Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 23 January 2012

Remove "Smart Protection 2012" (Uninstall Guide)

Posted on 12:51 by Unknown
Smart Protection 2012 is a fake anti-virus program that displays misleading security warnings and generates false positive reports of viruses and malware to scare you. Fake AVs are designed to convince you to purchase the full version of said software in order to remove the numerous problems and infections the scan has discovered. The truth be told, it doesn't actually scan your computer and even if you purchase this rogue antivirus program it won't fix anything. It just runs a fake 'scan' of your computer in front of your eyes, telling you that all sorts of spyware, viruses and trojans are installed. Dozens of new variants of Fake AV appeared in 2011 and the malware ecosystem isn't going to change any time soon. Besides, rougeware authors realize that internet users became smarter in distinguishing the name of fake and real antivirus programs, so they will definitely come up with new seemingly legit names. If you've just been snatched by Smart Protection 2012 or similar scareware, DO NOT follow instructions on screen and do not purchase it. To remove Smart Protection 2012 from your PC, please follow the removal instructions below.



OK, so let's take a closer look at the Smart Protection 2012. It has a rather unique GUI and it seems that cyber crooks are pretty happy with malware conversation rates if they brand the same malcode under multiple names. Apparently, it works. Once installed, Smart Protection 2012 will pretend to scan your computer for malicious software, spyware, Trojan horses, etc. Then, it will bombard you with false alarms.
Warning!
Application cannot be executed. The file notepad.exe is infected.
Please activate your antivirus software.
Smart Protection 2012 Warning
Your computer is still infected with dangerous viruses. Activate antivirus protection to prevent data loss and avoid theft of your credit card details.
Click here to activate protection.


Finally, it will take you to a fake payment page where you cant purchase this undoubtedly illegal software.



What is more, the rogue AV will modify Windows registry, alter system files, modify Windows Hosts file, disable certain system services and block legitimate anti-virus software. These changes can be fixed or restored quite easily, however the problem is that Smart Protection 2012 may come bundled with rootkits. And we are pretty sure that most of you are not comfortable with manually removing rootkits. Thankfully, you've got the removal instructions to help to remove Smart Protection 2012 and associated malware from your computer. If you need extra help removing this virus or you've found undetected hazards, please post a comment. Good luck and be safe online!


Quick Smart Protection 2012 removal guide:

1. Open Smart Protection 2012. Click the "Registration" button. Enter the following debugged registration key and click "Activate" to register this rogue antivirus program. Don't worry, this is completely legal.

AA39754E-715219CE



Once this is done, you are free to install anti-malware software and remove Smart Protection 2012 from your computer properly.

2. Next, download TDSSKiller. This malware usually (but not always) comes bundled with TDSS rootkit. Removing this rootkit from your computer is very important (if exists). Run TDSSKiller and remove the rootkit.



3. Then download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this virus from your computer.

4. And finally, to reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.


Smart Protection 2012 removal instructions in Safe Mode with Networking:

1. Please reboot your computer is "Safe Mode with Networking". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Networking" and press Enter key.


NOTE: Login as the same user you were previously logged in with in the normal Windows mode.

2. Download TDSSKiller. Run TDSSKiller and remove the rootkit (if exists).



3. Then download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this virus from your computer.

4. And finally, to reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.


Alternate Smart Protection 2012 removal instructions (manual removal):

Make sure that you can see hidden and operating system protected files in Windows. For more in formation, please read Show Hidden Files and Folders in Windows.

Under the Hidden files and folders section, click Show hidden files and folders, and remove the checkmarks from the checkboxes labeled:
  • Hide extensions for know file types
  • Hide protected operating system files
Click OK to save the changes.


1. Find the malicious Smart Protection 2012 file.

On computers running Windows XP, malware hides in:
C:\Documents and Settings\All Users\Application Data\

On computers running Windows Vista/7, malware hides in:
C:\ProgramData\

2. Look for malicious file in said directories depending on the Windows version you have.

Example Windows XP:
C:\Documents and Settings\All Users\Application Data\529C536F00018A6B00013FF8.exe

Example Windows Vista/7:
C:\ProgramData\529C536F00018A6B00013FF8.exe

Basically, there will be a malicious file named with a series of numbers or letters.



Rename 529C536F00018A6B00013FF8 to virus (do not delete it!).  Here's an example:



3. Restart your computer. After a reboot, Smart Protection 2012 won't start and you will be able to run anti-malware software.

4. Open Internet Explorer. Download TDSSKiller. Run TDSSKiller and remove the rootkit (if exists).



5. Download recommended anti-malware software (Spyware Doctor) and run a full system scan to remove this virus from your computer.

6. And finally, to reset the Hosts file back to the default automatically, download and run Fix it and follow the steps in the Fix it wizard.


Associated Smart Protection 2012 files and registry values:

Files:

Windows XP:
  • C:\Documents and Settings\All Users\Application Data\[SET OF RANDOM CHARACTERS].exe
Windows Vista/7:
  • C:\ProgramData\[SET OF RANDOM CHARACTERS].exe
Registry values:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce "[SET OF RANDOM CHARACTERS]"
Share this information with other people:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Rogue programs | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Antivired.com and other Antivirus Monitor Related Domains
    Just a short note about several malicious domains related to the Antivirus Monitor fraud. This rogue anti-virus program reports non-existent...
  • How to Remove Easy Scan (Uninstall Guide)
    Easy Scan is a rogue application that pretends to be legitimate software, in this case registry cleaner and hard drive optimization program...
  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Antispyis.com and other Antivirus Scan related domains
    New additions of misleading websites which promote a rogue security application called Antivirus Scan. antispyis.com afantispy.net softwaree...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Facebook Security and Privacy Best Practices
    Facebook is the most popular social networking site. Nearly all of my friends have Facebook accounts. They log on to Facebook at least a cou...
  • Smartphone Security: Using Your Mobile Phone Safely
    Smartphone is like a little copy of your computer with lots of personal information: photos, text messages, access to e-mail account and oth...
  • Fake avast! Antivirus: Avast-antivirus-francais.exe
    Cyber-criminals are attempting to benefit from unexperienced web users who are looking for anti-virus software. We found a couple of mislead...
  • Show Hidden Files and Folders in Windows
    By default Microsoft Windows hides important files from being seen with Windows Explorer in order to protect these files from being modified...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ►  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ▼  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ▼  January (20)
      • Youtube PREMIUM Player, Free Facebook Credits and ...
      • How to Remove Searchqu (Uninstall Guide)
      • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
      • Bitdefender Internet Security 2012 Giveaway! Hurry...
      • Antivirus Smart Protection and Malware Protection ...
      • Remove "Smart Protection 2012" (Uninstall Guide)
      • Remove "Internet Security 2012" Malware (Uninstall...
      • Temp:winupd.exe (Uninstall Guide)
      • Search.conduit.com (Uninstall Guide) - How To Remo...
      • PUP.CNET.Adware.Bundle (Uninstall Guide)
      • Remove Internet Security Guard (Uninstall Guide)
      • Remove Guardia di Finanza Ransomware (Uninstall Gu...
      • Remove Strathclyde Police Ransomware (Uninstall Gu...
      • Malicious Youtube Extension, YXH-youtube_player.xp...
      • Remove Audio Ads Virus (Uninstall Guide)
      • Msdcsc.exe Process Information
      • Remove EoRezo Adware/PUP (Uninstall Guide)
      • Remove BasicScan (Uninstall Guide)
      • Be A Guest Writer
      • Remove Tidserv Activity 2 (Uninstall Guide)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile