Showing posts with label fake antivirus. Show all posts
Showing posts with label fake antivirus. Show all posts

Saturday, July 12, 2014

How to remove Smart Guard Protection Part 2

How to remove Smart Guard Protection Part 1




Here is another way to disable and remove this fake antivirus

Copy Task Manager to Windows folder and rename it as CMD.exe


Launch the renamed file and terminate the fake AV process.  Smart Guard Protection will not block CMD.exe.  You can also copy File Assassin or any program to the Windows folder and rename it to trick Smart Guard Protection.


Now that the fake AV is no longer running in the background, we can start deleting the files and registry entry to prevent it from starting with Windows again

On your Desktop right click on Smart Guard Protection icon and click Properties.  Click the Find Target... button.  This will launch explorer to the location of the fake AV file.  Delete the entire folder.


Launch regedit and navigate to

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

Delete the value AS2014 


Alternative:  If you have CCleaner, launch it and go to Tools | Startup and delete AS2014


Scan your computer with MBAM to reverse the changes made by Smart Guard Protection.  Here is the result of the scan.

Registry Values: 1
Hijack.SecurityCenter, HKU\S-1-5-21-746137067-1078145449-682003330-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\CONTROL PANEL\DON'T LOAD|wscui.cpl, No, Quarantined, [e5be7d215d1e4ee8d3e93b1110f303fd]

Registry Data: 3
PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|AntiVirusDisableNotify, 1, Good: (0), Bad: (1),Replaced,[5350ccd2b1ca8fa79b556c2b8d7713ed]
PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|FirewallDisableNotify, 1, Good: (0), Bad: (1),Replaced,[6c375648b5c6d462f1003661e71d04fc]
PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|UpdatesDisableNotify, 1, Good: (0), Bad: (1),Replaced,[a8fb1886037811256f836433aa5ac63a]


Wednesday, July 9, 2014

How to remove Smart Guard Protection

Smart Guard Protect (Fake Antivirus)

Performing a bogus scan.


After the scan it shows the threats found.


If you click Repair All, it will show this screen.


After clicking Buy Full Edition you get this.  At this stage, don't get scared and never spend a dime on it.




While it is active and you want to launch for example taskman, you'll get this warning screen.  With the exception of explorer, mspaint and cmd anything else you run gives a warning.



Analysis

Values added

HKU\S-1-5-21-746137067-1078145449-682003330-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\AS2014: "C:\Documents and Settings\All Users\Application Data\d9ngVr33\d9ngVr33.exe"

Files Added

C:\Documents and Settings\All Users\Application Data\d9ngVr33\d9ngVr33.exe
C:\Documents and Settings\All Users\Application Data\d9ngVr33\d9ngVr33.exe.manifest
C:\Documents and Settings\All Users\Application Data\d9ngVr33\d9ngVr33.ico
C:\Documents and Settings\All Users\Application Data\d9ngVr33\d9ngVr33aQDsaggg.in
C:\Documents and Settings\All Users\Application Data\d9ngVr33\d9ngVr33aQDsaggg.lg


Folder added

C:\Documents and Settings\All Users\Application Data\d9ngVr33


Virustotal Scan
 

Removal 

Since CMD is not disabled we will be using it kill the Fake AV's process.  Launch CMD and run the following commands

TASKLIST 






Take note of the RandomName.exe on the list 

TASKKILL /F /IM snUa339g.exe





We can use explorer and regedit to remove Smart Guard Protection

Launch regedit.  Navigate to 

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

and delete the entry.  Take note of the path of snUa339g.exe


Launch explorer and navigate to the path of snUa339g.exe and delete the folder.





Run an updated MBAM to finish the cleaning process


Note:  This is just a quick analysis.  I'll update in case there are other registry keys that I've missed.