Posted on Tuesday, 23rd February 2010 by zippydux
Below is an example of a recent call-out and the actions taken to resolve the issue.
ISSUE
A customer had an Acer laptop running Microsoft Windows Vista and when starting Internet Explorer, they would see a ‘System Tools’ application starting to analyse the PC. This System Tools application looked very professional and appeared to scan the system very quickly so after only 10-15 seconds it showed that there were 30 critical viruses on the laptop. In order to allow System Tools to remove these threats, the user would need to click on the option to purchase the full version of the System Tools software.
RESOLUTION
There are several malware applications around that load themselves onto computers, then appear to run and find dangerous viruses on the unsuspecting users computer. In this case and many others, the only invading software on the computer is the malware itself and it’s only purpose is to try and trick the user to pay out for a removal tool that doesn’t do anything.
The first step in removing this malware was to start up the computer without the malware being loaded. Often once the malware is loaded, it stays hidden so that the process cannot be seen from the Task Manager. In the case of this System Tools malware code, it does appear in the Task Manager running as a process with an 8 digit name. For this type of Trojan, the name of the executable file can differ and in this case the process could be seen as 21639728.exe. Stopping this process prevented the program from causing us problems as we went onto the Internet.
There are a variety of tools that can remove viruses, spyware and malware such as this trojan and we first tried Spyware Doctor. This program is supplied by PC Tools and can be easily found on the Internet. The benefits of this tool is that it runs quickly (on this Acer laptop is only took 4 minutes to scan), and it found the malware causing our issue. The malware was found as Trojan.Agent/Gen-FakeAlert(AV). The downside is that once it detects the malware you then have to purchase the full program to remove it. At the time of writing this article, the cost was £29.95 for 1 year and it could be installed onto 3 PC’s.
Note, if you want to use this application to just remove a current threat, go to uninstall the Spyware Doctor program and it will open up an IE window and bring you to a web page offering you a 60-day version for £5.99.
In order to keep costs down for the customer we ran another anti spyware application called Super AntiSpyware to see if it could also find our threat. The benefits to this software is that it is free to home users and in our case it found the malware program causing the problem. It does take longer to scan however, and in this case took over 40 minutes.
It is interesting to note that the free edition of Super AntiSpyware found well over 100 tracking cookies as well as our malware code, compared to Spyware Doctor finding just over 50.
Once the Trojan/Malware application was removed, a quick test after a restart showed that we could now load Internet Explorer without any pop-up windows for System Tools appearing.
___________________________________________________________________________
Torian IT Solutions Ltd offer PC repair and virus, malware, spyware and trojan removal services to businesses and home users in West Yorkshire region (Leeds, Wakefield, Kirklees, Bradford, Castleford, Pontefract)
Tags: malware, spyware, trojan, virus
Posted in Support Call-Outs | Comments (0)

