Forum Home
Press F1
 
Thread ID: 103895 2009-10-10 01:11:00 "Security Tool" virus program - how to remove? starrekin61 (10116) Press F1
Post ID Timestamp Content User
818753 2009-12-02 23:51:00 What if you use something like ccleaner in safe mode, and remove whats in startup (if there's anything there) first? Or let me try :p with Teamviewerno exe would run in any mode, but I have managed to stop them running Via ERD commander bootable CD - thats how I found 4 of them.

Disabled Via ERD, removed the reg keys manually as well as the location folders - rebooted, still NO exe runs any mode, but Security Tools doesn't either - scanning the drive as a slave currently - Nod is going nuts - so I suspect theres more than just the Security Tool infection.
wainuitech (129)
818754 2009-12-03 00:52:00 Wainuitech 1 - Infections 0 :D wainuitech (129)
818755 2009-12-03 00:57:00 You can also do this. Right clicked on "Security Tool" icon on desktop, select properties & remove "read only" & click apply. On the properties tab, look at where the executable is located. Go to that location & renamed the file. Also renamed the folder where it resided. Restart computer & delete the renamed folder & all the files.
Now run Malware Bytes Anti-Malware to clean it up. If MBAM won't run, change it's executable to something.exe & run it again. Hopefully this time it will get rid of that sucker.
kamo1 (14583)
818756 2009-12-03 01:26:00 You can also do this. Right clicked on "Security Tool" icon on desktop, select properties & remove "read only" & click apply. On the properties tab, look at where the executable is located. Go to that location & renamed the file. Also renamed the folder where it resided. Restart computer & delete the renamed folder & all the files.
Now run Malware Bytes Anti-Malware to clean it up. If MBAM won't run, change it's executable to something.exe & run it again. Hopefully this time it will get rid of that sucker. Thats all assuming it will let you - the versions I have just finished wouldn't allow any of the above suggestions.

Other infections that Were on the PC may have been causing problems, but they are not ones that normally would.
wainuitech (129)
818757 2009-12-03 02:09:00 Thats all assuming it will let you - the versions I have just finished wouldn't allow any of the above suggestions.

Other infections that Were on the PC may have been causing problems, but they are not ones that normally would.

Well, at least you managed to get rid of it & good on you. I have friends with similar rogue ware, one in Singapore & two in the States. I run them through some options & they said it's all good & fixed. I am glad that you got to the bottom of things & got everything going again.
kamo1 (14583)
818758 2009-12-03 02:24:00 Well, at least you managed to get rid of it & good on you. I have friends with similar rogue ware, one in Singapore & two in the States. I run them through some options & they said it's all good & fixed. I am glad that you got to the bottom of things & got everything going again. Its my living :D Not all infections can be cleaned out the same way. wainuitech (129)
818759 2009-12-15 18:48:00 I have this same virus and I can't get rid of it. I tried to download the trojan remover, but the virus won't let it. It just closes the program out by itself. NotComputerSavy (15332)
818760 2009-12-15 19:06:00 Rename the task manager exe to iexplore. Then run task manager and end the process that's name is a random 8 digit number, and anything that says security tool. Then you will be able to install, run exe's etc stainton (15333)
818761 2009-12-15 22:52:00 I have this same virus and I can't get rid of it. I tried to download the trojan remover, but the virus won't let it. It just closes the program out by itself.

Try booting into safe mode(tap F8 on boot and select safe mode with networking)

Download it from there.

Make sure system restore is turned off before you attempt to remove the malware.

Blam
Blam (54)
818762 2009-12-15 22:57:00 I'm working on one at the moment - exact same thing -- Running in safe mode with networking allowed trojan remover to work BUT the option to disable system restore was gone - (vista) wasn't till TR had done its thing in safe mode, the desktop came back, and system restore was then able to be turned off. wainuitech (129)
1 2 3 4 5