Windows 7 - Security Tool

Asked By Joan
20-Nov-09 06:54 AM
A software program called "Security Tool" has been downloaded tp our laptop
in error.  It is clearly somesort of virus.  Any idea on how to uninstall
this?  It does not show up in the list of programs available to uninstall.
For the time being, I have been able to disable the software on startup..but
worried that it may cause me problems very soon.
Thanks.
HiJackThis
(1)
AntiSpyware
(1)
Diagnostics
(1)
Combofix
(1)
Registry
(1)
Justice
(1)
Gujar
(1)
Qasim
(1)
  FromTheRafters replied to Joan
20-Nov-09 07:10 AM
It is a rogue security program (not a virus AFAIK). The usual removal
tools should be including this new one in their repertoir soon.

Try Super AntiSpyware (SAS) MalwareBytes' Anti-Malware (MBAM) and maybe
Combofix too.

I have not heard yet if a "rootkit" is involved, but it will not hurt to run
GMER *first* just in case.

If the (more or less) automatic removal tools do not work, HiJackThis
(HJT) is a good tool to help experts to analyze your system.
  Comgeek replied to Joan
26-Jan-10 12:06 AM
Security Tool software is a fake program. It is a rogue spyare virus desgined
to earn some extra money by tricking users into buying the crap SECURITY
TOOL. You should follow the removal steps from the link below or run the free
antispyware program to get rid of Security Tool virus
http://www.darfuns.com/spyware-removal/security-tool-virus/
  Peter Foldes replied to Comgeek
26-Jan-10 01:15 AM
Wow. Posting to last years posting. A gain the wonder of the Web interface

--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.
  MEB replied to Peter Foldes
26-Jan-10 01:33 AM
Multiple posts to various groups and for various issues. Site has NOT
been personally checked.

DARFUN CORPORATION
Qasim dar ()

Fax:
HS#1, Gujar khan,
Gujar khan, Punjab 47850
PK

--
MEB
http://peoplescounsel.org/ref/windows-main.htm
Windows Info, Diagnostics, Security, Networking
http://peoplescounsel.org
The "real world" of Law, Justice, and Government
___---
  PA Bear [MS MVP] replied to MEB
26-Jan-10 01:53 AM
Ooo, he offers Registry cleaners, too!
http://www.darfuns.com/download-registry-cleaners/
  Peter Foldes replied to PA Bear [MS MVP]
26-Jan-10 02:03 AM
I did not pay attention to that fact nor did I open the link  but that changed the
whole scenario to Spam for me

--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.
  PA Bear [MS MVP] replied to Peter Foldes
26-Jan-10 04:30 AM
Reported as same, too.
  David H. Lipman replied to Comgeek
26-Jan-10 06:32 AM
| Security Tool software is a fake program. It is a rogue spyare virus desgined
| to earn some extra money by tricking users into buying the crap SECURITY
| TOOL. You should follow the removal steps from the link below or run the free
| antispyware program to get rid of Security Tool virus


That is not a "virus" either -- spammer !


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Create New Account
help
to clean? Should I just format and reinstall from scratch? Below is a report from HiJackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:34:37 PM, on 9 / 22 / 2007 Platform C: \ WINDOWS \ Explorer.EXE C: \ Program Files \ NavNT \ vptray.exe C: \ Program Files \ Creative \ SBLive \ Diagnostics \ diagent.exe C: \ Program Files \ Logitech \ MouseWare \ system \ em_exec.exe C: \ Program Files \ Real \ RealPlayer Files \ SuperAdBlocker.com \ Super Ad Blocker \ SABSVC.EXE C: \ Documents and Settings \ Ruby Sawyer \ Desktop \ HiJackThis.exe R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http: / / www.dellnet.com / R1 - HKCU C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ . . \ Run: [diagent] "C: \ Program Files \ Creative \ SBLive \ Diagnostics \ diagent.exe" startup O4 - HKLM \ . . \ Run: [UpdReg] C: \ WINDOWS \ UpdReg.EXE O4 - HKLM \ . . \ Run: [MCAgentExe cab O16 - DPF: {FA945BB6-9D37-43FC-9B2A-AF09F56CBBF0} - http: / / www.musicmatch.com / form / support / tech / diagnostics / cabs / DiagCollectionControl.cab O20 - Winlogon Notify: !SABWinLogon - C: \ Program Files \ SuperAdBlocker.com \ Super Ad Blocker immunizes you against everything. Antivirus software - you only needed one. Firewall, you only needed one. AntiSpyware - you will need several. I have a list and I recommend you use at least the first five. First - make sure you have NOT installed "Rogue AntiSpyware". There are people out there who created AntiSpyware products that actually install spyware of their
of surfin or workin and then BLAM! Help Pleze. Windows Vista Performance Discussions Vista (1) HiJackThis (1) BCCode (1) BartPE (1) Report (1) OEMs (1) RTlcreatemicrodon (1) BlueScreen (1) Hi, The org My thoughts http: / / rick-mvp.blogspot.com You might try uninstalling the AVG and antispyware application for the moment. To be honest with you, at this point I would be for more formal scanning from outside the OS using a tool like BartPE and memory diagnostics. Whatever is corrupting your system is masking itself sufficiently to make detection difficult when working from within Windows. Just for s&g, download and run HiJackThis from http: / / www.spywareinfo.com / ~merijn / programs.php and right click the file, choose 'run
general light use Any thoughts?? Many thanks Pete Critical 03 / 06 / 2010 11:20:11 Diagnostics-Performance 400 System Performance Monitoring Error 03 / 06 / 2010 11:19:33 Diagnostics-Performance 100 Boot Performance Monitoring Warning 03 / 06 / 2010 11:19:25 Diagnostics-Performance 200 Shutdown Performance Monitoring Warning 03 / 06 / 2010 11:19:25 Diagnostics-Performance 203 Shutdown Performance Monitoring Warning 03 / 06 / 2010 10:23:41 Diagnostics-Performance 108 Boot Performance Monitoring Error 03 / 06 / 2010 10:23:41 Diagnostics-Performance 100 Boot Performance Monitoring Warning 03 / 06 / 2010 10:23:31 Diagnostics-Performance 200 Shutdown Performance Monitoring Critical 03 / 06 / 2010 09:21:03 Diagnostics-Performance 100 Boot Performance Monitoring Warning 03 / 06 / 2010 09:21:03 Diagnostics-Performance 101
hijackthis.exe. . . Windows 7 hijackthis.exe file version 2.0.0.2 collected from aumha.org a few hours ago t dare cast aspersions on Jim Eshelman ! . . .it crossed my mind that Trend (who bought "hijackthis"could be adding something "not nice" to it ! . . .3 false positives maybe :- eSafe7.0.15 my observation might generate some usefeul observations ! . . .in http: / / aumha.net / viewforum.php?f = 30 "Hijackthis Logs" discussion forum, Bill Castner . . .decided to "distort" and "misinterpret" my question and get all your now-edited posts you admitted that you'd submitted (1) an earlier version of HijackThis (e.g., v1.99.1) to VirusTotal and that (2) you had NOT downloaded it read my most recent post(s). PM me from there if you wish. Dave * ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** ** * keywords: hijackthis.exe. . . description: hijackthis.exe file version 2.0.0.2 collected from aumha.org a few hours ago