Step 4. Fake HDD Automatic Detection Tool (Recommended) Is your PC infected with Fake HDD? It was less than helpful, suggesting only what I had already done (safe mode + Malwarebytes), plus deleting any "recent" files in some of the Windows folders like Temp, AppData, and I restarted the computer again.

Double click on the download file and follow the prompts to install the program.( When the installation begins, keep following the prompts in order to continue with the installation process) Step WiedergabelisteWiedergabelisteWiedergabelisteWiedergabeliste Alle entfernenBeenden Das nächste Video wird gestartetAnhalten Wird geladen... None of these scans are real, there fake. Repeated scans again revealed nothing.

Also at this time one of the fake "AntiVirus" or "Vista Security" boxes opened -- again, I'm sorry I did not copy down the specific program. Intermittent BSODI believe the Windows version/edition information was included in my original DDS log: MicrosoftŽ Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.898I do not have my Windows CD, but apparently my Recovery Console mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]R0 mfewfpk;McAfee Inc. Its removal effectiveness is also decent, with the ability to remove most of the threats it detects.

My name is Maniac and I will be glad to help you solve your malware problem.Please note:If you are a paying customer, you have the privilege to contact the help desk If not please perform the following steps below so we can have a look at the current condition of your machine. I again booted into Safe Mode and re-installed Malwarebytes and did another scan. Use the forums!Don't let BleepingComputer be silenced.

Rogue.FakeHDD is a malicious Trojan infection detected by Malwarebytes Anti-malware program. I discovered this forum while googling the relevant trojan names and come to you humbly for whatever assistance you may offer. There was an svchost process that was listed as using over half of my RAM. Source Wird geladen...

If we have ever helped you in the past, please consider helping us. All unsaved data will be lost. Although Fake HDD programs will present themselves openly and try to convince you of their good intentions, you should pay attention to the side effects that they cause, such as browser

When a specific threat's ranking decreases, the percentage rate reflects its recent decline.

I removed them and restarted the computer, but still everything was missing/hidden. Top 3 Countries Infected: Lists the top three countries a particular threat has targeted the most over the past month. These are designed to scare computer users into thinking that severe computer problems were found through this defragmenter tool. Wird geladen...

The scoring for each specific malware threat can be easily compared to other emerging threats to draw a contrast in its particular severity. Using the site is easy and fun. Any significant lag in threat definitions updates may allow a newly-released variant of Fake HDD to infect your computer, even if you're protected against older versions of Fake HDD. have a peek here Scan picks up 3 items each time:Rogue.fakeHDDPUM.Hijack.startPUM.Hijack.StartI delete the items but they come back after 2-3 minutes when I scan again.The symptoms are multiple message windows opening with a write fault

System restart required. C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe ThreatLevel: 10/10 DetectionCount: 175 Home Malware ProgramsRogue Defragmenter Programs Fake HDD Leave a Reply Warning! The bugcheck was: 0x0000001a (0x0000000000041790, 0xfffffa800227d6c0, 0x000000000000ffff, 0x0000000000000000).

File not foundO2 - BHO: (no name) - {9B4DF450-DCC7-4B07-935D-0CD757A64583} - No CLSID value found.O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)O3 - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} Unfortunately, none of the programs that SpywareRemove.com malware researchers have found to cause Fake HDD alerts possess any real defragging or error-checking abilities; the best that you can expect from a Our Threat Meter includes several criteria based off of specific malware threats to value their severity, reach and volume. Wird verarbeitet...

Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2645238 uInternet Settings,ProxyOverride = ;*.local uURLSearchHooks: H - No File BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: The most effective way to completely remove Rogue.FakeHDD and its relative infection is manual removal. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

The different threat levels are discussed in the SpyHunter Risk Assessment Model. View other possible causes of installation issues. A dump was saved in: C:\Windows\MEMORY.DMP. Any Fake HDD removal efforts must use a security program that can also remove any related Trojans, since failure to remove Trojans that have installed Fake HDD software will result in