Sunday, April 1, 2012

Remove S.M.A.R.T. Check, S.M.A.R.T. Repair, S.M.A.R.T. HDD as a trinity of malicious counterfeits

S.M.A.R.T. Check, S.M.A.R.T. Repair, S.M.A.R.T. HDD make a trinity of fake computer optimization solutions. Experts tend to consider all the three programs as one and same counterfeit. Hence this post will further refer to the three malwares as to a single virus, too, to facilitate understanding of the problem.
The virus lures or rather scares users into loading its trialware. The trialware promptly detects – as a matter of fact, fabricates detection of, a number of errors e.g. hard drive boot sector reading error. On this background, it hides items stored on your PC. For example, it may hide all desktop items.
All the errors induced by the malware are to its benefits as it issues comments explaining that it is because of the error it has detected the items have been blocked, the application has failed to run etc. Hence you need to remove S.M.A.R.T. Check, S.M.A.R.T. Repair, S.M.A.R.T. HDD virus in order to prevent further tricky errors.
Fortunately, removal of S.M.A.R.T. Check, S.M.A.R.T. Repair, S.M.A.R.T. HDD totally eliminates the errors as induced by the malicious and pretended utilities. Start the extermination routine with free scan available here.



S.M.A.R.T. HDD rogue Manual removal guide:
Delete infected files:
 %CommonAppData%\~[random]
 %CommonAppData%\~[random]
 %CommonAppData%\~[random]
 %CommonAppData%\[random].exe
 %AppData%\Microsoft\Internet Explorer\Quick Launch\Smart HDD.lnk
 %Desktop%\Smart HDD.lnk
 %StartMenu%\Programs\Smart HDD\
 %StartMenu%\Programs\Smart HDD\Smart HDD.lnk
 %StartMenu%\Programs\Smart HDD\Uninstall Smart HDD.lnk
 %Temp%\smtmp\
 %Temp%\smtmp\1
 %Temp%\smtmp\1
 %Temp%\smtmp\2
 %Temp%\smtmp\3
 %Temp%\smtmp\4

Delete registry entries:
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'

No comments: