Ask your question
Report

Total security VIRUS... cant do ANYTHING [Solved/Closed]

jazz00 1Posts August 14, 2009Registration date - Aug 15, 2009 2:15am BST - Last answer on May 4, 2010 10:01pm BST Ambucias
Hello,
having a problem with a friends computer.. got total security virus and now cant do anything.. downloaded malwarebytes at an earlier date re named and installed it won run.. cant run task manager get a msg saying "task manager has been disabled by your administrator" , cant run regedit, cant do system restore cant start in safe mode cant copy files to cd to back up cant connect to internet.... HELP PLZZZZConfiguration: Windows XP Firefox 3.5.2
Read more ...

Best answers

 Security tool warning virus removal - Forum

Hello, I need help. I can't figure out this SECURITY TOOL WARNING deal virus. When I go to task manager WHAT FILE .EXE DO I DELETE? I'm not sure. And when I download a spyware or malware deal the Security tool closes it down. I NEED HELP....

 Security tool virus removal windows 7 - Forum

Best answer: Security tool removal guide: http://www.geekpolice.net/...

 What internet security and anti-virus programs do you need to unistall before installing kaspersky anti-virus program on hp wind - Forum

Hello, I have a setup file of kis 2009 but i am not able to install in my computer

 Remove security tool virus rkill - Forum

Best answer: Security Tool is a self-proclaimed anti-spyware program, promoted through pop-ups, trojans and malware webites. The Security Tool is promoted just like Windows Police Pro or Green AV ( Antivirus ) 2009. The rogue anti-spyware programs are dis

 Windows security disable anit-virus - Tips

How to disable the security Center under windows XP? Introduction Disable Alerts Turn off Windows Security Center Introduction Windows security Center is a component that works under Windows XP service pack 2 for providing...

 Fixing security tool virus - Forum

Best answer: I was tasked with removing this from my brother-in-law's laptop, and after extensive searching I have a method that worked 100%. First, DON'T DELETE ANY .EXE or .DLL FILES BEFORE TRYING THIS FIX! On the infected machine, navigate to: C:\Progr

 Fix security warning virus wuauclt.exe registry fix - Forum

Best answer: Hello, I am desperate...can anyone help...Please! I had exactly the same symptoms as detailed by yavben in message of Aug 17. Then, I followed the recommendations in brakers message of Aug 19. However, when run, the resulting downloaded file.

 Security tool virus discussion - Forum

I was being helped with my Security Tool Hijacking 2010 and the discussion disappeared. What do I do? The person heping me screen name began with a A and his name I believe is Jules. Please help

 After removing virus Your current security settings do not allow this file to be downloaded - Forum

Best answer: This is what i had to do... go to the internet explorer symbol...right click it and it should say "run as administrator"...clike that and you will be able to download stuff...

 Removal of security center virus ran malware bytes and now able to get in but still having redirecting issues - Forum

Best answer: Malwarebytes' Anti-Malware as a suggested solution solved my pain in the @$$ problem. Time is money. This free solution could not have been found at a better time. Here is the long list of problems I had prior to finding the solution above: P

 "security tool" virus avast disabled - Forum

Best answer: Hello, It seems that your brother's computer is infected by a rogue virus which in effect is a scam to get to purchase it. Manually removing the virus, I am afraid, is possible but painstaking as processus must be stopped and many registry en

 Security tool virus removal license key - Forum

Best answer: The security tool is really a Virus itself. Download this toll to remove it. http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html Good Luck

 Norton security email error virus - Forum

Hello, Every time i boot up my pc i keep getting scanning email 1 of 1 from symantec , which then fill my entire screen, i done a virus scan, which found some trojans and removed them, i also installed spybot s&d, malwarebytes and superanti spyware...

 Black screen after blue screen security tools virus - Forum

Best answer: I have had this problem and have been one of the lucky few to get round it, however i believe i may know the cause or part of the cause for this, and a way to get round it hopefully. I got this issue after an unfortunate power cut, the system

 Internet explorer cannot display the webpage windows xp secure sites virus - Forum

Best answer: Try this, it worked for me: Open IE Tools tab > Internet Options > restore Adanced Settings and Reset Internet Explorer settings. Restart IE. Good Luck!

Sort by :   Vote | Date | Date descending 61 answers 2
+0
moins plus
After reading the posts and seeing that the application was listed as an 8 digit number under processes when using task manager I was able to delete it. If you open task manager right away and delete it as soon as it shows up you should be able to end the process before it locks up your computer then you can take your time to remove the virus properly.
+0
moins plus
Download MBAM. Install and updated. Reboot computer in safemode with networking. Do complete scan. Delete all files. Go to Kaspersky online scan and scan again.
source: http://www.im-infected.com/rogue/total-security.html
+0
moins plus
wow, so much trouble for 1 virus, you guys should try panda vaccine + bit defender 10 best combo

http://www.easy-share.com/1908015216/USBVaccine.exe

http://filehippo.com/download/file/c92f6187e59b2d2e1fc3788ba9e893f0f28e5dd29120276024cf51f81ed38332
+0
moins plus
This blog set up is to confusing. You can't tell who is replying
to whom. Which post is working and which is junk.
It should be just simply in order with the post showing who
you are replying too.
+0
moins plus
no its wrong u can format the computer. and immediately install kapersky 2010 internet security it is the best one. i had 50000 trojans and 30 malwares and it deleted it all i couldnt believe it.
+0
moins plus
ive removed this bug numerous times on XP.
this time is the kicker. i have tried EVERYTHING.
that is everything listed here, everything in every link here...nadda.
while anyone responding is being helpful, alot are not reading what people are saying
this virus does.

- Internet Security 2010 disables antivirus programs, including Malewarebytes.
(in most instances, it shuts down the system when one attempts to run an antivirus program)

- Internet Security 2010 disables all Administrative Functions, then disables all functions used to make changes
as well. the solutions given are moot by the fact that they require use of said shutdown functions.
any program that is used in the Run command fall under this, be that regedit.exe, gpedit.exe, ect...all
disabled. so using these programs to solve the problem is not an option.

i liked the option of going to the Application Directory and renaming the file/folder. the problem is
that folder is not visable. the Folder options tab is no longer present to make it visible. the navigation bar on explorer is not present to surf there manually. ( its almost as if the people who make this are reading these very blogs and posts and improving the virus against what is being suggested here).

seriously, im at a loss as to what to do with it now. if you have anything the help is appreciated.
and if you know where to register a complaint against these Internet Security people please link it.
+0
moins plus
This or Antivirus Live and windows alert. This is keeping you from launching Task manager, proc explorer, malwarebytes, combofix and basically any other tool you try to use? It will also make the computer blue screen upon entering safe mode? It is a very nasty infection, but it can be removed.

Perform a search for "sysguard.exe" and remove anything found. (enable show hidden folders for the next part)
Next go to the user folder %UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS]\
You likely will not be able to delete but you can rename the folder.
Now log off, then log back in. The item should not load as it wont be able to locate the folder.

Now you can run Task manager or Proc Explorer, but you shouldn't need it at this point. I was now able to run Malwarebytes here. Before you can update Malwarebytes (you will get an error) you will need to fix the IE settings. Open Internet Explorer > Tools > Internet settings > Connections tab > Lan Settings button at the bottom > Now UNCHECK Proxy server settings and set to "Automatically detect settings".

Malwarebytes and internet browsing should now work. Update Malwarebytes and scan/remove. I like to followup a malwarebytes scan with another malwarebytes scan and Combofix. Combofix can be found here http://www.bleepingcomputer.com/forums/index.php?showtopic=273628&hl=combofix

I hope this helps you remove and I spent a very long time figuring this out for my clients soooo your welcome :)
+0
moins plus
Hi All,
I am an CompTIA A+ Certified IT Technician.
This is a very common problem on many systems, the task manager disabled is a very common virus/malware trick to stop you killing it. The solution for renaming the file is an interesting one, good call. If you want to 'regain' control of your computer, i.e task manager, the quickest way is to reset the registry key that the virus/malware has changed with a .reg file;

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000

If you copy the above few lines into notepad and most virus or malware don't think anything of this so it is usually possible, then save it to desktop with and ext of .reg - in notepad you will have to save it as type 'all files', then type a 'name.reg' in the box. Once you have saved this file click on it, explorer will ask if you want to add it to the registry, click yes at the prompt and this will 'reset' this key and allow you to access task manager and kill the process(es) and then nuke it with a good anti virus/malware killer. As for preventing re-infection, I always have this reg file on my desktop and scattered around a few places in the computer just in case - And a great FREE anti virus/spyware/firewall/system monitoring software is COMODO Internet Security. Google for it, it is superior to many 'bought' solutions and you can't beat the price.
Hope this helps many people,
fearlessfred
+0
moins plus
nothing is working for me >< i cant find a 8digit forder or anything at all anything else i can try?
+0
moins plus
I have try everything and nothing seems to work i cant find anything cant download run or even open anything on my pc add/remove programs wont open, nothing seems to work but at the same time i dont see any weird folder anywhere ; ; if someone have any idea what i can do pls post it i been on this nightmare 19days :(
+0
moins plus
If a 67year old Illiterate Computer Dummie like myself can do it anyone can.
Just follow the instructions below:

Go into safe mode
Go to files and folders
find the Restore system folder.
Allow the 'restore system' to back date and restore your computer to a day before the virus entered.

I can't believe I did it.......just saved myself $240.00.
+0
moins plus
can't do anything
+0
moins plus
Reformat.
+0
moins plus
I cleared this rogue piece of shit. Download Malwarebytes (FREE and great). Google it.
Works great. Also, when virus is running, go to Control-Alt_Delete. That will bring up TASK MANAGER. Find "Vista Total Security" running on the list, and go to "processes tab". Left click and when you see a file with a lot of numbers THAT is the virus. Click on it to show you where the file resides. Then DELETE it, and delete it again in RECYCLE Bin. You may have to delete it many times for it to go. It might say "you don't have permission". Keep doing it, and it will go. I killed the F__ker. SpyHunter has a new Securiy suite that is great. I just updated my SpyHunter for free. Worth it. They have good support and help you.
+0
moins plus
Hi guys

[Update] I followed the other people's advice, and deleted the Temp files that were associated with when the problem started, and then...

Well I just finished battling with this thing, and my best bet is that if any of you can open Task manager, go to the processes tab.

For me, the virus was listed as ave.exe and if you right click it, a window comes up saying 'End Process Tree'

I've done that, and services have been resumed. However, when I need to open up a programme atm, I'm having to right click and 'Run as Administrator' first.

I'm currently in the process of installing AVG software, and hopefully if there is any of the virus remaining, it should track it down and eliminate it.

Will report back soonModified by mh90 on 2010/04/29 02:34 AM
+0
moins plus
i have encountered this security lock just recently nothing on this site would work for me i was just going to give up,

this is what worked for me hold ctrl, alt, del like you normally would but keep it pressed down this would give you about 25 taskmangers and a box should come up saying it is infected ask you to buy the software with the 2 boxes yes or no hit neither and it will stay on the task manager then it should let you use the internet i had mozilla firefox go to google download spybot its a very good free virus melware fighter download it install it and hit search and destroy once open do a full scan and it takes a bit but it finds everything right in your registry once completed hit fix problems and it might look like on your tab in the lower right hand corner its still there but its gone move your mouse over the symbol that is that security virus it should just disappear then hit that box i was talking about earlier with the yes or no answer and say no that should get your system back to normal it worked for me
Ambucias - May 4, 2010 10:01pm BST
Wow Iroc-z

Congratulations for the cybernetic gymnastics. I am glad you got rid of the beast and thank you for sharing your adventure and solution with the Community.

Best regards
-1
moins plus
Hi,
Not sure if this will help, I have this problem at the moment and none of the removal step-by-steps have the right file names, but I'm lucky enough to be able to get into regedit and task manager. If you can get in to talk manager maybe through safe mode, the process on mine ran as an eight digit random number, so have al ook for one of those, and at leats you can stop the constant barrage of pop ups.