Beware of Rogue Virus program

Closed Thread
Thread Tools
  #1  
Old 03-12-2011, 04:25 PM
laryb's Avatar
laryb laryb is offline
Veteran member
Join Date: Feb 2010
Location: Buttonwood, formerly Dartmouth, Ma
Posts: 841
Thanks: 44
Thanked 93 Times in 47 Posts
Default Beware of Rogue Virus program

Let me preface this by saying that I run Panda Internet Security 2011, Webroot Spysweeper, free version of Super Anti-Spyware, and Spy Doctor. Also, I am not a computer expert, nor do not play one in the movies, but this freaked me out and I hope this will help someone if they run into it too. The other day, I got a pop-up that said "System Tool" virus program had detected 73 serious level infections, and that I should pay $79 to download the program and remove these deadly viruses. Normally I would ignore this and continue on, but every thing had been disabled. Web page, browser, Panda, spysweeper, everything. Tried to reboot numerous times, but still frozen, except for message from "System Tool" asking for $79. Got on the other laptop and started to research "system Tool" and discovered that it is a rogue program. If you run into this program, DO NOT buy it or give out any of your info. What worked for me was to reboot in safe mode and do a system restore to a earlier safe date. I then ran a full scan of Panda, SpySweeper, Spy Doctor, the free version of MalWareBytes (http://www.malwarebytes.org/rogueremover.php ), and Microsoft Security Essentials. I know it was probably overkill, but I thought, better safe than sorry. If this sucker got through all my protection, it might get through yours. Remember, don't buy the program, your info will end up in Holland or Belgium.
__________________
"I ain't as good as I once was,
But I'm as good once as I ever was!" Toby Keith
  #2  
Old 03-12-2011, 05:04 PM
njbchbum's Avatar
njbchbum njbchbum is offline
Sage
Join Date: Feb 2009
Location: Summer at the Jersey Shore, Fall in New England [Maine], Winter in TV!
Posts: 5,633
Thanks: 3,060
Thanked 753 Times in 256 Posts
Default

thanx for the heads up, laryb!
__________________
Not sure if I have free time...or if I just forgot everything I was supposed to do!

  #3  
Old 03-12-2011, 05:30 PM
K9-Lovers's Avatar
K9-Lovers K9-Lovers is offline
Soaring Eagle member
Join Date: Jan 2010
Location: Village of El Cortez. Before: Canada, NY, VA, AL, AK, NV, DE & France, Germany
Posts: 2,135
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Thanks Laryb, I've run into this one before also. When something like this happens, I don't click on anything, and instead immediately turn off my computer by holding in the on/off button for 5 seconds. That's the best way I've found to bypass this bug. Then I turn the computer back on and run my malwarebytes and superantispyware scans. You are right, it disables all your virus protection. Sometimes, I have to download McAfee security all over again because it's disabled. Be sure to really check your security systems because sometimes they appear to be working but actually are not. Try running a virus scan with your McAfee or Norton, etc., and if it will not scan then you may need to download again.
__________________
K9-Lovers
  #4  
Old 03-12-2011, 05:51 PM
rjm1cc's Avatar
rjm1cc rjm1cc is offline
Soaring Eagle member
Join Date: Apr 2010
Posts: 2,368
Thanks: 238
Thanked 525 Times in 244 Posts
Default

In some cases your only option is to reformat your drive and rebuild your system. Best to have an external drive that you back up your data to on a regular basis. You should also have a backup of your operating system Windows/Mac). Buying the program will not help.
  #5  
Old 03-12-2011, 05:59 PM
memason's Avatar
memason memason is offline
Soaring Eagle member
Join Date: Aug 2009
Location: The Villages
Posts: 2,165
Thanks: 0
Thanked 12 Times in 6 Posts
Cool

I had this virus in Germany, last year. Like Larry, the only way I found to eliminate it was to reboot in safe mode and recover the system to a about a week in the past.

That took care of it, but I tell you, I got a few more gray hairs trying to get past the purchase screens.... It's a nasty virus, to be sure.

Unfortunately, the less initiated, will start clicking on the free scan or purchase screen.

Never had anything remotely resembling this on my Apple ...
  #6  
Old 03-12-2011, 08:38 PM
LittleDog's Avatar
LittleDog LittleDog is offline
Gold member
Join Date: Jun 2010
Location: Village of Poinciana
Posts: 1,055
Thanks: 0
Thanked 6 Times in 6 Posts
Default

I did the same thing when this virus attacked. Turn on the computer in safe mode and do a system restore. Worked like a charm. Then I ran a virus scan. Simple solution but effective.

John
__________________
Neptune, NJ 1963-2005
The Villages 2005-forever

"Don't curse the darkness when you can light a candle"
  #7  
Old 03-13-2011, 06:05 AM
ajbrown's Avatar
ajbrown ajbrown is offline
Sage
Join Date: Oct 2009
Location: Mallory Square (9 months/year), TBD the rest
Posts: 2,641
Thanks: 12
Thanked 20 Times in 11 Posts
Default Sandboxie

FWIW. Part of my job requires me to research Linux vulnerabilities which often takes me to some sites that are unknown and potentially malicious. I was always dealing with malware of some type. I had been running a virtual machine just for browsing, but then I found a piece of software called Sandboxie and have been using it for some time now. Sandboxie is a piece of software that allows you to run your browser (or other programs) in a "sandbox". In theory the browser cannot write to your real system. I have been hit by some malware last week and it worked. I simply cleared out the sandbox and was all set. If you are interested check it out here.

http://www.sandboxie.com/index.php?FAQ_Virus
  #8  
Old 03-13-2011, 07:49 AM
laryb's Avatar
laryb laryb is offline
Veteran member
Join Date: Feb 2010
Location: Buttonwood, formerly Dartmouth, Ma
Posts: 841
Thanks: 44
Thanked 93 Times in 47 Posts
Default

Thanks AJ.... will give it a look today
__________________
"I ain't as good as I once was,
But I'm as good once as I ever was!" Toby Keith
  #9  
Old 03-13-2011, 10:17 AM
rubicon rubicon is offline
Email Reported As Spam
Join Date: Nov 2010
Posts: 13,694
Thanks: 0
Thanked 13 Times in 11 Posts
Default Rogue virus

I am afraid of viruses that is four kinds little ones and big ones aliv ones and dead ones. You guys are way over my head if :systmes tools" strikes I have little choice but to call the Geek Squad
  #10  
Old 03-18-2011, 03:36 PM
inda50 inda50 is offline
Senior Member
Join Date: Oct 2007
Posts: 222
Thanks: 197
Thanked 28 Times in 15 Posts
Default

thanx for the heads up, laryb!
  #11  
Old 03-18-2011, 08:59 PM
gongoozler gongoozler is offline
Senior Member
Join Date: Oct 2009
Location: The Villages - North side
Posts: 260
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by jrheydt View Post
I did the same thing when this virus attacked. Turn on the computer in safe mode and do a system restore. Worked like a charm. Then I ran a virus scan. Simple solution but effective.

John
Thanks for this advise . . . was at the airport and used the "free" wifi and pick up this "System Tools" virus . . . did the reboot in safe mode (f8) and the system restore (Start . . . All Programs . . . Accessories . . . . System Tools . . . System Restore). Set the date to the day earlier and restarted . . . all clear! Thanks!

  #12  
Old 03-19-2011, 10:02 AM
mrdills mrdills is offline
Senior Member
Join Date: Nov 2009
Location: Villages
Posts: 410
Thanks: 0
Thanked 0 Times in 0 Posts
Default Rogue Virus Program !!!!!!

I had that problem yesterday, its comes up on your computer as "Windows Efficiency Magnifier" and if you download that program you will get that rouge virus, and they want you to spend money to clean it up but Don't fall for that scam. Do what jr said you will get it off your computer. Good job guys...
  #13  
Old 03-19-2011, 02:30 PM
StarbuckSammy StarbuckSammy is offline
Senior Member
Join Date: Mar 2010
Posts: 191
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Thanks gongoozler for the in-depth instructions on how to go into safe mode etc.
  #14  
Old 03-20-2011, 01:10 AM
harbor53 harbor53 is offline
Member
Join Date: Apr 2010
Location: Chicago
Posts: 83
Thanks: 0
Thanked 0 Times in 0 Posts
Default A Good Source for Computer Security News

http://www.securitynewsdaily.com/cat...security-news/
  #15  
Old 04-25-2011, 01:29 PM
gardenia gardenia is offline
Senior Member
Join Date: Jul 2008
Posts: 105
Thanks: 2
Thanked 0 Times in 0 Posts
Default Best thread ever!

Thank goodness for this thread and to gongoozler for the specific instructions on how to restore. Yesterday I got a pop up that had the McAfee icon saying "windows detected a virus...." and advised to purchase spyware removal tool by clicking on a YES button. I thought I hit the "X" button to close the pop up but must have hit "NO" instead and ended up getting an attack on my computer which disabled McAfee, could not get to to the internet or any of my local files, repeatedly got the annoying msg to purchase the tool which I knew was a total scam. Thankfully I was able to do my research from another computer, then thought of checking TOTV and sure enough, followed gongoozler steps and I am now safely back in business!!! And the restore didn't touch my documents. I did reboot using safe mode earlier but hadn't thought of the restore, so thanks a million for saving me "dinero"!
Closed Thread


You are viewing a new design of the TOTV site. Click here to revert to the old version.

All times are GMT -5. The time now is 04:52 PM.