Even though he was using Microsoft Security Essentials my son’s XP PC got infected with the Smart HDD virus. I have tried the steps in the link http://www.bleepingcomputer.com/virus-removal/remove-smart-hdd but they have not worked. Even in safe mode I can not get the process stopped so I can load Malwarebytes to remove the virus. Rkill various renamed files do not work and I have tried other programs including Microsoft Malicious software removal but so far nothing has worked. I can boot the PC using Hrien’s boot disk and read all his files but can not run Malwarebytes through mini Windows. Does anyone know of another program or way to remove the virus?
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Virus Smart HDD
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Virus Smart HDD
- This topic has 8 replies, 6 voices, and was last updated 13 years ago.
Viewing 3 reply threadsAuthorReplies-
satrow
AskWoody MVPApril 9, 2012 at 6:07 pm #1328301Hi Jerry, to ensure no mistakes are made and that no secondary infections are implicated, it’s best to get it checked out by real malware specialists; bleepingcomputer are very good, as are majorgeeks, geekstogo, techsupportforum …
If you really want to try on your own, Process Explorer and Autoruns will be of great assistance. Whatever route you choose, without expert analysis, there’s a distinct possibility of BSODs or an unbootable PC.
-
WSTinto Tech
AskWoody LoungerApril 9, 2012 at 6:37 pm #1328304Jerry, try the following processes (in the order they are shown):
-
[*]Boot into Safe Mode Without Networking (just plain old Safe Mode).
[*]Run a System Restore to a time that you know the machine was clean. If you have System Restore turned off you will have a much more difficult recovery path.
[*]Return to Safe Mode without Networking to complete the System Restore – do not return to normal mode as the system restore will not be complete – it must be completed from Safe Mode Without Networking.
[*]Once the System Restore has completed sucessfully, reboot into normal mode. Hopefully by now the active component will have been removed
[*]Download Malware Bytes and run a full scan. MBAM is looking for data files rather than registry and program entries.
[*]Run Kaspersky TDSS Killer and Sohpos anti-rootkit, though hopefully by now, you won’t need them.
[*]Install AutoRuns and look for the rogue process if it still remains.
[*]Verify the Hosts file has not been corrupted by the malware. Clean as required.
[*]Verify no proxy or DNS Hijack settings have been installed. Remove any proxy settings installed by the rogue app.
[*]If Either the hosts file, Proxy or DNS settings have been adjusted by the malware, re-run MBAM to check than no new malware has been injected by a rogue site since the initial infection has been cleaned.
[*]Update Java, Adobe Flash Player and Adobe Reader – these 3 are the most likely vector the malware used to infect the machine.
[*]Install AdBlocking software for the Browser – will help prevent malware being injected via rogue adverts exploiting Flash vulnerabilities.Why is it necessary to use Safe mode without networking? Because every instance I have seen of this type of scare-ware has been injected into a Windows networking component. Running without networking disables the launch mechanism of the malware.
The above processes have worked for me in every instance (and that’s a lot of cases!), unless there has been some user interaction with the malware. If that has occured, the malware may have injected additional attacks and be active even in Safe Mode without networking in which case, you have more than one problem and a difficult recovery path.
-
Anonymous
InactiveApril 10, 2012 at 1:33 pm #13283404 Star thanks for the info
I have tried system restore but it will not run even in safe mode. I have tried all versions of RKill. I also have downloaded MBAM on another PC and copied it to my son’s using safe mode but it will not run after an apparent install and I get an access denied error. I have also tried autoruns but can not identify the smart hdd files which are causing the problem. I have tried TDSS Killer in safe mode with no results. I have been running Safe Mode with command prompt but will try plain Safe Mode. Also in Safe Mode I selected view hidden files and tried to update my son’s existing MBAM installation on his C drive but got access denied when the attempted update completed. I have also used Norton’s disaster recovery disk and scanned the PC but it did not fix the problem. I have not returned to normal mode since I started all this process but that has not helped. However, I have restared in Safe Mode with Networking to try to get some updates but based on your info I will only use plain Safe Mode.
-
-
WSJust Plain Fred
AskWoody LoungerWSMedico
AskWoody LoungerApril 9, 2012 at 6:49 pm #1328305Tinto, Thanks for a very comprehensive list for others to follow. It would be nice if an Admin or Moderator could put this list in as a Sticky, it’s that good.
Jerry, Unfortunately no AV will catch everything, especially if they did follow the infestation routes outlined by Tinto, and especially if the operator was not vigilant enough. The weakest link in any security scheme is the operator themselves.
WSruirib
AskWoody LoungerApril 10, 2012 at 3:22 pm #1328346If the previous steps don’t solve it, give Emsisoft’s emergency kit a try (especially the command line tool): http://www.emsisoft.com/en/software/eek/
-
Anonymous
InactiveApril 12, 2012 at 3:38 pm #1328739Thanks for all the help. I have finally resolved the problem and I will detail what fixed it so maybe it will help others who get this virus. Since the virus hides most of your files so you think the HD is corrupt I used Safe mode and removed the hidden attribute on the files. After removing the hidden attributes I could read the HD again but be sure and stay or restart in Safe mode. You could probably use Hiren’s Boot disk to see and remove the hidden attributes if you can not remove them using safe mode. Once the hidden attributes were removed I went to the command prompt and entered the command C:windowssystem32restorerstrul.exe and got restore to run successfully. Apparently trying to run restore from a startup option does not work but the command does. After the restore completed for a date before the infection everything was back to normal and all data and programs were there. This was a very fustrating problem to resolve so good luck to anyone who gets this virus and I hope this helps.
-
WSJust Plain Fred
AskWoody Lounger
-
Viewing 3 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Multiple Partitions?
by
CWBillow
2 hours, 3 minutes ago -
World Passkey Day 2025
by
Alex5723
4 hours, 46 minutes ago -
Add serial device in Windows 11
by
Theodore Dawson
12 hours, 35 minutes ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
11 minutes ago -
Cached credentials is not a new bug
by
Susan Bradley
17 hours, 8 minutes ago -
Win11 24H4 Slow!
by
Bob Bible
17 hours, 19 minutes ago -
Microsoft hiking XBox prices starting today due to Trump’s tariffs
by
Alex5723
14 hours, 30 minutes ago -
Asus adds “movement sensor” to their Graphics cards
by
n0ads
19 hours, 29 minutes ago -
‘Minority Report’ coming to NYC
by
Alex5723
15 hours, 49 minutes ago -
Apple notifies new victims of spyware attacks across the world
by
Alex5723
1 day, 4 hours ago -
Tracking content block list GONE in Firefox 138
by
Bob99
1 day, 3 hours ago -
How do I migrate Password Managers
by
Rush2112
11 hours, 25 minutes ago -
Orb : how fast is my Internet connection
by
Alex5723
13 hours, 14 minutes ago -
Solid color background slows Windows 7 login
by
Alex5723
1 day, 15 hours ago -
Windows 11, version 24H2 might not download via Windows Server Updates Services
by
Alex5723
1 day, 14 hours ago -
Security fixes for Firefox
by
Susan Bradley
14 hours, 49 minutes ago -
Notice on termination of services of LG Mobile Phone Software Updates
by
Alex5723
2 days, 2 hours ago -
Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..
by
Alex5723
2 days, 11 hours ago -
Amazon denies it had plans to be clear about consumer tariff costs
by
Alex5723
2 days, 2 hours ago -
Return of the brain dead FF sidebar
by
EricB
1 day, 13 hours ago -
Windows Settings Managed by your Organization
by
WSDavidO61
16 hours, 53 minutes ago -
Securing Laptop for Trustee Administrattor
by
PeachesP
13 hours, 18 minutes ago -
The local account tax
by
Susan Bradley
1 day, 15 hours ago -
Recall is back with KB5055627(OS Build 26100.3915) Preview
by
Alex5723
3 days ago -
Digital TV Antenna Recommendation
by
Win7and10
2 days, 17 hours ago -
Server 2019 Domain Controllers broken by updates
by
MP Support
3 days, 12 hours ago -
Google won’t remove 3rd party cookies in Chrome as promised
by
Alex5723
3 days, 14 hours ago -
Microsoft Manager Says macOS Is Better Than Windows 11
by
Alex5723
3 days, 17 hours ago -
Outlook (NEW) Getting really Pushy
by
RetiredGeek
2 days, 19 hours ago -
Steps to take before updating to 24H2
by
Susan Bradley
17 hours, 45 minutes ago
Recent blog posts
Key Links
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | ||||
4 | 5 | 6 | 7 | 8 | 9 | 10 |
11 | 12 | 13 | 14 | 15 | 16 | 17 |
18 | 19 | 20 | 21 | 22 | 23 | 24 |
25 | 26 | 27 | 28 | 29 | 30 | 31 |
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.