Solved

How can I remove Malware: Smart Defender Pro?

Posted on 2009-07-07
7
1,079 Views
Last Modified: 2013-11-22
I have a user who has managed to snag a copy of this Smart Defender Pro malware.  Pop-ups every few seconds, bogus "Your browser is secure" screens, false threat warnings, the works.  The only files I see listed on the system are in her profile under Application Data.  I need to know if anyone has idea what reg keys and or files to look for so I can get rid of this thing.

The only info I have found on the web are sites advertising removal tools (always shady).  The app is an exact replica of "Virus Remover Pro."  After all the bogus literature I have come across, I would rather get some assistance via EE (with all our abundant knowledge!)

I will re-image the machine in the end but I wanted to see if anyone has some additional insight.
0
Comment
Question by:Mahoney-84
7 Comments
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 24795813
Have you tried MalwareBytes - www.malwarebytes.org - great free tool and finds all manner of spyware, malware and other nasties.
0
 
LVL 27

Assisted Solution

by:David-Howard
David-Howard earned 50 total points
ID: 24796025
As stated, Malwarebytes should remove this threat.
http://www.bleepingcomputer.com/virus-removal/remove-smart-defender-pro
If however you are unable to remove it in normal mode, you may need to boot into Safe Mode (F8 at startup) and run the scan in that mode.
You may also want to run HiJackThis. Once you run the utility look for and remove the following entry if present.
O4 - HKCU\..\Run: [Smart Defender PRO] %UserProfile%\\Application Data\Smart Defender PRO\smrtdefp.exe
Download HiJackThis from:
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
Once you run the utility save the log file.
You can post it for free analysis here or at
www.hijackthis.de
You are primarily looking for items marked with red X's.
You can get a brief overview of Hijackthis here:
http://www.bleepingcomputer.com/tutorials/tutorial42.html
0
 
LVL 23

Expert Comment

by:Admin3k
ID: 24801997
with rogue programs like this one , if Malwarebytes did not do the trick as advised above, you can jump rightaway to using Combofix
also please show us the logs form Hijack this, Combofix & MBAM

0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 2

Expert Comment

by:moatist
ID: 24805642
I would try  Spybot - Search & Destroy which you can download from:
http://www.safer-networking.org/en/download/index.html

Moatist
0
 
LVL 3

Accepted Solution

by:
Mahoney-84 earned 0 total points
ID: 24805820
The log is attached.
But this is after the fact - Ran a full scan in Norton (in SAFEMODE) and removed the executable from %UserProfile%\\Application Data\Smart Defender PRO\smrtdefp.exe prior to running hijackthis.  

I can log in as the user and the SmartDefender no longer appears in the tray and the popups have ceased.  I don't see any background processes that should not be there.

Hijackthislog.txt
0
 
LVL 23

Assisted Solution

by:Admin3k
Admin3k earned 75 total points
ID: 24806047
Nice work with the removal efforts , try to fix  those entries using hijack this to get rid of some leftovers
O4 - HKUSS-1-5-21-842925246-1659004503-1417001333-9722..Run: [Smart Defender PRO] C:Documents and Settingsocasis\Application DataSmart Defender PROsmrtdefp.exe (User 'ocasis')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

it is still a good idea to run a scan using MBAM.
finaly take a look here for the manual removal steps
http://windowsprotection.net/how-to-remove-smart-defender-pro-smartdefender-pro-removal-guide/



0
 
LVL 3

Author Comment

by:Mahoney-84
ID: 24858701
The hijackthis logs are very helpful - Thank you for suggesting the very handy utility
Prefer to try and remove threats like this manually without scan utilities or blow the machine away and start over.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
bypass UAC - always notifiy 4 55
Virus softwares 11 65
dma locker 3 query 7 109
Restoring files from Windows Server Backup 7 71
The term "Bad USB" is a buzz word that is usually used when talking about attacks on computer systems that involve USB devices. In this article, I will show what possibilities modern windows systems (win8.x and win10) offer to fight these attacks wi…
Transferring data across the virtual world became simpler but protecting it is becoming a real security challenge.  How to approach cyber security  in today's business world!
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now