterprise customers, according to the Technet blog, but now appears to be used by the common man as well. The option is included in all Windows Defender versions from Windows 8.
Microsoft added the functionality to System Center Endpoint Protection and Forefront Endpoint Protection. However, the new opt-in function will also work with Windows Defender after registry changes. The feature would block installation of unwanted software bundles containing adware, toolbars and other unwanted programs.
To enable the feature in Defender, “HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindows DefenderMpEngine” must have the DWORD “MpEnablePus” set to “1”. Users can do this by using notepad to create a file with the extension .reg containing the content below. After executing the .reg file, the adjustment has been made in Windows Defender.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindows DefenderMpEngine]
“MpEnablePus”=dword:00000001