We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Getting really sick of 'Security Tool' virus!

I've had a virus on my machine for a little while now but this week it has taken a turn for the worse ...

I keep getting a 'Security Tool' branded error message which I know from Google search is a fake anti-spyware program.

Problem right now is that it has got to the point where even the recommended course of action doesn't work, as the virus hides my desktop, stops Malawarebytes from running, stops all program except for browsers from running, and keeps coming up with error messages constantly.

I have tried this course of action but it doesn't work as the 'rkill' software it tells me to download doesn;t de-activate the 'Security Tool' virus as it should, and also when I try to re-load Malawarebytes, the Security Tool virus stops it from running:

https://www.bleepingcomputer.com/virus-removal/remove-security-tool

Is there any other way I can de-activate this irritating virus?!?!
"To be ignorant of one's ignorance is the malady of the ignorant." Amos Bronson Alcott
«13

Comments

  • Me too!
    Well, at least my DD's laptop has got infected and I haven't yet started the process of trying to fix it so if anyone can point me in a specific direction of what steps in what order, I'd be grateful.:o
  • londonman81
    londonman81 Posts: 1,130 Forumite
    Part of the Furniture 500 Posts Name Dropper Combo Breaker
    I should add: I am also getting increaisngly frequent blue screens giving 'FAULT_IN_NON_PAGED_AREA' error and references SPMCDSCON.sys (might be slightly wrong name) as the troublesome file , but again I can't find help on Google for it....

    Not sure if it's related to other problem with 'Security Tool'.... :-(
    "To be ignorant of one's ignorance is the malady of the ignorant." Amos Bronson Alcott
  • crampo_2
    crampo_2 Posts: 428 Forumite
    edited 11 April 2010 at 1:36AM
    Try this (someone else with same problem posted this elsewhere)
    1. Stop Security Tool Processes: [random numbers].exe (in task manager)
    2. Remove Security Tool Files
    3. C:\Documents and Settings\All Users\Application Data\[random numbers]\
    4. C:\Documents and Settings\All Users\Application Data\[random numbers]\[random numbers].exe
    5. Remove Security Tool Registry Keys
    *HKEY_CURRENT_USER\Software\Security Tool

    *HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Security Tool

    6. Remove Security Tool Startup Entry: [random numbers].exe

    For more info look:
    http://www.techjaws.com/how-to-remove-security-tool-virus/
    http://www.techjaws.com/how-to-remove-security-tool/
    Peter: Hey Lois... what's this word? Lois: Evil. Peter: And this one? Lois: Knievel. Peter: And this one? Lois: Was. Peter: And this one? Lois: Born. Peter: And this one? Lois: In.
    Peter: And this one? Lois: Montana. Peter: Ah... oh, hey Lois did you know Evil Knievel was born in Montana? Family Guy - I Take Thee, Quagmire 04x21
  • Browntoa
    Browntoa Posts: 49,620 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    have you tried renaming mbam.exe to something else , ie buffer.exe and trying to run it, also try the same with rkill , rename it to anything else and try to run it

    download this

    http://www.superantispyware.com/portablescanner.html

    it randomly generates a filename so the virus cannot stop it
    Ex forum ambassador

    Long term forum member
  • londonman81
    londonman81 Posts: 1,130 Forumite
    Part of the Furniture 500 Posts Name Dropper Combo Breaker
    Browntoa wrote: »
    have you tried renaming mbam.exe to something else , ie buffer.exe and trying to run it, also try the same with rkill , rename it to anything else and try to run it

    download this

    http://www.superantispyware.com/portablescanner.html

    it randomly generates a filename so the virus cannot stop it


    I've tried this but doesn't work...
    "To be ignorant of one's ignorance is the malady of the ignorant." Amos Bronson Alcott
  • taxi97w
    taxi97w Posts: 1,526 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker Photogenic
    This is an evaluation version http://www.greatis.com/unhackme/download.htm - it worked for me at the time.
    more dollar$ than sense
  • Paradigm
    Paradigm Posts: 3,666 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Reboot into safe mode with networking, update Malwarebytes, run Malwarebytes full scan, job done :)
    Always try to be at least half the person your dog thinks you are!
  • londonman81
    londonman81 Posts: 1,130 Forumite
    Part of the Furniture 500 Posts Name Dropper Combo Breaker
    Paradigm wrote: »
    Reboot into safe mode with networking, update Malwarebytes, run Malwarebytes full scan, job done :)

    Tried that today - but doesn't work. When I click on the 'run scan' button in Malwarebytes, it suddenly collapses the screen just like in the 'normal' mode...does this mean that Security Tool virus has even penetrated Safe Mode??!
    "To be ignorant of one's ignorance is the malady of the ignorant." Amos Bronson Alcott
  • crampo_2
    crampo_2 Posts: 428 Forumite
    Peter: Hey Lois... what's this word? Lois: Evil. Peter: And this one? Lois: Knievel. Peter: And this one? Lois: Was. Peter: And this one? Lois: Born. Peter: And this one? Lois: In.
    Peter: And this one? Lois: Montana. Peter: Ah... oh, hey Lois did you know Evil Knievel was born in Montana? Family Guy - I Take Thee, Quagmire 04x21
  • londonman81
    londonman81 Posts: 1,130 Forumite
    Part of the Furniture 500 Posts Name Dropper Combo Breaker
    crampo wrote: »
    Try this (someone else with same problem posted this elsewhere)
    1. Stop Security Tool Processes: [random numbers].exe (in task manager)


    Can't even get Task Manager to stay on the screen long enough to identify the process - the screen collapses just like when I try to open anti-virus/Malwarebytes etc.....i can't get any of these important screens to stay on!

    Help!
    "To be ignorant of one's ignorance is the malady of the ignorant." Amos Bronson Alcott
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.8K Banking & Borrowing
  • 254.3K Reduce Debt & Boost Income
  • 455.2K Spending & Discounts
  • 246.9K Work, Benefits & Business
  • 603.4K Mortgages, Homes & Bills
  • 178.2K Life & Family
  • 261K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.