'Security Tool' rogue antivirus
Tuesday, April 20, 2010 at 1:07PM | by
Dan Littley
There is a particularly nasty rogue antivirus application called 'Security Tool' doing the rounds just lately. It's been prevelant over the past month or two and once installed on your system it can be quite a pain to remove.
"Security Tool is a rogue antivirus application that deliberately gives reports of false system security threats on your computer and displays fake security alerts or notifications to make you think your PC is infected with malware. The misleading application is from the same family as Total security 2009 and System Security. When installed, Security Tool will be configured to start automatically when you log on into Windows. Then it will imitate system scan and display a variety of infections that can't be removed unless you purchase the program. The files detected during the scan are either harmless or legitimate system files and can't cause any damage to your computer." Source: http://www.2-spyware.com
Thats the official description. What actually happens is, you'll be on a web page (more often than not a free online flash games site) and you'll get a pop up that looks like this:

This looks like a legitimate Windows security warning doesn't it? Well, its actually pretty easy to tell its fake. Both the top and bottom paragraphs of text contain broken English and bad grammar. This is the biggest clue that its a rogue warning. Regardless of which option you choose, Security Tool will subsequently be installed on your system, either via a .exe download or via a backdoor trojan which you won't even see! If you have not clicked on anything and are looking at this fake window, at this point you have not been infected. Dont even try to close the window. Simply click on your Start button and hit Shut down. This will close all running applications (including the fake popup) and shutdown your PC. You can then start it back up again and your PC should start up and operate as normal.
Phew! That was a close one. But what happens if you clicked either of the buttons? Well usually at that point its too late. Your system will be infected with Security Tool and the next time you restart your PC it will hijack Windows. It doesn't actually cause any damage, its main line of attack is twofold. Firstly, it wants to be as intrusive as possible, throwing you pop-ups all the time telling you that your PC is infected with many trojans/malware. This is of course still fake, the only infection you have is Security Tool itself, all its trying to do is trick you into purchasing their software - which you'll be charged for, but never recieve. Swines! Secondly, it cripples the main functions of Windows to make it extremely difficult to get rid of.

At this point, try not to panic. You shouldn't lose any data and your PC is recoverable without the need for drastic measures such as formatting the hard drive or throwing it under a truck! Due to the prevelance of Security Tool there are some very comprehensive removal instructions available. The best I have found (and tested) can be found below.
Remove Security Tool and SecurityTool (Uninstall Guide)
Of course, if you have a Support Contract with FIRST4TECH all you have to do is give us a call and we'll do the rest. :)





Reader Comments