Hijack.SecurityRun

ThreatDown is now the name of the Malwarebytes line of business products. References to Malwarebytes below reflect the amazing technology used to first identify the threat.

Short bio

Hijack.SecurityRun is Malwarebytes’ detection name for a Software Restriction Policy used against security software.

Type of infection

Hijack.SecurityRun is a detection-only rule that looks at the subkeys of the registry key: HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowssafer codeidentifiersPaths and flags a detection if it finds a rule to block security software from running. Hijack.SecurityRun can be an indicator for a more serious threat that has disabled certain security software.

Home remediation

Malwarebytes can detect and remove Hijack.SecurityRun without further user interaction.