HELP! SMART HDD problem/ virus.

HELP! SMART HDD problem/ virus.

Author
Discussion

Codswallop

Original Poster:

5,250 posts

195 months

Sunday 1st April 2012
quotequote all
I was browsing the web (watching youtube, with PH and email in background), didn't click on any links/ download anything recently, and then my browser (Firefox) shut, and S.M.A.R.T HDD check started.

Quick google suggests this is a trojan virus. Is that true? And if so, how do I remove it?

All of my files appear ghosted out, but are still accesible for now, even though the computer is not seeing the Harddrive.

Any help would be much appreciated.

mph999

2,718 posts

221 months

Sunday 1st April 2012
quotequote all
Codswallop said:
I was browsing the web (watching youtube, with PH and email in background), didn't click on any links/ download anything recently, and then my browser (Firefox) shut, and S.M.A.R.T HDD check started.

Quick google suggests this is a trojan virus. Is that true? And if so, how do I remove it?

All of my files appear ghosted out, but are still accesible for now, even though the computer is not seeing the Harddrive.

Any help would be much appreciated.
Here you are ...

http://www.bleepingcomputer.com/virus-removal/remo...

scottS3

206 posts

184 months

Sunday 1st April 2012
quotequote all
Ive just had this,

Used malwarebytes to remove it, but the whole of my computer has been wiped, including programs etc, anything I can do about this?

rolex

3,112 posts

259 months

Sunday 1st April 2012
quotequote all
scottS3 said:
Ive just had this,

Used malwarebytes to remove it, but the whole of my computer has been wiped, including programs etc, anything I can do about this?
Same here, had this last night whilst using Pistonheads! Is there something nasty lurking here? Can Pistonheads techies check this out please?

Scott you're programmes etc have not been wiped, the trojan has just hidden them. Go to the given link above and download the "unhide exe" programme and all will be revealed

marshalla

15,902 posts

202 months

Sunday 1st April 2012
quotequote all
rolex said:
Same here, had this last night whilst using Pistonheads! Is there something nasty lurking here? Can Pistonheads techies check this out please?
http://www.pistonheads.com/gassing/topic.asp?h=0&f=24&t=1131915&mid=90714&nmt=Virus+Alert+-++April+Fools+day+spotting+thread+2012

scottS3

206 posts

184 months

Sunday 1st April 2012
quotequote all
rolex said:
Same here, had this last night whilst using Pistonheads! Is there something nasty lurking here? Can Pistonheads techies check this out please?

Scott you're programmes etc have not been wiped, the trojan has just hidden them. Go to the given link above and download the "unhide exe" programme and all will be revealed
I eventually used unhide.exe and that sorted it out cheers. Had me worried for a bit though!

Codswallop

Original Poster:

5,250 posts

195 months

Monday 2nd April 2012
quotequote all
Well, all sorted yesterday with the guide on bleeping computer (thanks for the link from the first poster). Had to run the PC in Safe mode to be able to download anything without the virus interferring, but all back to normal now.

zebedee

4,589 posts

279 months

Monday 2nd April 2012
quotequote all
Codswallop said:
Well, all sorted yesterday with the guide on bleeping computer (thanks for the link from the first poster). Had to run the PC in Safe mode to be able to download anything without the virus interferring, but all back to normal now.
I got hit Saturday night ,just spoke to McAfee and they told me Smart HDD was normally an issue with the hard drive - not very reassuring! I was a bit suspicious when it loaded properly, including my desktop wallpaper (1st time anyway, it is black now) and the list that came up said things like "dangerous" which I didn't think was a particulary techy term! So I googled it on the PS3 and came to conclusion that it is a virus. McAfee scan has quarantined 3 files but I guess I have to follow that bleeping computer thing to sort it out. So this antimalware thing is legitimate then and won't cause mcafee to trip up?

Codswallop

Original Poster:

5,250 posts

195 months

Monday 2nd April 2012
quotequote all
Yeah, I got the virus on Saturday too. Seems to have been a dodgy link someone posted on the April fool's day thread.

That's the thing though, my Avast anti virus did not find anything wrong when I ran a full scan, and google-ing did bring up some sites that seemed to suggest SMART HDD was a genuine program (notably, the SMART HDD wiki page).

However, as you say, all the hallmarks of the program are very much those of a virus (ie. the overly dramatic warnings and millions of pop up windows). Furthermore, my harddrive light was flashing away like mad (as per normal) while the anti-virus scan was running, which increased my suspicion (if the HDD was indeed kaput, the scan would not have taken 2 hours afterall...).

Like yourself, when the virus first hit, I had my background picture and all, and the files initially appeared ghosted out, but were still viewable. It was only after a restart that the background went black, and all files became invisible.

I ran the PC in safe mode with networking enabled to allow me to download rkill, antimalwarebytes, and the unhide file utility (following the guide and links on bleeping computer), because the virus blocked my internet access otherwise, and everything is back to normal now.

I didn't have any interferance issues with the new downloads and my existing anti-virus.

zebedee

4,589 posts

279 months

Monday 2nd April 2012
quotequote all
Codswallop said:
Yeah, I got the virus on Saturday too. Seems to have been a dodgy link someone posted on the April fool's day thread.

That's the thing though, my Avast anti virus did not find anything wrong when I ran a full scan, and google-ing did bring up some sites that seemed to suggest SMART HDD was a genuine program (notably, the SMART HDD wiki page).

However, as you say, all the hallmarks of the program are very much those of a virus (ie. the overly dramatic warnings and millions of pop up windows). Furthermore, my harddrive light was flashing away like mad (as per normal) while the anti-virus scan was running, which increased my suspicion (if the HDD was indeed kaput, the scan would not have taken 2 hours afterall...).

Like yourself, when the virus first hit, I had my background picture and all, and the files initially appeared ghosted out, but were still viewable. It was only after a restart that the background went black, and all files became invisible.

I ran the PC in safe mode with networking enabled to allow me to download rkill, antimalwarebytes, and the unhide file utility (following the guide and links on bleeping computer), because the virus blocked my internet access otherwise, and everything is back to normal now.

I didn't have any interferance issues with the new downloads and my existing anti-virus.
thank you so much, that is the best thing I have read all day! So did you go in in safe mode and then bring the bleeping computer website up and follow it from there?

Codswallop

Original Poster:

5,250 posts

195 months

Monday 2nd April 2012
quotequote all
I actually had the bleeping computer guide open on another PC aswell after I used the download links from their guide because at some points you need to close everything down to run the programs the bleeping computer guide recommends (but only to save myself the hassle of having to open and close the guide all the time).

Also, don't forget to leave safe mode (after downloading rKill and malwarebytes) and turn the PC back on in standard windows mode before going through the guide as the virus does not appear active in safe mode (so you have nothing to remove there).

Good luck and post back when you've cleared the problem smile

roscozs

477 posts

182 months

Monday 2nd April 2012
quotequote all
I was infected too after viewing the April fools thread. I knew straight way it was a virus and ran malware bytes. Absolute nightmare sorting it all back out but followed bleeping computers guide and I'm now all sorted. Any idea what caused it?

zebedee

4,589 posts

279 months

Monday 2nd April 2012
quotequote all
Codswallop said:
I actually had the bleeping computer guide open on another PC aswell after I used the download links from their guide because at some points you need to close everything down to run the programs the bleeping computer guide recommends (but only to save myself the hassle of having to open and close the guide all the time).

Also, don't forget to leave safe mode (after downloading rKill and malwarebytes) and turn the PC back on in standard windows mode before going through the guide as the virus does not appear active in safe mode (so you have nothing to remove there).

Good luck and post back when you've cleared the problem smile
the guide only suggests going back from safe mode once you have been through the first 21 steps though, when did you go back to normal mode?

Codswallop

Original Poster:

5,250 posts

195 months

Monday 2nd April 2012
quotequote all
Which guide are you using zebedee? I used the guide that starts from about half way down this page;

http://www.bleepingcomputer.com/virus-removal/remo...

and that has only 18 steps in total.

I only entered safe mode (with network access) so I could download rKill and Malwarebytes. Once those two were downloaded and accessible (I put copies on my desktop and kept the copy in the download window too), I went back to normal Windows mode and followed the guide from there.

Safe mode only allows essential programmes to run (hence why I got no SMART HDD pop-ups while in safe mode), so I doubt rKill would spot anything was amiss if you stayed in safe mode. Not sure if Malwarebytes would have picked up the virus from safe mode either...


zebedee

4,589 posts

279 months

Monday 2nd April 2012
quotequote all
Codswallop said:
Which guide are you using zebedee? I used the guide that starts from about half way down this page;

http://www.bleepingcomputer.com/virus-removal/remo...

and that has only 18 steps in total.

I only entered safe mode (with network access) so I could download rKill and Malwarebytes. Once those two were downloaded and accessible (I put copies on my desktop and kept the copy in the download window too), I went back to normal Windows mode and followed the guide from there.

Safe mode only allows essential programmes to run (hence why I got no SMART HDD pop-ups while in safe mode), so I doubt rKill would spot anything was amiss if you stayed in safe mode. Not sure if Malwarebytes would have picked up the virus from safe mode either...
they must have updated it as your link has 23 steps too now! the scan has found objects in safe mode.

Codswallop

Original Poster:

5,250 posts

195 months

Wednesday 4th April 2012
quotequote all
How peculiar - when I click onto the link from here, I still have 18 steps displayed confused

No matter, have you managed to get your PC back to normal?