Uninstall Smart HDD

Smart HDD is a malicious software that will display fake alerts, claiming that several hard drive errors were detected on your computer.The alerts are professional looking pop-ups and when you click on them, you’re advised to buy Smart HDD in order to fix this errors.
In reality, none of the reported issues are real, and are only used to scare you into buying Smart HDD and stealing your personal financial information.
If you’ve got a Smart HDD infection , you’ll be seeing this screens :

[Image: Smart-HDD.png]

Registration codes for Smart HDD

As an optional step,you can use the following license key to register Smart HDD and stop the fake alerts.
15801587234612645205224631045976
Please keep in mind that entering the above registration code will NOT remove Smart HDD from your computer , instead it will just stop the fake alerts so that you’ll be able to complete our removal guide more easily.
We strongly advise you to follow our Smart HDD removal guide and ignore any alerts that this malicious software might generate.Under no circumstance should you buy this rogue security software as this could lead to identity theft.

Removal guide for Smart HDD

STEP 1 : Start your computer in Safe Mode with Networking

  1. Remove all floppy disks, CDs, and DVDs from your computer, and then restart your computer.
  2. Press and hold the F8 key as your computer restarts.Please keep in mind that you need to press the F8 key before the Windows  start-up logo appears.
  3. On the Advanced Boot Options screen, use the arrow keys to highlight Safe Mode with Networking , and then press ENTER.
    [Image: Safemode.jpg]
  4. Log on to your computer with a user account that has administrator rights

STEP 2: Remove Smart HDD malicious proxy server

Smart HDD may add a proxy server which prevents the user from accessing the internet,follow the below instructions to remove the proxy.

  1. Start Internet Explorer [Image: Smart HDD- IE] and if you are using Internet Explorer 9 ,click on the gear icon   [Image: IE gear icon] (Tools for Internet Explorer 8 users) ,then select Internet Options.
    [Image: Internet-options-IE.png]
  2. Go to the tab Connections.At the bottom, click on LAN settings.
    [Image: Remove-proxy-server2.png]
  3. Uncheck the option Use a proxy server for your LAN. This should remove the malicious proxy server and allow you to use the internet again.
    [Image: Remove-proxy-server3.png]

If you are a Firefox users, go to Firefox(upper left corner) → Options → Advanced tab → Network → Settings → Select No Proxy

STEP 3: Run RKill to terminate known malware processes associated with Smart HDD.

RKill is a program that attempts to terminate any malicious processes associated with Smart HDD ,so that your normal security software can then run and clean your computer of infections.

As RKill only terminates a program’s running process, and does not delete any files, after running it you should not reboot your computer as any malware processes that are configured to start automatically will just be started again.

  1. While your computer is in Safe Mode with Networking ,please download the latest official version of RKill.
    [Image: download-rkill.png
  2. Double-click on the RKill iconin order to automatically attempt to stop any processes associated with Smart HDD.
    [Image: run-rkill-1.png]
  3. RKill will now start working in the background, please be patient while the program looks for various malware programs and tries to terminate them.
    [Image: run-rkill-2.png]
    IF you receive a message that RKill is an infection, that is a fake warning given by the rogue. As a possible solution we advise you to leave the warning on the screen and then try to run RKill again.Run RKill until the fake program is not visible but not more than ten times.
    IF you continue having problems running RKill, you can download the other renamed versions of RKill from here.
  4. When Rkill has completed its task, it will generate a log. You can then proceed with the rest of the guide.
    [Image: Smart HDD rkill3.jpg]

WARNING: Do not reboot your computer after running RKill as the malware process will start again , preventing you from properly performing the next step.

STEP 4: Remove Smart HDD malicious files with Malwarebytes Anti-Malware FREE

  1. Please download the latest official version of Malwarebytes Anti-Malware FREE.
    download Malwarebytes
  2. Install Malwarebytes’ Anti-Malware by double clicking on mbam-setup.
    [Image: malwarebytes-installer.png]
  3. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware checked. Then click on the Finishbutton. If Malwarebytes’ prompts you to reboot, please do not do so.
    [Image: install-malwarebytes.png]
  4. Malwarebytes Anti-Malware will now start and you’ll be prompted to start a trial period , please select ‘Decline‘ as we just want to use the on-demand scanner.
    [Image: decline-trial-malwarebytes.png]
  5. On the Scanner tab,please select Perform full scan and then click on the Scan button to start scanning your computer for any possible infections.
    [Image: malwarebytes-full-system-scan.png]
  6. Malwarebytes’ Anti-Malware will now start scanning your computer for Smart HDD malicious files as shown below.
    [Image: malwarebytes-scanning.png]
  7. When the scan is finished a message box will appear, click OK to continue.
    [Image: malwarebytes-scan-finish.png]
  8. You will now be presented with a screen showing you the malware infections that Malwarebytes’ Anti-Malware has detected.Please note that the infections found may be different than what is shown in the image.Make sure that everything is Checked (ticked) and click on the Remove Selected button.
    [Image: malwarebytes-scan-results.png]
  9. Malwarebytes’ Anti-Malware will now start removing the malicious files.If during the removal process Malwarebytes will display a message stating that it needs to reboot, please allow this request.
    [Image: malwarebytes-reboot-prompt.png]

STEP 5: Double check your system for any left over infections with HitmanPro

  1. This step can be performed in Normal Mode ,so please download the latest official version of HitmanPro.
    [Image: Download Hitman Pro]
  2. Double click on the previously downloaded file to start the HitmanPro installation.
    [Image: hitmanpro-icon.png]
    NOTE : If you have problems starting HitmanPro, use the “Force Breach” mode. Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the malware process. (How to start HitmanPro in Force Breach mode – Video)
  3. Click on Next to install HitmanPro on your system.
    [Image: installing-hitmanpro.png]
  4. The setup screen is displayed, from which you can decide whether you wish to install HitmanPro on your machine or just perform a one-time scan, select a option then click on Next to start a system scan.
    [Image: hitmanpro-setup-options.png]
  5. HitmanPro will start scanning your system for malicious files. Depending on the size of your hard drive, and the performance of your computer, this step will take several minutes.
    [Image: hitmanpro-scanning.png]
  6. Once the scan is complete,a screen displaying all the malicious files that the program found will be shown as seen in the image below.After reviewing each malicious object click Next.
    [Image: hitmanpro-scan-results.png]
  7. Click Activate free license to start the free 30 days trial and remove the malicious files.
    [Image: hitmanpro-activation.png]
  8. HitmanPro will now start removing the infected objects, and in some instances, may suggest a reboot in order to completely remove the malware from your system. In this scenario, always confirm the reboot action to be on the safe side.

STEP 6: Unhide your files and folders

Smart HDD modifies your file system in such a way that all files and folders become hidden, to restore the default settings , you’ll need to run the below program.

  1. Download Unhide.exe, to unhide your files and folders.
    Download Unhide.exe
  2. Double-click on the Unhide.exe icon on your desktop and allow the program to run.The whole process should not take more than 5 minutes to complete,and at the end this utility will generate a report.
    Unhide files utility

STEP 7 : Restore your shortcuts and remove any left over malicious registry keys

Smart HDD has moved your shortcuts files in the Temporary Internet folder and added some malicious registry keys to your Windows installation , to restore your files we will need to perform a scan with RogueKiller.

  1. Please download the latest official version of RogueKiller.
    download RogueKiller
  2. Double click on RogueKiller.exe to start this utility and then wait for the Prescan to complete.This should take only a few seconds and then you can click the Start button to perform a system scan.
    [Image: roguekiller-1.png]
  3. After the scan has completed, press the Delete button to remove any malicious registry keys.
    [Image: roguekiller-2.png]
  4. Next we will need to restore your shortcuts, so click on the ShortcutsFix button and allow the program to run.
    [Image: roguekiller-1.png]

STEP 8: Get your desktop look back!

Smart HDD changes your desktop background to a solid black color,to change it back to default one follow the below instruction.

    • Windows XP : Click on the Start button and then select Control Panel. When the Control Panel opens, please click on the Display icon. From this screen you can now change your Theme and desktop background.
    • Windows 7 and Vista : Click on the Start button and then select Control Panel. When the Control Panel opens, please click on the Appearance and Personalization category. Then select Change the Theme or Change Desktop Background to revert back to your original Theme and colors.

If you are still experiencing problems while trying to remove Smart HDD from your machine, please start a new thread in our Malware Removal Assistance forum.

What’s next? Join our amazing community and build up your malware defenses !

How to Stay Safe Online

Here are 10 basic security tips to help you avoid malware and protect your device:

  1. Use a good antivirus and keep it up-to-date.

    Shield Guide

    It's essential to use a good quality antivirus and keep it up-to-date to stay ahead of the latest cyber threats. We are huge fans of Malwarebytes Premium and use it on all of our devices, including Windows and Mac computers as well as our mobile devices. Malwarebytes sits beside your traditional antivirus, filling in any gaps in its defenses, and providing extra protection against sneakier security threats.

  2. Keep software and operating systems up-to-date.

    updates-guide

    Keep your operating system and apps up to date. Whenever an update is released for your device, download and install it right away. These updates often include security fixes, vulnerability patches, and other necessary maintenance.

  3. Be careful when installing programs and apps.

    install guide

    Pay close attention to installation screens and license agreements when installing software. Custom or advanced installation options will often disclose any third-party software that is also being installed. Take great care in every stage of the process and make sure you know what it is you're agreeing to before you click "Next."

  4. Install an ad blocker.

    Ad Blocker

    Use a browser-based content blocker, like AdGuard. Content blockers help stop malicious ads, Trojans, phishing, and other undesirable content that an antivirus product alone may not stop.

  5. Be careful what you download.

    Trojan Horse

    A top goal of cybercriminals is to trick you into downloading malware—programs or apps that carry malware or try to steal information. This malware can be disguised as an app: anything from a popular game to something that checks traffic or the weather.

  6. Be alert for people trying to trick you.

    warning sign

    Whether it's your email, phone, messenger, or other applications, always be alert and on guard for someone trying to trick you into clicking on links or replying to messages. Remember that it's easy to spoof phone numbers, so a familiar name or number doesn't make messages more trustworthy.

  7. Back up your data.

    backup sign

    Back up your data frequently and check that your backup data can be restored. You can do this manually on an external HDD/USB stick, or automatically using backup software. This is also the best way to counter ransomware. Never connect the backup drive to a computer if you suspect that the computer is infected with malware.

  8. Choose strong passwords.

    lock sign

    Use strong and unique passwords for each of your accounts. Avoid using personal information or easily guessable words in your passwords. Enable two-factor authentication (2FA) on your accounts whenever possible.

  9. Be careful where you click.

    cursor sign

    Be cautious when clicking on links or downloading attachments from unknown sources. These could potentially contain malware or phishing scams.

  10. Don't use pirated software.

    Shady Guide

    Avoid using Peer-to-Peer (P2P) file-sharing programs, keygens, cracks, and other pirated software that can often compromise your data, privacy, or both.

To avoid potential dangers on the internet, it's important to follow these 10 basic safety rules. By doing so, you can protect yourself from many of the unpleasant surprises that can arise when using the web.

364 thoughts on “Uninstall Smart HDD”

  1. Hello Craig,
    Below you can find some quick suggestions on what security products I would recommend:
    Free – Avast 7 Free version or COMODO Internet Security
    Paid : Norton Internet Security,Avast Internet Security,G-DATA Internet Security or Kaspersky Internet Security.
    Anyway ,you should really start a thread in our Security Configuration forum as you need to build a layered security config: http://malwaretips.com/Forum-Security-Configuration-Wizard

    Also it would very good if you took the time and read this article that I’ve wrote: http://malwaretips.com/blogs/how-to-easily-avoid-pc-infections/ .. If you follow it,then we’ll never meet again in this conditions:)

  2. thanks for this, i got nailed with this virus, it got through my eset and i have no idea how. so now im installing kerpaskey hoping thats better,

  3. Hello Joseph,
    You can ignore the warning from McAfee as it’s only a false positive.However,if you don’t want to do that ,you can use this alternative tool.
    ESET Online Scanner is a similar tool to RogueKiller.Here are the instructions on how to perform a scan:

    1. Download ESET Online Scanner utility.
      ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
    2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
    3. Check Yes, I accept the Terms of Use
    4. Click the Start button.
    5. Check Scan archives
    6. Push the Start button.
    7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    8. When the scan completes, push Finish
  4. i try to download roguekiller and unhide. mcafee tells me that the site isn’t safe? is this normal or is something up with mcafee??

  5. I REALLY need some help. I got this darn virus yesterday and I have pctools installed on my computer. Nothing is working. I just found this blog and wanted to try the steps but now the virus isn’t letting me log into windows! It says that my password is wrong when I haven’t changed it. And just a few minutes before I was able to run SUPERantispyware in safemode and then rebooted. So I have no clue what do to now.

  6. This walk through was very useful. I had already tried the method on a ask Microsoft forum but the PC was still infected and I had seriously considered formatting but thanks to this guide all is well. Thank you very much.

  7. Hey Stelian, you rock man! Brilliant explanations and great tutorial! Thanks very much! This smart HDD was a pain….Keep up the good work… Otis

  8. I know this is repetitive with previous comments, but this tutorial is fantastic and it worked like a charm. THANKS A BUNCH STELIAN!!

  9. Karla to remove this infection we will need an Administor account… Can’t you remember your password?

  10. What do I do if I have this virus and I don’t have access to the administrator account and no one knows the password to it? Because I’m sure it’ll ask me to enter the pw if I’m trying to download the files above..

  11. Hi, there are no words enough to say thank you for your help. My Laptop all of a sudden contracted a HDD smart infection so bad I thought I might have to have it serviced. As I said no words are enough to show gratitude, but thank you thank you.
    Al

  12. Thank you so much for your helpful and informative save. i was able to rescue my xp, thanks to you.

  13. Stelian!

    If it were biologically possible, I would bare your next child.

    THANK YOU!!!!!

    Sincerely,

    Brian

  14. Procedures where on point and worked exactly as indicated; thanks for taking the time to put together this detailed information. Very much appreciated!

  15. Hello nono,
    Can you please run a scan with Combofix and ESET online scanner and post the logs here :

    STEP 1 : Run a scan with Combofix

    Download ComboFix from one of the following locations:

    COMBOFIX DOWNLOAD LINK #1 (This link will automatically download Combofix on your computer)
    COMBOFIX DOWNLOAD LINK #2  (This link will automatically download Combofix on your computer)

    VERY IMPORTANT !!! Save as Combo-Fix.exe during the download. ComboFix must be renamed before you download to your Desktop

    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      ———————————————————–

      • Very Important! Temporarily disable your anti-virusscript blocking and any anti-malware real-time protection beforeperforming a scan. They can interfere with ComboFix or remove some of its embedded files which may cause “unpredictable results”.
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don’t know how to disable it, please ask.
        ———————————————————–
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

      ———————————————————–

     

    1. Double click on ComboFix.exe & follow the prompts.
    2. Accept the disclaimer and allow to update if it asks
    3. When finished, it shall produce a log for you.

    Notes:

    1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
    2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
    3.  If after the reboot you get errors about programms being marked for deletion then reboot, that will cure it.

    STEP 2: Run a scan with ESET Online Scanner:

    1. Download ESET Online Scanner utility.
      ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
    2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
    3. Check Yes, I accept the Terms of Use
    4. Click the Start button.
    5. Check Scan archives
    6. Push the Start button.
    7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    8. When the scan completes, push Finish

    Waiting for your reply to tell me if your machine is ok and the logs from this utilities.

  16. Hi
    My laptop is infected with virus which has made all the folders including files not to open how do i remove the virus without deleting the important files and also how do i open them.And the internet doesn’t wanna open how do i resolve this issue?

    Thank you
    nono

  17. Hello Will,
    Lets work in NORMAL MODE.
    Please run a scan with Malwarebytes Anti-Malware in Chameleon Mode in Norman mode:

    1. Download Malwarebytes Chameleon from here and extract it to a folder in a convenient location
    2. Make certain that your PC is connected to the internet and then open the folder where you extracted Chameleon to and double-click on the Chameleon help file and then follow the onscreen instructions to use it.
    3. If the Chameleon help file itself will not open, then double-click each file one by one until you find one that works, which will be indicated by a black DOS/command prompt window Note: Do not attempt to open mbam-killer as that is not a Chameleon executable and serves a different purpose)
    4. Follow the onscreen instructions to press a key to continue and Chameleon will proceed to download and install Malwarebytes Anti-Malware for you
    5. Once it has done this, it will attempt to update Malwarebytes Anti-Malware, click OK when it says that the database was updated successful
    6. Next, Malwarebytes Anti-Malware will automatically open and perform a Quick scan
    7. Upon completion of the scan, if anything has been detected, click on Show Result
    8. Have Malwarebytes Anti-Malware remove any threats that are detected and click Yes if prompted to reboot your computer to allow the removal process to complete
    9. After your computer restarts, open Malwarebytes Anti-Malware and perform a Full System scan to verify that there are no remaining threats

    2.Please perform a scan with HitmanPro,RogueKiller an Unhide.exe as seen on the guide.


    3.Run a scan with ESET Online Scanner:

    1. Download ESET Online Scanner utility.
      ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
    2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
    3. Check Yes, I accept the Terms of Use
    4. Click the Start button.
    5. Check Scan archives
    6. Push the Start button.
    7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    8. When the scan completes, push Finish
  18. Need xtra assistance, posting from my phone. I have Smart HDD and it will not allow me to enter safe mode or Windows altogether. It will hang if i try to enter safe mode & will claim a disk failure if i let it go. Im trying to get back in in order to follow your guide. Any tips?

  19. Can you ignore that warning? Just go ahead and try to download Malwarebytes Chameleon.
    If it doesn’t work than try the below step:
    While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
    3. Let HitmanPro scan and remove the detected infections.
    Next,run a scan with Malwarebytes Anti-Malware.

  20. I can’t get that far I try normal mode and it takes me to a scream saying checking file system on c: And says a lot more about checking a disk. Says to use system restore feature from control panel. but how can I get to control panel to do so?

  21. Hello steph,
    Lets work in NORMAL MODE.
    Please run a scan with Malwarebytes Anti-Malware in Chameleon Mode in Norman mode:

    1. Download Malwarebytes Chameleon from here and extract it to a folder in a convenient location
    2. Make certain that your PC is connected to the internet and then open the folder where you extracted Chameleon to and double-click on the Chameleon help file and then follow the onscreen instructions to use it.
    3. If the Chameleon help file itself will not open, then double-click each file one by one until you find one that works, which will be indicated by a black DOS/command prompt window Note: Do not attempt to open mbam-killer as that is not a Chameleon executable and serves a different purpose)
    4. Follow the onscreen instructions to press a key to continue and Chameleon will proceed to download and install Malwarebytes Anti-Malware for you
    5. Once it has done this, it will attempt to update Malwarebytes Anti-Malware, click OK when it says that the database was updated successful
    6. Next, Malwarebytes Anti-Malware will automatically open and perform a Quick scan
    7. Upon completion of the scan, if anything has been detected, click on Show Result
    8. Have Malwarebytes Anti-Malware remove any threats that are detected and click Yes if prompted to reboot your computer to allow the removal process to complete
    9. After your computer restarts, open Malwarebytes Anti-Malware and perform a Full System scan to verify that there are no remaining threats

    2.Please perform a scan with HitmanPro as seen on the guide.


    3.Run a scan with ESET Online Scanner:

    1. Download ESET Online Scanner utility.
      ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
    2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
    3. Check Yes, I accept the Terms of Use
    4. Click the Start button.
    5. Check Scan archives
    6. Push the Start button.
    7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    8. When the scan completes, push Finish
  22. Please help I try to get to safe mode with networking but as it loads files it stops and won’t go. I keep starting again and it keeps doing it

  23. Hi, both scans came back clear and generated no reports. Thanks again for your help! Apologies for the delay in replying, I was away from work for a week as I was unwell, and the following week I was on holiday.

  24. Hello,
    Is this your personal computer or from work?It’s important to know that only home users can use this product when it comes to malware removal. :)
    You can perform a scan with the following utilities:

    1.Run a scan with Kaspersky Virus Removal Tool
    Click here to download the Kaspersky Virus Removal Tool.

    1. Save it to your desktop.
    2. Double click the setup file to run it.
    3. Follow the onscreen prompts until it is installed
    4. Click the Options button (the ‘Gear’ icon), then make sure only the following are ticked:
      • System Memory
      • Hidden startup objects
      • Disk boot sectors
      • Local Disk (C:)
      • Also any other drives (Removable that you may have)
    5. Then click on Actions on the left hand side
    6. Click Select Action, then make sure both Disinfect and Delete if disinfection fails are ticked
    7. Click on Automatic Scan
    8. Now click the Start Scanning button, to run the scan
    9. After the scan is complete, click the reports button (‘Paper icon’, next to the ‘cog’ icon) on the right hand side
    10. Click Detected threats on the left
    11. Now click the Save button, and save it as kaslog.txt to your Desktop
    12. Please copy and paste the contents of kaslog.txt in your next reply.

    2.Run a scan with Eset Online Scanner.

    1. Download ESET Online Scanner utility.
      ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
    2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
    3. Check Yes, I accept the Terms of Use
    4. Click the Start button.
    5. Check Scan archives
    6. Push the Start button.
    7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    8. When the scan completes, push Finish
  25. Just a note that HitMan Pro no longer offers the free trial. I used all your steps and they helped rid my computer of this stupid virus, BUT HitMan Pro showed some suspicious items and now I can’t remove those :(

  26. Hiya I’ve tried uk hiding my programmes which has worked in safe mode but doesn’t in normal mode I’ve used unhind please help!!

    Thanks cecilia

  27. Hello,
    Lets try do this another way.Please follow the below steps…

    STEP 1. While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
    3. Let HitmanPro scan and remove the detected infections.

    STEP 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes
    1.Download any re-named version of Rkill (direct download links bellow):
    RKILL DOWNLOAD LINK #1
    RKILL DOWNLOAD LINK #2
    RKILL DOWNLOAD LINK #3
    2.Next,please perform a scan with Malwarebytes and then do a RogueKiller and Unhide.exe scan as seen on the guide


    STEP 3. Run a scan with ESET Online Scanner

    1. Download ESET Online Scanner utility.
      ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
    2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
    3. Check Yes, I accept the Terms of Use
    4. Click the Start button.
    5. Check Scan archives
    6. Push the Start button.
    7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    8. When the scan completes, push List of found threats
    9. Push Export to Text file  and save the file to your desktop using a unique name, such as ESET Scan. Include the contents of this report in your next reply.Note – when ESET doesn’t find any threats, no report will be created.
    10. Push the back button.
    11. Push Finish

    Waiting for your reply to tell me how everything is working.. :) Good luck!

  28. my dell has a virus that keeps restarting, ive hit safemode and it restarts before i get to run malwarebits….ive run rkill but it restarts before rkills is finished? any tips would be awesome

  29. Thank you so much, brilliant, my netbook is now back to its former self, such a relief!!

  30. Hello,
    Try the below steps and see if they work.
    STEP 1. While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
    3. Let HitmanPro scan and remove all the detected threats.

    Step 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes
    1.Download any re-named version of Rkill (direct download links bellow):
    http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
    http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
    http://download.bleepingcomputer.com/grinler/rkill.scr
    2.Next,please perform a scan with Malwarebytes as seen on the guide. (Direct download link for Malwarebytes: http://www.malwarebytes.org/mbam-download-exe.php )
    Let me know , how everything goes.

  31. Whenever I try to download the first step it begins to run then just completely disappears.

  32. Can you please perform the following scans…
    1.Run a scan with Kaspersky Virus Removal Tool
    Click here to download the Kaspersky Virus Removal Tool.

    1. Save it to your desktop.
    2. Double click the setup file to run it.
    3. Follow the onscreen prompts until it is installed
    4. Click the Options button (the ‘Gear’ icon), then make sure only the following are ticked:
      • System Memory
      • Hidden startup objects
      • Disk boot sectors
      • Local Disk (C:)
      • Also any other drives (Removable that you may have)
    5. Then click on Actions on the left hand side
    6. Click Select Action, then make sure both Disinfect and Delete if disinfection fails are ticked
    7. Click on Automatic Scan
    8. Now click the Start Scanning button, to run the scan
    9. After the scan is complete, click the reports button (‘Paper icon’, next to the ‘cog’ icon) on the right hand side
    10. Click Detected threats on the left
    11. Now click the Save button, and save it as kaslog.txt to your Desktop
    12. Please copy and paste the contents of kaslog.txt in your next reply.

    2.Run a scan with Eset Online Scanner.

    1. Download ESET Online Scanner utility.
      ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
    2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
    3. Check Yes, I accept the Terms of Use
    4. Click the Start button.
    5. Check Scan archives
    6. Push the Start button.
    7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    8. When the scan completes, push List of found threats
    9. Push Export to Text file  and save the file to your desktop using a unique name, such as ESET Scan. Include the contents of this report in your next reply.Note – when ESET doesn’t find any threats, no report will be created.
    10. Push the back button.
    11. Push Finish

    Waiting for your reply to tell me how everything is working.. :) Good luck!

  33. OK,lets make some further check-ups:
    1.Run a scan with Kaspersky Virus Removal Tool
    Click here to download the Kaspersky Virus Removal Tool.

    1. Save it to your desktop.
    2. Double click the setup file to run it.
    3. Follow the onscreen prompts until it is installed
    4. Click the Options button (the ‘Gear’ icon), then make sure only the following are ticked:
      • System Memory
      • Hidden startup objects
      • Disk boot sectors
      • Local Disk (C:)
      • Also any other drives (Removable that you may have)
    5. Then click on Actions on the left hand side
    6. Click Select Action, then make sure both Disinfect and Delete if disinfection fails are ticked
    7. Click on Automatic Scan
    8. Now click the Start Scanning button, to run the scan
    9. After the scan is complete, click the reports button (‘Paper icon’, next to the ‘cog’ icon) on the right hand side
    10. Click Detected threats on the left
    11. Now click the Save button, and save it as kaslog.txt to your Desktop
    12. Please copy and paste the contents of kaslog.txt in your next reply.

    2.Run a scan with Eset Online Scanner.

    1. Download ESET Online Scanner utility.
      ESET Online Scanner Download Link (This link will automatically download ESET Online Scanner on your computer.)
    2. Double click on the Eset installer program (esetsmartinstaller_enu.exe).
    3. Check Yes, I accept the Terms of Use
    4. Click the Start button.
    5. Check Scan archives
    6. Push the Start button.
    7. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    8. When the scan completes, push List of found threats
    9. Push Export to Text file  and save the file to your desktop using a unique name, such as ESET Scan. Include the contents of this report in your next reply.Note – when ESET doesn’t find any threats, no report will be created.
    10. Push the back button.
    11. Push Finish

    Waiting for your reply to tell me how everything is working.. :) Good luck!

  34. Hi

    I have followed this procedure 4 times now and it still keeps comming back. I have even got AVG installed and that does not stop it. Any suggestions?
    Mike

  35. Hi, thanks for getting back to me. I had previously tried the Force Breach launch for HitManPro, and have tried it again today, but I am still getting the response ‘HitManPro36.exe has encountered a problem and needs to close. We are sorry for the inconvenience.’ I have succesfully downloaded and run Rkill and Malwarebytes, and have had no further issues with the Data Recovery/Smart HDD virus, but it is still sitting in the Programs list. Is there a way to safely remove this? There is an uninstall option in the program list with it, but I am wary of using this as I know this is sometimes used to reinstall virus software.
    Thanks again for all your help.

  36. Hello,
    You have a MBR infection which is causing this redirect… Try the below steps and see if they work.
    STEP 1. While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
    3. Let HitmanPro scan and remove all the detected threats.

    Step 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes
    1.Download any re-named version of Rkill (direct download links bellow):
    http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
    http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
    http://download.bleepingcomputer.com/grinler/rkill.scr
    2.Next,please perform a scan with Malwarebytes as seen on the guide. (Direct download link for Malwarebytes: http://www.malwarebytes.org/mbam-download-exe.php )

    Report back if it doesn’t work:)

    Let me know , how everything goes.

  37. I was able to download and run RKill, but when I tried to download MalwareBytes nothing happened, it just kept boucing me between 2 different sites. Each one had a link saying ‘download now’ but each link just takes me to the other site. I tried skipping to the next step and downloaded HitManPro36, but when I try to run it I just get an error message saying HitManPro36.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

  38. Please ignore my earlier comments; by right-clicking on the empty Start Bar menu, I was able to get into properties, and change all options back to ‘display this item’. The Programs list is still empty, but I do have access to a browser (Firefox) so should be able to run the solutions outlined above. I will let you know how this goes.

  39. Also wanted to add, if I right-click on the desktop nothing happens, and the only things on the toolbar are the clock and a McAfee icon. A recurring message from McAfee keeps popping up saying ‘Your Computer is at Risk, Please check your status so you can address any security issues to keep your PC protected.’ If I click on status it says Real-Time Scanning is Off; if I click Turn On it goes green and says everything is secure, the turns off again a second or 2 later. I don’t know if this is in any way related though.

  40. Hi, apologies for not clarifying in the last post; I have no icons or Start Menu programs in noral mode either. I am posting this from another PC in the office. If I start in safe mode with networking and log in as administrator, I can access a few programs including internet explorer; however since the virus was downloaded to a user profile and that is the one having the problems, I was under the impression that running the solutions in Administator profile would not help.
    Is there anyway I can download the software to a CD or something on another PC and then load them on the problem PC? Would that work? How would I load them without access to My Computer or even the Run option? Apologies for the delay in posting this, as the PC is at work I can only access it during weekdays.

  41. Thank you for putting this out there. I am so computer stupid but it worked!!!! Thank you, thank you, thank you!!!

  42. While investigating further, I realized that my driver wasn’t showing for my LAN connection, once I updated the driver, bingo, my wireless was working.
    Thanks again for your great directions, you saved the day.

  43. also thanks. but I was in such bad shape the computer was useless. I finally succeeded by hitting F11 when rebooting
    (Vista on a Compaq Presario) and finding a backup point (had to choose older than 5 days). It is all very slow.

  44. Thank you for the instructions, got rid of smart on my Samsung 10 running xp.
    The only problem left is I can’t get the computer to recognize any wi-fi. I tried Tweaking.com but that didn’t work. Wi-fi is turned on but when I go to network connections the Local Area Connection Network Cable reads unplugged. I can plug in an ethernet cord and the internet works. However this netbook is not able to discover our home Wi-fi network!

  45. OPTION 1 : While in NORMAL MODE,download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including this rogue malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
    3. Let HitmanPro scan and remove all the detected threats.
    4.Run Rkill and then a scan with Malwarebytes.

    OPTION 2: While in NORMAL MODE,download/Run Rkill and then run a scan with Malwarebytes.!
    1.Download any re-named version of Rkill (direct download links bellow):
    http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
    http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
    http://download.bleepingcomputer.com/grinler/rkill.scr
    2.Next,please perform a scan with Malwarebytes as seen on the guide and then a scan with HitmanPro.

    Let me know , how everything goes.

  46. Hi Stelian,
    You are a hero, my friend.
    I do not know what I would have done without your instructions on how to get rid of this SMART HDD virus.
    If only there were more good guys like you in this world, guys who put there minds to doing good stuff instead of inflicting pain an misery on others.
    If your computer shop was in Brisbane, Australia, you would get all my business and that of everyone I know.
    Words are not enough to thank you but thank you very, very much anyway.

  47. Thank you so much for putting this on the Internet. I got blindsided by this stupid virus today and thought I’d have to drop serious $$$ to get my computer fixed. Thanks to you I did it all without having to take it in to Geek Squad or some other computer place. After following all of your steps to the letter my computer now runs perfectly! You’re a life-saver.

  48. Hi, I am trying to help fix a PC at work which has this virus. I have restarted in Safe mode with Networking, but there are still no icons and nothing in the Start Menu other than options to Log Off or Turn Off Computer. There is nothing in the All Programs list. I cannot get into a browser to download any of the software in your walkthrough. Any advice? I’m pretty clueless at this :/

  49. Hi Stelian Pilici,

    You are a genius. Thanks a mil. for the screen shots and detailed instructions.
    Each step worked flawlessly, Thanks again
    – DJ

  50. Download Windows Repair by Tweaking.com to your desktop.  Use the direct download link for the Portable version of Windows Repair by Tweaking.com

    1. Double-click tweaking.com_windows_repair_aio.zip and extract the Tweaking.com – Windows Repair folder to your desktop.
    2. Now open this folder and double-click Repair_Windows.exe.
    3. Click the Start Repairs tab on the far right.
    4. Click the Start button (bottom right)
      Note: When asked if you would like to create a restore point. It is recommended just in-case something does not go as planned.
    5. Click Unselect All
    6. Put a checkmark in the following items:
      • Repair Windows Firewall
      • Repair Hosts File
      • Repair Temp Files
      • Remove Policies Set By Infections
      • Set Windows Services To Default Startup

      Note: Leave everything else unchecked

    7. Put a checkmark in Restart System When Finished
    8. Now click the Start button (bottom right)

    What firewall are you using?

  51. Hi, thanks I finally deleted the virus, but there is one problem now, my laptop can’t find ani wifi signal, I turned off and on the wifi but nothing happened.

  52. Stelian you are awesome! Worked through all your steps and everything came back as it should. I tried a couple of the other methods from other sites and the S.M.A.R.T malware came back as before. I think that running Hitman after Malwarebytes was the key to getting this removed. Also running RogueKiller brought back all my hidden files without running unhide.exe, although I did run it anyway. Thanks so much for your help!

  53. Thanks Stelian!
    By following your directions I was able to fix my g/fs computer. I had already tried running malware bytes, but your suggestion to run hitmanpro found a potentially suspicious file. For what it’s worth for others, the first time I tried unhide, nothing seemed to happen for 25 minutes. I tried it again and 10 minutes later I noticed changes. So it might take a while.

  54. Yes,you can try to do that….You can force Malwarebytes to start by using this guide: http://helpdesk.malwarebytes.org/entries/21434202-how-to-use-malwarebytes-chameleon-when-it-cannot-be-opened-normally-through-the-start-menu

    Also if HitmanPro will detect any infections, make sure that they aren’t false possitive or compromised critical system files before removing them!I’m saying this because usually when you can’t connect to the internet while in Safe Mode with Networking could mean that you have other infections besides this Smart HDD Rogue.

  55. When I start my laptop in safe mode with networking, networking isn’t available and all my files show as empty. Can I go through this process outside of safe mode and still get rid of this nightmare?

  56. Everything is pretty much back to normal. Great job.

    The only major thing is my voice recorder which I plug into the computer through a USB port. When I try to eject it, I always get a message that a program is using it. I pull it out anyway.

  57. Yes I followed all your steps throughly and the HDD smart repair, and error pop us no longer appear. But programs such as microsft office, itunes, silverlight,quick time,adobe acrobat, most programs don’t appear. What may have happend and how do I fix that?

  58. Hello John,
    Here is the removal guide for Security Shield: http://malwaretips.com/blogs/security-shield-virus/


    MSE didn’t have signatures for this particular threat and because it doesn’t have any other powerful layers of protection it didn’t have any way to stop it.
    You should really change your antivirus to one that has additionl layers of protection besides the antivirus component!
    Here is one of the reasons why Avast is better than Microsoft Security Essentials: https://blog.avast.com/2012/03/20/autosandbox-why-are-you-annoying-me/
    Quick tips:
    Free – Avast 7 Free version or COMODO Internet Security
    Paid : Norton Internet Security 2012 or Avast Internet Security 7
    Anyway ,you should really start a thread in our Security Configuration forum as you need to build a layerd security config: http://malwaretips.com/Forum-Security-Configuration-Wizard

  59. I used these steps to take out Smart hdd from my computer and it successfully worked but now I got another virus called Security Shield. Would Rkill, Malwarwebytes, and those other programs work to take out this virus?
    And also what are some good free Security programs because these viruses just turn off Microsoft Security Essentials.
    Thanks

  60. Plese run Unhide.exe

    1. Download  >> Unhide.exe. < <<
    2. Double-click on the Unhide.exe icon on your desktop and allow the program to run.When it has completed its task it will generate a report.

    Then perform a scan with Emsisoft Anti-Malware :

    1. Download the latest official version of Emsisoft Emergency Kit
    2. After the download process will has comleted, you’ll need to unpack EmsisoftEmergencyKit.zip
      [Image: ekk1.png]
    3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
      [Image: ekk2.png]
    4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

      [Image: ekk3.png]

      [Image: ekk4.png]

    5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

      [Image: ekk5.png]

    6. Select “Smart scan” and click-on the below “SCAN” button.

      [Image: ekk6.png]

    7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

      [Image: ekk7.png]

    8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
      Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
      [Image: ekk8.png]
    9. Emsisoft Emergency Kit will now start removing the malicious files.
  61. Hi I went through all the steps and everything worked out great, but at the end my computer was having a hard time rebooting, so I did a start up repair through windows, and all of a sudden everything is gone again, desktop, start menu, toolbars etc. So should I rerun the unhide program? or is there something else that I should try, thanks for all of your hard work, you really are a life saver.

  62. When I switch my personal computer on it says that I’m contaminated and won’t let me close or perhaps open anything. What can I actually do?

  63. 1.Plese run Unhide.exe

    1. Download  >> Unhide.exe. < <<
    2. Double-click on the Unhide.exe icon on your desktop and allow the program to run.When it has completed its task it will generate a report.

    2.Restore your Start menu to a previous date

    1. Right click on your Windows Start menu and select Properties.
      [Image: Eu2Aq.png]
    2. Next put a check mark on
      Store and display recently opened programs in the start menu
      Store and display recently opened items in the start menu and taskbar
      [Image: h0z5v.png]
    3. Click on Customize and click on Use default settings at the bottom
      [Image: kxZSH.png]
    4. Browse to
      Code:
      C:\ProgramData\Microsoft\Windows

      [Image: vZZUz.png]

    5. Right click on Start Menu folder and click on Restore previous versions
    6. Now select a snapshot before you were infected by the rogue,click on restore
  64. Hi guys everything worked fine BUT I still cannot get my icons back on the desktop, not even by “trailing” them from dhe folder to the desktop (sorry I am not sure trailing is the righht english word…
    And from the Start menu I see all the programs BUT I do not see the column with Documents, Recent docs, computer, and so on. And sometimes I get a Empty answer…

  65. Thanks a lot. Got the virus a couple of days ago.
    Followed your instructions, worked perfectly!

  66. Thank you very much. The instructions were clear and worked great. I saved my laptopo thanks to your help. Grazie

  67. Thank you SO much. We’d decided to restore my computer to the day before to get rid of this BLUDDY virus, and thought everything was then hunky-dory. Until I discovered all my documents were gone. Nearly heart attack time. Followed your steps to unhide etc. (didn’t do the Malware bit because I’d already restored) … I run AVG and Spybot which have never let me down before so not sure how this virus got through. But so glad to be able to follow your instructions to restore. Worth your weight in gold. If I had it! :D

  68. Yes , all the software all compatible with Kaspersky/Norton as they are just on-demand scanner(will not add real-time protection). :)

  69. hey i have kaspersky internet security trial version instaled and the damn thing wont start with a comp reboot… i had norton 360 full version before this and it used to do the same thing (not start with reboot…) when i click on the kaspersky icon… there is only a slim chance that it works, so do u think this would help me?? also will the softwares be compatible with kaspersky?

  70. Thanks very much for the help … I ran the program and it found 11 malicious files, which I deleted. Still, when I restart the computer, all the icons are missing.

  71. When i try to open internet explorer it says “internet explorer has encountered a problem and needs to close”. Any suggestions?

  72. Yes, you can uninstall all of them if that’s what you want.. :)
    Stay safe!

  73. Thanks, all good now. Can I uninstall/ delete the downloaded programs from above after I am done?

  74. All it depends on the sizes of your hard drive and your PC speed but usually around 1 hour,however because this is an infected PC it can take longer………. Let the scan complete and then move on with the next steps, which will be a lot faster.

  75. How long is each scan suppose to take?? I am scanning using the Malwarebytes Anti-Malware and it has already been 6 hours with 18 detected. Is this normal??
    P.S. Whoever does these hacks needs to get a life :(

  76. Wow thanks!! All done and then like a dummy went into history and trued to delete site and clicked in Firefox “forget it” but somehow it launched :( Reran and back in business. THANKS!! I guess I will just leave it in history. Do you all have any recommendations as to what is good software to run so these stupid things get caught before they infect? My Free Malware version does not and my Mcaffee (paid) is worthless (grrrr).

  77. One stupid act spoiled my week and you saved me! Mucho gracious. Very nice step by step instruction.

  78. Internet Explorer is no where to be found on my computer. No icon. Did a search for it and nothing came up. Any ideas?

  79. Lets check with Emsisoft Emergency Kit to see if there are any active infection :

    1. Download the latest official version of Emsisoft Emergency Kit
    2. After the download process will has comleted, you’ll need to unpack EmsisoftEmergencyKit.zip
      [Image: ekk1.png]
    3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
      [Image: ekk2.png]
    4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

      [Image: ekk3.png]

      [Image: ekk4.png]

    5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

      [Image: ekk5.png]

    6. Select “Smart scan” and click-on the below “SCAN” button.

      [Image: ekk6.png]

    7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

      [Image: ekk7.png]

    8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
      Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
      [Image: ekk8.png]
    9. Emsisoft Emergency Kit will now start removing the malicious files.
      If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.
  80. Thanks a bunch for the answer but when I run unhide.exe the black screen comes up and gets to the Processing the c drive but doesn’t go any further.

  81. Did you scan with Malwarebytes and HitmanPro and remove the detected threats??
    If yes,please try to scan again….

    Next , perform a system scan with Emsisoft Emergency Kit:

    1. Download the latest official version of Emsisoft Emergency Kit
    2. After the download process will has comleted, you’ll need to unpack EmsisoftEmergencyKit.zip
      [Image: ekk1.png]
    3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
      [Image: ekk2.png]
    4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

      [Image: ekk3.png]

      [Image: ekk4.png]

    5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

      [Image: ekk5.png]

    6. Select “Smart scan” and click-on the below “SCAN” button.

      [Image: ekk6.png]

    7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

      [Image: ekk7.png]

    8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
      Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
      [Image: ekk8.png]
    9. Emsisoft Emergency Kit will now start removing the malicious files.
      If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.

    If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  82. I got a wicked virus and for the most part have cleaned it off. but now internet explorer 9 starts to open then closes, it won’t run and neither would google chrome. Games like league of legends and skype wont work either. I tried to re-install skype and it opens but you cant see anything other then the background. any suggestions???

  83. Lets try to run Unhide.exe and run it.

    1. Download Unhide.exe.
    2. Double-click on the Unhide.exe icon on your desktop and allow the program to run.When it has completed its task it will generate a report.
  84. Your instructions have been wonderful and helped me re-gain control of my computer after the smart virus. The main problem I’m having now is, each time my computer gets turned off (ie: storm) all my icons are missing and I have to re-run Rogue Killer. Is there a fix for this? Also, one other thing … I am no longer able to see a preview in my pictures folder. Thanks a bunch!!

  85. Thanks so much! Very easy to follow instructions… got rid of that horrible program very quickly :-)

  86. Nevermind…a restart fixed that issue. All the desktop shortcuts are not visible. Thanks again!!

  87. I followed these directions and everything seems to be working correctly except for on thing. We cannot get the desktop items to show on the desktop. Folder #4 was not in the smtmp folder and when I checked the desktop folders, both in all users and the user folder for the current user, the shortcuts were still there. However, they will not show on the desktop. I am unable to copy and paste anything onto the desktop either. Any ideas?

    Great directions, BTW!! Thanks so much!

  88. I got my MalwareBytes back after I ran every anti-malware program I could find, I’ll give it to em’, the Turds that made the SMART malware made one heck of a rabid nightmare, Malwarebytes had kept me safe for 8 months and I picked that SMART fawker up in a boxing message board, I’d like to KTFO the Turd that hid it in his postings but it dis-abled my Malwarebytes and started hiding everything on my computer which has 1 GB of pics and videos saved, I had back-ups but I hate to re-install my computer due to one idiots malware, so I tried it all and it took a cocktail of various programs to finally work… guess I need to keep all these anti-malware programs on my computer at all times… thanks alot Malware-Turds, I know you Fawkers browse here to admire your work!!!

  89. this stinkin’ piece of crap malware is like Frankenstein, it rises from the dead over and over and the nerds best software can’t stop it, the Turds that created this “SMART” Monster must be better Nerds!!! Anyone ever wonder if this whole “Malware” problem is just like the Mafia, they create a problem and offer you the solution for a Price $$$ !?! The so-called law is sleeping when it comes to on-line extortion from all these Malwares…. the people that make Malwares should be lined up and shot on Pay-Per-View and millions would pay to see their Slaughter! Muhahahahaaa…

  90. I’m having trouble with step 9. I’m in the temporary files, but I can’t find the smtmp files. could they be named something else? I’m using windows 7. Everything else has worked like a champ. Thank you so much.

  91. Not only did it work, it removed another virus I had & fixed a program that kept crashing. The steps laid out here were perfect & I consider myself a beginner when it comes to this kind of stuff. The SMART virus was the 1st virus I’ve ever had. Thank you for posting this page. It’s the only one I found that clearly laid out all the steps & it was easy to follow.

  92. Thanks guys! You saved my life today.

    Thanks so much for the excellent step by step guide.

  93. Hello Lindsey,

    STEP 1 : Download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the Smart HDD malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
    3. Let it scan and remove all the detected threats , after that run the RKILL scan and then try to scan with Malwarebytes!

    STEP 2: Run RKILL and then run a scan with Malawrebytes

    STEP 3: Next , perform a system scan with Emsisoft Emergency Kit:

    1. Download the latest official version of Emsisoft Emergency Kit
    2. After the download process will has comleted, you’ll need to unpack EmsisoftEmergencyKit.zip
      [Image: ekk1.png]
    3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
      [Image: ekk2.png]
    4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

      [Image: ekk3.png]

      [Image: ekk4.png]

    5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

      [Image: ekk5.png]

    6. Select “Smart scan” and click-on the below “SCAN” button.

      [Image: ekk6.png]

    7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

      [Image: ekk7.png]

    8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
      Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
      [Image: ekk8.png]
    9. Emsisoft Emergency Kit will now start removing the malicious files.
      If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.

    If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  94. YAY!! It worked!!Thank you so much! I wish I had found this 7 hours sooner. Worth every minute and I can’t thank you enough!!!

  95. Hi Jack, I’m stuck on Step 3 (Run RKill). I downloaded RKill from the “Download Now” button in this guide, but the RKill icon doesn’t appear. I tried downloading the other renamed versions of RKill from the “here” button in this guide:

    •RKill.com Download Link
    •RKill.exe Download Link
    •RKill.scr Download Link
    •eXplorer.exe Download Link
    •iExplore.exe Download Link
    •uSeRiNiT.exe Download Link
    •WiNlOgOn.exe Download Link

    but still no icon appears, therefore I haven’t been able to run RKill, and therefore no log has been generated.

    What should I do next?

  96. Option 1 : Try to download a different named Rkill (direct download links bellow):
    http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
    http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
    http://download.bleepingcomputer.com/grinler/rkill.scr
    And then follow the guide : http://malwaretips.com/blogs/uninstall-smart-hdd/
    Option 2: Try to download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the Smart HDD malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
    3. If it start ,let it scan and remove all the detected threats , then follow the guide : http://malwaretips.com/blogs/uninstall-smart-hdd/

    Next , perform a system scan with Emsisoft Anti-Malware:

    Download and scan with Emsisoft Emergency Kit

    1. Please download the latest official version of Emsisoft Emergency Kit.

    2. After the download process will finish , you’ll need to unpack EmsisoftEmergencyKit.zip
      [Image: ekk1.png]
    3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
      [Image: ekk2.png]
    4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

      [Image: ekk3.png]

      [Image: ekk4.png]

    5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

      [Image: ekk5.png]

    6. Select “Smart scan” and click-on the below “SCAN” button.

      [Image: ekk6.png]

    7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

      [Image: ekk7.png]

    8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
      Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
      [Image: ekk8.png]
    9. Emsisoft Emergency Kit will now start removing the malicious files.
      If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.

    If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  97. My computer was infected with this. I used Superantipayware to original remove. I have access to my computer can go online, followed instructions to show hidden files. Manually found programs to re-pin some. But when i go to I.E. and try to download the missing Adobe Flash it gives me an unspecified error. When i go to download Rkill or any program i get Access Denied or the same unspecified error C;\Users\Data user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CFENMA1N\Flash PlayerInstaller.exe. I also do not have the 4 smptp folders when i go to copy and paste my Quick Launch and Start Menu items. Also i have no option to save anything to desktop. My new desktop is inside my documents. Any help to get my computer back to normal would be appreciated. Thanks.

  98. Thanks a lot, an absolute cweaty sunt of a virus!! But with your help I’m now good to go again, thanks a bunch.

  99. IF YOU ARE NOT ABLE TO KILL THIS MONSTER AFTER DOING EVERYTHING!
    first thanks for a great help how to kill this bastard, it was rough. I owe you guys. I managed ;)
    one possible trick to those who are not able to do it following these otherwise great instructions (try them first and only if it doesnt work exactly what JAck wrote, try what I say). I did everything but Malware bytes always cleaned and things showed up again. My problem was, that RKiller didnt show anything in the log (guess, didnt see anything to kill) while I was in the safe mode with networking. So I rebooted (after I downloaded malware bytes AND RKiller) in a normal mode, so the thing virus started going (I just clicked Stop in its screen to stop popups) and than hit R Killer. It was able to identify the culprits and blocked them. Than Malware bytes had easier time to clean it (I think) properly. Immediately after that Hitman MUST follow (if you cannot download it, because you are not in a safe mode, press windows key and R, and that will get you into exlorer, than type back the address of this AWESOME blog so you see intructions again and dowload Hitman and run it immediately. Than restart. I am afraid, that just running malware bytes is not enough, Bytes showed only few hits, Hitman showed me dozens of crap that had the same name as the one stopped by RKiller. To unhide the icons, easier than the described method I think is to dowload unhide.exe, form the same dude who wrote RKiller (god bless him)

  100. Thanks so much this was a huge help. I was worried I lost something I was working on for a client for the last 2 months.

  101. Hey all….im back again…couple weeks ago i had this virus and it all seems clear after i run this
    program on my computer. The strainge thing is, he is getting slower and slower and now its
    verry hard to use again….I will run this scans again and hope it will make it better again
    really strainge and stupid virus….keep up the good work guys….:D

  102. Hey Jack,

    I am connected to the Internet but it will not allow me to use the browser. When I access the browser, it say cannot connect. I went in to the CMD and pinged yahoo but all the packets were lost.

    I cannot proceed beyond the step of using the Hitman Pro as I cannot get access to the Internet.

    My computer is showing it is connected to the wireless Internet. Please help.

  103. Yes it shows I am connected to the Internet in normal mode. I even get an ip address but it will not let me get to any website.

  104. Hello! Great step-by-step, but it doesn’t work for me:
    I have followed every step, in order, and smart HDD always goes “back to life”.
    Rkill log didn’t show any stopped process ever.
    Today, I have followed this guide for fifth time.
    At fourth and fifth time, Malwarebytes found nothing. But Hitman found some “exe” files.

    I don’t know what I am doing wrong.
    Please, I need some help.
    Thanks

  105. This step-by-step (even though it took awhile to complete) TOTALLY KICKS A**!!! I got a call from my wife – Her work computer got infected – thought the hard-drive had crashed, and we need to buy a new one as she needs it daily. Found this site and everything is as good as new. Can’t thank you guys enough for saving our bacon. Even considered paying the silly fee with credit-card online to the S.M.A.R.T. HDD fairy but was just savvy enough to do a little search about this issue and karma sent me to your link. Anything I can do to repay (even monitarily) will be worth it! Can’t express my gratitude enough…

  106. In order to fix your Menu in Windows 7….

    Look into %userprofile%\AppData\Local\Temp\smtmp

    Copy the contents of \1 to:
    %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu

    Copy the contents of \4 to:
    C:\Documents and Settings\%user&\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu

  107. HitmanPro is a cloud scanner so you need an internet connection to use it…
    While in Norman Mode does your Internet connection work?? Did you try performing this scan in Normal mode?

  108. I downloaded HitmanPro 3.6 and the program opened. However, when it begins to run, It says “Scanning computer”, but then I get a No Internet Connection, Waiting for Internet Connection message. I checked IPCONFIG and it shows I have access to the Internet based on the IP address listed.

    I turned off Proxy in Safe Mode for both my IE and my Firefox browsers. Any advice?

    By the way, thank you so much for this guide; all my files are back on my laptop but I just want to make sure I run HitmanPro 3.6.

  109. Option 1 : Try to download a different named Rkill (direct download links bellow):
    http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
    http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
    http://download.bleepingcomputer.com/grinler/rkill.scr
    And then follow the guide : http://malwaretips.com/blogs/uninstall-smart-hdd/
    Option 2: Try to download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the Smart HDD malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?v=m6eRWTv2STk
    3. If it start ,let it scan and remove all the detected threats , then follow the guide : http://malwaretips.com/blogs/uninstall-smart-hdd/

    If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  110. First off all , this shouldn’t happen in the first place.. You can build up a solid malware defense with our help ,just start a thread in this forum : http://malwaretips.com/Forum-Security-Configuration-Wizard
    As for the HitmanPro license, well in this 30days you can remove any piece of malware , however you’ll need to buy this product if this period expires. :*( But even after the 30 days trial you can still scan with this product and if it finds anything then you can use another product to remove the threats… :)

  111. Thanks a ton.I got hit with this Smart HDD crap and this really helped me out.It’s all gone now.However I do have a question.What if it were to happen again in the future?Acouple of the things used have an expiration date attached to them ie 30 days for HitmanPro.

  112. I followed through all the above steps, I was able to download RKill, I then ran it but when the log came up – a pop-up came up saying “Installation Failed” – i’d used the activation code so i assume it’s not a fake pop-up from the virus. IT appeared to then run, however when it generated the log everything came up like shown above^, however under the heading “Processes terminated by Rkill or while it was running” was blank, and then had “Rkill completed on 25/4/12 etc”
    I tried it a few times too, but each time the same thing happened.

  113. I made it all the way to the Deep Scan part of this process and Smart HDD reared it’s ugly head AGAIN! I’m back to square one. I followed the steps to a T, does anyone else have any suggestions? Should I add the step of going into “msconfig” as soon as I’m able and deleting the virus from the start up?

    Help! I was so optimistic, and now I’m just bummed beyond belief.

  114. I just had SMARTHDD pop up on my desktop, now I don’t know how to remove it. I am on my laptop

  115. SUPERB DOCUMENTATION…..Worked very well user back up & running.. However all his menu items in the allprograms are still empty???

  116. Great web site and assistance – while this fix process appears daunting, the links and clear instructions really helped me to fix this issue relatively quickly. In fact I found all this easier and quicker to do than working issues like this through with my anti-virus provider.

    Thank you so much for offering free and helpful assistance against a nasty scam

  117. Same thing here – thank you so much for posting this – it only ended up costing me $50 and a few hours of headache! :)

  118. Thank you SO much! Your advice worked perfectly and my PC’s running brilliantly!
    Very much appreciated :o)

  119. Option 1 : Try to download a different named Rkill (direct download links bellow):
    http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
    http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
    http://download.bleepingcomputer.com/grinler/rkill.scr
    And then follow the guide : http://malwaretips.com/blogs/uninstall-smart-hdd/
    Option 2: Try to download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the Smart HDD malicious process
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?feature=pla…6eRWTv2STk
    3. If it start ,let it scan and remove all the detected threats , then follow the guide : http://malwaretips.com/blogs/uninstall-smart-hdd/

    If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  120. Did you run the Tweaking.com-UnhideNonSystemFiles.exe utility? Please try to run it again!
    Also did you remove all the infected objects detected by MBAM and HitmanPro? Please run another scan Full System Scan with Malwarebytes to make sure everything is clean!
    If you are still experiencing problems , start a thread in our Malware Removal Support forum : http://malwaretips.com/Forum-Help-my-PC-is-infected

  121. I tried to run RogueKiller but it won’t work. :-(
    Here’s the message I get:
    “RogueKiller.exe is not a valid Win32 application.”
    It won’t run, and all my desktop icons are still missing, shortcuts are still missing, etc. :-(
    Can you help?
    Thanks in advance!

  122. I tried the above but it is not working.
    Rkill returns a message “access denied” and the log file it shows no processes terminated.
    Thanks

  123. you guyz are the best. I can never forget this and i would like to knw u guyz…. bjseriki is my facebook name, u can add me up :)

  124. Wery thankful for this information, that helped me rescue a Vista PC that had a bad SMART HDD version.
    All worked fine!

    :-)
    Regards
    Stefan

  125. Next to the ‘Skip’ action there is a little down arrow, press it and you should get the below menu… From there select Quarantine, after the action has been set, press NEXT.

  126. You can also try to make a scan with Emsisoft Emergency Kit… just to make sure everything is clean… :)

    Download and scan with Emsisoft Emergency Kit

    1. Please download the latest official version of Emsisoft Emergency Kit.

    2. After the download process will finish , you’ll need to unpack EmsisoftEmergencyKit.zip
      [Image: ekk1.png]
    3. Open the Emsisoft Emergency Kit Folder and double click EmergencyKitScanner.bat
      [Image: ekk2.png]
    4. A pop-up will prompt you to update Emsisoft Emergency Kit , please click the “Yes” button.

      [Image: ekk3.png]

      [Image: ekk4.png]

    5. After the Update process has completed , put the mouse cursor over the “Menu” tab on the left and click-on “Scan PC”.

      [Image: ekk5.png]

    6. Select “Smart scan” and click-on the below “SCAN” button.

      [Image: ekk6.png]

    7. Emsisoft Emergency Kit will now start scanning your computer for malicious files as shown below.

      [Image: ekk7.png]

    8. When the scan will be completed , you will be presented with a screen showing you the malware infections that Emsisoft Emergency Kit has detected.Please note that the infections found may be different than what is shown in the image.
      Make sure that everything is Checked (ticked) and click on the ‘Quarantine selected objects’ button.
      [Image: ekk8.png]
    9. Emsisoft Emergency Kit will now start removing the malicious files.
      If during the removal process Emsisoft will display a message stating that it needs to reboot, please allow this request.
  127. Much appreciated folks. However, Malwarebytes didnt get it the first 2 times I tried, it ended up being hitman that nipped it in the bud.

  128. RKill and HitmanPro did the trick for me.

    Most comprehensive guide on the net for removing this bastard of a trojan.

    To hell with the people behind this scam.

    Thank you once again.

  129. Thank You! It took a while but your instructions kicked SMART HDD to the curb. The only thing left was the text file stating SMART HDD was successfully registered. My recycle bin and delete key took care of it. Thanks again!!

  130. Thank You! Thank You! Thank You! Thank You! Thank You! Thank You! Thank You!
    Donate! Donate! Donate! Donate! Donate! Donate! Donate! Donate! Donate! Donate!

  131. Did you boot into Safe Mode with Networking?
    OK,let’s try a trick…..
    Try to download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the malware process)
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?feature=player_embedded&v=m6eRWTv2STk
    3. If it start ,let it scan and remove all the detected threats , then follow the guide… :)

    If you have problems doing this our forums always available : http://malwaretips.com/Forum-Help-my-PC-is-infected

  132. My computer has been hit by Smart HDD, I have been trying to run RKILL but I can’t get it to run, please help! I’m not computer savy and really need some help.

  133. No… If you’ve scanned with all the software from the guide and removed the detected threats then you’re good!:D

  134. Thank you so much! You have no ide how greatful I am of this blog and your help!
    I dont know computeres at all, but you made it very easy for me to fix my computer with your step-by-step advices.
    You really made my day!! THANK YOU!

  135. These files, which ones? than the antivirus or viruses? So I still have malware on my PC not having used the safe mode? Kiss!

  136. Once scan with HitmanPro is completed, I get the following message: “iExplore.exe
    There are indications that this file is a threat. However, it can also be benign.Contains high amount of malware related properties. It is potentially malicious software.” There were 5 identified threats.
    When I click Next in order to delete them, nothing happens. After rescanning, it is obvious that the threats were not deleted. Am I doing something wrong?

  137. Hello, I have done all the steps, but since I could not connect in safe mode, I inserted the code, I did a restore of configuration and have done all these operations in normal mode, I found 337 viruses and I deleted them by the book . I have to repeat everything in Safe Mode or I have removed the virus?
    Can I remove all the programs I have downloaded and used on my pc or risk of new infections (some programs are being tested for 30 days or for a single scan).

    ALSO WANTED TO THANK VI ….. IN TIME OF CRISIS YOU DID SAVE ME MONEY … THANKS THANKS THANKS THANKS!

  138. OK,let’s try a trick…..
    While in Normanl Mode , try to download HitmanPro and then start this program in ForceBreach Mode
    1.Here are the direct download links for HitmanPro,
    http://dl.surfright.nl/HitmanPro36.exe (For 32bit)
    http://dl.surfright.nl/HitmanPro36_x64.exe (For 64bit)
    2.Hold down the left CTRL-key when you start HitmanPro and all non-essential processes are terminated, including the malware process)
    Here is a video that explains with graphic details how to do this : http://www.youtube.com/watch?feature=player_embedded&v=m6eRWTv2STk
    3. If it start ,let it scan and remove all the detected threats , then follow the guide… :)

    Again… if you have problems doing this our forums are open and awesome (lol) : http://malwaretips.com/Forum-Help-my-PC-is-infected

  139. Finally after a few days of this nightmare, thanks to you guys i have my pc back in order. Thank You for your GENIUS.

  140. The reason I say I know I am connected is that when I unplu the router it will say not connected to network and when I replug it goes back to connected to unknown network/local access only or connected to unknown network/limited access.

    Thanks,
    Greg

  141. I am hoping you guys can help, I am unable to connect to the internet to get too far into the removal process. I checked the internet settings and the proxy server box is not checked. I know I am connected to the network, when I check the connection it either says connected to unknown network/local access only or connected to unknown network/limited access. Neither one allows me to connect to the internet using IE7. I am using Vista Home.

    Thanks for any help you cool folks can provide,
    Greg

  142. might work if you could get ti internet explorer
    only options with right click over start are properties and windows explorer
    only programs arw calculator and frostwire 4.20.7

  143. after running the unhide non system files.exe…. it looks like most of the icons are back HOWEVER there is now one for the Smart HDD and it is also listed in the program files. NOW what??

  144. I had to use the Tweaking Unhide System files program after went through all the steps, and ONLY after I was back in normal mode. It then restored all of my desktop items. I tired it in safe-mode and it only restored some icons but in normal mode the program restored all the desktop favs. My system is now clean. Thanks guys. Awesome job.

  145. Hi once again i did the dos command and it reported ACCESS DENEID, WHAT THE $&#@? does that mean???

  146. I came home from work today to find out this was on my parents Desktop. I tried doing a system restore to an earlier date, but it wouldn’t allow me to do it. So finally I said screw it and just did a system revert. Now that I found this out after a few hours of re-downloading updates and drivers, I wish I would have found it earlier. Looks so simple too. Damn.

  147. Did you follow Step 7?Please try to run it again.
    If it still doesn’t work,click the Start button in the lower left corner of your task bar. Type cmd in the search box at the bottom of the menu and press Enter. If you’re using Windows XP, click Run and type cmd into the Run box.
    Type attrib -s -h -r c:/*.* /s /d and press Enter to execute the command.

  148. oooohhhhpppssss

    I meant to say my Desktop Icons have not reappeared on my desktop, how can i get them back?????

  149. Thanks alot for this very impressive guide, i followed all the instructions to the letter and got my pc back, but in the end i cant get my icons back. what can i do???? please help. thanks

  150. Thank you so much..This was really help for me…SMART HDD, you are not smart any more…Thanks again…

  151. Press Ctrl + Shift + Esc at the same time to open Task Manager and then go to File > New Task(Run) > and type in : Iexplore

  152. Just wanted to say thank you, all the dickfaced hackers out there making programs like Windows 2000 or Smart HDD piss me off; just leave me alone. Guys (gals) like you who come up with ways to fix these problems deserve something…I don’t know, you just make life easier. I have nothing to offer other than thank you; you’ve made a difference for good in the world which is more than the majority of us can say.

  153. Uninstalled maywarebytes with clean.exe and reinstalled
    Malwarebytes several times. I keep getting the same error: “Error
    creating register key:
    HKEY_LOCAL_MACHINE\Software\\Malwarebytes’Anti-Malware

    RegcreateKeyEx failed; code 5. Access is denied.

    Any tips?? Thanks!

  154. Have worked on this for three days. Managed to “restore” almost all the links to my files but everything was called (2). I could have lived with it but it made me lose my help and support. I am so glad to have it back. Can’t thank you enough.

  155. All worked till hitman my free trial one screen says i have 31 days and the next says it expired! Any thoughts?

  156. By the way, unhide is NOT supported on Windows 7.
    Other than that though, I just about completely purged the virus.
    Only the program file icon remains however, so I want ot be on the safe side.
    What should I do?

  157. the virus won’t let me access internet explorer but I can get on the internet with Mozilla. Can I do this whole process with Mozilla? Thanks

  158. It took longer but worked perfect, thank you sooo much cause i was almost getting crazy about my new computer!!

  159. Great guide. Great follow-up on issues. The one part I didn’t see addressed was the missing icons in start/programs. Another site mentioned that this nasty hides files in the Windows Temp folder.

    Look in C:\Documents and Settings\%user%\Local Settings\Temp\smtmp\

    Copy the contents of /1 to:
    C:\Documents and Settings\%user%\Start Menu

    Copy the contents of /2 to:
    C:\Documents and Settings\%user&\Application Data\Microsoft\Internet Explorer\Quick Launch

    There’s also a Smart HDD link left over on the desktop and in quick launch that can be manualkly deleted.

    I hope that helps.

  160. Awesome, thanks a million :)

    Do you have any tips as to how to prevent stuff like this from getting onto my PC to begin with? I have McAfee total protection with automatic updates. Obviously that doesn’t give me enough protection.

  161. Whew! We went through all the steps, it took forever but it worked! Yay! Thank You! Thank You!

  162. Thank you so much this really helped. The only problem now is that the icons on the bottom of my taskbar are huge and not seem right, any way of putting them back to normal?

  163. I got it when I was trying to go to a legit website. It popped up as “Microsoft Security Essentials has identified a Malware attack. Do you want to isolate/remove it?”

    Thank God for my IT guy Pat!

  164. How does a blog describe everything i am going through and give a solution to the problem???…. Great job!! ….This worked like a charm!!! Thank you so much!…BTW i got the virus from …//1channel.ch… in the name of watching free movies, it recommended a plug in for my windows media player..BAM!!!… i learned my lesson the hard way!!!!.. go with Netflix people!!!

  165. I just got this virus on my comp last night and tried restarting my comp and it will NOT REBOOT! it shows the hp logo and then goes blank after that. I am extremely sad. i have no idea what to do. i tried pressing esc for the startup menu but there is no option for safe mode whatsoever and the F8 button does not work. what do you suggest i do??

  166. Thank you very much , i followed your steps and removed this virus, thank you for your compelet guide and help.You are great. ;)

  167. Downloaded the TDSSKiller, renamed it. Internet connection was lost shortly after. Ran the app, but get a message:

    ” The application failed to initialize properly (0xc0000005). Click on OK to terminate the application. ”

    Thoughts?

  168. OMG what a time sucker! Thank you SO much for this free advice! I “think” I’m restored! Do you have advice on how to prevent this in the future? Best firewall or other anti virus software? Never never had a virus that affected my PC before…never never want to again!

  169. first at all, thanks a lot for the help!!!!!
    I’ve got the same problem with the programs (they still show emty!). any idea?

  170. Hello there i install the tddkiller.exe and rename it to iexplore.exe but it just wont open?

  171. Hi, Guys,

    Thank you, thank you and thank you very much fot this complete guide to remove that hell of thing called “smart hdd”. At first, I thought it was reaaly a problem, but soon I realized it was a hell of a virus or sort of think. I found your page thanks to my iPad, trying to find a way to get rid off the plague, because I coudn’t find not even the browser in my Dell Notebook.

    I did all the steps and after an entire night without sleep, I finally restored my Dell. Thank you very much!

    I any case, I bookmarked this web page for fuure reference!

  172. How often should this process be done to keep from having any other of these stupid malware viruses? This is my second one in 2 days and I HAVE software to keep an eye out for it (maybe it’s outdated?). Thanks :-)

  173. Everything went well until I got to the unhide.exe. bleepingcomputers.com site won’t open for me.

    Now what do I do? I’d appreciate any help I can get. This virus is a biatch.

    Thanks so much! :D

  174. If you have Malwarebytes installed , you can use the Chameleon procedure to update and scan with it….

    1.Open the Task Manager, click on File at the top and choose New Task (Run…)
    2.Click on the Browse… button
    3.Navigate to the folder where Malwarebytes Anti-Malware is installed (normally C:\Program Files\Malwarebytes’ Anti-Malware or C:\Program Files (x86)\Malwarebytes’ Anti-Malware)
    4.Open the Chameleon folder
    5.Click on the drop-down menu that says Programs and choose All Files
    6.Double-click on the Chameleon.chm file (it will look like a help file)
    7.Once the Help file opens, click on each Test Now button until you see a black DOS/command prompt window that remains open and says MBAM-chameleon ver. 0.1 at the top
    This should start a MBAM scan

  175. You are AWESOME, thank you for saving my laptop you are worth your weight in gold.

    I thought everything was lost due to that POS smart hdd infection, I followed your fix completely and all the years of pics and videos along with everything else came back to normal.

    I owe you a big steak dinner

  176. I am unable to get past steps 5 or 6 in this. Running the TDSSKiller and the RKill doesn’t find anything when in SafeMode either.

    The problems begin after installing Malwarebytes. First it wants to update the Malware Data – it begins this process automatically after I click finish on the install, but then the software becomes unresponsive. It says that it’s connecting to a server, but never gets past that. So, I tried everything from the top after uninstalling Malwerebytes to see if I could bypass the software update (figured it may be bogus), and was successful in that. However, starting the scan of the computer again made the software unresponsive, and I can simply not get it to run.

    Having read some of the comments here, I figured… let’s run HitmanPro first then. But, the Next button that I’m supposed to click is greyed out, and so I’m getting nowhere with that one as well.

    So… Now what do I do?

  177. Hello I have tried to follow the instruction. But I downloaded TDSSKiller and had ran it. The problem is that it didn’t detect anything. I also ran Rkill, it seemed to have grabbed a bunch of stuff, but it couldn’t do anything, because the “file is used by another process…”

    My O/S is Windows 7 Ultimate.

    Thanks!

  178. Wow, this is the most comprehensive list of tools and help I have ever seen. Thanks so much for putting it together and figuring it all out. It is most appreciated. ; D

  179. I am an expert in virus and I must say this “step-by-step” works perfectly I didnt have to overthink.
    My desktop is back to normal and my computer ready to be used. Thank you very much.

  180. Well my computer is up and running but i can’t access my windows firewall nor window defender it seems like they both have errors.

  181. Brilliant! Excellent easy to follow instructions that WORKED. Thank you so much . I am very computer savvy, but without this step by step consise written help, it would have meant searching for ages on the net to find a solution.Luckily we have 3 computers so I was able to follow things on a laptop alongside the affected pc. It was on our main desktop pc on my partners side. We have it set up for 2 users. My side was ok apart from it had hidden my precious graphic files and documents. I already knew how to reveal them again so that was soon sorted before I followed the instructions on here to remove the smart hhd. It was a case of ‘you’ll have to sort the pc out’ words uttered by my partner as he has no idea about the techie side of computers lol. Just as well I have more idea and love the techie stuff.
    Anyway, all back as it was now thnaks to you great guys.
    Thanks again!

  182. I was in real panic but thanks for the instructions, my computer is clean and working as it should!

  183. Thank you so much!!!! The guide was easy to follow and worked like a charm. This has saved me a lot of trouble!!

  184. Almost back THANKS only thing wrong now is if I go the Programs…and like Microsoft Office it shows “empty”… but if I search for Excel etc its there.. most of the folders show empty I have run Unhide 3 X…. ideas???

  185. Thank you very much for this guide, my younger brother got the virus and considered wiping the hard drive after system restore failed, but then I found this. This guide was helpful in every aspect, and now I taught him not to go on bad sites.
    Thanks again!

  186. Thanks a lot for the easy to follow instructions.
    Got infected on April fools day, found your website and cleared my laptop up the next day.
    Some desktop icons had disappeared though, but maybe it was time to clean it up anyway.
    However I cannot change start-up programs as it gets blocked by the following message:
    “Windows Defender encountered an error: 0x80070424. The specified service does not exist as an installed service.”

  187. This uninstallation needed time, but was fully successful. Thank you for your precise, complete, easy-to-use and useful removal guide !

  188. my laptop keeps shutting off halfway through the malware scan, the other steps worked fine but I can’t seem to get to the end of that step. Any suggestions? Thanks

  189. No, this rogue software is still on your machine.Please follow the above removal guide.
    Try instead of pressing and holding the “F8 key”, tap the “F8 key” continuously until you get the startup menu.Please do this before the Windows logo appears.

  190. I tried to do the F8 and my computer just beeped really loudly and so after a minute of this I forced a shut down. When I turned it back on it said my computer didn’t start properly and ran a scan and luckily I had backed up my computer last month and when it ran the scan it asked if I wanted to try and recover to an earlier version and I said yes. It took 10 min or so but i got back on my computer and everything is working so far but i still have the SMART HDD License note on my desktop. Did this get rid of the virus? or should I do something else? Thank you for your help.

  191. Have tried using the guide but when I attempt to install Malwarebytes I get ACCESS DENIED…. ???

  192. Thanks so much. Computer seems to be working great. I still have a S.M.A.R.T HDD icon on my desktop and in the programs menu…how should I remove these?

  193. Thanks a lot. It was a great help.
    I still have one problem.
    I have got the links back on the Start Menu, but NOT the links to most of the programs in under the ‘All programs’. My PC runs XP. For instance all the preinstalled games like ‘Spider’ are gone from the Start Menu.
    Is there an easy way to get them back.
    But still – thanks a lot for the help!

  194. This was a great tutorial–thanks so much! I almost fell into the trap of clicking on the SMART HDD popups until I realized they had a spelling error in their message. It’s nice to turn on my computer and not have it go crazy!

  195. I removed all malicious objects and everything that was suggested to remove. I will try to run the Unhide.exe again. Does it take several hours or all day? Thanks so much for your help. This was scary.

  196. The procedure worked “almost” perfectly. One big problem though…

    Only remaining problem is that I have no file management capability beyond creating a new file/folder. I can’t move, delete or rename any files/folders. When I try, I get msg saying “Cannot delete (or move or rename) xxx. Access is denied. Make sure that disk is not full or write-protected and that the file is not currently in use.”

    Saving a doc from MS Word or Excel gives me the message that “Word cannot complete the save due to a file permission error”

    I followed all the steps and had to run the “unhide” program as well. Is there something else I should look at?

    Thanks for the great write-up, and any thoughts you might have on this problem.

  197. Did you remove the malicious objects that were detected by the on-demand scanners?
    If you don’t see your files and folders then run again Unhide.exe, wait until the log is genarated… please note that this may take awhile!

  198. Thank you so much for the help. I performed all of the above steps, however, none of my documents, pictures or videos are showing. Also, the S.M.A.R.T HDD icon is still showing on my desktop. Did I not remove the virus? Thank you.

  199. When I woke up this a.m. and needed a Remove START HDD For Dummies you guys were there to provide it. It was a process, but it worked and was well worth it. Thanks a bunch and keep up the good work!

  200. Hey. Thanks for all the tips and advices here! I just have a quick question. When I run the microsoftfixit, it gives me a error.
    The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2738.
    How do you fix this? I think my host files are still infected.
    Thanks!

  201. You can regain control of most of your computer by entering the registration code shown at http://malwaretips.com/blogs/uninstall-smart-hdd/ This means you can regain control of Task Manager, Registry Editor, and Windows Explorer (see below)

    “As an optional step,you can use the following license key to register Smart HDD and stop the fake alerts.
    15801587234612645205224631045976
    Please keep in mind that entering the above registration code will NOT remove Smart HDD from your computer , instead it will just stop the fake alerts so that you’ll be able to complete our removal guide more easily.”

    I also ran my antivirus scanner, which did NOT however identify this malware as a virus or shut it down. However, once I regained control of my computer, I activated Task Manager and shut down the process I could not identify (Bsy05V4MFLu7iT.exe). This shut down the malware.

    A File Search on Bsy05 led to some very recently installed files, which I deleted. I also deleted everything associated with Bsy05V4MFLu7iT in my Registry Editor.

    My computer now seems under control, and I can see my files although several icons are still missing from my desktop. The fact that using Task Manager to kill Bsy05V4MFLu7iT.exe shut down the malware suggests however that this is a good solution.

    I also reported this incident as Internet crime to the FBI (http://www.ic3.gov/default.aspx) because, as far as I know, it is a felony to install a virus on another person’s computer. I pointed out very specifically that the program kept me from accessing my control panel, Task Manager, and most of my file system.

    Caveat: I am NOT a computer professional. What worked for me was use of the registration code (I did not give my real E-mail address when “registering,” by the way, and I suggest you don’t either) to regain control of File Manager (or Windows Explorer) and the Registry editor, and Task Manager. Task Manager identified the unidentified process, and shutting it down shut down the malware. I used the identity of the process shown by Task Manager to delete all files and registry entries associated with Bsy05V4MFLu7iT.exe. The fact that the file was installed at the time the problem began shows that this is the problem file, and its removal should fix the problem.

  202. Replace this step with the HitmanPro scan….. Use the ForceBreach Mode if it doesn’t start ( instructions are in step 6) ..
    Please note that HitmanPro will detect some explorer.exe file running from temp files…. and will flag them as suspicious but it won’t move the for removal… You need to remove them by selecting ‘Quarantine’

  203. Replace the Kaspersky Scan with the HitmanPro scan…… If it doesn’t start use the Force Breach mode in HitmanPro ( all instructions are in step 6)

  204. Here is what you need to do : Click the Windows Start button and right click on the menu …. it will open up the “Taskbar and Menu properties” from it ..select Customize and then a new window will open…. Select to display as link or menu each time you need….
    http://imgur.com/u5wlb

  205. Thank you so much for this really really thank you!!!!!!!^_^ I WUB YOU FOR THIS!!!!^O^

  206. Thank you for the tools and instructions, they solved my (sons) PC problem.
    By the way, my Mac ClamXav identified iExplorer and RKILL as Trojan.Hupigon-33703 malware, which felt a bit like driving out the devil with the belzebub.

  207. Thank you for posting this step by step removal guide. It worked for me, and most importantly it save me $100 which is the amount Microsoft wanted to charge me to remove this virus. The only issue Im having is that when I click on the start menu my control panel list is still missing. I followed the link you gave and did Step 8 (Windows Repair All In One utility step ), but it did not work. Do you have any other possible solutions for this issue?

  208. Thanks, Malwaretips … saved my butt! This worked great! Now, I’m off to beat my children who probably downloaded this virus with their Jason Breibers and their Madame Graga or whatevers.

  209. Following the advice given for the previous comment, after skipping to step 6, HitmanPro 3.6 Build 151 didn’t find anything. No threats, it says.

  210. I cannot download Malwarebytes, and I cannot run Kasperky. Why Windows Explorer keeps restaring even in Safe Mode. I tried a system restore but it stays in the initializing screen for hours. Can anyone help me?

  211. Thank you for the well written instructions. However, they do not work for me. In step 3, the Kaspersky TDSSKiller won’t run even after renaming. Do you have any further advice?

  212. A very detailed explanation, thank you. I was able to get to step 3 and complete that step, but now when I try to reboot in safe mode by pressing F8 it just hangs there. Any ideas ? Thanks

  213. I followed the steps and got rid of Smart HDD but my icons are still messed up eg. my smart menu icons are missing.

  214. Totally top drawer explanation :) 10/10!! The people who make these Trojans should be.. well.. I will leave that up to you guys to imagine your own punishments :)

  215. Help! When I shut down my computer and tried to start it in safe mode I get “Missing operating system”.

  216. Thanks a million for posting this guide up! It certainly has saved me hours, if not days, of getting this nasty thing off my computer!

  217. After finishing step 6… system would not start. I have to do startup repair… to take back to a point of smart hdd again. What should i do

  218. Skip this stepfor now a download and run a scan with HitmanPro… please note that if it doesn’t start you can use the Force Breach mode, you have all the instructions in Step 6.
    After this step please run the malwarebytes scan.

  219. I can’t seem to get pass STEP 3, No. 2: After I rename it, “iexplore.exe” and double click, it asks for an administrative password and once I enter it, I’m getting a message box, THE EXTENDED ATTRIBUTES ARE INCONSISTENT. Please help…thanks!

  220. Sorry for my other message.. I found you “firefox guide” below the IE guide.. If you can delete the other and this comment.

  221. Just use Internet Explorer….it’s installed by default with Windows… you should have it installed… :)
    However if you really want to do it with Firefox : go to Firefox(upper left corner) → Options → Advanced tab → Network → Settings → Select No Proxy

  222. I’m with this error now, i was doing the steps but i’m in the firefox.. and I can’t finish the step 2. Please help me. Sorry for the English.

  223. You folks are heroes, plain and simple. Cheers and thank you so much for your excellent work!

  224. Thanks! been trying for ages to remove it. by the way when i click the start menu, the control panel list doesn’t show up, any ideas why?
    thanks again :)

  225. Hehe, glad it worked! Now …. don’t randomly run files… ;D Always keep in mind from where you’ve got the file before allowing to run … AND SECURE YOUR PC!:D
    Stay safe!

  226. Thank you so much!!! Worked great. If this fifty-something year old housewife with limited computer knowledge can fix that mess using your steps, I would think anyone would be able to.

  227. Thank you for the comment!;D
    You can join our community and build up your malware defenses …. infections shouldn’t happen ;)D

Leave a Comment