News
Contributed by: Aurelija Skurvydaite
Date: October 1, 2009
We are all familiar with computer security tools. These are various programs that help us to protect our systems from being hacked and corrupted. However, are you familiar with a security tool that is called exactly that, Security Tool?! I should say that you're the lucky one if you haven't encountered it yet. Why? My answer is very simple. Security Tool (also known as SecurityTool) is a new rogue anti-spyware application increasingly attacking huge numbers of unaware computer users. Security Tool is known to belong to the same rogueware family as Total Security 2009, Total Security, TotalSecurity, Total Security 4.52 or TotalSecurity2009. This fake security program can be dropped onto your system by other Trojan applications. All this is done without the users knowledge or consent. The other way Security Tool can enter your system is via a download from the browser hijacker, s i t e s e c u r i t y t e s t . c o m. The analysis of the above mentioned website has shown that the registrant is Victor Acton located at 1632 Berkshire Circle, Knoxville, US. However, according to the IP address of the site - 87.233.30.85 - the real birthplace of the malware is in Amsterdam, the Netherlands. These completely different results show that cyber criminals are doing their best to stay undetected and perform their malicious activities successfully. The tactics used by the creators of this program are similar to the ones used by other cyber criminals. When on the system, Security Tool performs a fake system scan and generates exaggerated results claiming that your system is infected with hundreds of malware. Of course, all you have to do then is buy the full version of the program. Will it remove all the found malware? No! It won't resolve any fake or real system security problems. Have a look at the fake system scan: Image 1. Security Tool fake scan results Let's move on to more precise information concerning Security Tool. As is the case with any other malware, this rogue application is associated with a number of distinct files. All of them have to be deleted if you want to remove the malware from your system. Therefore, have a look at the following table that provides information about Security Tool files, their size and MD5 signatures:
Table 1. Security Tool file information That is just a portion of the technical information related to Security Tool. If you're interested in more detailed facts, keep an eye out for my next article on Security Tool tomorrow. It will include file analysis and a video illustrating the rogue programs malicious activities. For now, don't forget that this software application will not protect your PC. Don't download it and use a reliable security tool that is not called Security Tool! |
|||||||||||||||||||||||||||||||||||||||||

User Comments
Thanks for putting up, very good stuff, It is pretty ideal for everyone.
Thank you!
<a href="http://www.register-domainname.in">Register website domain</a>
I have microsoft security essentials protecting the laptop. However this virus first disabled it and then infected the m/c. I am wondering if I should buy some other virus software. Any suggstions folks?
Thanks
does anyone no how to stop it
Good work!
Security Tool (also known as SecurityTool)this is a new rogue anti-spyware application increasingly attacking huge numbers of unaware computer users. (hijackers)
fake scanner
fake result infection
please do not purchase/buy the activation key.
This fake security program can be dropped into your system by other Trojan applications. All this is done without the users knowledge or consent. The other way Security Tool can enter your system is via a download from the browser hijacker.
Cool!
Thanks Jay, you have one more friend.
Guy
@jay rayel. great! thanks jay
Ryan :)
Thnks the forum too, send regarads.
I would like to thank pc1news.com and Aurelija who have come forward to resolve Security Tool Issue. Without their efforts such an awareness was not possible. Keep up the good work. Thank you.
I was forced to make a payment so that I could use my computer,I did speak with my TD Bank Visa Department (Approval code # 006587 )thru which I made a payment requested them to dispute it. The name of the company is PC Buy Repair.com based in Lakewood. New Jersey USA.I am going to contact FBI tomorrow thru my Federal MP in Canada.Please come forward if you have been cheated by this company I will going live on You Tube requesting everyone to resolve the issue.
Thanks.
They need to be shot.
1. First when you restart your PC quickly hit the F8 to go safe mode display and hold it down until the next screen appears.
2. Then Choose Safe Mode
3. Allow windows to start-up and loaded in the safe mode.
4. At Start Menu click "Start", "All Programs", then
Right Click "Security Tool" go to properties then click Find Target. then
5. New windows pages will appear and comes up with file folders of all applications on your computer.
You will see there are two file that contained numbers only; example "86623461.exe" and "85452363.exe" Do not open those file instead Remove it, used key SHIFT+DELETE to Remove it totally in your computer.
6. Restart your PC. Everything will back to normal.
and operating systems.
Run a system restore. Open your control panel and select Security Options, and the option to restore your computer to an earlier time period will be available. This feature is intended exactly for this purpose, to remove stubborn and unwanted programs from the harddrive.
Also, I've noticed that the art site http://www.deviantart.com is a hot spot for the virus to attack, ( DA is based in Amsterdam, perhaps that has something to do with it...) so if you're a Deviant, stay alert around there.
I hope my advice can be of some assistance, because this thing is one *** of a virus. >_>
THIS IS WHAT I DONE TO TAKE SECURITY TOOL OFF MY COMPUTER
Restart your computer as it is loading press F8 repeatadly your screen will have a number of safe mode options goto safe mode with network this will take you to your normal screen now you are free to go to your restore to a earlier date which will take this criminal activity off your computer.Again this activity is criminal and it keeps on going on and on why are these poeple getting away with this day light robbery.Hope this helps everyone.
Thank you so much for taking your time to provide the very valuable advice
lucky i found this page that i thing it is very useful for me...and thanks to Jacqui March 31, 2010...i follow your instruction and the results is security tool removed from my computer...i got back my file that i save in desktop...
BUT in the evening when i turn on again my laptop...the security tool APPEARS again...this happen 3 times after even though i follow again the steps....HOW TO AVOID FROM INFECTING AGAIN BY THIS STUPID SECURITY TOOL?????I really need some advise...
It is FREE and can find and remove rogue malware like Security Tool. However, Security Tool usually won't let you run anything it senses as a "threat", so first you have to disable Security Tool. To do that, download rkill at http://www.technibble.com/rkill-repair-tool-of-the-week/
Again, this is a free, simple program. All it does is stop Security Tool from blocking programs on your computer so you can use another program (like malwarebytes) to remove it. IF Security Tool will NOT let you access your internet, download both programs on another computer and copy them to a CD, floppy disc or zip drive. Then move the programs onto the affected computer.
So, here's a basic outline of the steps described above:
1. If you can't access your internet, get on another computer with internet access. Download MalwareBytes at http://malwarebytes.org/
and rKill at
http://www.technibble.com/rkill-repair-tool-of-the-week/
2. Don't run the setup for either program on the unaffected computer. Just transfer whatever is downloaded straight to a CD, floppy disk or zip drive.
3. Insert CD, floppy disk or zip drive into the affected computer.
4. Go to START > COMPUTER > and then either CD or zip drive
5. Double click on "rkill"
6. This should kill the malware. Wait a minute or two and your desktop icons should appear again.
7. Now go back to the same place where you opened "rkill" (START > COMPUTER > _____)and drag and drop "mbam-setup" onto the desktop screen.
8. Double click "mbam-setup" on the desktop. Run the setup WITHOUT changing any options. It should automatically update and open when its finished installing.
9. Run a full scan- this can take a long time, but let it do its work!
10. When it's done, pick that you want to quarantine the viruses. Then go to the Quarantine tab and select "remove all."
11. Now go to START > PROGRAM FILES and see if you can find a folder called "Security Tools". If you do, send it to the recycle bin then empty the recycle bin. If you don't find the folder, it was deleted along with the rest of the virus by MalwareByte.
You're good to go! Good luck!
IAM NOT THE ONLY ONE who has been attacked by the "SECURITYTOOL" monsters! It actually happened to my granddaughters' new laptop. I had explained to her about been fooled into downloading ANYTHING, but this scared her real bad and she thought she was doing the right thing, as I'm sure everyone did. I have spent MANY hours trying to research what happened and was certain this "Security Tool" had something to do with it, but until now, I have gotten so much info that didn't include it, I've been at a loss at what to do. I was even shunned at Microsoft website, where I thought they were concerned of anytype of virus, etc. Perhaps I went about it the wrong way, but I wanted more info about it before I made accusations. Looks as though Aurelija is way ahead of me! Thank God! Thank you Aurelija for your diligent work! What else is being done to stop these crooks? Can we stop their website? Can we stop them from selling their software? Please let me know if I can help in anyway. I will help in the only way I know how at the moment, I will tell anything or anybody who will listen about this. Get the word out. We have to stop them and others like them. We are all vuneralbe at sometime, especially if we think something is wrong with our PCs. Again, I can't THANK YOU enough.
Sanfords son lamont "big dummy"
Andreas method worked. Easiest and fastest virus removal I have ever had to do. Thanks for that!
as effected with virus
getting a mssg stating security tool warning
not even the desktop ikons missing
not able to open single file
please help me in this
that will stop the annoying false messages anyway
THE SERIAL WORKS!
This is ONE NASTY, NASTY program! An employee in my office had her computer infected with this vicious program. The MIT DEPT could not figure it out as this program blocks anyone from entering ANY PROGRAMS on their computer.
Philly Keith is right on the button. I was able to remove this program. I wrote everything down so I could relay to others what works. This is step by step as some people are not as computer savvy as others, so bare with me please : ) Here is what I did:
*When you are restarting windows, the first screen to appear (in my case) is a blue screen that says DELL and has the F commands for set up and safe mode in the upper right of the screen.
*when this screen appears it only stays on a few seconds so VERY QUICKLY hit the F8 safe mode key and hold it down until the next screen appears.
*This new screen prompts you to choose what mode you want to start windows in. Use the up and down keys (located below the delete, end, page down keys) to select the safe mode and hit enter.
* Allow windows to start up and fully load in the safe mode.
* Once fully loaded, click on the start menu. Then click on the run€¦.which is usually located below the search.
* When this opens type C:documents and settingsall usersapplication data
* Click ok
* A page comes up with file folders of all applications on your computer. There was only one file that contained numbers only. Click open that file.
* A new page opens that shows The virus €œSecurity Tool€.
* I left clicked on the file (do not open!!!!) and clicked on the delete (which sends it to the recycle bin).
* I then clicked the back button and sent the file folder with the number (which is now empty) to the recycle bin.
* I closed out that window. I opened the recycle bin from my desk top and emptied my recycle bin.
* I shut my computer down and restarted. The virus was gone. I had to go into my display options and fix some of the display settings that had been changed from this virus. I also ran my anti virus program and scanned my computer right away. Everything is working good now. I hope that this helps someone out.
and press advanced settings before searching. Then click the boxabout hiddn files and folders so that it is checked. Then, search. In application data
folder that comes up in search results, delete the few folders
that have 8 digit names, I.e 17364977 or 73955727, but they are not those exact numbers. You can eben double check, one of the folders may have an exe file in it, that is he security tool but will be named different. Delete them from there, then from he recycle bin. You may have to do this on safe mode if the program doesn't let you, as did I.
To find system restore just search for it on start menu. ok
I wannu take out a shotgun, and shoot whoever did this!!!!!!!!!!
Sue
Hit me back. Jimmycano01@yahoo.com
This guy made a tool that removed the most common of this type of mal, but I don't know if he updates it at all, and the list of phony programs that use this scam probably grows exponentially. You could see if it works, though it's a fairly crude way of doing it, just attempting to delete all known components brute-force style.
This tool also seized my laptop last week, but with help from here and elsewhere I was able to remove it (for now!)
here's what i did - http://vikramdhunta.com/blog/2009/11/15/security-tool-trojan/
regards
I stupidly paid for the now apparently "fake" security tool, costing me a lot of money.
Firstly, i need this off my computer, and secondly i need to know how i can get my money back
Previous to that it stopped all attempts to download anti-malware tools...
Damn it sucked.
Help!!!.