Gaming Security tool

  • Thread starter Thread starter WeeBabyDoll
  • Start date Start date
  • Views Views 1,940
  • Replies Replies 13

WeeBabyDoll

Well-Known Member
Member
Joined
Jan 29, 2010
Messages
259
Reaction score
0
Trophies
0
Age
37
Location
Scotland
Website
Visit site
XP
94
Country
So this morning I woke up and found my boyfriend had downloaded Security Tool and performing a scan on our laptop. My desktop has gone black with no icons anywhere and random warnings keep coming up like File is infected with a worm and is trying to send credit card details to a third party and when I try to open notepad or malwarebytes it closes the program and says it is infected with a worm. This teaches me for nodding off early and leaving the computer illiterate one to his own devices.
lecture.gif
 
So where can we help ?

i'd recommend disconnecting from the internet, you wouldn't want any more credit card numbers being sent.
 
I have never and will never put any details like that over a computer - too risky so am okay there.
I have tried to download the removal program from that link lolzed but when I try to run it it says the file is infected with a worm and wont allow it. Should I just uninstall it and then try and run Malwarebytes??
 
There's also a manual removal on that site:
QUOTE said:
Security Tool manual removal:
Kill processes:
4946550101.exe

Delete registry values:
HKEY_CURRENT_USER\Software\Security Tool
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "4946550101"

Delete files:
4946550101.bat
4946550101.cfg
4946550101.exe
Security Tool.lnk
Security Tool.lnk

Delete directories:
%UserProfile%\Application Data\4946550101
 
When I try and get task manager up to kill the processes it says it's infected with a bloody worm.
I'm going to take the face right off him when he wakes up...
 
Right I am logged on in safe mode with networking and I have opened task manager and in the processes I can't find 4946550101.exe
Should I uninstall and run Malwarebytes?
 
Ok nice, your in "save mode".. the program wont start now so it wont apair in processes list;)

continue with the next stap, remove the registry keys

This key will start the virus at startup:
QUOTE said:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "4946550101"
make sure that you delete this one
 
I've dealt with a version of that (or similar symptoms). Just keep slammin CRTL+SHIFT+ESC on login to launch the proc manager before the virus can block it!
 

Site & Scene News

Popular threads in this forum