+ Reply to Thread
Results 1 to 1 of 1
  1. #1
    putercer
    Guest

    Smart Virus Eliminator

    Smart Virus Eliminator is a rogue anti-spyware program from the same family as Windows Protection Suite. Smart Virus Eliminator uses fake scan results and false security alerts as a tactic to make you think you are infected. It does this because the developers feel if they can convince you that your computer is infected then you will be more likely to purchase it. In reality, though, when you purchase Smart Virus Eliminator it does not provide any protection at all. Instead it just scams you out of your money. If you have paid for the this program already then I suggest you contact your credit card company and dispute the charges.

    When Smart Virus Eliminator is installed it will be configured to start automatically when you login to Windows. It will also create numerous, but harmless, files on your computer that will be detected as malware when the program scans your computer. When the program performs a scan it will detect the files it had created during its installation, but not allow you to remove them until you purchase it. Essentially it is trying to get you to pay for a program so that it can remove the harmless files it created in the first place.

    While the program is running you will also see a constant barrage of fake security alerts and warnings on your computer. These warnings will state that your computer is infected or that someone is trying to hack your computer and then suggest you purchase Smart Virus Eliminator to protect yourself. These alerts, like the fake infections, are just another attempt of the program to try and convince you that you are infected. It goes without saying that you should ignore anything this program reports to you.

    If you are infected with this rogue, then please do not purchase it. Instead use the removal guide below to remove this program and related malware for free.



    Threat Classification:

    Information on Rogue Programs & Scareware



    Advanced information:

    View Smart Virus Eliminator files.
    View Smart Virus Eliminator Registry Information.

    Symptoms that may be in a HijackThis Log:

    Note: The name of the files and directory for this rogue are random.

    O1 - Hosts: 74.125.45.100 4-open-davinci.com
    O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
    O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
    O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
    O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
    O1 - Hosts: 74.125.45.100 secure-plus-payments.com
    O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
    O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
    O1 - Hosts: 74.125.45.100 www.getavplusnow.com
    O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
    O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
    O1 - Hosts: 64.86.17.32 google.ae
    O1 - Hosts: 64.86.17.32 google.as
    O1 - Hosts: 64.86.17.32 google.at
    O1 - Hosts: 64.86.17.32 google.az
    O1 - Hosts: 64.86.17.32 google.ba
    O1 - Hosts: 64.86.17.32 google.be
    O1 - Hosts: 64.86.17.32 google.bg
    O1 - Hosts: 64.86.17.32 google.bs
    O1 - Hosts: 64.86.17.32 google.ca
    O1 - Hosts: 64.86.17.32 google.cd
    O1 - Hosts: 64.86.17.32 google.com.gh
    O1 - Hosts: 64.86.17.32 google.com.hk
    O1 - Hosts: 64.86.17.32 google.com.jm
    O1 - Hosts: 64.86.17.32 google.com.mx
    O1 - Hosts: 64.86.17.32 google.com.my
    O1 - Hosts: 64.86.17.32 google.com.na
    O1 - Hosts: 64.86.17.32 google.com.nf
    O1 - Hosts: 64.86.17.32 google.com.ng
    O1 - Hosts: 64.86.17.32 google.ch
    O1 - Hosts: 64.86.17.32 google.com.np
    O1 - Hosts: 64.86.17.32 google.com.pr
    O1 - Hosts: 64.86.17.32 google.com.qa
    O1 - Hosts: 64.86.17.32 google.com.sg
    O1 - Hosts: 64.86.17.32 google.com.tj
    O1 - Hosts: 64.86.17.32 google.com.tw
    O1 - Hosts: 64.86.17.32 google.dj
    O1 - Hosts: 64.86.17.32 google.de
    O1 - Hosts: 64.86.17.32 google.dk
    O1 - Hosts: 64.86.17.32 google.dm
    O1 - Hosts: 64.86.17.32 google.ee
    O1 - Hosts: 64.86.17.32 google.fi
    O1 - Hosts: 64.86.17.32 google.fm
    O1 - Hosts: 64.86.17.32 google.fr
    O1 - Hosts: 64.86.17.32 google.ge
    O1 - Hosts: 64.86.17.32 google.gg
    O1 - Hosts: 64.86.17.32 google.gm
    O1 - Hosts: 64.86.17.32 google.gr
    O1 - Hosts: 64.86.17.32 google.ht
    O1 - Hosts: 64.86.17.32 google.ie
    O1 - Hosts: 64.86.17.32 google.im
    O1 - Hosts: 64.86.17.32 google.in
    O1 - Hosts: 64.86.17.32 google.it
    O1 - Hosts: 64.86.17.32 google.ki
    O1 - Hosts: 64.86.17.32 google.la
    O1 - Hosts: 64.86.17.32 google.li
    O1 - Hosts: 64.86.17.32 google.lv
    O1 - Hosts: 64.86.17.32 google.ma
    O1 - Hosts: 64.86.17.32 google.ms
    O1 - Hosts: 64.86.17.32 google.mu
    O1 - Hosts: 64.86.17.32 google.mw
    O1 - Hosts: 64.86.17.32 google.nl
    O1 - Hosts: 64.86.17.32 google.no
    O1 - Hosts: 64.86.17.32 google.nr
    O1 - Hosts: 64.86.17.32 google.nu
    O1 - Hosts: 64.86.17.32 google.pl
    O1 - Hosts: 64.86.17.32 google.pn
    O1 - Hosts: 64.86.17.32 google.pt
    O1 - Hosts: 64.86.17.32 google.ro
    O1 - Hosts: 64.86.17.32 google.ru
    O1 - Hosts: 64.86.17.32 google.rw
    O1 - Hosts: 64.86.17.32 google.sc
    O1 - Hosts: 64.86.17.32 google.se
    O1 - Hosts: 64.86.17.32 google.sh
    O1 - Hosts: 64.86.17.32 google.si
    O1 - Hosts: 64.86.17.32 google.sm
    O1 - Hosts: 64.86.17.32 google.sn
    O1 - Hosts: 64.86.17.32 google.st
    O1 - Hosts: 64.86.17.32 google.tl
    O1 - Hosts: 64.86.17.32 google.tm
    O1 - Hosts: 64.86.17.32 google.tt
    O1 - Hosts: 64.86.17.32 google.us
    O1 - Hosts: 64.86.17.32 google.vu
    O1 - Hosts: 64.86.17.32 google.ws
    O1 - Hosts: 64.86.17.32 google.co.ck
    O1 - Hosts: 64.86.17.32 google.co.id
    O1 - Hosts: 64.86.17.32 google.co.il
    O1 - Hosts: 64.86.17.32 google.co.in
    O1 - Hosts: 64.86.17.32 google.co.jp
    O1 - Hosts: 64.86.17.32 google.co.kr
    O1 - Hosts: 64.86.17.32 google.co.ls
    O1 - Hosts: 64.86.17.32 google.co.ma
    O1 - Hosts: 64.86.17.32 google.co.nz
    O1 - Hosts: 64.86.17.32 google.co.tz
    O1 - Hosts: 64.86.17.32 google.co.ug
    O1 - Hosts: 64.86.17.32 google.co.uk
    O1 - Hosts: 64.86.17.32 google.co.za
    O1 - Hosts: 64.86.17.32 google.co.zm
    O1 - Hosts: 64.86.17.32 google.com
    O1 - Hosts: 64.86.17.32 google.com.af
    O1 - Hosts: 64.86.17.32 google.com.ag
    O4 - HKCU\..\Run: [Smart Virus Eliminator] "C:\Documents and Settings\All Users\Application Data\61a60\SM83b.exe" /s /d

    Your computer should now be free of the Smart Virus Eliminator program. If your current anti-virus solution let this infection through, you may want to consider purchasing the PRO version of Malwarebytes' Anti-Malware to protect against these types of threats in the future.

    If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:

    Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help





    Associated Smart Virus Eliminator Files:

    Note: The name of the files and directory for this rogue are random.

    c:\Documents and Settings\All Users\Application Data\61a60
    c:\Documents and Settings\All Users\Application Data\61a60\SM83b.exe
    c:\Documents and Settings\All Users\Application Data\SMVESys
    c:\Documents and Settings\All Users\Application Data\SMVESys\smve.cfg
    %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Virus Eliminator.lnk
    %UserProfile%\Application Data\Smart Virus Eliminator
    %UserProfile%\Application Data\Smart Virus Eliminator\cookies.sqlite
    %UserProfile%\Desktop\Smart Virus Eliminator.lnk
    %UserProfile%\Local Settings\Temp\asp2009.exe
    %UserProfile%\Start Menu\Smart Virus Eliminator.lnk
    %UserProfile%\Start Menu\Programs\Smart Virus Eliminator.lnk
    c:\Program Files\Mozilla Firefox\searchplugins\search.xml

    File Location Notes:

    %UserProfile% refers to the current user's profile folder. By default, this is C:\Documents and Settings\ for Windows 2000/XP, C:\Users\ for Windows Vista/7, and c:\winnt\profiles\ for Windows NT.



    Associated Smart Virus Eliminator Windows Registry Information:

    HKEY_CLASSES_ROOT\asp2009.DocHostUIHandler
    HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
    HKEY_CURRENT_USER\Software\Classes\Software\Micros oft\Internet Explorer\SearchScopes "URL" = "http://search-gala.com/?&uid=8000&q={searchTerms}"
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PRS"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings\5.0\User Agent\Post Platform "969904308603"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run "Smart Virus Eliminator"


 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts