Smart Protector

Smart Protector is a bogus security application that introduces self as a lightweight tool that provides PC’s ultimate safety in one single click. This one is not the legitimate Smart Protector Pro that comes from SmartSoft, a legitimate software provider. To better distinguish differences between the original and fake ones, we include the exact image of the fake Smart Protector below including the website where it can be downloaded.

Also, the rogue Smart Protector is employing aggressive propagation method by installing the program on computers without user’s interference. This was made possible by another Trojan infection. Additionally, malicious website called “Spyware Scanner Online: Scan in Progress…” will drop this malware on computer and execute the installation on its own using a drive-by-download mechanism. After successful installation, it will pop-up its own virus scanner and begins a simulated scanning. Next, the rogue software intends to deceive victims by issuing fake detection results. It advises to register the program before it can proceed with the virus removal.

On this situation, the only thing that must get rid out from the system is no other than Smart Protector. Use a legitimate anti-malware product to eliminate the presence of this potentially unwanted application.

Screen Shot Images:

fake-smart-protector

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

[expand title="View More" swaptitle="Hide This"]

Characteristics (Analysis)
This malware can configure itself to run every time Windows starts by adding the following registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “smrtprt”

Malware Behavior
The rogue security application will display excessive pop-up alerts and advertisements as promotional tactics.

Smart Protector can modify Internet browser settings and redirect web searches to the following addresses:

  • scan.topsecuritycenter.cn
  • scan.hirovecul . cn
  • scan.levasycu . cn
  • scan.join2bestsecuritynow . com
  • towersecuritypcshield . com
  • smartprotectorpro . com
  • gosmrtprt . com
  • dlsmrtprt . com

The above web sites may scan the computer and provides the following result:

smart-protector-website

Added Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "smrtprt"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "SysiNet" 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Smart Protector
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}\S
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "smartprotector"
HKEY_CLASSES_ROOT\CLSID\{0C955DE5-2D3C-45EA-A879-3113C888BAB6}
Associated Files and Folders:
%UserProfile%\Desktop\Smart Protector.lnk
%UserProfile%\Start Menu\Programs\Smart Protector
%UserProfile%\Start Menu\Programs\Smart Protector\Smart Protector.lnk
%UserProfile%\Start Menu\Programs\Smart Protector\Uninstall.lnk 
C:\Documents and Settings\All Users\Microsoft AData
C:\Documents and Settings\All Users\Microsoft AData\catmon.exe
C:\Documents and Settings\All Users\Microsoft AData\setup.exe
C:\Documents and Settings\All Users\Microsoft AData\sysinet.dll
C:\Documents and Settings\All Users\Microsoft AData\t.sid
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\internet.dll
C:\Program Files\Smart Protector
C:\Program Files\Smart Protector\q
C:\Program Files\Smart Protector\config.scf
C:\Program Files\Smart Protector\mmbase.sdb
C:\Program Files\Smart Protector\q.sdb
C:\Program Files\Smart Protector\queue.sdb
C:\Program Files\Smart Protector\smrtprt.exe
C:\Program Files\Smart Protector\uninstalls.exe
C:\Program Files\Smart Protector\vvbase.sdb
C:\WINDOWS\certsystem.exe
C:\WINDOWS\microsoftdef.dll
C:\WINDOWS\regred.exe
C:\WINDOWS\securits.com
C:\WINDOWS\spoov.exe
C:\WINDOWS\usexplorer.exe
C:\WINDOWS\system32\winsc.exe

How to Remove Smart Protector

1. Temporarily Disable System Restore (Windows Me/XP). [how to]
2. Open your antivirus application and update the virus definition file. This method ensures that your antivirus program can detect even newer variants of Smart Protector

3. Start Windows in Safe Mode with Networking.
- From a power-off state, turn on the computer and press F8 on your keyboard repeatedly.
- Your computer will display Windows Advanced Boot Options menu. Please select Safe Mode with Networking.
- The system will now boot Windows and loads only necessary drivers and files.

4. Open your antivirus program and run a full system scan. After the scan, delete all infected items. If unable, better place them in quarantine. Once the scan is complete, please proceed with the next step.

Online Virus Scanner:

Another way to remove Smart Protector without the need to install additional antivirus application is to perform a thorough scan with free online virus scanner that can be found on websites of legitimate anti-virus and security provider.

5. Go to Online Virus Scanner list and run a virus scan. This may require plug-ins, add-on or Activex object, please install if you want to proceed with scan.
6. After completing the necessary download, your system is now ready for online virus scanning.
7. Select an option in which you can thoroughly scan the computer to make sure that it will find and delete entirely all infections not detected on previous scan.
8. Remove or delete all detected items.
9. When scanning is finished you may now restart the computer in normal mode.

Automatic Removal of Smart Protector

In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.