We help IT Professionals succeed at work.

How can I remove Malware: Smart Defender Pro?

1,107 Views
Last Modified: 2013-11-22
I have a user who has managed to snag a copy of this Smart Defender Pro malware.  Pop-ups every few seconds, bogus "Your browser is secure" screens, false threat warnings, the works.  The only files I see listed on the system are in her profile under Application Data.  I need to know if anyone has idea what reg keys and or files to look for so I can get rid of this thing.

The only info I have found on the web are sites advertising removal tools (always shady).  The app is an exact replica of "Virus Remover Pro."  After all the bogus literature I have come across, I would rather get some assistance via EE (with all our abundant knowledge!)

I will re-image the machine in the end but I wanted to see if anyone has some additional insight.
Comment
Watch Question

Alan HardistyCo-Owner
CERTIFIED EXPERT
Top Expert 2011

Commented:
Have you tried MalwareBytes - www.malwarebytes.org - great free tool and finds all manner of spyware, malware and other nasties.
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION
Mohamed OsamaSenior IT Consultant
CERTIFIED EXPERT

Commented:
with rogue programs like this one , if Malwarebytes did not do the trick as advised above, you can jump rightaway to using Combofix
also please show us the logs form Hijack this, Combofix & MBAM

Commented:
I would try  Spybot - Search & Destroy which you can download from:
http://www.safer-networking.org/en/download/index.html

Moatist
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION
Mohamed OsamaSenior IT Consultant
CERTIFIED EXPERT
Commented:
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION

Author

Commented:
The hijackthis logs are very helpful - Thank you for suggesting the very handy utility
Prefer to try and remove threats like this manually without scan utilities or blow the machine away and start over.
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.