News
Contributed by: Aurelija
Date: October 1, 2009
We are all familiar with computer security tools. These are various programs that help us to protect our systems from being hacked and corrupted. However, are you familiar with a security tool that is called exactly that, Security Tool?! I should say that you're the lucky one if you haven't encountered it yet. Why? My answer is very simple. Security Tool (also known as SecurityTool) is a new rogue anti-spyware application increasingly attacking huge numbers of unaware computer users. Security Tool is known to belong to the same rogueware family as Total Security 2009, Total Security, TotalSecurity, Total Security 4.52 or TotalSecurity2009. This fake security program can be dropped onto your system by other Trojan applications. All this is done without the users knowledge or consent. The other way Security Tool can enter your system is via a download from the browser hijacker, s i t e s e c u r i t y t e s t . c o m. The analysis of the above mentioned website has shown that the registrant is Victor Acton located at 1632 Berkshire Circle, Knoxville, US. However, according to the IP address of the site - 87.233.30.85 - the real birthplace of the malware is in Amsterdam, the Netherlands. These completely different results show that cyber criminals are doing their best to stay undetected and perform their malicious activities successfully. The tactics used by the creators of this program are similar to the ones used by other cyber criminals. When on the system, Security Tool performs a fake system scan and generates exaggerated results claiming that your system is infected with hundreds of malware. Of course, all you have to do then is buy the full version of the program. Will it remove all the found malware? No! It won't resolve any fake or real system security problems. Have a look at the fake system scan: Image 1. Security Tool fake scan results Let's move on to more precise information concerning Security Tool. As is the case with any other malware, this rogue application is associated with a number of distinct files. All of them have to be deleted if you want to remove the malware from your system. Therefore, have a look at the following table that provides information about Security Tool files, their size and MD5 signatures:
Table 1. Security Tool file information That is just a portion of the technical information related to Security Tool. If you're interested in more detailed facts, keep an eye out for my next article on Security Tool tomorrow. It will include file analysis and a video illustrating the rogue programs malicious activities. For now, don't forget that this software application will not protect your PC. Don't download it and use a reliable security tool that is not called Security Tool! |
|||||||||||||||||||||||||||||||||||||||||
Software Downloads


User Comments
IAM NOT THE ONLY ONE who has been attacked by the "SECURITYTOOL" monsters! It actually happened to my granddaughters' new laptop. I had explained to her about been fooled into downloading ANYTHING, but this scared her real bad and she thought she was doing the right thing, as I'm sure everyone did. I have spent MANY hours trying to research what happened and was certain this "Security Tool" had something to do with it, but until now, I have gotten so much info that didn't include it, I've been at a loss at what to do. I was even shunned at Microsoft website, where I thought they were concerned of anytype of virus, etc. Perhaps I went about it the wrong way, but I wanted more info about it before I made accusations. Looks as though Aurelija is way ahead of me! Thank God! Thank you Aurelija for your diligent work! What else is being done to stop these crooks? Can we stop their website? Can we stop them from selling their software? Please let me know if I can help in anyway. I will help in the only way I know how at the moment, I will tell anything or anybody who will listen about this. Get the word out. We have to stop them and others like them. We are all vuneralbe at sometime, especially if we think something is wrong with our PCs. Again, I can't THANK YOU enough.
Sanfords son lamont "big dummy"
Andreas method worked. Easiest and fastest virus removal I have ever had to do. Thanks for that!
as effected with virus
getting a mssg stating security tool warning
not even the desktop ikons missing
not able to open single file
please help me in this
that will stop the annoying false messages anyway
THE SERIAL WORKS!
This is ONE NASTY, NASTY program! An employee in my office had her computer infected with this vicious program. The MIT DEPT could not figure it out as this program blocks anyone from entering ANY PROGRAMS on their computer.
Philly Keith is right on the button. I was able to remove this program. I wrote everything down so I could relay to others what works. This is step by step as some people are not as computer savvy as others, so bare with me please : ) Here is what I did:
*When you are restarting windows, the first screen to appear (in my case) is a blue screen that says DELL and has the F commands for set up and safe mode in the upper right of the screen.
*when this screen appears it only stays on a few seconds so VERY QUICKLY hit the F8 safe mode key and hold it down until the next screen appears.
*This new screen prompts you to choose what mode you want to start windows in. Use the up and down keys (located below the delete, end, page down keys) to select the safe mode and hit enter.
* Allow windows to start up and fully load in the safe mode.
* Once fully loaded, click on the start menu. Then click on the run¦.which is usually located below the search.
* When this opens type C:documents and settingsall usersapplication data
* Click ok
* A page comes up with file folders of all applications on your computer. There was only one file that contained numbers only. Click open that file.
* A new page opens that shows The virus Security Tool.
* I left clicked on the file (do not open!!!!) and clicked on the delete (which sends it to the recycle bin).
* I then clicked the back button and sent the file folder with the number (which is now empty) to the recycle bin.
* I closed out that window. I opened the recycle bin from my desk top and emptied my recycle bin.
* I shut my computer down and restarted. The virus was gone. I had to go into my display options and fix some of the display settings that had been changed from this virus. I also ran my anti virus program and scanned my computer right away. Everything is working good now. I hope that this helps someone out.
and press advanced settings before searching. Then click the boxabout hiddn files and folders so that it is checked. Then, search. In application data
folder that comes up in search results, delete the few folders
that have 8 digit names, I.e 17364977 or 73955727, but they are not those exact numbers. You can eben double check, one of the folders may have an exe file in it, that is he security tool but will be named different. Delete them from there, then from he recycle bin. You may have to do this on safe mode if the program doesn't let you, as did I.
To find system restore just search for it on start menu. ok
I wannu take out a shotgun, and shoot whoever did this!!!!!!!!!!
Sue
Hit me back. Jimmycano01@yahoo.com
This guy made a tool that removed the most common of this type of mal, but I don't know if he updates it at all, and the list of phony programs that use this scam probably grows exponentially. You could see if it works, though it's a fairly crude way of doing it, just attempting to delete all known components brute-force style.
This tool also seized my laptop last week, but with help from here and elsewhere I was able to remove it (for now!)
here's what i did - http://vikramdhunta.com/blog/2009/11/15/security-t ool-trojan/
regards
I stupidly paid for the now apparently "fake" security tool, costing me a lot of money.
Firstly, i need this off my computer, and secondly i need to know how i can get my money back
Previous to that it stopped all attempts to download anti-malware tools...
Damn it sucked.
Help!!!.