HELP! SMART HDD problem/ virus.

HELP! SMART HDD problem/ virus.

Author
Discussion

Codswallop

Original Poster:

5,250 posts

196 months

Sunday 1st April 2012
quotequote all
I was browsing the web (watching youtube, with PH and email in background), didn't click on any links/ download anything recently, and then my browser (Firefox) shut, and S.M.A.R.T HDD check started.

Quick google suggests this is a trojan virus. Is that true? And if so, how do I remove it?

All of my files appear ghosted out, but are still accesible for now, even though the computer is not seeing the Harddrive.

Any help would be much appreciated.

Codswallop

Original Poster:

5,250 posts

196 months

Monday 2nd April 2012
quotequote all
Well, all sorted yesterday with the guide on bleeping computer (thanks for the link from the first poster). Had to run the PC in Safe mode to be able to download anything without the virus interferring, but all back to normal now.

Codswallop

Original Poster:

5,250 posts

196 months

Monday 2nd April 2012
quotequote all
Yeah, I got the virus on Saturday too. Seems to have been a dodgy link someone posted on the April fool's day thread.

That's the thing though, my Avast anti virus did not find anything wrong when I ran a full scan, and google-ing did bring up some sites that seemed to suggest SMART HDD was a genuine program (notably, the SMART HDD wiki page).

However, as you say, all the hallmarks of the program are very much those of a virus (ie. the overly dramatic warnings and millions of pop up windows). Furthermore, my harddrive light was flashing away like mad (as per normal) while the anti-virus scan was running, which increased my suspicion (if the HDD was indeed kaput, the scan would not have taken 2 hours afterall...).

Like yourself, when the virus first hit, I had my background picture and all, and the files initially appeared ghosted out, but were still viewable. It was only after a restart that the background went black, and all files became invisible.

I ran the PC in safe mode with networking enabled to allow me to download rkill, antimalwarebytes, and the unhide file utility (following the guide and links on bleeping computer), because the virus blocked my internet access otherwise, and everything is back to normal now.

I didn't have any interferance issues with the new downloads and my existing anti-virus.

Codswallop

Original Poster:

5,250 posts

196 months

Monday 2nd April 2012
quotequote all
I actually had the bleeping computer guide open on another PC aswell after I used the download links from their guide because at some points you need to close everything down to run the programs the bleeping computer guide recommends (but only to save myself the hassle of having to open and close the guide all the time).

Also, don't forget to leave safe mode (after downloading rKill and malwarebytes) and turn the PC back on in standard windows mode before going through the guide as the virus does not appear active in safe mode (so you have nothing to remove there).

Good luck and post back when you've cleared the problem smile

Codswallop

Original Poster:

5,250 posts

196 months

Monday 2nd April 2012
quotequote all
Which guide are you using zebedee? I used the guide that starts from about half way down this page;

http://www.bleepingcomputer.com/virus-removal/remo...

and that has only 18 steps in total.

I only entered safe mode (with network access) so I could download rKill and Malwarebytes. Once those two were downloaded and accessible (I put copies on my desktop and kept the copy in the download window too), I went back to normal Windows mode and followed the guide from there.

Safe mode only allows essential programmes to run (hence why I got no SMART HDD pop-ups while in safe mode), so I doubt rKill would spot anything was amiss if you stayed in safe mode. Not sure if Malwarebytes would have picked up the virus from safe mode either...


Codswallop

Original Poster:

5,250 posts

196 months

Wednesday 4th April 2012
quotequote all
How peculiar - when I click onto the link from here, I still have 18 steps displayed confused

No matter, have you managed to get your PC back to normal?