PDA

View Full Version : MALWARE: SecurityToolNow.com



STARZAN
2009-12-10, 07:41
Hi, THANKS in advance.

RECENTLY, a few days ago, SUDDENLY THE FOLLOWING SUSPICIOUS ITEM (from: http://www.SecurityToolNow.com ) POPPED UP WHEN I DID NOT CLICK ON ANY WEB PAGE:

"MESSAGE FROM WEB-PAGE"
warning that my PC had been detected to have some viruses!

http://www.SecurityToolNow.com

~TROJAN~BANDIT~
http://www.SecurityToolNow.Com/index.php?AffID=91107 ~ My computer Online Scan.mht

1.
I RECENTLY HAD THE SYSTEM SCANNED; AND NO VIRUSES WERE DETECTED.

2.
RECENTLY, A FEW DAYS AGO, I HAD TRIED TO INSTALL A FREEWARE ANTI-VIRUS SOFTWARE from “IObit”, ASC “Advanced System Care” similar appearing brand name; ASC~SetUp.EXE (8.684-KB size).

I ABORTED THE INSTALLATION WHEN I OBSERVED THAT IT WAS INSTALLING ADDITIONAL EXTRANEOUS 3RD PARTY DEFAULT SEARCH APPLICATIONS AND MODIFICATIONS TO THE “BHOs” THAT I DID NOT WANT.

This Iobit-ASC may have maliciously left some of its false “foot-prints” on the system to create doubt in the mind of the users to scare them into using their product.

3.
I TRIED TO CLOSE THIS FRAUDULENT "SecurityToolNow.com" web-page BUT UNABLE TO CLOSE OR MINIMIZE IT.

4.
SUDDENLY THE "Security Tool Now" page started to act like it was doing a quick scan and then it quickly displayed the LIST showing "virus infection" results!

5.
UNABLE TO STOP THE "FAKE" SCAN.

6.
SecurityToolNow.com web-page AUTOMATICALLY PRESENTED ITSELF TO DOWNLOAD AND TRIGGERED “SAVE” FILE DIALOG.

I TRIED TO CANCEL, BUT IT WAS PERSISTENT.
PULLED THE NETWORK CABLE FROM THE BROADBAND MODEM.
Later, CAREFULLY DOWNLOADED THE (147KB-size) FILE, BUT CHANGED ITS FILE SUFFIX “*.EXE” TO “*.BANDIT5X5” to prevent its opening / execution.

7.
PERFORMED: "CTL+ALT+DEL" COMBO-KEYS TO BRING UP TASK MANAGER TO MANUALLY STOP THIS "SecurityToolNow.com" FALSE APPLICATION PAGE.

8.
TRACED THE “SecurityToolNow.com” website TO SEE IF THE WEBSITE WAS A MALICIOUS WEBSITE, AND SAME MALICIOUS SCENARIOS REPLAYED AS ABOVE.

9.
MY REQUEST TO YOU IS TO CHECK THIS MALICIOUS WEBSITE AND ITS MALICIOUS SOFTWARE APPLICATIONS AND NEUTRALIZE IT!

10.
WOULD LIKE YOUR UPDATE AS TO WHAT KIND OF MALICIOUS WEBSITE IS THIS. AND WHY AND HOW WAS IT ABLE TO BYPASS THE active MICROSOFT “ONE-CARE” ANTI-VIRUS and the “SPYBOT S&D”.

11.
THANK YOU!

BEST REGARDS,

STARZAN90210 .

tashi
2009-12-10, 18:36
Hello STARZAN,

Please see this FAQ, "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start a new thread and copy paste the HJT log into it.

If HJT won't run please start a new topic anyway, make note of the situation and a volunteer analyst will advise you when available.

Best regards.