Monday, October 25, 2010

How to Remove Security Tool Virus

Was doing some totally legit website surfing (guitar tabs, thank you), and got a pop-up saying a virus had been detected and that a scan was running to find the problem. These items were masquerading as legitimate Windows programs. The name of the running program was simply "Security Tool".

Don't believe the hype, it is a virus and it is trying to force you to purchase their tool (via credit card) to remove the virus (which it just created). Very dodgy shit. Once you enter in your credit card information who knows what gets done with it. Totally illegal.

Not only did Security Tool constantly pop up after I closed it saying the same message over and over, it also managed to completely take over my Internet access and stop my antivirus programs from running. Fortunately I had an IPhone so I was able to search for solutions.

The simplest way I found to get rid of it and regain internet access was this:
1) Stop the computer and restart it with booting options (F-12 in Windows).
2) Start the computer in Safe Mode with Networking (because you'll need the Internet).
3) Download MalwareBytes' free product and make sure it is updated to the most recent version.
4) Run a full system scan with MalwareBytes. This will find the evil files and remove them. It will take around an hour to complete.
5) Select all the items the program found and remove them using the MalwareBytes tool. (Seriously these MalwareBytes people are awesome!)
6) Restart your computer normally. You should no longer see any evil messages and whatnot, the virus should be removed and you should be good to go now.....
7) EXCEPT!!! When you try to launch the Internet, you'll be unable to. This is because the virus does some ignorant shit to force your internet requests to go to a proxy server (the evil virus' proxy server...this is how they control your internet access).
8) The way to turn this proxy server off differs depending on your browser, but for Google Chrome, go to Wrench Icon -> Options -> Under the Hood -> Change proxy settings -> LAN Settings (similar for other browsers I suspect)
9) Uncheck the "Use a proxy server for your LAN" button and "OK" out of those windows. Now when you restart your browser you should have your internet back.

Simple as that. Thanks to MalwareBytes for totally being wonderful human beings.

And whoever the a-holes are that created the Security Tool virus/trojan horse/malware that is taking over peoples computers and stealing credit cards.....you're pieces of trash.

No comments:

Post a Comment