answersLogoWhite

0

How do you get rid of security tool?

User Avatar

Anonymous

15y ago
Updated: 8/17/2019

what i found useful is this website

http://www.bleepingcomputer.com/virus-removal/remove-system-security

the instructions are

System Security is a rogue anti-spyware program from the same family as Winweb Security. This program is classified as a rogue because it uses false scan results as a method of scaring you into purchasing the software. If System Security is installed, it will be set to start automatically when you login to your computer. Once running, the program will begin to scan your computer and list a variety of infections that cannot be removed unless you first purchase the program. A dangerous problem is that System Security will list legitimate and necessary programs as infections. For example, one of the files that it states is an infection is C:\Windows\System32\svchost.exe. This file is not only legitimate, but a very important file for the operation of your computer. Without that file, your computer would not operate correctly and Windows itself may not start.

Another byproduct of System Security is that when it is running you will see a variety of false security alerts. These alerts range from warnings that your computer is being attacked to being infected with a variety of fake infections such as Lsas.Blaster.Keyloger and Spyware.IEMonster. If you click on these alerts, the program will open up a web browser and go to a page asking you to purchase the software. Just like the false scan results, these alerts are only trying to scare you into buying the program. Please ignore these alerts and instead use the free removal guide below.

System Security screen shot

For more screen shots of this infection click on the image above.

There are a total of 5 images you can view.

This guide will walk you through removing the System Security program and its associated malware for free.

Threat Classification:

  • Information on Rogue Programs & Scareware

Advanced information:Answers.com

Answers.com

Tools Needed for this fix:

  • Malwarebytes' Anti-Malware

Symptoms that may be in a HijackThis Log:Note: Some of the file and folder names are random:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "1632575944"

Guide Updates:12/24/08 - Initial guide creation.

Automated Removal Instructions for System Security using Malwarebytes' Anti-Malware:

  1. Print out these instructions as we may need to close every window that is open later in the fix.
  2. Before we can do anything we must first end the System Security process as it disables the ability to run various programs, including MalwareBytes' Anti-Malware. To do this we must first download and install a Microsoft program called Process Explorer. Normally, we would have you use the Windows Task Manager to terminate the process, but this rogue will disable this utility as well. Please download Process Explorer from the following link and save it to your desktop.

    Process Explorer Download Link

  3. Once the program has finished downloading, look for the procexp.exe file that should now be located on your desktop. Once you find it, right-click on it and select Rename. After you click on the Rename option, you will now be able to change the name of the icon. Please change the name to explorer.exe. Once the file has been renamed, double-click on it and you will be asked to agree to the license agreement. You may also see a screen with Windows asking if you are sure you want to run the program. Please do so and you should be presented with a screen similar to the one below.
  4. Scroll through the list of running programs until you see a process that has a name consisting of random numbers, such as 13279294.exe or 51231676.exe. This process is the main System Security process, which is blocking access to our programs. A further way to identify the process is that there will be a small picture of a shield next to the process in question. When you have identified this process, select it by left-clicking on it once so it becomes highlighted. Then click on the red X button as shown in the image below.
  5. When you click on the red X to kill the process, Process Explorer will ask you to confirm if you are sure you want to terminate it as shown in the image below.

    At this point you should press the Yes button in order to kill the process.

  6. Download Malwarebytes' Anti-Malware, or MBAM, from the following location and save it to your desktop:

    Malwarebytes' Anti-Malware Download Link

  7. Once downloaded, close all programs and Windows on your computer, including this one.
  8. Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MBAM onto your computer.
  9. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malwarechecked. Then click on the Finish button. If MalwareBytes' prompts you to reboot, please do not do so.
  10. MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program as shown below.
  11. On the Scanner tab, make sure the the Perform quick scan option is selected and then click on the Scanbutton to start scanning your computer for System Securityrelated files.
  12. MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. When MBAM is scanning it will look like the image below.
  13. When the scan is finished a message box will appear as shown in the image below.

    You should click on the OK button to close the message box and continue with the SystemSecurity removal process.

  14. You will now be back at the main Scanner screen. At this point you should click on the Show Results button.
  15. A screen displaying all the malware that the program found will be shown as seen in the image below. Please note that the infections found may be different than what is shown in the image.

    You should now click on the Remove Selected button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine. When removing the files, MBAM may require a reboot in order to remove some of them. If it displays a message stating that it needs to reboot, please allow it to do so. Once your computer has rebooted, and you are logged in, please continue with the rest of the steps.

  16. When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.
  17. You can now exit the MBAM program.

Your computer should now be free of the SystemSecurityprogram. If your current anti-virus solution let this infection through, you may want to consider purchasing the PRO version of Malwarebytes' Anti-Malware to protect against these types of threats in the future.

If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below:

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help

Associated System Security Files:Note: Some of the file and folder names are random:

c:\Documents and Settings\All Users\Application Data\538654387

c:\Documents and Settings\All Users\Application Data\538654387\Languages

c:\Documents and Settings\All Users\Application Data\538654387\1632575944.exe

c:\Documents and Settings\All Users\Application Data\538654387\config.udb

c:\Documents and Settings\All Users\Application Data\538654387\init.udb

c:\Documents and Settings\All Users\Application Data\538654387\Languages\English.lng

c:\Documents and Settings\All Users\Application Data\538654387\Languages\German.lng

c:\Documents and Settings\All Users\Application Data\538654387\Languages\Spanish.lng

\Desktop\System Security.lnk

\Start Menu\Programs\System Security

\Start Menu\Programs\System Security\System Security.lnk

Associated System Security Windows Registry Information:Note: The Registry value names are random:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "1632575944"

This is a self-help guide. Use at your own risk

User Avatar

Wiki User

15y ago

What else can I help you with?

Related Questions

Security Tool will not let me launch from the directory so I can not run Spy Doctor or other malware programs How do I get rid of this beast?

This beast can also be removed manually:http://www.2-viruses.com/remove-security-tool


What dangers does the security tool pose?

Security Tool is actually a virus that is posing as a legitimate computer security program. If you get a pop up telling you that you have infections and that you need to purchase some software to get rid of them this is a scam and you should not click on the link or your computer will be infected. If you do not have legitimate and current anti-virus software running you may risk a crash of your system and loss of files.


What security key for Dragon City hack tool 2.1.1?

what is the security key to dragon city tool v3.1


When was Security Administrator Tool for Analyzing Networks created?

Security Administrator Tool for Analyzing Networks was created in 1995.


What is the security key of stormfall age of war hack tool?

stormfall age of war hack tool v1.5 security key


How do you get the security key for Dragon City hack tool v1.2?

k1j2h3g4 this is the security key for dragon city hack tool v 1.2


How do you get rid of norton 360?

Use the Norton Removal Tool:


Which security identifiers to object created in its domain?

rid


What is the security key to Clash of Clans hack tool 1.2v?

The security key to Clash of Clans Hack Tool 1.2V is Single User. To get the security key you need to upgrade to a premium user.


How do you get rid of the security notice on Tumblr?

Once you view the security message, it should go away.


What is the most recommended security tool for Macs?

The best security program for Macs is Intego Internet Security Barrier.


Which tool allows administrators to create and manage security profiles?

Security configuration Wizard