• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove System Tool and SystemTool (Uninstall instructions)

Myantispyware team October 24, 2010    

System Tool or SystemTool is a fake security program which is a clone of Security Tool. The program is classified as a rogue antispyware tool because detects numerous false infections and displays a lot of fake security alerts in order to scare you into thinking your computer in danger. It hopes that you will then purchase its full version. But you should know, System Tool is unable to detect or remove any viruses, trojans, worms nor will be protect you from legitimate future security threats. Thus, you need to remove this malware from your computer as soon as possible.

SystemTool is distributed through the use of malware that pretends to be flash updates, or even video codecs required to watch an online movie. Once started, it will configure itself to run automatically when Windows starts. Next, the rogue will perform a system scan and report numerous infections to make you think that your computer is infected with trojans, spyware and other malware. Then it will prompt you to pay for a full version of System Tool to remove these threats. Of course, all of these infections are fake and don’t actually exist on your computer. So you can safely ignore them.

While SystemTool is running, it blocks the ability to run any programs, including legitimate antivirus and antispyware applications. The following warning will be shown when you try to run any program:

Application cannot be executed. The file {file name} is infected.
Please activate your antivirus software.

More over, System Tool will display a lot of false security alerts and nag screens. Some of the alerts:

System Tool Warning
Intercepting program that may compromise your privacy and
harm your system have been detected on your PC.
Click here to remove them immediately with System Tool

System Tool
WARNING 23 infections found!!!

System Tool Warning
Some critical system files of your computer were modified by
malicious program. It may cause system instability and data
loss.

SystemTool will also replace your current Windows background with a fake security warning that states:

Warning!
Your’re in Danger!
Your Computer is infected with Spyware!

Of course, all of these warnings and alerts are a fake and like scan false results should be ignored!

If your computer is infected with SystemTool, then most importantly, do not purchase it! Uninstall the rogue from your PC as soon as possible. Use the removal guide below to remove System Tool and any associated malware from the system for free.

Symptoms in a HijackThis Log

O4 – HKCU\..\RunOnce: [{RANDOM}] C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe

Automatic removal instructions for System Tool

Step 1. Reboot your computer in Safe mode with networking

Restart your computer.

After hearing your computer beep once during startup, start pressing the F8 key on your keyboard. On a computer that is configured for booting to multiple operating systems, you can press the F8 key when the Boot Menu appears.

Instead of Windows loading as normal, Windows Advanced Options menu appears similar to the one below.

safe-mode-how-to
Windows Advanced Options menu

When the Windows Advanced Options menu appears, select Safe mode with networking and then press ENTER.

Step 2. Remove SystemTool and any associated malware

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer for System Tool infection. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

System Tool remover
Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove System Tool. MalwareBytes Anti-malware will now remove all of associated SystemTool files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Step 3. Reset HOSTS file

System Tool will change the Windows system HOSTS file so you need reset this file with the default version for your operating system.

Please download OTM by OldTimer from here and save it to desktop. Run OTM, copy, then paste the following text in “Paste Instructions for Items to be Moved” textarea (under the yellow bar):

:Commands
[resethosts]

Click the red Moveit! button. Close OTM.

SystemTool removal notes

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Note 3: your current antispyware and antivirus software let the infection through ? Then you may want to consider purchasing the FULL version of MalwareBytes Anti-malware to protect your computer in the future.

System Tool creates the following files and folders

C:\Documents and Settings\All Users\Application Data\{RANDOM}
C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe.

SystemTool creates the following registry keys and values

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\{RANDOM}

Malware removal Rogue Anti Spyware

 Previous Post

Remove antispyway.com hijacker and Antivirus Action malware

Next Post 

How to remove AntiVirus Solution 2010 (Uninstall instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

260 Comments

  1. chen
    ― December 7, 2010 - 6:18 am  Reply

    thank you for your help.. the process/ instructions you shared helps me to remove the system tool that prompts on my computer.. now i can already install and download again..

  2. john Calabrese
    ― December 10, 2010 - 9:52 pm  Reply

    The paste to OTM does not work. I get the message
    cannot create file C:\WINDOWS\System32\drivers\etc\Hosts
    Other than that, your fix was dabomb. That bullshit System Tool is gone! Thank you Thank you.

  3. Patrik
    ― December 11, 2010 - 3:09 am  Reply

    Calabrese, if you using Vista/7 then you need run OTM as administrator. Right click to OTM and click Run as Administrator option.

  4. Basil
    ― December 11, 2010 - 7:47 am  Reply

    I already had Malwarebytes but had to update it, after which it ID’d 150-plus infections and took System Tool away! Thanks!

    But OTM doesn’t work (I have Windows XP). It opened; I dopied
    :commands
    [resethosts}
    under yellow bar, clicked “Move It” and “Commands” when over to under the green bar, leaving “[resethosts]” under the yellow bar. Then OTM went “not responding” and won’t do anything, like close. I tried “End Task” and it doesn’t work on OTM, which appears twice on that screen. What should I do???

  5. Basil
    ― December 11, 2010 - 7:57 am  Reply

    Whoops! OTM is gone. I went to desktop, re-opened and recopied and it told me the action was complete and it had created a log. I clicked exit and that worked too. I presume I’m all set to trot normally.

    Thanks for great instructions and help!

  6. Matt
    ― December 11, 2010 - 11:34 am  Reply

    I ran the quick scan and it tells me the is nothing there but the system tool is still all over my computer how do I get rid of this thing…

  7. Jennie
    ― December 11, 2010 - 1:34 pm  Reply

    This has not helped me…i ran through the entire process, and system tool is still on my laptop?

  8. officer808
    ― December 12, 2010 - 2:51 pm  Reply

    Thanks for the help, it was invaluable. Wasted about an hour or so running a full scan, without updating, then finally updated and did quick scan, but rebooted without taking out the file folders and the regkey. Followed your instructions again to the T and got rid of it. No idea where I picked it up…twitter? Anyway I’m back on track again. Thanks and mahalo!

  9. Gloria Fuerte
    ― December 12, 2010 - 9:28 pm  Reply

    I followed all the steps and BINGO! that “system tool” is gone! You saved my day. You saved my MIND!
    THANK YOU!

  10. tom claybo
    ― December 12, 2010 - 9:46 pm  Reply

    Ran program but after re starting virus [System Tool] is still here

  11. cameron
    ― December 13, 2010 - 12:58 am  Reply

    oh man [resethosts] is not working. Keep getting the same message even after making it ambass. ahh broke heart. any suggestions?

  12. Morgan
    ― December 13, 2010 - 2:35 am  Reply

    not working for me…
    so, i have restarted my comp in safe mode, run rkill, updated MBAM, run MBAM, manually deleted all “system tool” paraphernalia and restarted my comp regularly and it STILL is 100% infected.
    any pointers??

  13. Michelle
    ― December 13, 2010 - 9:24 pm  Reply

    Thank you, thank you, thank you. This saved my life and so much of my time. I thought my computer was kaput. It took me less than 40, 50 minutes to uninstall System Tool. Man, thank you so much.

  14. renee
    ― December 14, 2010 - 12:59 pm  Reply

    do you restart before resetting the host

  15. Patrik
    ― December 14, 2010 - 1:20 pm  Reply

    Matt and Jennie, ask for help in our Spyware removal forum.

  16. Jeremy
    ― December 14, 2010 - 4:37 pm  Reply

    Perfect! thanks

  17. Tyler Stewart
    ― December 14, 2010 - 5:41 pm  Reply

    Information to remove system tool was very helpful I’m glad that bullshit is gone thanks

  18. ATaylor
    ― December 15, 2010 - 12:13 am  Reply

    thank you, thank you, thank you! I worked twelve hours today trying to remove system tool from my computer. and once i discovered this helpful page it took all of ten minutes. you are my hero!

  19. Patrik
    ― December 15, 2010 - 9:08 am  Reply

    Morgan, probably your computer is infected with a trojan that reinstalls the rogue. Start a new topic in our Spyware removal forum. I will help you to remove this malware.

  20. Patrik
    ― December 15, 2010 - 9:10 am  Reply

    renee, yes, reboot your computer before resetting the hosts file.

  21. mike
    ― December 15, 2010 - 4:58 pm  Reply

    this virus SUCKS. i didnt trust it from the start ><

  22. Stephen
    ― December 15, 2010 - 10:07 pm  Reply

    Has anybody run into a problem where system tool does not show up as an infection using mbam?

  23. Fatimeh
    ― December 16, 2010 - 12:52 am  Reply

    So it says that i got it off on safe mode but once i start my computer again it’s still there. So i went back to safe mode to rescan but it says 0 infections found! HELP!

  24. Ben
    ― December 16, 2010 - 10:02 am  Reply

    Great help, thank you. All steps worked and I’m now much more up-to-date on general protection tools.

  25. tish
    ― December 16, 2010 - 11:13 am  Reply

    do i need to reboot my pc in safe mode or the regular one? bc i rebooted in regular and stupid system tool came back :S
    help plz

  26. Patrik
    ― December 16, 2010 - 11:17 am  Reply

    Stephen and Fatimeh, try the following:
    Reboot computer in Safe mode with networking. Download HijackThis from here. Run HijackThis and click Scan button to perform a system scan. Place a checkmark against each of lines:

    O4 – HKCU\..\RunOnce: [{RANDOM}] C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe

    Example:

    O4 – HKCU\..\RunOnce: [932849] C:\Documents and Settings\All Users\Application Data\832748\123123.exe

    Note: list of infected items may be different. Template of the malicious entries:
    O4 – HKCU\..\RunOnce: [{RANDOM}] C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe
    If you unsure, then start a new topic in our Spyware removal forum. I will help you.

    Place a checkmark against each of them. Once you have selected all entries, close all running programs then click once on the “fix checked” button. Close HijackThis.

  27. Patrik
    ― December 16, 2010 - 11:19 am  Reply

    tish, you need use Safe mode. It will stop the rogue from autorunning.

  28. tish
    ― December 16, 2010 - 11:34 am  Reply

    Thankyou Patrik – You DA MAN! =)

  29. Dave
    ― December 16, 2010 - 12:23 pm  Reply

    Tough nut to crack. Had to search through registry for all RunOnce instances. Found one that pointed to the random-named folder/file. They used a guid/SID/class in the registry path that threw Malwarebytes off. Erased by hand.

  30. Kevin
    ― December 16, 2010 - 3:13 pm  Reply

    I too had trouble tracking this one down. With hijack this I was able to delete an odd RunOnce entry that was random but was not in the Documents and settings\all users\application data folder mentioned above. It was in Program Data folder.

1 2 3 … 9 Next »

Leave a Reply to Glenn Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

Best free malware removal tools
Best Free Malware Removal Tools 2025
Malwarebytes won’t install, run or update – How to fix it
How to reset Internet Explorer settings to default
search.yahoo.com
Remove Search.yahoo.com Redirect Virus ✅ (Quick & Easy) in 2024
Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide

Recent Guides

Remove antispyway.com hijacker and Antivirus Action malware
How to remove ThinkPoint (Uninstall instructions)
How to remove antispytag.com browser hijacker
How to remove System Defragmenter (Uninstall instructions)
How to remove Smart Engine (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.