Based on my quick research, here’s a bit of background about this malware (http://support.kaspersky.com/viruses/rogue?qid=208286454):
- It is consider rogue security software by the AV vendors,
- It doesn’t actually do damage, rather it installs itself and hides files prompting users to pay for services to retrieve them, and
- The removal tool available is proven successful and will unhide all hard drive files and remove offending registry entries.
I have also got some info from symantec :
1What is this virus?
Smart HDD is a fake hard drive optimization and analysis program that displays false information.Smart HDD is installed via Trojans that display fake error messages on the infected computer. These messages will state that there is something wrong with your computer's hard drive in order to scare you into purchasing the program.
Some examples of the fake problems that it will report are:
Hard drive boot sector reading error
System blocks were not found
Error 0x00000024 - NTFS_FILE_SYSTEM
Error 0x00000078 - INACCESSIBLE_BOOT_DEVICE
Error 0x0000002E - DATA_BUS_ERROR
Error 0x00000050 - PAGE_FAULT_IN_NONPAGED_AREA
The DRM attribute value is too small before disk scan
If you are infected with Smart HDD it is important that you do not delete any files from your Temp folder or use any temp file cleaners. This is because when the infection is installed it will delete shortcuts found in various locations and store backups of them in the %Temp%\smtmp folder. It does this so that you when try to launch a program from your start menu, none of your shortcuts will appear and thus making you think that your computer has a serious problem. Therefore, you do not want to delete any of the files in your Temp folder as it will remove the backups that we will use later in the guide to restore your Windows Start Menu.
Smart HDD also attempts to make it so you cannot run any programs on your computer. If you attempt to launch a program it will terminate it and state that the program or hard drive is corrupted. It does this to protect itself from anti-virus programs you may attempt to run and to make your computer unusable so that you will be further tempted to purchase the rogue. The messages that you will see when you attempt run a program are:
Windows detected a hard drive problem.
A hard drive error occurred while starting the application.
Or
Windows cannot find notepad. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.
In addition, the rogue hides relevant data from the screen so that you think that it has been destroyed. You do not see icons in Start menu and program shortcuts in the screen. Not to mention the fact that you cannot view relevant files of the system when you open programs' folders by clicking on them. These actions taken against you are planned to make you believe that you are at risk. To restore your data, follow the instructions given:
1.If you are running Windows XP, in Start menu click Run option.
2.Enter cmd and press OK button.
3.When a black screen opens, enter a line: attrib.exe -s -h -r [home_drive]:\*.* /s /d which should be changed according to your home drive. Usually, it is C disk, so instead of [home_drive] enter C.
If you are using Windows Vista or Windows 7, enter cmd in start menu and hit Ctrl+Shift+Enter. Then select OK in Windows dialog box to open C:\WINDOWS\System32\cmd.exe. To restore the data, go back to see step 3 above.
These are just further alerts trying to make you think your computer has a serious hard drive problem. It should be noted that if you attempt to run a program enough times it will eventually work.
Files associated with Smart HDD infection:
==========================================
9903f2.exe
%Programs%\Smart HDD\Uninstall Smart HDD.lnk
%Programs%\Smart HDD\Smart HDD.lnk
%Programs%\Smart HDD
%Desktop%\Smart HDD.lnk
%Temp%\Windows Update.exe
%Temp%\dfrgr
%Temp%\dfrg
%Temp%\[random].dll
%Temp%\[random].exe
%Temp%\[random]
Smart HDD DLL's to remove:
==========================
%Temp%\[random].dll
Smart HDD processes to kill:
============================
9903f2.exe
%Temp%\[random].exe
%Temp%\Windows Update.exe
Remove Smart HDD registry entries:
==================================
HKCU\Software\Microsoft\Windows\CurrentVersion\Run [random].exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run [random]
Please check the below document to avoid such Fake Antivirus getting triggered or loaded to the machines
Title: Hardening Symantec Endpoint Protection (SEP) with an Application and Device Control Policy to increase security
Web URL: http://www.symantec.com/docs/TECH132337