Uninstall Smart HDD

Smart HDD is a malicious software that will display fake alerts, claiming that several hard drive errors were detected on your computer.The alerts are professional looking pop-ups and when you click on them, you’re advised to buy Smart HDD in order to fix this errors.
In reality, none of the reported issues are real, and are only used to scare you into buying Smart HDD and stealing your personal financial information.
If you’ve got a Smart HDD infection , you’ll be seeing this screens :

[Image: Smart-HDD.png]

Registration codes for Smart HDD

As an optional step,you can use the following license key to register Smart HDD and stop the fake alerts.
15801587234612645205224631045976
Please keep in mind that entering the above registration code will NOT remove Smart HDD from your computer , instead it will just stop the fake alerts so that you’ll be able to complete our removal guide more easily.
We strongly advise you to follow our Smart HDD removal guide and ignore any alerts that this malicious software might generate.Under no circumstance should you buy this rogue security software as this could lead to identity theft.

Removal guide for Smart HDD

STEP 1 : Start your computer in Safe Mode with Networking

  1. Remove all floppy disks, CDs, and DVDs from your computer, and then restart your computer.
  2. Press and hold the F8 key as your computer restarts.Please keep in mind that you need to press the F8 key before the Windows  start-up logo appears.
  3. On the Advanced Boot Options screen, use the arrow keys to highlight Safe Mode with Networking , and then press ENTER.
    [Image: Safemode.jpg]
  4. Log on to your computer with a user account that has administrator rights

STEP 2: Remove Smart HDD malicious proxy server

Smart HDD may add a proxy server which prevents the user from accessing the internet,follow the below instructions to remove the proxy.

  1. Start Internet Explorer [Image: Smart HDD- IE] and if you are using Internet Explorer 9 ,click on the gear icon   [Image: IE gear icon] (Tools for Internet Explorer 8 users) ,then select Internet Options.
    [Image: Internet-options-IE.png]
  2. Go to the tab Connections.At the bottom, click on LAN settings.
    [Image: Remove-proxy-server2.png]
  3. Uncheck the option Use a proxy server for your LAN. This should remove the malicious proxy server and allow you to use the internet again.
    [Image: Remove-proxy-server3.png]

If you are a Firefox users, go to Firefox(upper left corner) → Options → Advanced tab → Network → Settings → Select No Proxy

STEP 3: Run RKill to terminate known malware processes associated with Smart HDD.

RKill is a program that attempts to terminate any malicious processes associated with Smart HDD ,so that your normal security software can then run and clean your computer of infections.

As RKill only terminates a program’s running process, and does not delete any files, after running it you should not reboot your computer as any malware processes that are configured to start automatically will just be started again.

  1. While your computer is in Safe Mode with Networking ,please download the latest official version of RKill.
    [Image: download-rkill.png
  2. Double-click on the RKill iconin order to automatically attempt to stop any processes associated with Smart HDD.
    [Image: run-rkill-1.png]
  3. RKill will now start working in the background, please be patient while the program looks for various malware programs and tries to terminate them.
    [Image: run-rkill-2.png]
    IF you receive a message that RKill is an infection, that is a fake warning given by the rogue. As a possible solution we advise you to leave the warning on the screen and then try to run RKill again.Run RKill until the fake program is not visible but not more than ten times.
    IF you continue having problems running RKill, you can download the other renamed versions of RKill from here.
  4. When Rkill has completed its task, it will generate a log. You can then proceed with the rest of the guide.
    [Image: Smart HDD rkill3.jpg]

WARNING: Do not reboot your computer after running RKill as the malware process will start again , preventing you from properly performing the next step.

STEP 4: Remove Smart HDD malicious files with Malwarebytes Anti-Malware FREE

  1. Please download the latest official version of Malwarebytes Anti-Malware FREE.
    download Malwarebytes
  2. Install Malwarebytes’ Anti-Malware by double clicking on mbam-setup.
    [Image: malwarebytes-installer.png]
  3. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware checked. Then click on the Finishbutton. If Malwarebytes’ prompts you to reboot, please do not do so.
    [Image: install-malwarebytes.png]
  4. Malwarebytes Anti-Malware will now start and you’ll be prompted to start a trial period , please select ‘Decline‘ as we just want to use the on-demand scanner.
    [Image: decline-trial-malwarebytes.png]
  5. On the Scanner tab,please select Perform full scan and then click on the Scan button to start scanning your computer for any possible infections.
    [Image: malwarebytes-full-system-scan.png]
  6. Malwarebytes’ Anti-Malware will now start scanning your computer for Smart HDD malicious files as shown below.
    [Image: malwarebytes-scanning.png]
  7. When the scan is finished a message box will appear, click OK to continue.
    [Image: malwarebytes-scan-finish.png]
  8. You will now be presented with a screen showing you the malware infections that Malwarebytes’ Anti-Malware has detected.Please note that the infections found may be different than what is shown in the image.Make sure that everything is Checked (ticked) and click on the Remove Selected button.
    [Image: malwarebytes-scan-results.png]
  9. Malwarebytes’ Anti-Malware will now start removing the malicious files.If during the removal process Malwarebytes will display a message stating that it needs to reboot, please allow this request.
    [Image: malwarebytes-reboot-prompt.png]

STEP 5: Double check your system for any left over infections with HitmanPro

  1. This step can be performed in Normal Mode ,so please download the latest official version of HitmanPro.
    [Image: Download Hitman Pro]
  2. Double click on the previously downloaded file to start the HitmanPro installation.
    [Image: hitmanpro-icon.png]
    NOTE : If you have problems starting HitmanPro, use the “Force Breach” mode. Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the malware process. (How to start HitmanPro in Force Breach mode – Video)
  3. Click on Next to install HitmanPro on your system.
    [Image: installing-hitmanpro.png]
  4. The setup screen is displayed, from which you can decide whether you wish to install HitmanPro on your machine or just perform a one-time scan, select a option then click on Next to start a system scan.
    [Image: hitmanpro-setup-options.png]
  5. HitmanPro will start scanning your system for malicious files. Depending on the the size of your hard drive, and the performance of your computer, this step will take several minutes.
    [Image: hitmanpro-scanning.png]
  6. Once the scan is complete,a screen displaying all the malicious files that the program found will be shown as seen in the image below.After reviewing each malicious object click Next.
    [Image: hitmanpro-scan-results.png]
  7. Click Activate free license to start the free 30 days trial and remove the malicious files.
    [Image: hitmanpro-activation.png]
  8. HitmanPro will now start removing the infected objects, and in some instances, may suggest a reboot in order to completely remove the malware from your system. In this scenario, always confirm the reboot action to be on the safe side.

STEP 6: Unhide your files and folders

Smart HDD modifies your file system in such a way that all files and folders become hidden, to restore the default settings , you’ll need to run the below program.

  1. Download Unhide.exe, to unhide your files and folders.
    Download Unhide.exe
  2. Double-click on the Unhide.exe icon on your desktop and allow the program to run.The whole process should not take more than 5 minutes to complete,and at the end this utility will generate a report.
    Unhide files utility

STEP 7 : Restore your shortcuts and remove any left over malicious registry keys

Smart HDD has moved your shortcuts files in the Temporary Internet folder and added some malicious registry keys to your Windows installation , to restore your files we will need to perform a scan with RogueKiller.

  1. Please download the latest official version of RogueKiller.
    download RogueKiller
  2. Double click on RogueKiller.exe to start this utility and then wait for the Prescan to complete.This should take only a few seconds and then you can click the Start button to perform a system scan.
    [Image: roguekiller-1.png]
  3. After the scan has completed, press the Delete button to remove any malicious registry keys.
    [Image: roguekiller-2.png]
  4. Next we will need to restore your shortcuts, so click on the ShortcutsFix button and allow the program to run.
    [Image: roguekiller-1.png]

STEP 8: Get your desktop look back!

Smart HDD changes your desktop background to a solid black color,to change it back to default one follow the below instruction.

    • Windows XP : Click on the Start button and then select Control Panel. When the Control Panel opens, please click on the Display icon. From this screen you can now change your Theme and desktop background.
    • Windows 7 and Vista : Click on the Start button and then select Control Panel. When the Control Panel opens, please click on the Appearance and Personalization category. Then select Change the Theme or Change Desktop Background to revert back to your original Theme and colors.

If you are still experiencing problems while trying to remove Smart HDD from your machine, please start a new thread in our Malware Removal Assistance forum.

What’s next? Join our amazing community and build up your malware defenses !

IT’S YOUR TURN TO HELP!

If we have managed to help you with your computer issues, then it's your duty to let other people know that this article will help them!
You can share this article on Facebook,Twitter or Google Plus by using the below buttons.

SUPPORT MALWARETIPS! (OPTIONAL)

All our malware removal guides and utilities are completely free!
We do not request any kind of payment for our services, however if you like to support us with our website costs, you can make a small donation. Any amount is appreciated, and will support our fight against malware.

ABOUT STELIAN PILICI

I am the creator and owner of MalwareTips.com.
My area of expertise includes malware removal and computer forensics. I'm active in the various online anti-malware communities where I do researches for new malware threats as they are released.
I live in Bucharest (Romania), where I run my own local computer repair shop.
I repair both hardware and other operating systems related issues, however most of my business is malware related problems.

You can follow me on Google+ and I will keep you up-to-date with the latest computer infections and malware threats.

  • ugg outlet

    Hello, I read your new stuff like every week. Your humoristic style is awesome, keep up the good work!
    ugg outlet http://www.ugglocalweb.com

  • Jennifer

    Thank you! The virus is gone thanks to your thorough directions!

  • Hattie

    Thank you so much! Followed instructions step by step and the virus is gone!

  • craig

    thanks for this, i got nailed with this virus, it got through my eset and i have no idea how. so now im installing kerpaskey hoping thats better,

    • Stelian Pilici

      Hello Craig,
      Below you can find some quick suggestions on what security products I would recommend:
      Free – Avast 7 Free version or COMODO Internet Security
      Paid : Norton Internet Security,Avast Internet Security,G-DATA Internet Security or Kaspersky Internet Security.
      Anyway ,you should really start a thread in our Security Configuration forum as you need to build a layered security config: http://malwaretips.com/Forum-Security-Configuration-Wizard

      Also it would very good if you took the time and read this article that I’ve wrote: http://malwaretips.com/blogs/how-to-easily-avoid-pc-infections/ .. If you follow it,then we’ll never meet again in this conditions:)

  • Amanda

    i try to download roguekiller and unhide. mcafee tells me that the site isn’t safe? is this normal or is something up with mcafee??

    • Stelian Pilici

      Hello Joseph,
      You can ignore the warning from McAfee as it’s only a false positive.However,if you don’t want to do that ,you can use this alternative tool.
      ESET Online Scanner is a similar tool to RogueKiller.Here are the instructions on how to perform a scan:

      1. Download ESET Online Scanner utility.
        ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
      2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
      3. Check Yes, I accept the Terms of Use
      4. Click the Start button.
      5. Check Scan archives
      6. Push the Start button.
      7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      8. When the scan completes, push Finish
  • Alba

    I REALLY need some help. I got this darn virus yesterday and I have pctools installed on my computer. Nothing is working. I just found this blog and wanted to try the steps but now the virus isn’t letting me log into windows! It says that my password is wrong when I haven’t changed it. And just a few minutes before I was able to run SUPERantispyware in safemode and then rebooted. So I have no clue what do to now.

  • Ismael Hongeva

    thank you!we are lucky to have some great people like you among us!

  • Gooey

    All steps done and it seems like I’ve manage to kill this virus!Thank you Mr. Stelian Pilici!

  • Victor

    How can I ever say thank you enough?! You saved my computer! What could we have done without you?!

  • Grated

    Thank you!!

  • Telma Tanikella

    AWESOME!!! THANK YOU!

  • Irina84

    THANK YOU SO MUCH!YOU SAVED ALL MY WORK! :-*

  • ZachChev

    This walk through was very useful. I had already tried the method on a ask Microsoft forum but the PC was still infected and I had seriously considered formatting but thanks to this guide all is well. Thank you very much.

  • Draddelia

    thank you Stelian!

  • Pingback: Gaudi

  • rosco

    thank you so much!

  • otis75

    Hey Stelian, you rock man! Brilliant explanations and great tutorial! Thanks very much! This smart HDD was a pain….Keep up the good work… Otis

  • JAYMIE

    brilliant!
    thanks, with these my windows back to normal.

  • Computer Hack in Baltimore

    I know this is repetitive with previous comments, but this tutorial is fantastic and it worked like a charm. THANKS A BUNCH STELIAN!!

  • Karla

    What do I do if I have this virus and I don’t have access to the administrator account and no one knows the password to it? Because I’m sure it’ll ask me to enter the pw if I’m trying to download the files above..

    • Stelian Pilici

      Karla to remove this infection we will need an Administor account… Can’t you remember your password?

  • ama

    God bless you!

  • Danubis

    This is “THE GUIDE”! You are awesome Stelian!!

  • jos lsari

    Thank you so much for your helpful and informative save. i was able to rescue my xp, thanks to you.

    • Al

      Hi, there are no words enough to say thank you for your help. My Laptop all of a sudden contracted a HDD smart infection so bad I thought I might have to have it serviced. As I said no words are enough to show gratitude, but thank you thank you.
      Al

  • Brian L

    Stelian!

    If it were biologically possible, I would bare your next child.

    THANK YOU!!!!!

    Sincerely,

    Brian

  • Wendell Boyd

    Procedures where on point and worked exactly as indicated; thanks for taking the time to put together this detailed information. Very much appreciated!

  • rinaya

    Thank you so much Stelian Pilici !
    Wonderful guide! it has rescued my XP!

    Rinaya

  • nono

    Hi
    My laptop is infected with virus which has made all the folders including files not to open how do i remove the virus without deleting the important files and also how do i open them.And the internet doesn’t wanna open how do i resolve this issue?

    Thank you
    nono

    • Stelian Pilici

      Hello nono,
      Can you please run a scan with Combofix and ESET online scanner and post the logs here :

      STEP 1 : Run a scan with Combofix

      Download ComboFix from one of the following locations:

      COMBOFIX DOWNLOAD LINK #1 (This link will automatically download Combofix on your computer)
      COMBOFIX DOWNLOAD LINK #2  (This link will automatically download Combofix on your computer)

      VERY IMPORTANT !!! Save as Combo-Fix.exe during the download. ComboFix must be renamed before you download to your Desktop

      • Close any open browsers.
      • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
        ———————————————————–

        • Very Important! Temporarily disable your anti-virusscript blocking and any anti-malware real-time protection beforeperforming a scan. They can interfere with ComboFix or remove some of its embedded files which may cause “unpredictable results”.
        • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don’t know how to disable it, please ask.
          ———————————————————–
        • Close any open browsers.
        • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
        • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
        • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

        ———————————————————–

       

      1. Double click on ComboFix.exe & follow the prompts.
      2. Accept the disclaimer and allow to update if it asks
      3. When finished, it shall produce a log for you.

      Notes:

      1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
      2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
      3.  If after the reboot you get errors about programms being marked for deletion then reboot, that will cure it.

      STEP 2: Run a scan with ESET Online Scanner:

      1. Download ESET Online Scanner utility.
        ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
      2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
      3. Check Yes, I accept the Terms of Use
      4. Click the Start button.
      5. Check Scan archives
      6. Push the Start button.
      7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      8. When the scan completes, push Finish

      Waiting for your reply to tell me if your machine is ok and the logs from this utilities.

  • Will

    Need xtra assistance, posting from my phone. I have Smart HDD and it will not allow me to enter safe mode or Windows altogether. It will hang if i try to enter safe mode & will claim a disk failure if i let it go. Im trying to get back in in order to follow your guide. Any tips?

    • Stelian Pilici

      Hello Will,
      Lets work in NORMAL MODE.
      Please run a scan with Malwarebytes Anti-Malware in Chameleon Mode in Norman mode:

      1. Download Malwarebytes Chameleon from here and extract it to a folder in a convenient location
      2. Make certain that your PC is connected to the internet and then open the folder where you extracted Chameleon to and double-click on the Chameleon help file and then follow the onscreen instructions to use it.
      3. If the Chameleon help file itself will not open, then double-click each file one by one until you find one that works, which will be indicated by a black DOS/command prompt window Note: Do not attempt to open mbam-killer as that is not a Chameleon executable and serves a different purpose)
      4. Follow the onscreen instructions to press a key to continue and Chameleon will proceed to download and install Malwarebytes Anti-Malware for you
      5. Once it has done this, it will attempt to update Malwarebytes Anti-Malware, click OK when it says that the database was updated successful
      6. Next, Malwarebytes Anti-Malware will automatically open and perform a Quick scan
      7. Upon completion of the scan, if anything has been detected, click on Show Result
      8. Have Malwarebytes Anti-Malware remove any threats that are detected and click Yes if prompted to reboot your computer to allow the removal process to complete
      9. After your computer restarts, open Malwarebytes Anti-Malware and perform a Full System scan to verify that there are no remaining threats

      2.Please perform a scan with HitmanPro,RogueKiller an Unhide.exe as seen on the guide.


      3.Run a scan with ESET Online Scanner:

      1. Download ESET Online Scanner utility.
        ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
      2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
      3. Check Yes, I accept the Terms of Use
      4. Click the Start button.
      5. Check Scan archives
      6. Push the Start button.
      7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      8. When the scan completes, push Finish
  • steph

    Please help I try to get to safe mode with networking but as it loads files it stops and won’t go. I keep starting again and it keeps doing it

    • Stelian Pilici

      Hello steph,
      Lets work in NORMAL MODE.
      Please run a scan with Malwarebytes Anti-Malware in Chameleon Mode in Norman mode:

      1. Download Malwarebytes Chameleon from here and extract it to a folder in a convenient location
      2. Make certain that your PC is connected to the internet and then open the folder where you extracted Chameleon to and double-click on the Chameleon help file and then follow the onscreen instructions to use it.
      3. If the Chameleon help file itself will not open, then double-click each file one by one until you find one that works, which will be indicated by a black DOS/command prompt window Note: Do not attempt to open mbam-killer as that is not a Chameleon executable and serves a different purpose)
      4. Follow the onscreen instructions to press a key to continue and Chameleon will proceed to download and install Malwarebytes Anti-Malware for you
      5. Once it has done this, it will attempt to update Malwarebytes Anti-Malware, click OK when it says that the database was updated successful
      6. Next, Malwarebytes Anti-Malware will automatically open and perform a Quick scan
      7. Upon completion of the scan, if anything has been detected, click on Show Result
      8. Have Malwarebytes Anti-Malware remove any threats that are detected and click Yes if prompted to reboot your computer to allow the removal process to complete
      9. After your computer restarts, open Malwarebytes Anti-Malware and perform a Full System scan to verify that there are no remaining threats

      2.Please perform a scan with HitmanPro as seen on the guide.


      3.Run a scan with ESET Online Scanner:

      1. Download ESET Online Scanner utility.
        ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
      2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
      3. Check Yes, I accept the Terms of Use
      4. Click the Start button.
      5. Check Scan archives
      6. Push the Start button.
      7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      8. When the scan completes, push Finish
      • steph

        I can’t get that far I try normal mode and it takes me to a scream saying checking file system on c: And says a lot more about checking a disk. Says to use system restore feature from control panel. but how can I get to control panel to do so?

        • Stelian Pilici

          Can you ignore that warning? Just go ahead and try to download Malwarebytes Chameleon.
          If it doesn’t work than try the below step:
          While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
          1.Here are the direct download links for HitmanPro,
          http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
          http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
          2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
          Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
          3. Let HitmanPro scan and remove the detected infections.
          Next,run a scan with Malwarebytes Anti-Malware.

  • joseph

    my dell has a virus that keeps restarting, ive hit safemode and it restarts before i get to run malwarebits….ive run rkill but it restarts before rkills is finished? any tips would be awesome

    • Stelian Pilici

      Hello,
      Lets try do this another way.Please follow the below steps…

      STEP 1. While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
      1.Here are the direct download links for HitmanPro,
      http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
      http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
      2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
      Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
      3. Let HitmanPro scan and remove the detected infections.

      STEP 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes
      1.Download any re-named version of Rkill (direct download links bellow):
      RKILL DOWNLOAD LINK #1
      RKILL DOWNLOAD LINK #2
      RKILL DOWNLOAD LINK #3
      2.Next,please perform a scan with Malwarebytes and then do a RogueKiller and Unhide.exe scan as seen on the guide


      STEP 3. Run a scan with ESET Online Scanner

      1. Download ESET Online Scanner utility.
        ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
      2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
      3. Check Yes, I accept the Terms of Use
      4. Click the Start button.
      5. Check Scan archives
      6. Push the Start button.
      7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      8. When the scan completes, push List of found threats
      9. Push Export to Text file  and save the file to your desktop using a unique name, such as ESET Scan. Include the contents of this report in your next reply.Note – when ESET doesn’t find any threats, no report will be created.
      10. Push the back button.
      11. Push Finish

      Waiting for your reply to tell me how everything is working.. :) Good luck!

      • L Olson

        Just a note that HitMan Pro no longer offers the free trial. I used all your steps and they helped rid my computer of this stupid virus, BUT HitMan Pro showed some suspicious items and now I can’t remove those :(

        • Stelian Pilici

          Hello,
          Is this your personal computer or from work?It’s important to know that only home users can use this product when it comes to malware removal. :)
          You can perform a scan with the following utilities:

          1.Run a scan with Kaspersky Virus Removal Tool
          Click here to download the Kaspersky Virus Removal Tool.

          1. Save it to your desktop.
          2. Double click the setup file to run it.
          3. Follow the onscreen prompts until it is installed
          4. Click the Options button (the ‘Gear’ icon), then make sure only the following are ticked:
            • System Memory
            • Hidden startup objects
            • Disk boot sectors
            • Local Disk (C:)
            • Also any other drives (Removable that you may have)
          5. Then click on Actions on the left hand side
          6. Click Select Action, then make sure both Disinfect and Delete if disinfection fails are ticked
          7. Click on Automatic Scan
          8. Now click the Start Scanning button, to run the scan
          9. After the scan is complete, click the reports button (‘Paper icon’, next to the ‘cog’ icon) on the right hand side
          10. Click Detected threats on the left
          11. Now click the Save button, and save it as kaslog.txt to your Desktop
          12. Please copy and paste the contents of kaslog.txt in your next reply.

          2.Run a scan with Eset Online Scanner.

          1. Download ESET Online Scanner utility.
            ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
          2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
          3. Check Yes, I accept the Terms of Use
          4. Click the Start button.
          5. Check Scan archives
          6. Push the Start button.
          7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
          8. When the scan completes, push Finish
  • hp

    This’s AWESOME!!!!! U saved my laptop! Thank you so much

  • Gaurav Nanda

    Thank you so much!

  • Evelyn Burges

    Thank you so much, brilliant, my netbook is now back to its former self, such a relief!!

  • Jeff

    Whenever I try to download the first step it begins to run then just completely disappears.

  • mike

    Hi

    I have followed this procedure 4 times now and it still keeps comming back. I have even got AVG installed and that does not stop it. Any suggestions?
    Mike

    • Stelian Pilici

      OK,lets make some further check-ups:
      1.Run a scan with Kaspersky Virus Removal Tool
      Click here to download the Kaspersky Virus Removal Tool.

      1. Save it to your desktop.
      2. Double click the setup file to run it.
      3. Follow the onscreen prompts until it is installed
      4. Click the Options button (the ‘Gear’ icon), then make sure only the following are ticked:
        • System Memory
        • Hidden startup objects
        • Disk boot sectors
        • Local Disk (C:)
        • Also any other drives (Removable that you may have)
      5. Then click on Actions on the left hand side
      6. Click Select Action, then make sure both Disinfect and Delete if disinfection fails are ticked
      7. Click on Automatic Scan
      8. Now click the Start Scanning button, to run the scan
      9. After the scan is complete, click the reports button (‘Paper icon’, next to the ‘cog’ icon) on the right hand side
      10. Click Detected threats on the left
      11. Now click the Save button, and save it as kaslog.txt to your Desktop
      12. Please copy and paste the contents of kaslog.txt in your next reply.

      2.Run a scan with Eset Online Scanner.

      1. Download ESET Online Scanner utility.
        ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
      2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
      3. Check Yes, I accept the Terms of Use
      4. Click the Start button.
      5. Check Scan archives
      6. Push the Start button.
      7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      8. When the scan completes, push List of found threats
      9. Push Export to Text file  and save the file to your desktop using a unique name, such as ESET Scan. Include the contents of this report in your next reply.Note – when ESET doesn’t find any threats, no report will be created.
      10. Push the back button.
      11. Push Finish

      Waiting for your reply to tell me how everything is working.. :) Good luck!

  • Karie

    Thank you for putting this out there. I am so computer stupid but it worked!!!! Thank you, thank you, thank you!!!

  • brendan

    also thanks. but I was in such bad shape the computer was useless. I finally succeeded by hitting F11 when rebooting
    (Vista on a Compaq Presario) and finding a backup point (had to choose older than 5 days). It is all very slow.

  • Bill

    Thank you for the instructions, got rid of smart on my Samsung 10 running xp.
    The only problem left is I can’t get the computer to recognize any wi-fi. I tried Tweaking.com but that didn’t work. Wi-fi is turned on but when I go to network connections the Local Area Connection Network Cable reads unplugged. I can plug in an ethernet cord and the internet works. However this netbook is not able to discover our home Wi-fi network!

    • Bill

      While investigating further, I realized that my driver wasn’t showing for my LAN connection, once I updated the driver, bingo, my wireless was working.
      Thanks again for your great directions, you saved the day.

  • AL

    Thank you so much for putting this on the Internet. I got blindsided by this stupid virus today and thought I’d have to drop serious $$$ to get my computer fixed. Thanks to you I did it all without having to take it in to Geek Squad or some other computer place. After following all of your steps to the letter my computer now runs perfectly! You’re a life-saver.

  • Adam

    Hi, I am trying to help fix a PC at work which has this virus. I have restarted in Safe mode with Networking, but there are still no icons and nothing in the Start Menu other than options to Log Off or Turn Off Computer. There is nothing in the All Programs list. I cannot get into a browser to download any of the software in your walkthrough. Any advice? I’m pretty clueless at this :/

    • Stelian Pilici

      OPTION 1 : While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
      1.Here are the direct download links for HitmanPro,
      http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
      http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
      2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
      Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
      3. Let HitmanPro scan and remove all the detected threats.
      4.Run Rkill and then a scan with Malwarebytes.

      OPTION 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes.!
      1.Download any re-named version of Rkill (direct download links bellow):
      http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
      http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
      http://download.bleepingcomputer.com/grinler/rkill.scr
      2.Next,please perform a scan with Malwarebytes as seen on the guide and then a scan with HitmanPro.

      Let me know , how everything goes.

      • Adam

        Hi, apologies for not clarifying in the last post; I have no icons or Start Menu programs in noral mode either. I am posting this from another PC in the office. If I start in safe mode with networking and log in as administrator, I can access a few programs including internet explorer; however since the virus was downloaded to a user profile and that is the one having the problems, I was under the impression that running the solutions in Administator profile would not help.
        Is there anyway I can download the software to a CD or something on another PC and then load them on the problem PC? Would that work? How would I load them without access to My Computer or even the Run option? Apologies for the delay in posting this, as the PC is at work I can only access it during weekdays.

        • Adam

          Also wanted to add, if I right-click on the desktop nothing happens, and the only things on the toolbar are the clock and a McAfee icon. A recurring message from McAfee keeps popping up saying ‘Your Computer is at Risk, Please check your status so you can address any security issues to keep your PC protected.’ If I click on status it says Real-Time Scanning is Off; if I click Turn On it goes green and says everything is secure, the turns off again a second or 2 later. I don’t know if this is in any way related though.

          • Adam

            Please ignore my earlier comments; by right-clicking on the empty Start Bar menu, I was able to get into properties, and change all options back to ‘display this item’. The Programs list is still empty, but I do have access to a browser (Firefox) so should be able to run the solutions outlined above. I will let you know how this goes.

          • Adam

            I was able to download and run RKill, but when I tried to download MalwareBytes nothing happened, it just kept boucing me between 2 different sites. Each one had a link saying ‘download now’ but each link just takes me to the other site. I tried skipping to the next step and downloaded HitManPro36, but when I try to run it I just get an error message saying HitManPro36.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

            • Stelian Pilici

              Hello,
              You have a MBR infection which is causing this redirect… Try the below steps and see if they work.
              STEP 1. While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
              1.Here are the direct download links for HitmanPro,
              http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
              http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
              2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
              Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
              3. Let HitmanPro scan and remove all the detected threats.

              Step 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes
              1.Download any re-named version of Rkill (direct download links bellow):
              http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
              http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
              http://download.bleepingcomputer.com/grinler/rkill.scr
              2.Next,please perform a scan with Malwarebytes as seen on the guide. (Direct download link for Malwarebytes: http://www.malwarebytes.org/mbam-download-exe.php )

              Report back if it doesn’t work:)

              Let me know , how everything goes.

              • Adam

                Hi, thanks for getting back to me. I had previously tried the Force Breach launch for HitManPro, and have tried it again today, but I am still getting the response ‘HitManPro36.exe has encountered a problem and needs to close. We are sorry for the inconvenience.’ I have succesfully downloaded and run Rkill and Malwarebytes, and have had no further issues with the Data Recovery/Smart HDD virus, but it is still sitting in the Programs list. Is there a way to safely remove this? There is an uninstall option in the program list with it, but I am wary of using this as I know this is sometimes used to reinstall virus software.
                Thanks again for all your help.

                • Stelian Pilici

                  Can you please perform the following scans…
                  1.Run a scan with Kaspersky Virus Removal Tool
                  Click here to download the Kaspersky Virus Removal Tool.

                  1. Save it to your desktop.
                  2. Double click the setup file to run it.
                  3. Follow the onscreen prompts until it is installed
                  4. Click the Options button (the ‘Gear’ icon), then make sure only the following are ticked:
                    • System Memory
                    • Hidden startup objects
                    • Disk boot sectors
                    • Local Disk (C:)
                    • Also any other drives (Removable that you may have)
                  5. Then click on Actions on the left hand side
                  6. Click Select Action, then make sure both Disinfect and Delete if disinfection fails are ticked
                  7. Click on Automatic Scan
                  8. Now click the Start Scanning button, to run the scan
                  9. After the scan is complete, click the reports button (‘Paper icon’, next to the ‘cog’ icon) on the right hand side
                  10. Click Detected threats on the left
                  11. Now click the Save button, and save it as kaslog.txt to your Desktop
                  12. Please copy and paste the contents of kaslog.txt in your next reply.

                  2.Run a scan with Eset Online Scanner.

                  1. Download ESET Online Scanner utility.
                    ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
                  2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
                  3. Check Yes, I accept the Terms of Use
                  4. Click the Start button.
                  5. Check Scan archives
                  6. Push the Start button.
                  7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
                  8. When the scan completes, push List of found threats
                  9. Push Export to Text file  and save the file to your desktop using a unique name, such as ESET Scan. Include the contents of this report in your next reply.Note – when ESET doesn’t find any threats, no report will be created.
                  10. Push the back button.
                  11. Push Finish

                  Waiting for your reply to tell me how everything is working.. :) Good luck!

                  • Adam

                    Hi, both scans came back clear and generated no reports. Thanks again for your help! Apologies for the delay in replying, I was away from work for a week as I was unwell, and the following week I was on holiday.

  • Derek j

    Hi Stelian Pilici,

    You are a genius. Thanks a mil. for the screen shots and detailed instructions.
    Each step worked flawlessly, Thanks again
    – DJ

    • TonyD

      Hi Stelian,
      You are a hero, my friend.
      I do not know what I would have done without your instructions on how to get rid of this SMART HDD virus.
      If only there were more good guys like you in this world, guys who put there minds to doing good stuff instead of inflicting pain an misery on others.
      If your computer shop was in Brisbane, Australia, you would get all my business and that of everyone I know.
      Words are not enough to thank you but thank you very, very much anyway.

  • catalina

    Hi, thanks I finally deleted the virus, but there is one problem now, my laptop can’t find ani wifi signal, I turned off and on the wifi but nothing happened.

    • Stelian Pilici

      Download Windows Repair by Tweaking.com to your desktop.  Use the direct download link for the Portable version of Windows Repair by Tweaking.com

      1. Double-click tweaking.com_windows_repair_aio.zip and extract the Tweaking.com – Windows Repair folder to your desktop.
      2. Now open this folder and double-click Repair_Windows.exe.
      3. Click the Start Repairs tab on the far right.
      4. Click the Start button (bottom right)
        Note: When asked if you would like to create a restore point. It is recommended just in-case something does not go as planned.
      5. Click Unselect All
      6. Put a checkmark in the following items:
        • Repair Windows Firewall
        • Repair Hosts File
        • Repair Temp Files
        • Remove Policies Set By Infections
        • Set Windows Services To Default Startup

        Note: Leave everything else unchecked

      7. Put a checkmark in Restart System When Finished
      8. Now click the Start button (bottom right)

      What firewall are you using?

  • SteveMac

    Stelian you are awesome! Worked through all your steps and everything came back as it should. I tried a couple of the other methods from other sites and the S.M.A.R.T malware came back as before. I think that running Hitman after Malwarebytes was the key to getting this removed. Also running RogueKiller brought back all my hidden files without running unhide.exe, although I did run it anyway. Thanks so much for your help!

  • http://earthquakecharts.com Kevin

    Who are you people? The Justice League? A blessing on you for helping the helpless victims of Smart HDD.

    • SteveMac

      Stelian is a one man Justice League! Saved me from untold grief!

  • David

    Thanks Stelian!
    By following your directions I was able to fix my g/fs computer. I had already tried running malware bytes, but your suggestion to run hitmanpro found a potentially suspicious file. For what it’s worth for others, the first time I tried unhide, nothing seemed to happen for 25 minutes. I tried it again and 10 minutes later I noticed changes. So it might take a while.

  • Frank

    When I start my laptop in safe mode with networking, networking isn’t available and all my files show as empty. Can I go through this process outside of safe mode and still get rid of this nightmare?

  • CEJulius

    $10.00 is going to every piece of software I used. Thanks folks!

    • Stelian Pilici

      All the software is FREE..so use the money for yourself!:D
      Stay safe!

      • Kevin

        Well, Roguekiller has a Paypal button so I am going to give them money.

  • Bryan

    Everything is pretty much back to normal. Great job.

    The only major thing is my voice recorder which I plug into the computer through a USB port. When I try to eject it, I always get a message that a program is using it. I pull it out anyway.

  • chris

    Thank you so much for this guide! Good karma sent your way!

  • jeremiah

    Yes I followed all your steps throughly and the HDD smart repair, and error pop us no longer appear. But programs such as microsft office, itunes, silverlight,quick time,adobe acrobat, most programs don’t appear. What may have happend and how do I fix that?

  • John

    I used these steps to take out Smart hdd from my computer and it successfully worked but now I got another virus called Security Shield. Would Rkill, Malwarwebytes, and those other programs work to take out this virus?
    And also what are some good free Security programs because these viruses just turn off Microsoft Security Essentials.
    Thanks

  • Jecca

    Hi I went through all the steps and everything worked out great, but at the end my computer was having a hard time rebooting, so I did a start up repair through windows, and all of a sudden everything is gone again, desktop, start menu, toolbars etc. So should I rerun the unhide program? or is there something else that I should try, thanks for all of your hard work, you really are a life saver.

    • Stelian Pilici

      Plese run Unhide.exe

      1. Download  >> Unhide.exe. < <<
      2. Double-click on the Unhide.exe icon on your desktop and allow the program to run.When it has completed its task it will generate a report.

      Then perform a scan with Emsisoft Anti-Malware :

      1. Download the latest official version of Emsisoft Emergency Kit
      2. After the download process will has comleted, you’ll need to unpack EmsisoftEmergencyKit.zip
        [Image: ekk1.png]
      3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
        [Image: ekk2.png]
      4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

        [Image: ekk3.png]

        [Image: ekk4.png]

      5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

        [Image: ekk5.png]

      6. Select “Smart scan” and click-on the below “SCAN” button.

        [Image: ekk6.png]

      7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

        [Image: ekk7.png]

      8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
        Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
        [Image: ekk8.png]
      9. Emsisoft Emergency Kit will now start removing the malicious files.
  • nick dakins

    worked, thank you!@

  • http://dirkdiggity@gmail.com Geasouscunc

    When I switch my personal computer on it says that I’m contaminated and won’t let me close or perhaps open anything. What can I actually do?

    • Stelian Pilici

      Did you follow the above removal guide??

  • Francine

    Hi guys everything worked fine BUT I still cannot get my icons back on the desktop, not even by “trailing” them from dhe folder to the desktop (sorry I am not sure trailing is the righht english word…
    And from the Start menu I see all the programs BUT I do not see the column with Documents, Recent docs, computer, and so on. And sometimes I get a Empty answer…

    • Stelian Pilici

      1.Plese run Unhide.exe

      1. Download  >> Unhide.exe. < <<
      2. Double-click on the Unhide.exe icon on your desktop and allow the program to run.When it has completed its task it will generate a report.

      2.Restore your Start menu to a previous date

      1. Right click on your Windows Start menu and select Properties.
        [Image: Eu2Aq.png]
      2. Next put a check mark on
        Store and display recently opened programs in the start menu
        Store and display recently opened items in the start menu and taskbar
        [Image: h0z5v.png]
      3. Click on Customize and click on Use default settings at the bottom
        [Image: kxZSH.png]
      4. Browse to
        Code:
        C:\ProgramData\Microsoft\Windows

        [Image: vZZUz.png]

      5. Right click on Start Menu folder and click on Restore previous versions
      6. Now select a snapshot before you were infected by the rogue,click on restore
  • Martin

    Thanks a lot. Got the virus a couple of days ago.
    Followed your instructions, worked perfectly!

  • Claudio

    Thank you very much. The instructions were clear and worked great. I saved my laptopo thanks to your help. Grazie

  • Charmian H

    Thank you SO much. We’d decided to restore my computer to the day before to get rid of this BLUDDY virus, and thought everything was then hunky-dory. Until I discovered all my documents were gone. Nearly heart attack time. Followed your steps to unhide etc. (didn’t do the Malware bit because I’d already restored) … I run AVG and Spybot which have never let me down before so not sure how this virus got through. But so glad to be able to follow your instructions to restore. Worth your weight in gold. If I had it! :D

  • NoleVeinnyBen

    Worked perfectly for me!!Recommended guide!

  • Tanuj

    hey i have kaspersky internet security trial version instaled and the damn thing wont start with a comp reboot… i had norton 360 full version before this and it used to do the same thing (not start with reboot…) when i click on the kaspersky icon… there is only a slim chance that it works, so do u think this would help me?? also will the softwares be compatible with kaspersky?

    • Stelian Pilici

      Yes , all the software all compatible with Kaspersky/Norton as they are just on-demand scanner(will not add real-time protection). :)

      • Tanuj

        Thank u soo much maan!

        • Stelian Pilici

          Stay safe Tanuj! And have a good (malware-free) day! :D

  • John

    How long is each scan suppose to take?? I am scanning using the Malwarebytes Anti-Malware and it has already been 6 hours with 18 detected. Is this normal??
    P.S. Whoever does these hacks needs to get a life :(

    • Stelian Pilici

      All it depends on the sizes of your hard drive and your PC speed but usually around 1 hour,however because this is an infected PC it can take longer………. Let the scan complete and then move on with the next steps, which will be a lot faster.

      • John

        Thanks, all good now. Can I uninstall/ delete the downloaded programs from above after I am done?

        • Stelian Pilici

          Yes, you can uninstall all of them if that’s what you want.. :)
          Stay safe!

  • Andrei Homorodean

    Thank you! Worked!

  • carolyn

    Wow thanks!! All done and then like a dummy went into history and trued to delete site and clicked in Firefox “forget it” but somehow it launched :( Reran and back in business. THANKS!! I guess I will just leave it in history. Do you all have any recommendations as to what is good software to run so these stupid things get caught before they infect? My Free Malware version does not and my Mcaffee (paid) is worthless (grrrr).

    • http://malwaretips.com/ Stelian Pilici

      McAfee is the worst!! :)
      As a quick answer :
      Free – Avast 7 Free version or COMODO Internet Security
      Paid : Norton Internet Security 2012 or Avast Internet Security 7
      Anyway ,you should really start a thread in our Security Configuration forum as you need to build a layerd security config: http://malwaretips.com/Forum-Security-Configuration-Wizard

  • Anill

    One stupid act spoiled my week and you saved me! Mucho gracious. Very nice step by step instruction.

  • James

    Internet Explorer is no where to be found on my computer. No icon. Did a search for it and nothing came up. Any ideas?

    • http://malwaretips.com/ Stelian Pilici

      Try to launch Internet Explorer from Task Manager > by clicking File, New Task, and type iexplore in the Open box.

  • Roby T

    Works good!!! Thks…

  • http://None Cam

    Awesome instructions, fixed everything for me. Great job!

  • bernie sanchezee

    I got a wicked virus and for the most part have cleaned it off. but now internet explorer 9 starts to open then closes, it won’t run and neither would google chrome. Games like league of legends and skype wont work either. I tried to re-install skype and it opens but you cant see anything other then the background. any suggestions???

    • http://malwaretips.com/ Stelian Pilici

      Did you scan with Malwarebytes and HitmanPro and remove the detected threats??
      If yes,please try to scan again….

      Next , perform a system scan with Emsisoft Emergency Kit:

      1. Download the latest official version of Emsisoft Emergency Kit
      2. After the download process will has comleted, you’ll need to unpack EmsisoftEmergencyKit.zip
        [Image: ekk1.png]
      3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
        [Image: ekk2.png]
      4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

        [Image: ekk3.png]

        [Image: ekk4.png]

      5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

        [Image: ekk5.png]

      6. Select “Smart scan” and click-on the below “SCAN” button.

        [Image: ekk6.png]

      7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

        [Image: ekk7.png]

      8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
        Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
        [Image: ekk8.png]
      9. Emsisoft Emergency Kit will now start removing the malicious files.
        If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.

      If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • juli

    Your instructions have been wonderful and helped me re-gain control of my computer after the smart virus. The main problem I’m having now is, each time my computer gets turned off (ie: storm) all my icons are missing and I have to re-run Rogue Killer. Is there a fix for this? Also, one other thing … I am no longer able to see a preview in my pictures folder. Thanks a bunch!!

    • http://malwaretips.com/ Stelian Pilici

      Lets try to run Unhide.exe and run it.

      1. Download Unhide.exe.
      2. Double-click on the Unhide.exe icon on your desktop and allow the program to run.When it has completed its task it will generate a report.
      • juli

        Thanks a bunch for the answer but when I run unhide.exe the black screen comes up and gets to the Processing the c drive but doesn’t go any further.

        • http://malwaretips.com/ Stelian Pilici

          Lets check with Emsisoft Emergency Kit to see if there are any active infection :

          1. Download the latest official version of Emsisoft Emergency Kit
          2. After the download process will has comleted, you’ll need to unpack EmsisoftEmergencyKit.zip
            [Image: ekk1.png]
          3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
            [Image: ekk2.png]
          4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

            [Image: ekk3.png]

            [Image: ekk4.png]

          5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

            [Image: ekk5.png]

          6. Select “Smart scan” and click-on the below “SCAN” button.

            [Image: ekk6.png]

          7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

            [Image: ekk7.png]

          8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
            Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
            [Image: ekk8.png]
          9. Emsisoft Emergency Kit will now start removing the malicious files.
            If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.
          • juli

            Thanks very much for the help … I ran the program and it found 11 malicious files, which I deleted. Still, when I restart the computer, all the icons are missing.

            • Stelian Pilici

              OK….Please run again > Unhide.exe

  • Coen

    THANKS, you save my day!!

  • Jess

    Thanks so much! Very easy to follow instructions… got rid of that horrible program very quickly :-)

  • kevin

    I followed these directions and everything seems to be working correctly except for on thing. We cannot get the desktop items to show on the desktop. Folder #4 was not in the smtmp folder and when I checked the desktop folders, both in all users and the user folder for the current user, the shortcuts were still there. However, they will not show on the desktop. I am unable to copy and paste anything onto the desktop either. Any ideas?

    Great directions, BTW!! Thanks so much!

    • kevin

      Nevermind…a restart fixed that issue. All the desktop shortcuts are not visible. Thanks again!!

      • http://malwaretips.com/ Stelian Pilici

        Stay safe!:D

  • Duffield

    this stinkin’ piece of crap malware is like Frankenstein, it rises from the dead over and over and the nerds best software can’t stop it, the Turds that created this “SMART” Monster must be better Nerds!!! Anyone ever wonder if this whole “Malware” problem is just like the Mafia, they create a problem and offer you the solution for a Price $$$ !?! The so-called law is sleeping when it comes to on-line extortion from all these Malwares…. the people that make Malwares should be lined up and shot on Pay-Per-View and millions would pay to see their Slaughter! Muhahahahaaa…

  • André Atz

    NICE JOB!

  • Jim

    I’m having trouble with step 9. I’m in the temporary files, but I can’t find the smtmp files. could they be named something else? I’m using windows 7. Everything else has worked like a champ. Thank you so much.

    • http://malwaretips.com Stelian Pilici

      Did you get back all your files and folders?
      If yes, then you don’t need to worry about that step :)
      Stay safe!

  • Larry

    Not only did it work, it removed another virus I had & fixed a program that kept crashing. The steps laid out here were perfect & I consider myself a beginner when it comes to this kind of stuff. The SMART virus was the 1st virus I’ve ever had. Thank you for posting this page. It’s the only one I found that clearly laid out all the steps & it was easy to follow.

    • http://malwaretips.com Stelian Pilici

      Thank you!
      Stay safe!

    • Duffield

      I got my MalwareBytes back after I ran every anti-malware program I could find, I’ll give it to em’, the Turds that made the SMART malware made one heck of a rabid nightmare, Malwarebytes had kept me safe for 8 months and I picked that SMART fawker up in a boxing message board, I’d like to KTFO the Turd that hid it in his postings but it dis-abled my Malwarebytes and started hiding everything on my computer which has 1 GB of pics and videos saved, I had back-ups but I hate to re-install my computer due to one idiots malware, so I tried it all and it took a cocktail of various programs to finally work… guess I need to keep all these anti-malware programs on my computer at all times… thanks alot Malware-Turds, I know you Fawkers browse here to admire your work!!!

  • Sergio

    It also worked fine here! Thanks a lot!

  • Kirpa Gill

    Thanks guys! You saved my life today.

    Thanks so much for the excellent step by step guide.

  • Dawn Marie

    YAY!! It worked!!Thank you so much! I wish I had found this 7 hours sooner. Worth every minute and I can’t thank you enough!!!

  • Lindsey

    Hi Jack, I’m stuck on Step 3 (Run RKill). I downloaded RKill from the “Download Now” button in this guide, but the RKill icon doesn’t appear. I tried downloading the other renamed versions of RKill from the “here” button in this guide:

    •RKill.com Download Link
    •RKill.exe Download Link
    •RKill.scr Download Link
    •eXplorer.exe Download Link
    •iExplore.exe Download Link
    •uSeRiNiT.exe Download Link
    •WiNlOgOn.exe Download Link

    but still no icon appears, therefore I haven’t been able to run RKill, and therefore no log has been generated.

    What should I do next?

    • http://malwaretips.com Stelian Pilici

      Hello Lindsey,

      STEP 1 : Download HitmanPro and then start this program in ForceBreach Mode
      1.Here are the direct download links for HitmanPro,
      http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
      http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
      2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the Smart HDD malicious process
      Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
      3. Let it scan and remove all the detected threats , after that run the RKILL scan and then try to scan with Malwarebytes!

      STEP 2: Run RKILL and then run a scan with Malawrebytes

      STEP 3: Next , perform a system scan with Emsisoft Emergency Kit:

      1. Download the latest official version of Emsisoft Emergency Kit
      2. After the download process will has comleted, you’ll need to unpack EmsisoftEmergencyKit.zip
        [Image: ekk1.png]
      3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
        [Image: ekk2.png]
      4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

        [Image: ekk3.png]

        [Image: ekk4.png]

      5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

        [Image: ekk5.png]

      6. Select “Smart scan” and click-on the below “SCAN” button.

        [Image: ekk6.png]

      7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

        [Image: ekk7.png]

      8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
        Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
        [Image: ekk8.png]
      9. Emsisoft Emergency Kit will now start removing the malicious files.
        If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.

      If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • hooverman

    thank you,everything is ok now!

  • donnyal2

    My computer was infected with this. I used Superantipayware to original remove. I have access to my computer can go online, followed instructions to show hidden files. Manually found programs to re-pin some. But when i go to I.E. and try to download the missing Adobe Flash it gives me an unspecified error. When i go to download Rkill or any program i get Access Denied or the same unspecified error C;\Users\Data user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CFENMA1N\Flash PlayerInstaller.exe. I also do not have the 4 smptp folders when i go to copy and paste my Quick Launch and Start Menu items. Also i have no option to save anything to desktop. My new desktop is inside my documents. Any help to get my computer back to normal would be appreciated. Thanks.

    • http://malwaretips.com Stelian Pilici

      Option 1 : Try to download a different named Rkill (direct download links bellow):
      http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
      http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
      http://download.bleepingcomputer.com/grinler/rkill.scr
      And then follow the guide : http://malwaretips.com/blogs/uninstall-smart-hdd/
      Option 2: Try to download HitmanPro and then start this program in ForceBreach Mode
      1.Here are the direct download links for HitmanPro,
      http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
      http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
      2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the Smart HDD malicious process
      Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
      3. If it start ,let it scan and remove all the detected threats , then follow the guide : http://malwaretips.com/blogs/uninstall-smart-hdd/

      Next , perform a system scan with Emsisoft Anti-Malware:

      Download and scan with Emsisoft Emergency Kit

      1. Please download the latest official version of Emsisoft Emergency Kit.

      2. After the download process will finish , you’ll need to unpack EmsisoftEmergencyKit.zip
        [Image: ekk1.png]
      3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
        [Image: ekk2.png]
      4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

        [Image: ekk3.png]

        [Image: ekk4.png]

      5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

        [Image: ekk5.png]

      6. Select “Smart scan” and click-on the below “SCAN” button.

        [Image: ekk6.png]

      7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

        [Image: ekk7.png]

      8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
        Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
        [Image: ekk8.png]
      9. Emsisoft Emergency Kit will now start removing the malicious files.
        If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.

      If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • mike w

    worked great thank you so much

  • Johnny H

    Thanks a lot, an absolute cweaty sunt of a virus!! But with your help I’m now good to go again, thanks a bunch.

  • Matija

    IF YOU ARE NOT ABLE TO KILL THIS MONSTER AFTER DOING EVERYTHING!
    first thanks for a great help how to kill this bastard, it was rough. I owe you guys. I managed ;)
    one possible trick to those who are not able to do it following these otherwise great instructions (try them first and only if it doesnt work exactly what JAck wrote, try what I say). I did everything but Malware bytes always cleaned and things showed up again. My problem was, that RKiller didnt show anything in the log (guess, didnt see anything to kill) while I was in the safe mode with networking. So I rebooted (after I downloaded malware bytes AND RKiller) in a normal mode, so the thing virus started going (I just clicked Stop in its screen to stop popups) and than hit R Killer. It was able to identify the culprits and blocked them. Than Malware bytes had easier time to clean it (I think) properly. Immediately after that Hitman MUST follow (if you cannot download it, because you are not in a safe mode, press windows key and R, and that will get you into exlorer, than type back the address of this AWESOME blog so you see intructions again and dowload Hitman and run it immediately. Than restart. I am afraid, that just running malware bytes is not enough, Bytes showed only few hits, Hitman showed me dozens of crap that had the same name as the one stopped by RKiller. To unhide the icons, easier than the described method I think is to dowload unhide.exe, form the same dude who wrote RKiller (god bless him)

  • Taylor

    Thanks so much this was a huge help. I was worried I lost something I was working on for a client for the last 2 months.

  • JP

    This was a particularly nasty virus in my opinion. Who is responsible for this?

  • Mystica

    Hey all….im back again…couple weeks ago i had this virus and it all seems clear after i run this
    program on my computer. The strainge thing is, he is getting slower and slower and now its
    verry hard to use again….I will run this scans again and hope it will make it better again
    really strainge and stupid virus….keep up the good work guys….:D

  • gis

    thanks!!!!!!

  • Julian

    Hello! Great step-by-step, but it doesn’t work for me:
    I have followed every step, in order, and smart HDD always goes “back to life”.
    Rkill log didn’t show any stopped process ever.
    Today, I have followed this guide for fifth time.
    At fourth and fifth time, Malwarebytes found nothing. But Hitman found some “exe” files.

    I don’t know what I am doing wrong.
    Please, I need some help.
    Thanks

  • Tom

    This step-by-step (even though it took awhile to complete) TOTALLY KICKS A**!!! I got a call from my wife – Her work computer got infected – thought the hard-drive had crashed, and we need to buy a new one as she needs it daily. Found this site and everything is as good as new. Can’t thank you guys enough for saving our bacon. Even considered paying the silly fee with credit-card online to the S.M.A.R.T. HDD fairy but was just savvy enough to do a little search about this issue and karma sent me to your link. Anything I can do to repay (even monitarily) will be worth it! Can’t express my gratitude enough…

  • DJAM

    I downloaded HitmanPro 3.6 and the program opened. However, when it begins to run, It says “Scanning computer”, but then I get a No Internet Connection, Waiting for Internet Connection message. I checked IPCONFIG and it shows I have access to the Internet based on the IP address listed.

    I turned off Proxy in Safe Mode for both my IE and my Firefox browsers. Any advice?

    By the way, thank you so much for this guide; all my files are back on my laptop but I just want to make sure I run HitmanPro 3.6.

    • http://malwaretips.com Jack

      HitmanPro is a cloud scanner so you need an internet connection to use it…
      While in Norman Mode does your Internet connection work?? Did you try performing this scan in Normal mode?

      • Name *

        Yes it shows I am connected to the Internet in normal mode. I even get an ip address but it will not let me get to any website.

      • DJAM

        Hey Jack,

        I am connected to the Internet but it will not allow me to use the browser. When I access the browser, it say cannot connect. I went in to the CMD and pinged yahoo but all the packets were lost.

        I cannot proceed beyond the step of using the Hitman Pro as I cannot get access to the Internet.

        My computer is showing it is connected to the wireless Internet. Please help.

  • Jeffery

    Thanks a ton.I got hit with this Smart HDD crap and this really helped me out.It’s all gone now.However I do have a question.What if it were to happen again in the future?Acouple of the things used have an expiration date attached to them ie 30 days for HitmanPro.

    • http://malwaretips.com Jack

      First off all , this shouldn’t happen in the first place.. You can build up a solid malware defense with our help ,just start a thread in this forum : http://malwaretips.com/Forum-Security-Configuration-Wizard
      As for the HitmanPro license, well in this 30days you can remove any piece of malware , however you’ll need to buy this product if this period expires. :*( But even after the 30 days trial you can still scan with this product and if it finds anything then you can use another product to remove the threats… :)

  • Hannah

    I followed through all the above steps, I was able to download RKill, I then ran it but when the log came up – a pop-up came up saying “Installation Failed” – i’d used the activation code so i assume it’s not a fake pop-up from the virus. IT appeared to then run, however when it generated the log everything came up like shown above^, however under the heading “Processes terminated by Rkill or while it was running” was blank, and then had “Rkill completed on 25/4/12 etc”
    I tried it a few times too, but each time the same thing happened.

  • Meghan

    I made it all the way to the Deep Scan part of this process and Smart HDD reared it’s ugly head AGAIN! I’m back to square one. I followed the steps to a T, does anyone else have any suggestions? Should I add the step of going into “msconfig” as soon as I’m able and deleting the virus from the start up?

    Help! I was so optimistic, and now I’m just bummed beyond belief.

  • Jeanne

    I just had SMARTHDD pop up on my desktop, now I don’t know how to remove it. I am on my laptop

  • Jeanne

    I have SMART HDD on my desktop, all my files are gone and I don’t know how to remove it.

    • http://malwaretips.com Jack

      Follow this guide…step by step.. don’t skip any step!
      If you have problems removing this rogue , start a thread in this forum : http://malwaretips.com/Forum-Help-my-PC-is-infected
      Under no circumstance should you buy this rogue security software as this could lead to identity theft!
      Good luck!

  • JUANKAGZ

    Excelent info, thanks!

  • Richard G

    SUPERB DOCUMENTATION…..Worked very well user back up & running.. However all his menu items in the allprograms are still empty???

  • Marco

    Great Job, thanks a lot.

  • Caroline

    Thanks so much for this thread! It saved my pc

  • Paul

    Great web site and assistance – while this fix process appears daunting, the links and clear instructions really helped me to fix this issue relatively quickly. In fact I found all this easier and quicker to do than working issues like this through with my anti-virus provider.

    Thank you so much for offering free and helpful assistance against a nasty scam

  • skrill

    tnx alot for this. it worked:)

  • Laura

    Thank you SO much! Your advice worked perfectly and my PC’s running brilliantly!
    Very much appreciated :o)

  • 64bit version of RogueKiler?

    I tried to run RogueKiller but it won’t work. :-(
    Here’s the message I get:
    “RogueKiller.exe is not a valid Win32 application.”
    It won’t run, and all my desktop icons are still missing, shortcuts are still missing, etc. :-(
    Can you help?
    Thanks in advance!

    • http://malwaretips.com Jack

      Did you run the Tweaking.com-UnhideNonSystemFiles.exe utility? Please try to run it again!
      Also did you remove all the infected objects detected by MBAM and HitmanPro? Please run another scan Full System Scan with Malwarebytes to make sure everything is clean!
      If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • Tim

    I tried the above but it is not working.
    Rkill returns a message “access denied” and the log file it shows no processes terminated.
    Thanks

  • bjseriki

    you guyz are the best. I can never forget this and i would like to knw u guyz…. bjseriki is my facebook name, u can add me up :)

    • Alison

      Same thing here – thank you so much for posting this – it only ended up costing me $50 and a few hours of headache! :)

  • Stefan Larsson

    Wery thankful for this information, that helped me rescue a Vista PC that had a bad SMART HDD version.
    All worked fine!

    :-)
    Regards
    Stefan

  • Wes

    Excellent help, thank you! All clean now!

  • Katikuta

    Thank you!! Thank you!! Thank you!! You save my day! Greetings from Germany. :-***

  • Capgun

    Much appreciated folks. However, Malwarebytes didnt get it the first 2 times I tried, it ended up being hitman that nipped it in the bud.

    • http://malwaretips.com Jack

      You can also try to make a scan with Emsisoft Emergency Kit… just to make sure everything is clean… :)

      Download and scan with Emsisoft Emergency Kit

      1. Please download the latest official version of Emsisoft Emergency Kit.

      2. After the download process will finish , you’ll need to unpack EmsisoftEmergencyKit.zip
        [Image: ekk1.png]
      3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
        [Image: ekk2.png]
      4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

        [Image: ekk3.png]

        [Image: ekk4.png]

      5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

        [Image: ekk5.png]

      6. Select “Smart scan” and click-on the below “SCAN” button.

        [Image: ekk6.png]

      7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

        [Image: ekk7.png]

      8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
        Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
        [Image: ekk8.png]
      9. Emsisoft Emergency Kit will now start removing the malicious files.
        If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.
  • Ray

    RKill and HitmanPro did the trick for me.

    Most comprehensive guide on the net for removing this bastard of a trojan.

    To hell with the people behind this scam.

    Thank you once again.

  • Mike

    Thank You! It took a while but your instructions kicked SMART HDD to the curb. The only thing left was the text file stating SMART HDD was successfully registered. My recycle bin and delete key took care of it. Thanks again!!

  • Clare

    Thank you very much! Huge relief.

  • Dalila

    Here are my sincerely thanks from Brazil!

  • John

    you all are amazing! Thank you so much!

  • Ruth

    Thank you SO, SOOO much for your help; I cannot thank you enough. You are a complete hero! xx

  • Valdez LV

    Thank You! Thank You! Thank You! Thank You! Thank You! Thank You! Thank You!
    Donate! Donate! Donate! Donate! Donate! Donate! Donate! Donate! Donate! Donate!

    • http://malwaretips.com Jack

      No need to donate! We’re doing it for the fun!:D
      Stay safe and secure your PC!!!

  • Lori

    My computer has been hit by Smart HDD, I have been trying to run RKILL but I can’t get it to run, please help! I’m not computer savy and really need some help.

  • Miriam

    Thank you so much! You have no ide how greatful I am of this blog and your help!
    I dont know computeres at all, but you made it very easy for me to fix my computer with your step-by-step advices.
    You really made my day!! THANK YOU!

  • Ina

    Once scan with HitmanPro is completed, I get the following message: “iExplore.exe
    There are indications that this file is a threat. However, it can also be benign.Contains high amount of malware related properties. It is potentially malicious software.” There were 5 identified threats.
    When I click Next in order to delete them, nothing happens. After rescanning, it is obvious that the threats were not deleted. Am I doing something wrong?

    • http://malwaretips.com Jack

      Those files are running from the Temporary Internet folder (look at the path) so you need to Quarantine them. :)

      • Ina

        Many thanks Jack. It worked out for me too. Wish you all the best!!! :)

        • http://malwaretips.com Jack

          Thank you for your comment! Stay safe!

      • Atena

        These files, which ones? than the antivirus or viruses? So I still have malware on my PC not having used the safe mode? Kiss!

        • http://malwaretips.com Jack

          No… If you’ve scanned with all the software from the guide and removed the detected threats then you’re good!:D

      • Susan

        I am having this same issue. How do I quarantine these files?

        • http://malwaretips.com Jack

          Next to the ‘Skip’ action there is a little down arrow, press it and you should get the below menu… From there select Quarantine, after the action has been set, press NEXT.

  • Atena

    Hello, I have done all the steps, but since I could not connect in safe mode, I inserted the code, I did a restore of configuration and have done all these operations in normal mode, I found 337 viruses and I deleted them by the book . I have to repeat everything in Safe Mode or I have removed the virus?
    Can I remove all the programs I have downloaded and used on my pc or risk of new infections (some programs are being tested for 30 days or for a single scan).

    ALSO WANTED TO THANK VI ….. IN TIME OF CRISIS YOU DID SAVE ME MONEY … THANKS THANKS THANKS THANKS!

  • Jose

    Finally after a few days of this nightmare, thanks to you guys i have my pc back in order. Thank You for your GENIUS.

  • Greg

    I am hoping you guys can help, I am unable to connect to the internet to get too far into the removal process. I checked the internet settings and the proxy server box is not checked. I know I am connected to the network, when I check the connection it either says connected to unknown network/local access only or connected to unknown network/limited access. Neither one allows me to connect to the internet using IE7. I am using Vista Home.

    Thanks for any help you cool folks can provide,
    Greg

    • Greg

      The reason I say I know I am connected is that when I unplu the router it will say not connected to network and when I replug it goes back to connected to unknown network/local access only or connected to unknown network/limited access.

      Thanks,
      Greg

    • http://malwaretips.com Jack

      This happens when you are in Safe Mode with Networking or in Normal Mode?
      You can get free malware support on our forums : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • Bill

    might work if you could get ti internet explorer
    only options with right click over start are properties and windows explorer
    only programs arw calculator and frostwire 4.20.7

  • Kathy

    after running the unhide non system files.exe…. it looks like most of the icons are back HOWEVER there is now one for the Smart HDD and it is also listed in the program files. NOW what??

    • http://malwaretips.com Jack

      Don’t worry about that,if you did scan with Malwarebytes,HitmanPro and RogueKiller and remove the detected threats then that’s is just an left over icon which you can delete…..
      How’s your PC running? If you have doubts that Smart HDD is installed you can eihter perform a scan with Eset Online Scanner : http://www.eset.com/us/online-scanner/ or start a thread in our support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • Facets

    This took some time but IT WORKED ALL OF IT!!!!! Stay with the directions. I had a few problems downloading from Tweaking.com for the unhide. I had to copy the actual path…listed in one of the posts; http://www.tweaking.com/content/page/unhide_non_system_files.html
    so read all the comments they helped.

  • Hady

    Many many thanks, the problem is fixed now
    YOU ROCK! ;)

  • Matt

    I had to use the Tweaking Unhide System files program after went through all the steps, and ONLY after I was back in normal mode. It then restored all of my desktop items. I tired it in safe-mode and it only restored some icons but in normal mode the program restored all the desktop favs. My system is now clean. Thanks guys. Awesome job.

    • http://malwaretips.com Jack

      Yes,this utility needs to be run in Normal Mode….. :)
      Stay safe!

  • Terrance

    I came home from work today to find out this was on my parents Desktop. I tried doing a system restore to an earlier date, but it wouldn’t allow me to do it. So finally I said screw it and just did a system revert. Now that I found this out after a few hours of re-downloading updates and drivers, I wish I would have found it earlier. Looks so simple too. Damn.

  • KEV

    all worked fine for me, REMOVED
    many thanks

  • Mads

    Worked for me. Wife was ready to call geeksquad.com – saved me $300 :)

    Cheers.

  • Jose

    oooohhhhpppssss

    I meant to say my Desktop Icons have not reappeared on my desktop, how can i get them back?????

    • http://malwaretips.com Jack

      Did you follow Step 7?Please try to run it again.
      If it still doesn’t work,click the Start button in the lower left corner of your task bar. Type cmd in the search box at the bottom of the menu and press Enter. If you’re using Windows XP, click Run and type cmd into the Run box.
      Type attrib -s -h -r c:/*.* /s /d and press Enter to execute the command.

      • Jose

        Hi Jack, yes i ran step 7 to no effect, please help……

      • Jose

        Hi once again i did the dos command and it reported ACCESS DENEID, WHAT THE $&#@? does that mean???

  • Jose

    Thanks alot for this very impressive guide, i followed all the instructions to the letter and got my pc back, but in the end i cant get my icons back. what can i do???? please help. thanks

  • Roshan

    Thank you so much..This was really help for me…SMART HDD, you are not smart any more…Thanks again…

  • hayden

    i put it into safe mode with networking then i cant find internet explorer anywhere

    • http://malwaretips.com Jack

      Press Ctrl + Shift + Esc at the same time to open Task Manager and then go to File > New Task(Run) > and type in : Iexplore

  • Blake

    Just wanted to say thank you, all the dickfaced hackers out there making programs like Windows 2000 or Smart HDD piss me off; just leave me alone. Guys (gals) like you who come up with ways to fix these problems deserve something…I don’t know, you just make life easier. I have nothing to offer other than thank you; you’ve made a difference for good in the world which is more than the majority of us can say.

  • T

    Another reason to get a Mac – no viruses in 10 years.

  • Ken

    Uninstalled maywarebytes with clean.exe and reinstalled
    Malwarebytes several times. I keep getting the same error: “Error
    creating register key:
    HKEY_LOCAL_MACHINE\Software\\Malwarebytes’Anti-Malware

    RegcreateKeyEx failed; code 5. Access is denied.

    Any tips?? Thanks!

  • D

    Have worked on this for three days. Managed to “restore” almost all the links to my files but everything was called (2). I could have lived with it but it made me lose my help and support. I am so glad to have it back. Can’t thank you enough.

  • Paul

    All worked till hitman my free trial one screen says i have 31 days and the next says it expired! Any thoughts?

  • Scott

    the virus won’t let me access internet explorer but I can get on the internet with Mozilla. Can I do this whole process with Mozilla? Thanks

  • Samuel Malonja

    It took longer but worked perfect, thank you sooo much cause i was almost getting crazy about my new computer!!

  • Kevin

    Its ike badda bing fixed!!Hopefuly Thanks

  • LeonD

    Great guide. Great follow-up on issues. The one part I didn’t see addressed was the missing icons in start/programs. Another site mentioned that this nasty hides files in the Windows Temp folder.

    Look in C:\Documents and Settings\%user%\Local Settings\Temp\smtmp\

    Copy the contents of /1 to:
    C:\Documents and Settings\%user%\Start Menu

    Copy the contents of /2 to:
    C:\Documents and Settings\%user&\Application Data\Microsoft\Internet Explorer\Quick Launch

    There’s also a Smart HDD link left over on the desktop and in quick launch that can be manualkly deleted.

    I hope that helps.

    • JUANKAGZ

      In order to fix your Menu in Windows 7….

      Look into %userprofile%\AppData\Local\Temp\smtmp

      Copy the contents of \1 to:
      %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu

      Copy the contents of \4 to:
      C:\Documents and Settings\%user&\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu

  • Henri

    Awesome, thanks a million :)

    Do you have any tips as to how to prevent stuff like this from getting onto my PC to begin with? I have McAfee total protection with automatic updates. Obviously that doesn’t give me enough protection.

  • Jo Ann

    Whew! We went through all the steps, it took forever but it worked! Yay! Thank You! Thank You!

  • roberto

    Thank you so much this really helped. The only problem now is that the icons on the bottom of my taskbar are huge and not seem right, any way of putting them back to normal?

  • Bill

    I got it when I was trying to go to a legit website. It popped up as “Microsoft Security Essentials has identified a Malware attack. Do you want to isolate/remove it?”

    Thank God for my IT guy Pat!

    • http://malwaretips.com Jack

      Yes, that’s how a rogue software acts!;D
      Quick tip… Drop MSE.. it just sucks…. instead go with Avast 7 Free ;) …..
      For more tips on how to build up your security configuration , start a thread in this forum : http://malwaretips.com/Forum-Security-Configuration-Wizard

  • Name *

    How does a blog describe everything i am going through and give a solution to the problem???…. Great job!! ….This worked like a charm!!! Thank you so much!…BTW i got the virus from …//1channel.ch… in the name of watching free movies, it recommended a plug in for my windows media player..BAM!!!… i learned my lesson the hard way!!!!.. go with Netflix people!!!

  • Sha

    I just got this virus on my comp last night and tried restarting my comp and it will NOT REBOOT! it shows the hp logo and then goes blank after that. I am extremely sad. i have no idea what to do. i tried pressing esc for the startup menu but there is no option for safe mode whatsoever and the F8 button does not work. what do you suggest i do??

    • http://malwaretips.com Jack

      With some computers, if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the “F8 key”, tap the “F8 key” continuously until you get the startup menu.
      If that doesn’t work then you’ll need to create a bootable disk : http://malwaretips.com/blogs/how-to-use-kaspersky-rescue-disk/

  • Jill

    I can’t get the Hitman Pro to give me the option for a 30 day free trial.

    • http://malwaretips.com Jack

      That never happen to me …. you can try to re-download the installer (make sure that it’s for your system architecture) …. If you are still experiencing problems than you can start a thread in this forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • aria

    Thank you very much , i followed your steps and removed this virus, thank you for your compelet guide and help.You are great. ;)

  • Vince

    Downloaded the TDSSKiller, renamed it. Internet connection was lost shortly after. Ran the app, but get a message:

    ” The application failed to initialize properly (0xc0000005). Click on OK to terminate the application. ”

    Thoughts?

  • Rick

    Thank you for these straight-forward and easy to follow instructions!

  • Mari

    OMG what a time sucker! Thank you SO much for this free advice! I “think” I’m restored! Do you have advice on how to prevent this in the future? Best firewall or other anti virus software? Never never had a virus that affected my PC before…never never want to again!

    • http://malwaretips.com Jack

      Any security setup should be customize to the level of the knowldge of the user, so I would strongly advise you to start a thread in this forum and we will help you build up a very solid malware defense!
      http://malwaretips.com/Forum-Security-Configuration-Wizard

  • Frederik

    Hello there i install the tddkiller.exe and rename it to iexplore.exe but it just wont open?

    • http://malwaretips.com Jack

      Replace this step with the HitmanPro scan.. if it doesn’t start use the Force Breach mode… you have all the instructions above…
      If you can’t remove it then you can start a thread in this forum and we will help you remove it….
      http://malwaretips.com/Forum-Help-my-PC-is-infected

  • Cris

    Hi, Guys,

    Thank you, thank you and thank you very much fot this complete guide to remove that hell of thing called “smart hdd”. At first, I thought it was reaaly a problem, but soon I realized it was a hell of a virus or sort of think. I found your page thanks to my iPad, trying to find a way to get rid off the plague, because I coudn’t find not even the browser in my Dell Notebook.

    I did all the steps and after an entire night without sleep, I finally restored my Dell. Thank you very much!

    I any case, I bookmarked this web page for fuure reference!

  • Mike

    Thanks for this! Great instructions that worked perfectly.

  • Indy

    How often should this process be done to keep from having any other of these stupid malware viruses? This is my second one in 2 days and I HAVE software to keep an eye out for it (maybe it’s outdated?). Thanks :-)

    • http://malwaretips.com Jack

      Seems like you didn’t remove it… Make sure everything is checked before pressing the Remove Selected button……
      If it still happens please start a thread in our free malware removal support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • Kat

    Everything went well until I got to the unhide.exe. bleepingcomputers.com site won’t open for me.

    Now what do I do? I’d appreciate any help I can get. This virus is a biatch.

    Thanks so much! :D

  • Walmara

    Very very very nice!!!!! Thanks!!!!

  • Just me

    Thank you!!! You are a star! :-)

  • Craig U.

    You are AWESOME, thank you for saving my laptop you are worth your weight in gold.

    I thought everything was lost due to that POS smart hdd infection, I followed your fix completely and all the years of pics and videos along with everything else came back to normal.

    I owe you a big steak dinner

  • Lee

    I am unable to get past steps 5 or 6 in this. Running the TDSSKiller and the RKill doesn’t find anything when in SafeMode either.

    The problems begin after installing Malwarebytes. First it wants to update the Malware Data – it begins this process automatically after I click finish on the install, but then the software becomes unresponsive. It says that it’s connecting to a server, but never gets past that. So, I tried everything from the top after uninstalling Malwerebytes to see if I could bypass the software update (figured it may be bogus), and was successful in that. However, starting the scan of the computer again made the software unresponsive, and I can simply not get it to run.

    Having read some of the comments here, I figured… let’s run HitmanPro first then. But, the Next button that I’m supposed to click is greyed out, and so I’m getting nowhere with that one as well.

    So… Now what do I do?

    • http://malwaretips.com Jack

      If you have Malwarebytes installed , you can use the Chameleon procedure to update and scan with it….

      1.Open the Task Manager, click on File at the top and choose New Task (Run…)
      2.Click on the Browse… button
      3.Navigate to the folder where Malwarebytes Anti-Malware is installed (normally C:\Program Files\Malwarebytes’ Anti-Malware or C:\Program Files (x86)\Malwarebytes’ Anti-Malware)
      4.Open the Chameleon folder
      5.Click on the drop-down menu that says Programs and choose All Files
      6.Double-click on the Chameleon.chm file (it will look like a help file)
      7.Once the Help file opens, click on each Test Now button until you see a black DOS/command prompt window that remains open and says MBAM-chameleon ver. 0.1 at the top
      This should start a MBAM scan

    • http://malwaretips.com Jack

      You can also post a help request in our malware assistance forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  • zad dong

    Hello I have tried to follow the instruction. But I downloaded TDSSKiller and had ran it. The problem is that it didn’t detect anything. I also ran Rkill, it seemed to have grabbed a bunch of stuff, but it couldn’t do anything, because the “file is used by another process…”

    My O/S is Windows 7 Ultimate.

    Thanks!

  • Jeanne

    Wow, this is the most comprehensive list of tools and help I have ever seen. Thanks so much for putting it together and figuring it all out. It is most appreciated. ; D

  • Ricardo J.

    I am an expert in virus and I must say this “step-by-step” works perfectly I didnt have to overthink.
    My desktop is back to normal and my computer ready to be used. Thank you very much.

  • Lexx

    Well my computer is up and running but i can’t access my windows firewall nor window defender it seems like they both have errors.

  • Janet

    Brilliant! Excellent easy to follow instructions that WORKED. Thank you so much . I am very computer savvy, but without this step by step consise written help, it would have meant searching for ages on the net to find a solution.Luckily we have 3 computers so I was able to follow things on a laptop alongside the affected pc. It was on our main desktop pc on my partners side. We have it set up for 2 users. My side was ok apart from it had hidden my precious graphic files and documents. I already knew how to reveal them again so that was soon sorted before I followed the instructions on here to remove the smart hhd. It was a case of ‘you’ll have to sort the pc out’ words uttered by my partner as he has no idea about the techie side of computers lol. Just as well I have more idea and love the techie stuff.
    Anyway, all back as it was now thnaks to you great guys.
    Thanks again!

  • S R

    Thanks much – this got me through cleaning up my PC

  • tom elk

    thanks so much

  • Suzanne

    I was in real panic but thanks for the instructions, my computer is clean and working as it should!

  • Max

    Thank you so much!!!! The guide was easy to follow and worked like a charm. This has saved me a lot of trouble!!

  • KV

    Almost back THANKS only thing wrong now is if I go the Programs…and like Microsoft Office it shows “empty”… but if I search for Excel etc its there.. most of the folders show empty I have run Unhide 3 X…. ideas???

    • spontan

      first at all, thanks a lot for the help!!!!!
      I’ve got the same problem with the programs (they still show emty!). any idea?

  • Kristen

    This worked miracles. THANK YOU SO MUCH!!!

  • Brett

    Thank you very much for this guide, my younger brother got the virus and considered wiping the hard drive after system restore failed, but then I found this. This guide was helpful in every aspect, and now I taught him not to go on bad sites.
    Thanks again!

  • Laust

    Thanks a lot for the easy to follow instructions.
    Got infected on April fools day, found your website and cleared my laptop up the next day.
    Some desktop icons had disappeared though, but maybe it was time to clean it up anyway.
    However I cannot change start-up programs as it gets blocked by the following message:
    “Windows Defender encountered an error: 0x80070424. The specified service does not exist as an installed service.”

  • A.R., from France

    This uninstallation needed time, but was fully successful. Thank you for your precise, complete, easy-to-use and useful removal guide !

  • Tash

    my laptop keeps shutting off halfway through the malware scan, the other steps worked fine but I can’t seem to get to the end of that step. Any suggestions? Thanks

  • cablebug

    thank you!i followed all the steps and cleaned up my computer.
    thanks again!

  • Megan

    I tried to do the F8 and my computer just beeped really loudly and so after a minute of this I forced a shut down. When I turned it back on it said my computer didn’t start properly and ran a scan and luckily I had backed up my computer last month and when it ran the scan it asked if I wanted to try and recover to an earlier version and I said yes. It took 10 min or so but i got back on my computer and everything is working so far but i still have the SMART HDD License note on my desktop. Did this get rid of the virus? or should I do something else? Thank you for your help.

    • http://malwaretips.com Jack

      No, this rogue software is still on your machine.Please follow the above removal guide.
      Try instead of pressing and holding the “F8 key”, tap the “F8 key” continuously until you get the startup menu.Please do this before the Windows logo appears.

  • Lee

    Can you just do a system restore to a previous date?

    • http://malwaretips.com Jack

      No, you need to remove it…..A System Restore can’t remove this infection.

  • KV

    Have tried using the guide but when I attempt to install Malwarebytes I get ACCESS DENIED…. ???

  • Al

    This fix worked perfectly!! Thank you so much!!

  • Dustin Hobbs

    Thanks so much. Computer seems to be working great. I still have a S.M.A.R.T HDD icon on my desktop and in the programs menu…how should I remove these?

  • Jacob

    Thanks a lot. It was a great help.
    I still have one problem.
    I have got the links back on the Start Menu, but NOT the links to most of the programs in under the ‘All programs’. My PC runs XP. For instance all the preinstalled games like ‘Spider’ are gone from the Start Menu.
    Is there an easy way to get them back.
    But still – thanks a lot for the help!

  • MEE

    This was a great tutorial–thanks so much! I almost fell into the trap of clicking on the SMART HDD popups until I realized they had a spelling error in their message. It’s nice to turn on my computer and not have it go crazy!

  • dave

    The procedure worked “almost” perfectly. One big problem though…

    Only remaining problem is that I have no file management capability beyond creating a new file/folder. I can’t move, delete or rename any files/folders. When I try, I get msg saying “Cannot delete (or move or rename) xxx. Access is denied. Make sure that disk is not full or write-protected and that the file is not currently in use.”

    Saving a doc from MS Word or Excel gives me the message that “Word cannot complete the save due to a file permission error”

    I followed all the steps and had to run the “unhide” program as well. Is there something else I should look at?

    Thanks for the great write-up, and any thoughts you might have on this problem.

  • Jill

    Thank you so much for the help. I performed all of the above steps, however, none of my documents, pictures or videos are showing. Also, the S.M.A.R.T HDD icon is still showing on my desktop. Did I not remove the virus? Thank you.

    • http://malwaretips.com Jack

      Did you remove the malicious objects that were detected by the on-demand scanners?
      If you don’t see your files and folders then run again Unhide.exe, wait until the log is genarated… please note that this may take awhile!

      • Jill

        I removed all malicious objects and everything that was suggested to remove. I will try to run the Unhide.exe again. Does it take several hours or all day? Thanks so much for your help. This was scary.

  • SDG

    When I woke up this a.m. and needed a Remove START HDD For Dummies you guys were there to provide it. It was a process, but it worked and was well worth it. Thanks a bunch and keep up the good work!

  • Thomas Y

    Hey. Thanks for all the tips and advices here! I just have a quick question. When I run the microsoftfixit, it gives me a error.
    The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2738.
    How do you fix this? I think my host files are still infected.
    Thanks!

  • Bill

    You can regain control of most of your computer by entering the registration code shown at http://malwaretips.com/blogs/uninstall-smart-hdd/ This means you can regain control of Task Manager, Registry Editor, and Windows Explorer (see below)

    “As an optional step,you can use the following license key to register Smart HDD and stop the fake alerts.
    15801587234612645205224631045976
    Please keep in mind that entering the above registration code will NOT remove Smart HDD from your computer , instead it will just stop the fake alerts so that you’ll be able to complete our removal guide more easily.”

    I also ran my antivirus scanner, which did NOT however identify this malware as a virus or shut it down. However, once I regained control of my computer, I activated Task Manager and shut down the process I could not identify (Bsy05V4MFLu7iT.exe). This shut down the malware.

    A File Search on Bsy05 led to some very recently installed files, which I deleted. I also deleted everything associated with Bsy05V4MFLu7iT in my Registry Editor.

    My computer now seems under control, and I can see my files although several icons are still missing from my desktop. The fact that using Task Manager to kill Bsy05V4MFLu7iT.exe shut down the malware suggests however that this is a good solution.

    I also reported this incident as Internet crime to the FBI (http://www.ic3.gov/default.aspx) because, as far as I know, it is a felony to install a virus on another person’s computer. I pointed out very specifically that the program kept me from accessing my control panel, Task Manager, and most of my file system.

    Caveat: I am NOT a computer professional. What worked for me was use of the registration code (I did not give my real E-mail address when “registering,” by the way, and I suggest you don’t either) to regain control of File Manager (or Windows Explorer) and the Registry editor, and Task Manager. Task Manager identified the unidentified process, and shutting it down shut down the malware. I used the identity of the process shown by Task Manager to delete all files and registry entries associated with Bsy05V4MFLu7iT.exe. The fact that the file was installed at the time the problem began shows that this is the problem file, and its removal should fix the problem.

  • Amanda

    Thanks so much. This really helped me get my netbook clean.

  • SamFunyun

    Thank you so much for this really really thank you!!!!!!!^_^ I WUB YOU FOR THIS!!!!^O^

  • Kristine

    Lovely. THANK YOU SO MUCH!

  • Zibersbaze

    Thank you for the tools and instructions, they solved my (sons) PC problem.
    By the way, my Mac ClamXav identified iExplorer and RKILL as Trojan.Hupigon-33703 malware, which felt a bit like driving out the devil with the belzebub.

  • Veerudu

    Thanks a lot! Works great!!

  • Stephanie

    Thank you for posting this step by step removal guide. It worked for me, and most importantly it save me $100 which is the amount Microsoft wanted to charge me to remove this virus. The only issue Im having is that when I click on the start menu my control panel list is still missing. I followed the link you gave and did Step 8 (Windows Repair All In One utility step ), but it did not work. Do you have any other possible solutions for this issue?

    • http://malwaretips.com Jack

      Here is what you need to do : Click the Windows Start button and right click on the menu …. it will open up the “Taskbar and Menu properties” from it ..select Customize and then a new window will open…. Select to display as link or menu each time you need….
      http://imgur.com/u5wlb

      • Stephanie

        Thank you so much!!

  • Carlie

    In step 3, when I click on iexplore.exe nothing happens – please help!

    • http://malwaretips.com Jack

      Replace the Kaspersky Scan with the HitmanPro scan…… If it doesn’t start use the Force Breach mode in HitmanPro ( all instructions are in step 6)

  • Chris

    Thanks, Malwaretips … saved my butt! This worked great! Now, I’m off to beat my children who probably downloaded this virus with their Jason Breibers and their Madame Graga or whatevers.

    • http://malwaretips.com Jack

      LOL. :D you can post in our Security Wizard forum and build a solid security config for him.. stay safe!

  • Reilly

    I cannot download Malwarebytes, and I cannot run Kasperky. Why Windows Explorer keeps restaring even in Safe Mode. I tried a system restore but it stays in the initializing screen for hours. Can anyone help me?

  • helpme

    Thank you for the well written instructions. However, they do not work for me. In step 3, the Kaspersky TDSSKiller won’t run even after renaming. Do you have any further advice?

    • helpme

      Following the advice given for the previous comment, after skipping to step 6, HitmanPro 3.6 Build 151 didn’t find anything. No threats, it says.

    • http://malwaretips.com Jack

      Replace this step with the HitmanPro scan….. Use the ForceBreach Mode if it doesn’t start ( instructions are in step 6) ..
      Please note that HitmanPro will detect some explorer.exe file running from temp files…. and will flag them as suspicious but it won’t move the for removal… You need to remove them by selecting ‘Quarantine’

  • Alan

    A very detailed explanation, thank you. I was able to get to step 3 and complete that step, but now when I try to reboot in safe mode by pressing F8 it just hangs there. Any ideas ? Thanks

  • Kelly

    I followed the steps and got rid of Smart HDD but my icons are still messed up eg. my smart menu icons are missing.

  • Anton + Ana

    Totally top drawer explanation :) 10/10!! The people who make these Trojans should be.. well.. I will leave that up to you guys to imagine your own punishments :)

  • Rhonda

    Help! When I shut down my computer and tried to start it in safe mode I get “Missing operating system”.

  • Jim

    Thanks a million for posting this guide up! It certainly has saved me hours, if not days, of getting this nasty thing off my computer!

  • sam

    After finishing step 6… system would not start. I have to do startup repair… to take back to a point of smart hdd again. What should i do

  • Pat

    I can’t seem to get pass STEP 3, No. 2: After I rename it, “iexplore.exe” and double click, it asks for an administrative password and once I enter it, I’m getting a message box, THE EXTENDED ATTRIBUTES ARE INCONSISTENT. Please help…thanks!

    • http://malwaretips.com Jack

      Skip this stepfor now a download and run a scan with HitmanPro… please note that if it doesn’t start you can use the Force Breach mode, you have all the instructions in Step 6.
      After this step please run the malwarebytes scan.

  • R

    thanks much for the guide.

  • Ed

    Thanks so much guys, excellent guide, keep up the great work.

  • Rodrigo

    Sorry for my other message.. I found you “firefox guide” below the IE guide.. If you can delete the other and this comment.

  • Rodrigo

    I’m with this error now, i was doing the steps but i’m in the firefox.. and I can’t finish the step 2. Please help me. Sorry for the English.

    • http://malwaretips.com Jack

      Just use Internet Explorer….it’s installed by default with Windows… you should have it installed… :)
      However if you really want to do it with Firefox : go to Firefox(upper left corner) → Options → Advanced tab → Network → Settings → Select No Proxy

  • Dave

    You folks are heroes, plain and simple. Cheers and thank you so much for your excellent work!

  • Thariq

    Gr8 guide..it’s does what it says..Thanks a lot for the help

  • John21

    Thanks! been trying for ages to remove it. by the way when i click the start menu, the control panel list doesn’t show up, any ideas why?
    thanks again :)

  • Anon2

    Thank you so much!!! Worked great. If this fifty-something year old housewife with limited computer knowledge can fix that mess using your steps, I would think anyone would be able to.

    • http://malwaretips.com Jack

      Hehe, glad it worked! Now …. don’t randomly run files… ;D Always keep in mind from where you’ve got the file before allowing to run … AND SECURE YOUR PC!:D
      Stay safe!

  • Anon

    Thanks! Instructions worked great!

  • bagus

    work smoothly ….. recommended!!!
    just follow it step-by-step.

    • http://malwaretips.com Jack

      Thank you for the comment!;D
      You can join our community and build up your malware defenses …. infections shouldn’t happen ;)D

  • http://malwaretips.com Jack

    Try to reset Internet Explorer options….. Go here : http://malwaretips.com/blogs/remove-whitesmoke-translator/ : and check step 3 to see how to reset IE to its default settings..

  • SamPD

    By the way, unhide is NOT supported on Windows 7.
    Other than that though, I just about completely purged the virus.
    Only the program file icon remains however, so I want ot be on the safe side.
    What should I do?

  • http://malwaretips.com Jack

    Delete the icon and perform a system check with ESET online scanner : http://www.eset.com/us/online-scanner/