Jump to content

Recommended Posts

Posted

Hi all,

 

Just had a teacher come to me with her laptop and say it's got 33 infections on it and can I sort it before the day is out?

This is the school laptop which is taken home and so has Sophos on it as do all of our machines and it's very rare for Sophos to actually alert the user to anything strange, it just gets on with it's job so I asked her what she had been doing with it/ had she used some other anti-virus. I got the reply of "yes, I've used a 3rd party bit of software". great...

Turned the laptop on and up pops "Security Tool" which then proceeds to do what looks like the fastest full system scan in history and tells me that the computer is full of infections even though sophos reckons it's fine. It even recreates the little red warning shield in the taskbar to say there is a problem.

Now before I delete this software and let Sophos carry on, is there any chance it's legit or has anyone used it before?

 

Regards

Rich

Posted

Definitely malware. Had this several times here and can be tricky to remove. If it's any use, this is how we did it.

 

  1. Copy TaskMgr.exe and call the new copy iexplore.exe (some versions of "Security Tool" will close applications such as Task Manager by identifying the exe's name - thus renaming it gets you round this).
  2. Kill off the Security Tool process - each time I've seen this it's been named a random number in the list.
  3. Download and run Malbytes Antimalware. Run a full scan and remove all that it finds.

  • Thanks 1
Posted

Have you sneaked into the school I'm in at the moment and decided to take *** ****** and their problems of my hands?

 

Had a similar problem recently where a teacher downloaded/installed something similar and then their "computer whiz" other half decided to install Norton to cure the problem. Got it sorted, but 1 month (and a spanking new W7 laptop later) and they've got the same problem :mad:.

Posted

LeMarchand, I hate it when there "friend who is a computer expert (obviously much better than you but is out of a job atm because of x,y,z) said....".

I think in this case it was probably caused by her kids using it. Also had the cheek to blame me for it and the best bit, she has cancelled all of her credit cards/banking because it came up with a message saying they were being transmitted by MSN!

Posted
I think in this case it was probably caused by her kids using it.

 

Yeah, I get that too! Particularly annoying when they say "but I told little Johnny/Jenny not to use my laptop..." (why not just not give then your password) or "I never let little Johnny/Jenny use my machine" and you find loads of kid's sites in their browsing history or MSN launches with Windows into their kid's account or they have installed Barbie/GTA/other games. (Yes, I know, but if SMT won't agree to the machines being locked down...)

Posted

If you're Sophos subscribers, you can ask Sophos for the link to a bootable disc.

 

As soon as anything like this crops up, I just boot the machine this and run the scan from there.

(Had the exact same issue last week)

 

Avira also do one for free. We just download the latest version each work and burn it to a CD/RW.

 

Great addition to the arsenal.

Posted (edited)
What I would like to know is why Sophos never seems to stop these from infecting machines. In the past month I have notices an increase on the number of staff laptops getting infected with this type of Malware. All have Sophos installed and up-to-date.

 

Am I missing something glaringly obvious?

 

We are having this same issue and I've been told by Sophos... upgrade to endpoint [costs £]... really not good enough.

 

Don't get me started on Conficker & Sophos, it is just not enterprise grade security.

Edited by dwhyte85
Posted
Had to clean that one of a heads home PC before and it was a right pain to do, can't remember now how I did it but think it had installed it somewhere in a non descript named folder hidden away, begger to find but did it in the end.
Posted
What I would like to know is why Sophos never seems to stop these from infecting machines. In the past month I have notices an increase on the number of staff laptops getting infected with this type of Malware. All have Sophos installed and up-to-date.

 

Am I missing something glaringly obvious?

 

Our LEA uses McAfee - same problem.

Posted

Kaspersky do a great bootable disk that IS proxy aware, so will update definitions if you provide proxy details and you don't need to burn a new disc every week.

 

Need to burn a few to take to Church after someone got their computer compromised and sent everyone "Lol! This is you!" messages on Facebook. :(

 

Standard response when trying to marshall some kind of awareness to prevent it spreading was "What is antivirus?". In one case I gave the user a link to MSE and she installed it but then neglected to perform the update and run a full scan part of the instructions. :rolleyes:

  • 2 weeks later...
Posted
Tried these instructions but I get an error code 707 (3, 0) so Malwarebytes won't run. I don't want to pay for it either as it is a teachers laptop!

Couldn't find a free version...:mad:

 

Of MalwareBytes?

 

The link on that page seems to be for the free version.

  • 1 month later...
Posted
The easiest way to get rid of that kind of virus is to use System Restore, every time I've seen something akin to that type of virus, a system restore has worked. Provided System restore is turned on of course...
Guest theeldergeek
Posted
The easiest way to get rid of that kind of virus is to use System Restore, every time I've seen something akin to that type of virus, a system restore has worked. Provided System restore is turned on of course...

 

System Restore can of course also harbour an infection, and 'restoring' simply re-introduces the infection back onto the computer. Might not be the case in this situation, but something to be aware of.

Posted

Surely the reason this "security tool" gets past AV is because the user has manually installed the software...this makes it look legitimate to the AV software.

 

There has been a problem on Google recently where someone managed to insert loads of rogue entries that relate to searches for educational resources.

 

The results that are returned point to a site that displays a very convincing web page that looks like a real windows alert page. This does the rapid scan mentioned and then alerts the user to 100s of (fictitious) virus infections. It then offers to install a clean up tool which so far no users here have been dumb enough to accept.

 

I did have to clean a teachers home computer a while back after she fell for a very similar scam where the download was installed and at next restart tried to get her to give credit card details to pay for cleaning the computer of the non-existent viruses. Luckily she stopped there and called me.

Posted
If these are standard issue school laptops, a re-image would be far quicker and probably more effective

 

I would agree and if that staff member looses some documents that were not backed up then perhaps (just perhaps!!) they will learn to be more careful in the future.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...