We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Eeek security tool scareware infection

I've picked up the security tool scareware on my XP laptop :-(
I've been following the steps on the malware removal guide (already had all the recommended software installed).
Have booted into safe mode and run MBAM (as nothing will run in regular mode even when renamed) and it picked up a rogue security tool (which I then deleted). I then rebooted in normal mode and the infection is still there, is there something more I should have done?
Lx.
«1

Comments

  • fiddiwebb
    fiddiwebb Posts: 1,806 Forumite
    Are you scanning with the latest version of Malwarebytes which is 1.46 also did you update the virus definition files before running a scan?
  • spakkker
    spakkker Posts: 1,322 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Can you run it in normal mode now? When I've had these I run malwarebytes then combofix.
  • Post your Malwarebytes log that would give us a clue
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • Thanks for replying so quickly!
    - Nope, because I freaked out and switched off the network card the moment I knew something was up! MBAM seemed to pick up the infection anyway but maybe not everything?
    I'm currently booting into safe mode with networking and will update MBAM and re run the scan.
    I'll let you know how I get on
    Lx.
  • fiddiwebb
    fiddiwebb Posts: 1,806 Forumite
    Don't run Combofix unless advised to by a qualified user.
  • spakkker
    spakkker Posts: 1,322 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    "Don't run Combofix unless advised to by a qualified user" -why do you say this?
  • Post your Malwarebytes log that would give us a clue
    I've not worked out how to update mbam as the infection blocks the program from running in normal mode and I can't seem to access the internet in safe networking mode.
    here's the log run in safe mode:

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org
    Database version: 4903
    Windows 5.1.2600 Service Pack 3 (Safe Mode)
    Internet Explorer 8.0.6001.18702
    10/11/2010 20:22:48
    mbam-log-2010-11-10 (20-22-48).txt
    Scan type: Quick scan
    Objects scanned: 149970
    Time elapsed: 18 minute(s), 20 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    C:\Documents and Settings\Administrator\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
  • Knarf44
    Knarf44 Posts: 557 Forumite
    You can download the MBAM update directly from here. Suggest save it to Desktop then just click of mbam-rules.exe to install.
  • OK I have updated MBAM I also found this guide to removing securitytool and have followed the instructions running rkill then mbam however after mbam removes the rogue security tool and restarts the securitytool program is still there on return to normal mode. am I doing something wrong? should I follow all the steps before rebooting?
  • Fingers crossed I thing the update may have done it, it has picked up a registry entry which wasn't picked up before.
    I can now use my security software in normal mode so am updating everything and will rescan everything overnight.
    So thank you very much for your help folks.

    I currently have all the programs on the malware removal guide list (mbab) spybot s&d, windows defender, adaware, ccleaner, and am use firefox for browsing and have all the recent windows updates) and run the free version of avira as my main antivirus software is there anything I shuld be doing anything differently?

    I am pretty sure I didn't click on anything stupid, but the attack happened immediatly after I reinstalled the adobe reader plugin (via the firefox website) and the bleeding thing installed the mcaffee security scanner dispite me unchecking the box I'm not sure if it's connected, I would havew expected the firefox/adobe websites to be quite safe!
    Lx.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.5K Banking & Borrowing
  • 253.7K Reduce Debt & Boost Income
  • 454.5K Spending & Discounts
  • 245.5K Work, Benefits & Business
  • 601.4K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.