SmartEngine
SmartEngine is similar to My Security Shield and is from the VirusDoctor family of rouges.
Same ole, the rouge installs dropping files* then detecting them as threats trying to extort money for removal while goading the user by generating a lot of fake system alerts. It also hijacks startpage with hxxp://findgala.com and disable the security center alerts,
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter)
*
%UserProfile%\Recent\ANTIGEN.dll
%UserProfile%\Recent\ANTIGEN.drv
%UserProfile%\Recent\cid.tmp
%UserProfile%\Recent\CLSV.exe
%UserProfile%\Recent\CLSV.sys
%UserProfile%\Recent\DBOLE.drv
%UserProfile%\Recent\delfile.sys
%UserProfile%\Recent\eb.sys
%UserProfile%\Recent\energy.exe
%UserProfile%\Recent\exec.exe
%UserProfile%\Recent\fan.drv
%UserProfile%\Recent\kernel32.dll
%UserProfile%\Recent\pal.exe
%UserProfile%\Recent\PE.dll
%UserProfile%\Recent\ppal.drv
%UserProfile%\Recent\tempdoc.tmp
These were the only files I could glean as it wasn't my machine.
http://www.virustotal.com/file-scan/rep ... 1289826865
http://www.virustotal.com/file-scan/rep ... 1289827402
Interesting at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options turned up over 700 entries to disallow items from working including quite a few old relics for example 'Atguard' and from the screen 'Trojan Defense Suite 2' for 98 and NT and 3 discontinued by DiamondCS for the HIPS 'ProcessGuard' but not only antimalware but other rouges :)