FYI - There's a nasty new rogue going around called Smart Defender Pro. We have updated our definitions to detect and remove all traces of this rogue.

Download SUPERAntiSpyware from www.superantispyware.com.

Run the install.exe file.

Select “Scan Your Computer.”

Select “Perform Complete Scan.”

Follow the prompts to quarantine/remove the infected files.

Make sure to reboot following the scan.

If you are currently running a copy of SUPERAntiSpyware Professional, update the latest version/definition before running a scan and completing the quarantine/removal process.

Dani AI

Generated

Thanks for the heads-up, . Smart Defender Pro is a classic fake AV: it throws scare popups, sets a system proxy to block security sites, and often respawns via Run keys or scheduled tasks. If it blocks installs or terminates your scan, try this quick playbook first, then run your cleaner again.

  • Start in Safe Mode to limit what loads at boot. If F8 is unavailable, use Windows recovery options to reach Safe Mode ().
  • Stop the rogue process: use Process Explorer to find and kill suspicious apps launching from AppData/Temp, or run RKill to terminate malicious processes (do not reboot until after your cleaner runs).
  • If the rogue blocks installers, rename the installer to iexplore.exe or explorer.exe and launch it.
  • Clear potential network hijacks (reboot after these):
netsh winhttp reset proxy
netsh winsock reset
ipconfig /flushdns
  • Remove persistence: check Task Scheduler and the HKCU/HKLM ...\Run keys; delete entries pointing to random-named EXEs in user profile paths. Autoruns makes this quick (hide Microsoft entries first).
  • Check and reset the HOSTS file if it was modified (). Note: if you are on a corporate network that requires a proxy, reapply the legitimate proxy afterward.

If the malware still interferes, run a boot-time scanner such as a . Never pay or enter card details into the rogue. After cleanup, patch Windows and browsers, and create a fresh restore point. And +1 to ’s nudge on attribution; when vendor reps like share file paths or registry keys their tools remove, it helps helpers verify nothing is left behind.

Recommended Answers

All 2 Replies

We have updated our definitions to detect and remove all traces of this rogue.

Thanks for the info.

we are

who exactly?

Thanks for the info. who exactly?

I'm so sorry, I forgot to signature my post! This is Mike Duncan of SUPERAntiSpyware

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.