<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: SecurityTool and Security Tool Virus</title> <atom:link href="http://www.precisesecurity.com/rogue/securitytool/feed" rel="self" type="application/rss+xml" /><link>http://www.precisesecurity.com/rogue/securitytool</link> <description></description> <lastBuildDate>Thu, 09 Feb 2012 05:23:27 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.2.1</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>By: teamtempest</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-8611</link> <dc:creator>teamtempest</dc:creator> <pubDate>Wed, 01 Dec 2010 00:08:59 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-8611</guid> <description>The Security Tool Virus infected my brother+sister-in-law&#039;s WinXP computer last Saturday, 27th Nov 2010 around 5:40 PM, according to the timestamps I found. This computer was running Microsoft Security Essentials, and I noticed its history indicated it woke up for one of the few times since its installation right about then and got rid of several other viruses - but not this one.Only my sister-in-law&#039;s account was affected, of five or so on the machine. The others seemed normal.Here are some things that did not work to get rid of Security Tool:- access to &quot;taskmgr&quot; ([CTRL-ALT-DEL]) was blocked by Security Tool
- access to &quot;regedit&quot; (via RUN start menu entry) was blocked by Security Tool
- access to &quot;control panel&quot; (via start menu entry) was blocked by Security Tool
- access to the directory tree of the affected account (via the command prompt) was &quot;denied&quot;, presumably by Security Tool
- restoring the machine to an earlier time (via System Restore) was impossible because there was only one backup listed in the restore calendar - Saturday, 27th Nov 2010 6:30 PM
- a &quot;full&quot; scan by Microsoft Security Essentials, a process that took hours due to the number of files on the machine, found three more viruses but did not get rid of Security ToolAnother odd thing was the appearance in all accounts of &quot;Whitesmoke Translator&quot;, which made its presence known by altering the menu of Internet Explorer (version 8). Timestamps again showed this appeared on Saturday, 27th Nov 2010 around 5:40 PM. Internet Explorer&#039;s default home page for this account was re-set from Yahoo! to Bing. Navigation became difficult because of random re-direction whenever any link was clicked.No one admitted to downloading and/or installing this software. The download package was found in a &quot;Whitesmoke&quot; directory in a &quot;temp&quot; directory, and a file in that directory was named &quot;Whitesmoke Silent Install&quot;.After finding this list of comments (thanks everyone!) I found this to be fairly effective (fingers are still crossed):- after selecting the infected account, pressing [CTRL-ALT-DEL] while the account was initializing brought up Task Manager before Security Tool obtained control
- on the &quot;Process&quot; tab, sorting on &quot;Image Name&quot; brought up Security Tool&#039;s random alias at the top of the list (in this case, &quot;441287&quot;). This didn&#039;t actually happen right away, as there was still a slight wait after Task Manager began running before Security Tool began running and displaying its annoying messages
- using Task Manager to &quot;End Task&quot; stopped &quot;441287&quot; running. Full control of the account appeared to return
- a slight detour: brought up &quot;Control Panel&quot; and then &quot;Add/Delete Programs&quot; to try to get rid of &quot;Whitesmoke Translator&quot;. Two entries found: one for &quot;Whitesmoke Toolbar&quot; and one for &quot;Whitesmoke Translator&quot;. The first was deleted easily with no fuss (IE&#039;s menus returned to normal). Deleting the second caused a message to appear: &quot;&#039;mfptray.exe&#039; is preventing access to Whitesmoke Translator. Please stop this process and try again&quot;
- found &quot;mfptray&quot; in Task Manager and stopped it running (oops)
- attempting to delete &quot;Whitesmoke Translator&quot; again brought up a message: &quot;&#039;rundll32.exe&#039; is preventing access to Whitesmoke Translator. Please stop this process and try again&quot;
- yeah, well, by now it looks to me like Security Tool is taunting me. &#039;Mfptray.exe&#039;, a little too-late research shows, is part of the McAfee anti-virus suite that came with the machine
- gave up on that and began looking for &quot;441287.exe&quot;. Set &quot;Folder Options&quot; to show all hidden and system files. Found &quot;441287.exe&quot; in &quot;C:\Documents and Settings\[UserName]\Local Settings\Appplication Data&quot;. Deleted the file.
- went through the entire directory tree under &quot;C:\Documents and Settings\[UserName]&quot; and deleted every file and directory I could find, but not confirm harmless, dated 27 Nov 2010 or later (bye-bye &quot;Whitesmoke&quot; directory)
- used RegEdit&#039;s search feature to look for &quot;441287&quot; in the registry. Found only one occurance  at &quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce&quot;. Note this was not the &quot;Run&quot; key, and nothing was found under &quot;HKEY_CURRENT_USER&quot;, so apparently Security Tool doesn&#039;t always do things the same way
- deleted &quot;Security Tool&quot; from the Start Menu. There was no desktop icon for it that I could see
- used the Start Menu &quot;Search&quot; to look for all files with &quot;441287&quot; in their names, including hidden and system files and all subdirectories. &quot;441287.exe&quot; was already deleted and the search did not find any with different extensions (&quot;.bat&quot;, &quot;.ini&quot;, &quot;.cfg&quot;, etc)Then I did a soft reboot, ie., selected the restart option without turning off the machine. Got back into the infected account, but only saw the backround image. No icons, no menu, no nothing. No way to shut down the machine the &quot;nice&quot; way.Turned off the machine by holding the power button down long enough. Re-booted into the affected account. This time the icons and menus came up as expected. No Security Tool messages, no problem accessing anything.So things appear mostly cleaned up. However...IE8 still shows signs of random re-direction. Whethere this is a remnant of Security Tool or some other &quot;opportunitic&quot; virus is not apparent. Microsoft Security Essentials reports failure to update to the latest definitions even when manually told to (definitions remained at &quot;.654.&quot;, 25 Nov 2010, before the infection, when latest were &quot;.808.&quot;). Another little present left behind by unwelcome visitors...?The long term solution may be to wipe the drive and install Win7 - once my sister-in-law transfers off of it thousands of &quot;must have&quot; photos (the drive is almost full; no wonder Microsoft Security Essentials took so long to do a full scan).Hope this helps someone!</description> <content:encoded><![CDATA[<p>The Security Tool Virus infected my brother+sister-in-law&#8217;s WinXP computer last Saturday, 27th Nov 2010 around 5:40 PM, according to the timestamps I found. This computer was running Microsoft Security Essentials, and I noticed its history indicated it woke up for one of the few times since its installation right about then and got rid of several other viruses &#8211; but not this one.</p><p>Only my sister-in-law&#8217;s account was affected, of five or so on the machine. The others seemed normal.</p><p>Here are some things that did not work to get rid of Security Tool:</p><p>- access to &#8220;taskmgr&#8221; ([CTRL-ALT-DEL]) was blocked by Security Tool<br
/> - access to &#8220;regedit&#8221; (via RUN start menu entry) was blocked by Security Tool<br
/> - access to &#8220;control panel&#8221; (via start menu entry) was blocked by Security Tool<br
/> - access to the directory tree of the affected account (via the command prompt) was &#8220;denied&#8221;, presumably by Security Tool<br
/> - restoring the machine to an earlier time (via System Restore) was impossible because there was only one backup listed in the restore calendar &#8211; Saturday, 27th Nov 2010 6:30 PM<br
/> - a &#8220;full&#8221; scan by Microsoft Security Essentials, a process that took hours due to the number of files on the machine, found three more viruses but did not get rid of Security Tool</p><p>Another odd thing was the appearance in all accounts of &#8220;Whitesmoke Translator&#8221;, which made its presence known by altering the menu of Internet Explorer (version 8). Timestamps again showed this appeared on Saturday, 27th Nov 2010 around 5:40 PM. Internet Explorer&#8217;s default home page for this account was re-set from Yahoo! to Bing. Navigation became difficult because of random re-direction whenever any link was clicked.</p><p>No one admitted to downloading and/or installing this software. The download package was found in a &#8220;Whitesmoke&#8221; directory in a &#8220;temp&#8221; directory, and a file in that directory was named &#8220;Whitesmoke Silent Install&#8221;.</p><p>After finding this list of comments (thanks everyone!) I found this to be fairly effective (fingers are still crossed):</p><p>- after selecting the infected account, pressing [CTRL-ALT-DEL] while the account was initializing brought up Task Manager before Security Tool obtained control<br
/> - on the &#8220;Process&#8221; tab, sorting on &#8220;Image Name&#8221; brought up Security Tool&#8217;s random alias at the top of the list (in this case, &#8220;441287&#8243;). This didn&#8217;t actually happen right away, as there was still a slight wait after Task Manager began running before Security Tool began running and displaying its annoying messages<br
/> - using Task Manager to &#8220;End Task&#8221; stopped &#8220;441287&#8243; running. Full control of the account appeared to return<br
/> - a slight detour: brought up &#8220;Control Panel&#8221; and then &#8220;Add/Delete Programs&#8221; to try to get rid of &#8220;Whitesmoke Translator&#8221;. Two entries found: one for &#8220;Whitesmoke Toolbar&#8221; and one for &#8220;Whitesmoke Translator&#8221;. The first was deleted easily with no fuss (IE&#8217;s menus returned to normal). Deleting the second caused a message to appear: &#8220;&#8216;mfptray.exe&#8217; is preventing access to Whitesmoke Translator. Please stop this process and try again&#8221;<br
/> - found &#8220;mfptray&#8221; in Task Manager and stopped it running (oops)<br
/> - attempting to delete &#8220;Whitesmoke Translator&#8221; again brought up a message: &#8220;&#8216;rundll32.exe&#8217; is preventing access to Whitesmoke Translator. Please stop this process and try again&#8221;<br
/> - yeah, well, by now it looks to me like Security Tool is taunting me. &#8216;Mfptray.exe&#8217;, a little too-late research shows, is part of the McAfee anti-virus suite that came with the machine<br
/> - gave up on that and began looking for &#8220;441287.exe&#8221;. Set &#8220;Folder Options&#8221; to show all hidden and system files. Found &#8220;441287.exe&#8221; in &#8220;C:\Documents and Settings\[UserName]\Local Settings\Appplication Data&#8221;. Deleted the file.<br
/> - went through the entire directory tree under &#8220;C:\Documents and Settings\[UserName]&#8221; and deleted every file and directory I could find, but not confirm harmless, dated 27 Nov 2010 or later (bye-bye &#8220;Whitesmoke&#8221; directory)<br
/> - used RegEdit&#8217;s search feature to look for &#8220;441287&#8243; in the registry. Found only one occurance  at &#8220;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce&#8221;. Note this was not the &#8220;Run&#8221; key, and nothing was found under &#8220;HKEY_CURRENT_USER&#8221;, so apparently Security Tool doesn&#8217;t always do things the same way<br
/> - deleted &#8220;Security Tool&#8221; from the Start Menu. There was no desktop icon for it that I could see<br
/> - used the Start Menu &#8220;Search&#8221; to look for all files with &#8220;441287&#8243; in their names, including hidden and system files and all subdirectories. &#8220;441287.exe&#8221; was already deleted and the search did not find any with different extensions (&#8220;.bat&#8221;, &#8220;.ini&#8221;, &#8220;.cfg&#8221;, etc)</p><p>Then I did a soft reboot, ie., selected the restart option without turning off the machine. Got back into the infected account, but only saw the backround image. No icons, no menu, no nothing. No way to shut down the machine the &#8220;nice&#8221; way.</p><p>Turned off the machine by holding the power button down long enough. Re-booted into the affected account. This time the icons and menus came up as expected. No Security Tool messages, no problem accessing anything.</p><p>So things appear mostly cleaned up. However&#8230;IE8 still shows signs of random re-direction. Whethere this is a remnant of Security Tool or some other &#8220;opportunitic&#8221; virus is not apparent. Microsoft Security Essentials reports failure to update to the latest definitions even when manually told to (definitions remained at &#8220;.654.&#8221;, 25 Nov 2010, before the infection, when latest were &#8220;.808.&#8221;). Another little present left behind by unwelcome visitors&#8230;?</p><p>The long term solution may be to wipe the drive and install Win7 &#8211; once my sister-in-law transfers off of it thousands of &#8220;must have&#8221; photos (the drive is almost full; no wonder Microsoft Security Essentials took so long to do a full scan).</p><p>Hope this helps someone!</p> ]]></content:encoded> </item> <item><title>By: mega</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-8466</link> <dc:creator>mega</dc:creator> <pubDate>Mon, 22 Nov 2010 10:35:26 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-8466</guid> <description>this is&quot;Maged&quot; method:-
go to:tools &gt; view &gt;show hidden files
go to:start&gt;programs&gt;security tool to determine virus location
its usual path is:
Documents And Settings&gt;[UserName]&gt;Local Setting&gt;Application Data.
u will find the virus icon named with some numbers, rename virus file with my name: maged
restart pc then go back to virus file and delete it manually
use registery crawler program to delete any keys left in registery..good luck</description> <content:encoded><![CDATA[<p>this is&#8221;Maged&#8221; method:-<br
/> go to:tools &gt; view &gt;show hidden files<br
/> go to:start&gt;programs&gt;security tool to determine virus location<br
/> its usual path is:<br
/> Documents And Settings&gt;[UserName]&gt;Local Setting&gt;Application Data.<br
/> u will find the virus icon named with some numbers, rename virus file with my name: maged<br
/> restart pc then go back to virus file and delete it manually<br
/> use registery crawler program to delete any keys left in registery..good luck</p> ]]></content:encoded> </item> <item><title>By: Pavel</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-7189</link> <dc:creator>Pavel</dc:creator> <pubDate>Tue, 31 Aug 2010 06:58:33 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-7189</guid> <description>Thanks a lot! It worked. Had to download the program on the other computer since the virus was blocking my browser. Did a scan found a lot of things, restarted the computer in normal mode (before was in safe mode), browser still not working, turned off proxy and it worked. Did another virus scan with avg, found more stuff. All good now. Thanks for posting this.</description> <content:encoded><![CDATA[<p>Thanks a lot! It worked. Had to download the program on the other computer since the virus was blocking my browser. Did a scan found a lot of things, restarted the computer in normal mode (before was in safe mode), browser still not working, turned off proxy and it worked. Did another virus scan with avg, found more stuff. All good now. Thanks for posting this.</p> ]]></content:encoded> </item> <item><title>By: Monica</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-7180</link> <dc:creator>Monica</dc:creator> <pubDate>Sun, 29 Aug 2010 23:57:39 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-7180</guid> <description>It took me all day to get rid of it with no extra fees what-so-ever. The virus attached to my task bar and when I put my mouse over it the number was there.  I suggest highly that you follow youtube&#039;s video on removing security tool to remove this virus.  Also, the program wasn&#039;t under all users, it was hiding under documents and settings, my name, and local.  Weird....</description> <content:encoded><![CDATA[<p>It took me all day to get rid of it with no extra fees what-so-ever. The virus attached to my task bar and when I put my mouse over it the number was there.  I suggest highly that you follow youtube&#8217;s video on removing security tool to remove this virus.  Also, the program wasn&#8217;t under all users, it was hiding under documents and settings, my name, and local.  Weird&#8230;.</p> ]]></content:encoded> </item> <item><title>By: Kathryn</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-7023</link> <dc:creator>Kathryn</dc:creator> <pubDate>Mon, 16 Aug 2010 12:56:44 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-7023</guid> <description>Have just had the world&#039;s worst weekend trying to get rid of the Security Tool virus program. Have run Malwarebyte&#039;s Antimalware program repeatedly and Advanced SystemCare. It works but I have some queries. The malware program is no longer recognising any threats, however ASC is still finding threats. Have run ASC several times today with it repairing each time, and rebooted following same. Have I got rid of this horrible virus completely?  Can I trust Google or Internet Explorer ever again? Found virus as 730845 (didn&#039;t start with 8)hiding in/via Internet Explorer shortcut. How do I know if I got it all?</description> <content:encoded><![CDATA[<p>Have just had the world&#8217;s worst weekend trying to get rid of the Security Tool virus program. Have run Malwarebyte&#8217;s Antimalware program repeatedly and Advanced SystemCare. It works but I have some queries. The malware program is no longer recognising any threats, however ASC is still finding threats. Have run ASC several times today with it repairing each time, and rebooted following same. Have I got rid of this horrible virus completely?  Can I trust Google or Internet Explorer ever again? Found virus as 730845 (didn&#8217;t start with 8)hiding in/via Internet Explorer shortcut. How do I know if I got it all?</p> ]]></content:encoded> </item> <item><title>By: Greg</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-6911</link> <dc:creator>Greg</dc:creator> <pubDate>Wed, 04 Aug 2010 11:18:38 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-6911</guid> <description>SuperAntiSpyware will get rid of this, make sure system restore is off, this is a TSR program that will keep coming back if you don&#039;t have System Restore turned off, which isn&#039;t a big deal as long as you&#039;re backing your system up anyway, which is what you shold be doing.  Took me two times running it but it&#039;s gone now.  Good luck.</description> <content:encoded><![CDATA[<p>SuperAntiSpyware will get rid of this, make sure system restore is off, this is a TSR program that will keep coming back if you don&#8217;t have System Restore turned off, which isn&#8217;t a big deal as long as you&#8217;re backing your system up anyway, which is what you shold be doing.  Took me two times running it but it&#8217;s gone now.  Good luck.</p> ]]></content:encoded> </item> <item><title>By: Ferdi</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-6828</link> <dc:creator>Ferdi</dc:creator> <pubDate>Mon, 26 Jul 2010 21:42:07 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-6828</guid> <description>We have just successfully removed Security tool virus from my mates pc- running windows 7 Here is a step by step. Try it, I hope it works for you.
1.restart pc in normal mode.
2.The moment you log into your account(If you have one)Key cont.Alt.Del in order to start task manager before the malicious virus program has a chance to start running, because when given time to start it blocks access to task manager.
3.We got task manager started this way and it reveled to us where the location of the .exe file was.(look for a 10 digit numbered.exe file)
4.Now make a note of where the file is and stop the process in task manager.
5. The file will be hidden so you need to go to folder view and choose option tick show hidden files,folders and drives and un-tick hide protected operating system files.
6.Now, from the location note you have made, find the file (normaly a 10 digit number.exe) and delete it. Also empty your recycle bin.
And we hope you have done it!!! Good luck when restarting your PC.</description> <content:encoded><![CDATA[<p>We have just successfully removed Security tool virus from my mates pc- running windows 7 Here is a step by step. Try it, I hope it works for you.<br
/> 1.restart pc in normal mode.<br
/> 2.The moment you log into your account(If you have one)Key cont.Alt.Del in order to start task manager before the malicious virus program has a chance to start running, because when given time to start it blocks access to task manager.<br
/> 3.We got task manager started this way and it reveled to us where the location of the .exe file was.(look for a 10 digit numbered.exe file)<br
/> 4.Now make a note of where the file is and stop the process in task manager.<br
/> 5. The file will be hidden so you need to go to folder view and choose option tick show hidden files,folders and drives and un-tick hide protected operating system files.<br
/> 6.Now, from the location note you have made, find the file (normaly a 10 digit number.exe) and delete it. Also empty your recycle bin.<br
/> And we hope you have done it!!! Good luck when restarting your PC.</p> ]]></content:encoded> </item> <item><title>By: Rog</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-6081</link> <dc:creator>Rog</dc:creator> <pubDate>Thu, 13 May 2010 17:07:04 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-6081</guid> <description>What does this virus do, i just got it the other day and norton quarantined it and is no longer there I also did a system restore to earlier that day just in case, is there anything else i should do? thanks.</description> <content:encoded><![CDATA[<p>What does this virus do, i just got it the other day and norton quarantined it and is no longer there I also did a system restore to earlier that day just in case, is there anything else i should do? thanks.</p> ]]></content:encoded> </item> <item><title>By: ian</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-5802</link> <dc:creator>ian</dc:creator> <pubDate>Sun, 18 Apr 2010 16:37:41 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-5802</guid> <description>how do i shut it down</description> <content:encoded><![CDATA[<p>how do i shut it down</p> ]]></content:encoded> </item> <item><title>By: murad</title><link>http://www.precisesecurity.com/rogue/securitytool#comment-5791</link> <dc:creator>murad</dc:creator> <pubDate>Sun, 18 Apr 2010 03:03:16 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/?p=4291#comment-5791</guid> <description>help my coputer from security tool virus</description> <content:encoded><![CDATA[<p>help my coputer from security tool virus</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 5/6 queries in 0.003 seconds using disk: basic
Object Caching 412/414 objects using disk: basic

Served from: www.precisesecurity.com @ 2012-02-12 03:50:17 -->
