imiddleton25 Posted April 12, 2011 Posted April 12, 2011 Ok so done all the normal stuff booted to safe mode ran malwarebytes it find nothing at all. used these online instuctions and deleted the below but every time i reboot it still comes back •%Documents and Settings%\[user Name]\Desktop\Internet Protection 2011.lnk •%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011 •%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011\Internet Protection 2011.lnk •%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011\Uninstall Internet Protection 2011.lnk to make it worse its my mothers pc and she is 350 miles away so doing it remotely. any ideas welcome right now.
Steve21 Posted April 12, 2011 Posted April 12, 2011 (edited) •%Documents and Settings%\[user Name]\Desktop\Internet Protection 2011.lnk •%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011 •%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011\Internet Protection 2011.lnk •%Documents and Settings%\[user Name]\Start Menu\Programs\Internet Protection 2011\Uninstall Internet Protection 2011.lnk Is that all you deleted? Bearing in mind .lnk is just shortcuts. Malware bytes updated before scanning? Have you sorted the dll files, and registry keys it changes? Did you disable system restore before killing it? etc etc If not, I'll post some areas to check. 1) Stop any exes running from it (SmartIP2011.exe etc) 2) Regedit, and delete: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Smart Internet Protection 2011" HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no" HKEY_CLASSES_ROOT\SmartIP2011.DocHostUIHandler HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:25401" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "UID" = "7" HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0User Agent\Post Platform "88780570603" 3) Unhook services regsrv32 /u mozcrt19.dll regsrv32 /u sqlite3.dll 4) Delete %UserProfile%\Application Data\Smart Internet Protection 2011\ %UserProfile%\Application Data\Personal Internet Security 2011\cookies.sqlite %UserProfile%\Application Data\Personal Internet Security 2011\Instructions.ini c:\Documents and Settings\All Users\Application Data\e659\ c:\Documents and Settings\All Users\Application Data\e659\7377.mof c:\Documents and Settings\All Users\Application Data\e659\80e9877130a15854a99bf6dd8d368239.ocx c:\Documents and Settings\All Users\Application Data\e659\mozcrt19.dll c:\Documents and Settings\All Users\Application Data\e659\SmartIP2011.exe c:\Documents and Settings\All Users\Application Data\e659\PIS.ico c:\Documents and Settings\All Users\Application Data\e659\sqlite3.dll c:\Documents and Settings\All Users\Application Data\e659\unins000.dat c:\Documents and Settings\All Users\Application Data\e659\PISSys\ c:\Documents and Settings\All Users\Application Data\e659\Quarantine Items\ c:\Documents and Settings\All Users\Application Data\PIKKS\ c:\Documents and Settings\All Users\Application Data\PIKKS\PIQBS.cfg %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Internet Protection 2011.lnk %UserProfile%\Application Data\Smart Internet Protection 2011\ %UserProfile%\Application Data\Smart Internet Protection 2011\cookies.sqlite %UserProfile%\Desktop\Smart Internet Protection 2011.lnk %UserProfile%\Start Menu\Smart Internet Protection 2011.lnk %UserProfile%\Start Menu\Programs\Smart Internet Protection 2011.lnk Steve Edited April 12, 2011 by Steve21
dhicks Posted April 13, 2011 Posted April 13, 2011 (edited) %Documents and Settings%\[user Name] I removed a similar fake-antivirus application from a laptop a week or so ago - the actual thing being run was simply a randomly-named executable in the user's Documents and Settings folder, I just removed that and rebooted and that seemed to fix it. Check Documents and Settings for executables, probably via a boot CD (I used SystemRescueCD) - the application might be able to hide references to its own executable file. Edited April 13, 2011 by dhicks
eddyc Posted April 13, 2011 Posted April 13, 2011 I find that if you use a good machine to download combofix and stick it on a memory stick then boot the bad machine into safe mode it generally works well at removing fake viruses - it sounds simular to one that I have removed this weekend. Ed
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now