Jump to content

Removal instructions for TechSmart

Recommended Posts

  • Staff
What is TechSmart?

The Malwarebytes research team has determined that TechSmart is adware. These adware applications display advertisements not originating from the sites you are browsing.

How do I know if my computer is affected by TechSmart?

You may see warning during install:


these Scheduled Tasks:


and these proxy settings:


How did TechSmart get on my computer?

Adware applications use different methods for distributing themselves. This particular one was bundled with other software.

How do I remove TechSmart?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Is there anything else I need to do to get rid of TechSmart?
  • No, Malwarebytes' Anti-Malware removes TechSmart completely.
  • This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the TechSmart adware. It would have warned you before the adware could install itself, giving you a chance to stop it before it became too late.



Technical details for experts

Possible signs in FRST logs:
 (The Privoxy team - www.privoxy.org) C:\Program Files (x86)\Techsmart Computer\privoxy.exe
 ProxyEnable: [{currentuserID}] => Proxy is enabled.
 ProxyServer: [{currentuserID}] =>
 R2 PrivoxyService; C:\Program Files (x86)\Techsmart Computer\privoxy.exe [371200 2016-04-26] (The Privoxy team - www.privoxy.org) [File not signed] <==== ATTENTION
 C:\Windows\System32\Tasks\Network Checker
 C:\Windows\System32\Tasks\Network Checker Logon
 C:\Windows\System32\Tasks\Techsmart Computer Service
 C:\Users\{username}\AppData\Roaming\Network Checker
 C:\Program Files (x86)\Techsmart Computer

Task: {5B06CF43-569E-4150-B1C8-1C98479F7E91} - System32\Tasks\Network Checker => C:\Users\{username}\AppData\Roaming\Network Checker\Network Checker.exe [2016-04-26] () <==== ATTENTION
Task: {702248C0-48B7-4E9F-AAE4-F1BBF4292ED1} - System32\Tasks\Techsmart Computer Service => C:\Program Files (x86)\Techsmart Computer\ittask.exe [2016-04-26] (East CH Soft) <==== ATTENTION
Task: {7FAA750D-C9C8-4B61-A2DF-E762AE4712F4} - System32\Tasks\Network Checker Logon => C:\Users\{username}\AppData\Roaming\Network Checker\Network Checker.exe [2016-04-26] ()
() C:\Program Files (x86)\Techsmart Computer\mgwz.dll
Alterations made by the installer:
File system details [View: All details] (Selection)
    Adds the folder C:\Program Files (x86)\Techsmart Computer
       Adds the file config.txt"="4/26/2016 8:41 AM, 411 bytes, A
       Adds the file default.action"="4/26/2016 8:41 AM, 21 bytes, A
       Adds the file default.filter"="4/26/2016 8:41 AM, 154 bytes, A
       Adds the file ittask.exe"="4/26/2016 8:41 AM, 963584 bytes, A
       Adds the file mgwz.dll"="4/26/2016 8:41 AM, 86528 bytes, A
       Adds the file privoxy.exe"="4/26/2016 8:41 AM, 371200 bytes, A
       Adds the file privoxy.log"="4/26/2016 8:41 AM, 0 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Network Checker
       Adds the file Network Checker.exe"="4/26/2016 8:41 AM, 817152 bytes, A
    In the existing folder C:\Windows\System32\Tasks
       Adds the file Network Checker"="4/26/2016 8:41 AM, 3660 bytes, A
       Adds the file Network Checker Logon"="4/26/2016 8:41 AM, 3322 bytes, A
       Adds the file Techsmart Computer Service"="4/26/2016 8:41 AM, 3292 bytes, A

Registry details [View: All details] (Selection)
       "Channel"="REG_SZ", "UN"
       "DisplayName"="REG_SZ", "Privoxy (PrivoxyService)"
       "ErrorControl"="REG_DWORD", 1
       "ImagePath"="REG_EXPAND_SZ, ""C:\Program Files (x86)\Techsmart Computer\privoxy.exe" --service"
       "ObjectName"="REG_SZ", "LocalSystem"
       "Start"="REG_DWORD", 2
       "Type"="REG_DWORD", 272
       "WOW64"="REG_DWORD", 1
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
       "ProxyEnable"="REG_DWORD", 1
       "ProxyServer"="REG_SZ", ""
Malwarebytes Anti-Malware log:
Malwarebytes Anti-Malware

Scan Date: 4/26/2016
Scan Time: 8:54 AM
Logfile: mbamTechSmart.txt
Administrator: Yes

Malware Database: v2016.04.26.01
Rootkit Database: v2016.04.17.01
License: Premium
Malware Protection: Disabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {username}

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 364573
Time Elapsed: 9 min, 45 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 1
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\privoxy.exe, 4092, Delete-on-Reboot, [93d6971cdcbd56e020132be417ecc33d]

Modules: 1
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\mgwz.dll, Delete-on-Reboot, [93d6971cdcbd56e020132be417ecc33d], 

Registry Keys: 1
PUP.Optional.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PrivoxyService, Quarantined, [93d6971cdcbd56e020132be417ecc33d], 

Registry Values: 1
PUM.Optional.ProxyHijacker, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer,, Quarantined, [5f0a3f74bcdd56e0c87ea6d818ec5ca4]

Registry Data: 0
(No malicious items detected)

Folders: 1
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer, Delete-on-Reboot, [93d6971cdcbd56e020132be417ecc33d], 

Files: 9
PUP.Optional.Privoxy, C:\Users\{username}\Desktop\TechSmart.exe, Quarantined, [f376bdf6277254e2333c3bf6b15118e8], 
Backdoor.Agent.WD, C:\Users\{username}\AppData\Local\Temp\91C0.tmp.exe, Quarantined, [b5b4ab08dabf0f27f19771ad99677090], 
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\config.txt, Quarantined, [93d6971cdcbd56e020132be417ecc33d], 
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\default.action, Quarantined, [93d6971cdcbd56e020132be417ecc33d], 
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\default.filter, Quarantined, [93d6971cdcbd56e020132be417ecc33d], 
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\ittask.exe, Quarantined, [93d6971cdcbd56e020132be417ecc33d], 
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\mgwz.dll, Delete-on-Reboot, [93d6971cdcbd56e020132be417ecc33d], 
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\privoxy.exe, Delete-on-Reboot, [93d6971cdcbd56e020132be417ecc33d], 
PUP.Optional.PrxySvrRST, C:\Program Files (x86)\Techsmart Computer\privoxy.log, Delete-on-Reboot, [93d6971cdcbd56e020132be417ecc33d], 

Physical Sectors: 0
(No malicious items detected)

As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.