HDD Defragmenter

HDD Defragmenter or sometimes called as the HDDDefragmenter virus is another piece of malicious application patterned from its previous variants like Smart Defragmenter and System Defragmenter. Developing this fake optimization software is specific for its mission of earning a profit by misleading victims. It is very much achievable by producing fake alerts and warning messages to trick users into purchasing the licensed version of HDD Defragmenter. As stated, it insists that only registered version of HDD Defragmenter is able to remove threats detected on virus scan and pop-up alerts.

If so happen that this rogue security program has invaded the computer. Immediately scan with a trusted anti-malware program. Anti-malware programs that are useful in eliminating viruses and malware such as HDD Defragmenter are available for free download. Doing a complete scan of the system with anti-malware can certainly remove presence of HDD Defragmenter. Just be sure to download and install the most recent database before proceeding with the virus scan.

When malware is gone, your next move should be to protect your system against this attack. There is no harm in trying unregistered version of security products that offers malware intrusion protection. Guarding your PC from invasion of virus and malware also prevents hackers from stealing your precious data.

HDD Defragmenter Screen Shot:

HDD Defragmenter Image

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

HDD Defragmenter Removal Procedures

Manual Removal:
1. Stop HDD Defragmenter process by pressing Ctrl+Alt+Del. Windows Task Manager will open. Look for the following process:
(random characters).exe
winsp2up.exe

2. Update your installed anti-virus program.
3. Run a full system scan and clean/delete all detected infected file(s). A manual removal of virus-related files should also be performed.
4. Edit Windows registry and delete HDD Defragmenter entries. [how to edit registry]
5. Exit registry editor.
6. Remove HDD Defragmenter start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. System Configuration Utility will open. Go to Startup tab and uncheck the following Startup item(s):
(random characters).exe
winsp2up.exe

7. Click Apply and restart Windows.

HDD Defragmenter Removal Tool:
In order to completely remove the threat, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.

Using Portable SuperAntiSpyware:
To thoroughly remove the virus, it is best to do a separate scan of another security program so that other infected files not detected by anti-virus application can be remove as well. Click here to download and run SAS Portable Scanner.

Technical Details and Additional Information:

Malicious Files Added by HDD Defragmenter:
%UserProfile%\Start Menu\Programs\HDD Defragmenter
%Temp%\[random].bmp
%Temp%\[random].exe
%Temp%\winsp2up.exe
%Temp%\winsp2upd.dll

HDD Defragmenter Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]“
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “winsp2up.exe”

What to do next...