computer_expert Posted March 6, 2011 Posted March 6, 2011 Found this on another site: 1. Click the "Registration" link in System Tool. 2. Enter the following registration code: WNDS-S0DF5-GS5E0-FG14S-2DF8G Note: If that code does not work, try one of these WNDS-JUYH3-24GHJ-HGKSH-FKLSD WNDS-89OF7-7324R-5SAD4-TG68U WNDS-HFVDR-9844O-U54DA-5TBSC WNDS-G8FB6-1V87S-DRT1S-63SRG WNDS-4BGY2-JY4KO-IT98Y-7HJ43 WNDS-5D1V2-XB0D5-JT1TY-97DS3 WNDS-F40SA-1ER5H-4FG5D-F8412 WNDS-SERFH-2642S-F04SD-64FG1 WNDS-S0DF5-GS5E0-FG14S-2DF8G WNDS-452S3-ER00F-TSE35-S8FSD WNDS-FGS5D-649RG-4S53D-412SF WNDS-4TS8R-D6F5D-4JH8T-U4JK5 WNDS-2AE32-1VFC2-B6894-G67YU WNDS-P9685-4H41A-DSW3A-2R64T WNDS-5SRTS-AEHUF-YA54S-D6F35 WNDS-A1SDF-RY4E8-7U98D-F1GB2 3. Click OK to allow System Tool to scan. 4. When it prompts you, reboot. 5. Download MBAM from here: Bleeping Computer Downloads: Malwarebytes' Anti-malware 6. Install. Leave "Update" and "Launch" checked. 7. After updating, run a Full Scan. This is because Security Tool files have been found in old System Restore archives. Video of the above here An Alternative way Actually you can get rid of this in 2 steps. Just click on my computer, then on local disk, then documents and settings, then all users, then application data. You will look for a folder with random letters, like hvbcgdsfh. Open it and you will see 2 files. One of those files is the executable or .exe. rename that file with a new extension like.bmp and delete the other file. Now reboot and go back to that folder and delete it. Then continue from 5. above Note dependent on the variant of the malware you may have to go the longer route as here http://www.bleepingcomputer.com/viru...ve-system-tool The above has been found from information on the net. MoneySavingExpert.com Forums
CHR1S Posted March 7, 2011 Posted March 7, 2011 There seems to be a fresh batch of these coming up from this weekend, 3 more laptops, same virus! Grrr
themightymrp Posted March 7, 2011 Posted March 7, 2011 Yep, we had another 3 before 8:15 this morning
JJonas Posted March 7, 2011 Posted March 7, 2011 (edited) What needs to be updated to stop this installing? Doing a Windows update doesn’t appear to close the loophole. Edited March 7, 2011 by JJonas
CHR1S Posted March 7, 2011 Posted March 7, 2011 What needs to be updated to stop this installing? Automatic running of scripts turned off for trusted sites (well all sites) will stop it, but would be a pain.
JJonas Posted March 7, 2011 Posted March 7, 2011 What about spywareblaster will that stop it installing?
CHR1S Posted March 7, 2011 Posted March 7, 2011 Unlikely, it seems to be selective in how it attacks. All laptops infected had fully up to date Sophos Endpoint and one had AVG Free and both were disabled by the virus. In our case a rootkit was installed and the system compromised that way. These were all SP3 XP and reasonably patched as they were staff laptops I wont say fully Seems it tries out different vulnerabilities and finds one that works.
JJonas Posted March 7, 2011 Posted March 7, 2011 Is there a list of vulnerabilities that need to be patched?
AyatollahPies Posted March 7, 2011 Posted March 7, 2011 What happens when a new variant comes out that blocks MBAM from running?
CHR1S Posted March 7, 2011 Posted March 7, 2011 Nothing, you just have to hope that the detection algorithms evolve quicker than the virus wrapper used to make the package. You could look at some software that does DLL monitoring and prevents changes, hopefully stopping some forms of rootkit but thats only one avenue of attack. Patch, protect and be vigilant... all you can do really.
simpsonj Posted March 7, 2011 Posted March 7, 2011 Got a particularly nasty variant of Vista Antivirus 2011 running on a laptop here. I think I've removed the main part of the problem, but now the laptop blue screens on a normal boot. I've tried disabling drivers in Device manager, and turning off the automatic reboot through regedit, but as soon as the PC reboots, these changes aren't saved. In all likelyhood it has probably latched onto System Restore, but I'm loathe to turn that off. Any other ideas?
timzim Posted March 7, 2011 Posted March 7, 2011 Found this on another site: MoneySavingExpert.com Forums Not too impressed with the last link: Remove System Tool and SystemTool (Uninstall Guide) - when I followed its instructions to download RKill my McAfee detected that was infected with another Trojan and promptly deleted it. Rest of page seems valid but is very long-winded...
JJonas Posted March 7, 2011 Posted March 7, 2011 What do I patch? My colleagues machine was fully up to date with microsoft, running an up to date antivirus and he still caught it.
tech_guy Posted March 7, 2011 Author Posted March 7, 2011 That's a false-positive from McAfee for RKill. We had that as well. 1
JJonas Posted March 7, 2011 Posted March 7, 2011 I've read reports JRE is to blame? Ive seen the same reports but no definite confirmation.
CHR1S Posted March 7, 2011 Posted March 7, 2011 Got a particularly nasty variant of Vista Antivirus 2011 running on a laptop here. I think I've removed the main part of the problem, but now the laptop blue screens on a normal boot. I've tried disabling drivers in Device manager, and turning off the automatic reboot through regedit, but as soon as the PC reboots, these changes aren't saved. In all likelyhood it has probably latched onto System Restore, but I'm loathe to turn that off. Any other ideas? Boot to safe mode and run Anti-rootkit utility TDSSKiller These fake AV viruses often throw up fake BSODs too. Try the rootkit checker above and report back 1
CHR1S Posted March 14, 2011 Posted March 14, 2011 Had a fresh infection this weekend, its still out there. Teacher went to a website via google and got infected.
somabc Posted March 14, 2011 Posted March 14, 2011 What version of JRE, Acrobat and Flash are they running?
FragglePete Posted March 14, 2011 Posted March 14, 2011 We've had a laptop in this morning with another one. Interesting, last week I was on youTube and while looking for a video on how to make something for Cubs when the browser screen went compleletly white and then this page showed up. Must have kicked in from an advert on the page. It does this fake scan and then you get an official looking dialogue box up something along the lines of 'do you want to remove this infection' and the innocent user click yes; job done machine is bu**ered! Note the address people; I've added *.freello.ce.ms* to our blocklist. Pete
somabc Posted March 14, 2011 Posted March 14, 2011 That is not an infection that is a website 'pretending' to show that your PC is infected.
Thefuturesbright Posted March 14, 2011 Posted March 14, 2011 I had to remove it last week, right pain in the ass.
Sirbendy Posted March 14, 2011 Posted March 14, 2011 I had one last week too from a staff member. I've seen worse..but it IS a PITA. Very SpyAxe-esque.
FragglePete Posted March 14, 2011 Posted March 14, 2011 That is not an infection that is a website 'pretending' to show that your PC is infected. Didn't say it was. This is one location that innocent users are being directed to and then installing the infection without realising. Pete
FragglePete Posted March 30, 2011 Posted March 30, 2011 Another attempt this morning, directed from an compromised advert. Directed the user to: http://update3.leger.ce.ms which again, did a fake scan, etc, etc. Add to your block lists! Pete 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now