Jump to content

Recommended Posts

Posted

Ok so done all the normal stuff

 

booted to safe mode

ran malwarebytes it find nothing at all.

used these online instuctions and deleted the below but every time i reboot it still comes back

 

•%Documents and Settings%\[user Name]\Desktop\Internet Protection 2011.lnk

•%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011

•%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011\Internet Protection 2011.lnk

•%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011\Uninstall Internet Protection 2011.lnk

 

to make it worse its my mothers pc and she is 350 miles away so doing it remotely.

 

any ideas welcome right now.

Posted (edited)
•%Documents and Settings%\[user Name]\Desktop\Internet Protection 2011.lnk

•%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011

•%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011\Internet Protection 2011.lnk

•%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011\Uninstall Internet Protection 2011.lnk

 

 

Is that all you deleted? Bearing in mind .lnk is just shortcuts. Malware bytes updated before scanning? Have you sorted the dll files, and registry keys it changes? Did you disable system restore before killing it? etc etc If not, I'll post some areas to check.

 

1) Stop any exes running from it (SmartIP2011.exe etc)

 

2) Regedit, and delete:

 

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Smart Internet Protection 2011"

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"

HKEY_CLASSES_ROOT\SmartIP2011.DocHostUIHandler

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:25401"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "UID" = "7"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0User Agent\Post Platform "88780570603"

 

3) Unhook services

regsrv32 /u mozcrt19.dll

regsrv32 /u sqlite3.dll

 

4) Delete

%UserProfile%\Application Data\Smart Internet Protection 2011\

%UserProfile%\Application Data\Personal Internet Security 2011\cookies.sqlite

%UserProfile%\Application Data\Personal Internet Security 2011\Instructions.ini

c:\Documents and Settings\All Users\Application Data\e659\

c:\Documents and Settings\All Users\Application Data\e659\7377.mof

c:\Documents and Settings\All Users\Application Data\e659\80e9877130a15854a99bf6dd8d368239.ocx

c:\Documents and Settings\All Users\Application Data\e659\mozcrt19.dll

c:\Documents and Settings\All Users\Application Data\e659\SmartIP2011.exe

c:\Documents and Settings\All Users\Application Data\e659\PIS.ico

c:\Documents and Settings\All Users\Application Data\e659\sqlite3.dll

c:\Documents and Settings\All Users\Application Data\e659\unins000.dat

c:\Documents and Settings\All Users\Application Data\e659\PISSys\

c:\Documents and Settings\All Users\Application Data\e659\Quarantine Items\

c:\Documents and Settings\All Users\Application Data\PIKKS\

c:\Documents and Settings\All Users\Application Data\PIKKS\PIQBS.cfg

%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Internet Protection 2011.lnk

%UserProfile%\Application Data\Smart Internet Protection 2011\

%UserProfile%\Application Data\Smart Internet Protection 2011\cookies.sqlite

%UserProfile%\Desktop\Smart Internet Protection 2011.lnk

%UserProfile%\Start Menu\Smart Internet Protection 2011.lnk

%UserProfile%\Start Menu\Programs\Smart Internet Protection 2011.lnk

 

Steve

Edited by Steve21
Posted (edited)
%Documents and Settings%\[user Name]

 

I removed a similar fake-antivirus application from a laptop a week or so ago - the actual thing being run was simply a randomly-named executable in the user's Documents and Settings folder, I just removed that and rebooted and that seemed to fix it. Check Documents and Settings for executables, probably via a boot CD (I used SystemRescueCD) - the application might be able to hide references to its own executable file.

Edited by dhicks
Posted

I find that if you use a good machine to download combofix and stick it on a memory stick then boot the bad machine into safe mode it generally works well at removing fake viruses - it sounds simular to one that I have removed this weekend.

 

Ed

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...