Defender.exe aka 'Spyware Protection'

osaddictosaddict London, UK
edited December 2010 in Science & Tech
A colleague came up to me earlier today saying his PC had 'gone mental' sure enough his description wasn't far wrong... he'd visited a news website and it had loaded a virus on his machine which shut everything else down.

I logged in as myself (an Admin user) and could see defender.exe running under his account.

I killed this process and logged in as the user, everything looked to be ok.

Looking around the appdata/roaming folder I located defender.exe and deleted it.

A reboot and everything looked fine... this seemed far too simple so I dug around the registry a little bit and found

Current user\Windows\Run (or to that effect!) and found an entry for defender.exe and also found one for sdra64.exe I deleted both of these.

The PC seems fine now, and a KAspersky Scan seems to work fine.

I'm concerned this seems too simple a fix and not sure what else to do to 100% clarify that it's gone!

Was a nasty thing - popped up and killed every other process, was scanning the PC (really, it was scanning the CS3 directory - not many PCs have CS3 installed!), making up all sorts of junk.

Oh and the user does not have admin rights so nothing can be installed...

Any pointers?! -Sorry if the above is a little garbled, hopefully it makes sense...

Thanks in advance :)

Comments

  • ThraxThrax 🐌 Austin, TX Icrontian
    edited December 2010
    Common spyware. Run ComboFix and MBAM to make sure it's gone, follow up with HJT.
  • TushonTushon I'm scared, Coach Alexandria, VA Icrontian
    edited December 2010
    Spice it up with ccleaner's temp file and registry scan and you are done.
  • osaddictosaddict London, UK
    edited December 2010
    ComboFix, MBAM, HJT and CCleaner didn't seem to find any nasties from what I could see, so I guess it's fixed. Thanks for the help guys.
  • TushonTushon I'm scared, Coach Alexandria, VA Icrontian
    edited December 2010
    no problem
Sign In or Register to comment.