Friday 16 September 2011

Virus: "Security Tool"... help!?

Read my story about how my PC went from bad, to worse, to absolute ******* train wreck, and weep. And try to help...



Okay, so my PC had been acting a bit weird, but mostly with Firefox. A lot of websites would time out, and I was getting pop-up ads for the first time in forever, which would open up a new window in IE disguised as Firefox (the symbol was Firefox's but it showed IE running in the processes). I downloaded Opera and tried that out for a while, but it didn't have any of those problems, so it had to be Firefox.



I uninstalled Firefox, and told Avast to run a thorough boot scan, and I planned on reinstalling Firefox after that was done. But for reasons I can't explain, that only made things worse. When the computer restarted, and the scan finished, and viruses were supposedly fixed, the first thing I saw was a thing called %26quot;Security Tool%26quot; doing an obviously fake virus scan, and telling me I have a bunch of phony viruses on my computer, and that I need to buy their software to get rid of them. Since I've never seen or heard of %26quot;Security Tool%26quot; before, I didn't fall for it. But it wouldn't stop bothering me. On top of that, and maybe this isn't related to Security Tool, but all the icons on my desktop weren't showing, my desktop picture was gone and replaced with blue, and I couldn't open any programs! Some were temperamental, but most wouldn't open at all.



I managed to get Avast open again, to see if it can't do another scan and remove this sonuvabitch, but I blue-screened in the middle of the scan. ****!



I did some research on Security Tool, and to no surprise, it's a virus disguised as an antivirus. I read instruction on how to end the process, delete the registry files, etc... but all that had to be done in safe mode. I tried booting in safe mode the normal way (press F8 while booting) but it said %26quot;We apologize for the inconvenience, but Windows did not start successfully. A recent hardware or software change might have caused this.%26quot; Every time I tried to boot into safe mode, I got that message, but it'd boot into the normal mode just fine.



Then I read about another way I can get it to boot into safe mode, which involved Run%26gt;msconfig%26gt;boot.ini%26gt;safeboot. I tried that, and now I'm really ******. It still won't boot in safe mode, I'm still getting that same message, and to make matters worse, the same exact thing happens when I try to boot in normal mode.



So there you have it. It started with me having some minor issues with Firefox, and it ended with my computer not even being able to get to the log-in screen. What can I do? I don't have the money for a computer guy and I don't have my OS install disc.



If the whole world is going to conspire against me, can't it wait until I can afford to deal with this crap?
Virus: %26quot;Security Tool%26quot;... help!?
Really do not want to make you feel any worse but reinstalling os will not solve the problem.. This virus is a old virus with a new twist. It has the ability to rewrite itself almost as fast as you can get rid of it. The tool

used to remove is Malwarebytes.org. But it has to be used in safe mode

to isolate the virus. The name of the malwarebytes file has to be changed

from mbam.exe to xxxx.exe to fool the virus. This step enables the scan to run. The error you related,windows did not....... you shoud not see that

because windows files do not load till after you click on safe mode page.

Make sure you are taping F8 as soon as you turn it on. Have provided links below with complete instructions on removal and the use of the tool. If you are not able to suggest replacing hard drive.

http://www.bleepingcomputer.com/virus-re鈥?/a>

http://en.community.dell.com/wikis/spywa鈥?/a>
Virus: %26quot;Security Tool%26quot;... help!?
u have malware

if u would follow this link which is a safe legit site

ur porblem will be solved

www.remove-malware.com

his youtube site is

http://youtube.com/mrizos

look for his malware removal video ----he is excellent
Security Tool Removal Instructions For Xp

1.Download and run this free cleaner, choose %26quot;Select all%26quot; and %26quot;Empty selected%26quot;.

(Free)http://download.cnet.com/ATF-Cleaner/300鈥?/a>



2.Right click on %26quot;My Computer and choose %26quot;Properties%26quot;,%26quot;System Restore tab%26quot;,check the box %26quot;Turn off System Restore to all drives%26quot; and hit apply,Ok.



3.Hit Ctrl Shift and Esc at the same time and bring up your task manager and choose the processes tab and look for 4946550101.exe? Rt click on it and choose end process.If you can't end the process move on.



4.When your done shutting it down click on [File] at the top left corner of your task manager and choose New Task (Run).Type msconfig and hit Ok. Go in BOOT.INI tab and tick both %26quot;Safe boot%26quot; and to the right of that %26quot;Networking%26quot; and hit Apply and Close.(It will boot in %26quot;Safe with networking mode%26quot; Choose Administrator)



5.While in %26quot;Safe with networking mode%26quot; download Malwarebytes.

(Free) http://download.cnet.com/Malwarebytes-An鈥?/a>

(Note)If you already have Malwarebytes installed and it won't run go in it's program file and rt click on the red mbam app and rename it mbam.bat then rt click and choose send to-%26gt; Desktop (create shortcut) now close out of everything and go to your desk top and use that app to launch M-Bam for now on.



6.Right click on the mbam setup app you downloaded and rename it xxxx then Dbl click on it and install and update it and run a full scan and delete/quarantine all entities it finds and restart if it asks? (Note) If it won't update use this link to download and install the latest rules: http://www.malwarebytes.org/mbam/databas鈥?/a>



7.Go to Start,Run,type msconfig and hit ok.Go in BOOT.INI tab and untick Safe Boot and then go in the Startup tab and (uncheck) all programs (not) needed at startup (Only check programs you want running all the time like antivirus,IM,etc)%26quot;Less is better in this case%26quot; and hit apply,close,restart.

Your computer will boot normally and on your desktop a window will popup,check %26quot;Don't show this message%26quot; box and hit ok.



(Note)Check here for info's on startup programs http://www.techspot.com/startup/

(How to video) http://www.youtube.com/watch?v=rbSwtNiBx鈥?/a>



8..Download Bitdefender free antivirus and install,update,and run a %26quot;System Scan%26quot; and delete/quarantine all entities it finds

(Free)http://www.bitdefender.com/PRODUCT-14-en鈥?/a>



(Note) Don't turn on %26quot;System Restore%26quot; till your sure your clean and everything is running ok.



If you need more battle plans

drop me an email by clicking

on my name under my avatar?



Stay Safe Out There (^.^)
You can try this :



Turn on your computer power switch, keep pressing 'F8' on your keyboard, it will display a boot menu, one menu item should be like this :



Last known good configuration



Choose this item and press %26quot;enter%26quot;, if your Windows can come back, try to download some antispyware program. I recommend this free tool : http://www.thestubware.com/malware_remov鈥?/a>



If your Windows still can't start, you may need to find your XP disc to make a repair installation. Check here for how to perform a repair installation : http://www.microsoft.com/windowsxp/using鈥?/a>
I would see if you can get your OS install disks from somewhere.



With these kind of infections, the best solution is a clean install.



Do you have a backup? If not - make one now - and then do a format and re install everything.



First action after re installation : Antivirus and malware protection.

Winpatrol is usually good, and has a free and a paid version.



Sorry that i do not have a solution - other than format - but trying tools and tricks will not solve this issue i`m afraid.
i had this virus i tried every thing to get rid of it but you cant run any anti virus. go to this site http://www.removal-tool.org/Remove-Secur鈥?/a> . Follow the instructions it worked for me good luck man