My name is Blue Cardinal, and I have a problem.
My laptop got hit with a virus from Facebook(I think) I have AVG 9.0 but a scan didn't work. The virus keeps me from doing anything period in normal mode, I could only do the scan starting up my computer is safe mode. What it does is (aside from not letting me do anything)change my desktop to a big message that says something to the effect of Your're(yes it's spelled wrong) computer is in danger. Everything you do is logged and your boss, kids, and wife can see everything you do.
Basically it wants me to buy this spyware (the icon pops up on my desktop with a combination lock picture and it's called Security Tool) and it locks everything.
You're in luck, I've actually dealt with this virus twice in the last week, so I know exactly how to kill it.
1. You need to download a couple of programs, and one anti-virus definition. One is called RKill and the other is Microsoft Security Essentials (MSE), and the virus definition is for MSE. Either download these programs on a different computer (and burn to a CD, you don't want to use USB drives when you have a virus) or download them in Safe Mode with Networking on your computer. Either way should work.
RKill:
http://www.bleepingcomputer.com/download/anti-virus/rkill
(download the file that says "iExplore.exe download link)
Microsoft Security Essentials:
http://www.microsoft.com/security_essentials/
Anti-Virus Definition:
http://www.intowindows.com/how-to-update-microsoft-security-essentials-mse-offline/
2. Download those three programs and if you're not already, go into Safe mode and copy the files onto your Desktop.
3. Go into your Add/Remove Programs and uninstall AVG 9. We're going to use MSE, and I think MSE is better anyways.
4. Restart your computer into regular mode.
5. If you have not done so already, there should be an icon for System Tools 2011. Delete the icon completely, including from Recycle Bin.
6. Once your computer comes up, run RKill. RKill will terminate all running processes of malware (which System Tools 2011 is).
7. After running RKill, install MSE.
8. After you've installed MSE, it SHOULD update automatically before scanning. If for some reason MSE cannot update, you have the updated definitions that you downloaded. Either way, get your MSE up-to-date.
9. Once MSE is up to date, run a scan with it. MSE has found this virus both times I've used it, and several times it's been noted on the web. Clean any infection MSE finds, restart your computer, and you should be free and clear.
10. Just to be completely safe though, once you've restarted your machine, run RKill again, and run Malwarebytes once, just to make sure your system is totally clean.
I'd recommend printing out these instructions before you start the cleaning process. Removing this nasty little bug is fairly easy, just takes time to do all the scans. Also, you can try removing this program with AVG, I just know MSE works for sure.
Do me a favour and press control, Alt and delete and bring up your task manager.
Hit "new task" and then type in "explorer"
Hopefully, that should bring up your desktop. If not, keep up the task manager and go to the processes tab. Look for something that shouldn't be there. Of course, I cannot see it myself, so you are going to have to do your best at finding it. Either that or take a screen-capture if you can and upload it here. Try and get all the processes in.
To get rid of this virus, you need to kill the process first and then you can download Spyware Doctor or something similar to remove it.
So yes, processes.
This virus disables the ability to use Task Manager. Normally, though, that'd be good advice.