Hi all,
Just finished a fun few hours getting rid of this bit rubish. Pretty much everything listed below happened.
Would not allow me to run “Start Task Manager” or “Restore”.
Running Vista Home Edition, Avast Free Program V6.0.1000 with Virus V110331-0.
Avast did not pick up anything. Tried a boot scan, that failed to find anything. Tried a full scan with everything set to max, that failed to find anything. In the end had to do a Start in Safe Mode and do a system restore from in there. Also noticed that a restore point had been created today (when infected) and dont know if this bit of crap created that to ensure that even a resore would not get rid of it.
It is a nasty bit of work and has been the only thing that has slipped past Avast since I have had it for three years.
Would be nice if you guys could look into this further.
Regards
Darryl
[i]http://www.wiki-security.com/wiki/Parasite/MSRemovalTool/
Don’t forget that while MS Removal Tool may have a different name and interface, it is the same culprit that keeps attacking your PC in an attempt to trick you into buying its fake antimalware program. Once you identify the behavior, you should be able to detect the intrusion early on and shut down these rogue security programs that much quicker.
The Behavior of Windows Simple Protector:
1.After gaining deceptive entry, i.e. an infected download of shareware, freeware or codec for viewing a movie or video, or after clicking on a dubious link or visiting a malicious website, Trojan horse, a component of the security rogue program model, will immediately go to work. Trojan horse is multi-talented and will disarm your antimalware, disable your admin controls (Desktop and Taskbar), and will hijack your browser, so that you cannot download or visit a real anti-malware solution.
2.Trojan horse will install MS Removal Tool, which runs upon reboot. Trojan horse also will alter your registry files to hide itself and ensure that MS Removal Tool is allowed to run every time you reboot – until you give in and download the full version.
3.MS Removal Tool’s skin or interface pops-up on your screen and blocks you from using other applications while it screams bloody murder in the form of alerts and annoying pop-ups.
4.MS Removal Tool runs an unauthorized scan and shows you proof that your PC has been infected by UnknownWin32/Trojan, a vapor virus, and gives you the below alert:
Microsoft Security Essentials Alert!
Potential Threat Details!
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these
items may be suspended until you take an action. Click ‘show details’ to learn more.
5.MS Removal Tool asks you to get involved and run a scan to find ‘all’ intruders. The fake scan returns a list of violations, i.e. infected files and named vapor viruses.
6.MS Removal Tool offers to remove or clean your system if you buy and download its ‘full-version.’[/i]