• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove System Tool and SystemTool (Uninstall instructions)

Myantispyware team October 24, 2010    

System Tool or SystemTool is a fake security program which is a clone of Security Tool. The program is classified as a rogue antispyware tool because detects numerous false infections and displays a lot of fake security alerts in order to scare you into thinking your computer in danger. It hopes that you will then purchase its full version. But you should know, System Tool is unable to detect or remove any viruses, trojans, worms nor will be protect you from legitimate future security threats. Thus, you need to remove this malware from your computer as soon as possible.

SystemTool is distributed through the use of malware that pretends to be flash updates, or even video codecs required to watch an online movie. Once started, it will configure itself to run automatically when Windows starts. Next, the rogue will perform a system scan and report numerous infections to make you think that your computer is infected with trojans, spyware and other malware. Then it will prompt you to pay for a full version of System Tool to remove these threats. Of course, all of these infections are fake and don’t actually exist on your computer. So you can safely ignore them.

While SystemTool is running, it blocks the ability to run any programs, including legitimate antivirus and antispyware applications. The following warning will be shown when you try to run any program:

Application cannot be executed. The file {file name} is infected.
Please activate your antivirus software.

More over, System Tool will display a lot of false security alerts and nag screens. Some of the alerts:

System Tool Warning
Intercepting program that may compromise your privacy and
harm your system have been detected on your PC.
Click here to remove them immediately with System Tool

System Tool
WARNING 23 infections found!!!

System Tool Warning
Some critical system files of your computer were modified by
malicious program. It may cause system instability and data
loss.

SystemTool will also replace your current Windows background with a fake security warning that states:

Warning!
Your’re in Danger!
Your Computer is infected with Spyware!

Of course, all of these warnings and alerts are a fake and like scan false results should be ignored!

If your computer is infected with SystemTool, then most importantly, do not purchase it! Uninstall the rogue from your PC as soon as possible. Use the removal guide below to remove System Tool and any associated malware from the system for free.

Symptoms in a HijackThis Log

O4 – HKCU\..\RunOnce: [{RANDOM}] C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe

Automatic removal instructions for System Tool

Step 1. Reboot your computer in Safe mode with networking

Restart your computer.

After hearing your computer beep once during startup, start pressing the F8 key on your keyboard. On a computer that is configured for booting to multiple operating systems, you can press the F8 key when the Boot Menu appears.

Instead of Windows loading as normal, Windows Advanced Options menu appears similar to the one below.

safe-mode-how-to
Windows Advanced Options menu

When the Windows Advanced Options menu appears, select Safe mode with networking and then press ENTER.

Step 2. Remove SystemTool and any associated malware

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer for System Tool infection. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

System Tool remover
Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove System Tool. MalwareBytes Anti-malware will now remove all of associated SystemTool files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Step 3. Reset HOSTS file

System Tool will change the Windows system HOSTS file so you need reset this file with the default version for your operating system.

Please download OTM by OldTimer from here and save it to desktop. Run OTM, copy, then paste the following text in “Paste Instructions for Items to be Moved” textarea (under the yellow bar):

:Commands
[resethosts]

Click the red Moveit! button. Close OTM.

SystemTool removal notes

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Note 3: your current antispyware and antivirus software let the infection through ? Then you may want to consider purchasing the FULL version of MalwareBytes Anti-malware to protect your computer in the future.

System Tool creates the following files and folders

C:\Documents and Settings\All Users\Application Data\{RANDOM}
C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe.

SystemTool creates the following registry keys and values

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\{RANDOM}

Malware removal Rogue Anti Spyware

 Previous Post

Remove antispyway.com hijacker and Antivirus Action malware

Next Post 

How to remove AntiVirus Solution 2010 (Uninstall instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

260 Comments

  1. Luke
    ― December 27, 2010 - 10:14 am  Reply

    Thanks a million. It worked to tee. I couldn’t get online so I had to download the Malwarebytes onto a flash drive from another computer to get started, and just followed your instructions. Thanks again.

  2. Greg
    ― December 27, 2010 - 11:50 am  Reply

    System Tool popped up on one of my notebooks on Christmas; couldn’t do anything to fix it. Your site came up on Google and I gave it a try. After downloading the program to a USB stick and booting the notebook in SAFE mode, I ran the program and it worked perfectly. Thanks for the help!

  3. Patrik
    ― December 28, 2010 - 6:20 am  Reply

    christian, the rogue may change the Windows system HOSTS file, so you need reset it with the default version for your operating system.

  4. French Sun
    ― December 28, 2010 - 4:18 pm  Reply

    So everyone had been attacked by SystemTool in that Christmas and every website I find on how to delete the virus suggests ONLY malwarebytes.. Making an educated guess and you could easily found who create this virus.. Am I being paranoid?

  5. Fidel
    ― December 28, 2010 - 4:26 pm  Reply

    Thank you very much for the information, It really helped me to get rid of the %#$/&()#?) system tool, Thanks.

  6. Rob
    ― December 28, 2010 - 11:39 pm  Reply

    Whoever you are, you are my hero. Terrifying, awful, bewildering beast that has plagued me all night and you have saved me. Go well and thank you! x

  7. Jason
    ― December 29, 2010 - 2:07 am  Reply

    Hi I got hit by system tool too. My computer won’t open in any safe mode thing, it just goes to a black screen afterwards. I’ve tried system restore but that doesn’t work either. No programs will run nor the internet. Could use your help for any new ideas….

  8. Jason
    ― December 29, 2010 - 2:54 am  Reply

    Actually no need to reply to my last post. I tried system restore in another user account again and it worked this time around. Thanks to whoever’s comment I robbed that idea from. What a bunch of basterds that made this thing, and thanks to anyone who helps us computer idiots out of a jam.

  9. mlawa
    ― December 29, 2010 - 5:30 am  Reply

    YOU GUYZ R DA BEST

  10. taftazani
    ― December 29, 2010 - 6:38 pm  Reply

    thank you very very very much…

  11. Isaac
    ― December 29, 2010 - 9:06 pm  Reply

    Thank you so much, it’s good to have guides like these online!

  12. JosT
    ― December 31, 2010 - 8:26 am  Reply

    This worked GREAT! You ROCK!

  13. broigel
    ― December 31, 2010 - 10:26 am  Reply

    My computer will not boot in safe mode. I have got this system tool infection and nothing will run in normal mode. Neither will the .exe file in \allusers\application data be deleted – it says it’s in use. So without safe mode I am stuck – and it won’t go into safe mode. Any suggestions? Perhaps I should open a new topic in spyware removal forum?

  14. sania
    ― January 1, 2011 - 7:25 am  Reply

    thanx alot I got rid of that system tool don’t know how i got it can u tell me how can i get my pc save from that system tool thanx again u saved me

  15. Patrik
    ― January 1, 2011 - 7:22 pm  Reply

    French Sun, Malwarebytes is a good and legitimate malware remover. You can use it for free to remove the rogue.

  16. Patrik
    ― January 1, 2011 - 7:30 pm  Reply

    broigel and Jason, try the following:
    Run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to Lan Settings button. Click Advanced button to open Proxy settings. Copy and paste the following text into “Do not use proxy server for addresses beginning with:”

    go.trendmicro.com;www.myantispyware.com;www.malwarebytes.org;

    Click OK to save Proxy settings, then Click OK to close Lan Settings and Click OK to close Internet Explorer settings.

    Download HijackThis from here. Once Save dialog opens, you need first to rename hijackthis.exe to

    iexplore.exe

    Further click Save button to save it to desktop. If you are using the Firefox, then you need right click to the above link to open a Save dialog.

    Run HijackThis. Click Scan button. Select entries that looks like:

    R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:{RANDOM}
    O4 – HKCU\..\RunOnce: [{RANDOM}] C:\ProgramData\{RANDOM}\{RANDOM}.exe

    Example:

    R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:49512
    O4 – HKCU\..\RunOnce: [kEdGm06300] C:\ProgramData\kEdGm06300\kEdGm06300.exe

    Place a checkmark against each of them. Once you have selected all entries, close all running programs then click once on the “fix checked” button. Close HijackThis.
    Reboot your computer.
    Go to step 2 above.

  17. NItin
    ― January 2, 2011 - 2:09 am  Reply

    Hi,

    I downloaded malwarebytes and ran it under safe mode – it came up with two errors whicc I removed – after that I rebooted the computer in normal mode – but the system tool is still there.

    Any suggestions on what I can do different to remove it?

  18. sania
    ― January 2, 2011 - 11:05 am  Reply

    system tool is gone but my pc is not starting normally I’m so fed up

  19. Afel
    ― January 2, 2011 - 2:18 pm  Reply

    i cant go to start safe mode.
    i cant click on it..

  20. Afel
    ― January 2, 2011 - 2:19 pm  Reply

    oh and uhh
    i cant download the malware

  21. KENJAE
    ― January 2, 2011 - 9:45 pm  Reply

    This thing latched onto my computer on January 2, 2011. What a way to start the new year! Thank GAWD we found your site and followed the instructions!!! Working great now….Thank you, thank you, THANK YOU!!!!!!!!!!!!

  22. rachel
    ― January 3, 2011 - 1:07 am  Reply

    when i try to reboot in safe mode, it goes to the black screen and says “no boot device”. It seems my hard drive is kaput. should I still have hope?

  23. sania
    ― January 3, 2011 - 1:54 pm  Reply

    i’m stuck with my computer its not working properly after removal of the virus it says something about hardware settings changes im so tense plz plz smbdy help me……………..

  24. Carlo
    ― January 3, 2011 - 11:21 pm  Reply

    Worked perfectly, thanks, that thing fought me every step of the way. At one point disabled my internet connection, disabled spybot, couldnt bring up task manager. Once I was in safe mode, I nailed the bastard.

  25. Eldar Zeynalov
    ― January 4, 2011 - 5:13 am  Reply

    THAAAAAAAANNNKKKK YOOOOOUUUUUU VERYYYYYYY MUUUUUUCHHHH

  26. Patrik
    ― January 4, 2011 - 9:10 am  Reply

    NItin and rachel, try use HijackThis to remove this malware. Look my previous comment.

  27. Patrik
    ― January 4, 2011 - 9:12 am  Reply

    sania, what you mean “but my pc is not starting normally” ? Computer won`t boot in Normal mode ?

  28. Patrik
    ― January 4, 2011 - 9:13 am  Reply

    Afel, use HijackThis. See my answer to “broigel and Jason”.

  29. Ade
    ― January 4, 2011 - 4:31 pm  Reply

    superb Patrik.. from a very gracious UK customer.

  30. zjaknight
    ― January 5, 2011 - 9:49 am  Reply

    Saved my ass big time.
    Worked a treat in less than 20 minutes.

« Previous 1 2 3 4 5 … 9 Next »

Leave a Reply to Karen Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
adwcleaner
AdwCleaner – Review, How to use, Comments
How to reset Google Chrome settings to default
How to reset Internet Explorer settings to default
Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)

Recent Guides

Remove antispyway.com hijacker and Antivirus Action malware
How to remove ThinkPoint (Uninstall instructions)
How to remove antispytag.com browser hijacker
How to remove System Defragmenter (Uninstall instructions)
How to remove Smart Engine (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.