• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove System Tool and SystemTool (Uninstall instructions)

Myantispyware team October 24, 2010    

System Tool or SystemTool is a fake security program which is a clone of Security Tool. The program is classified as a rogue antispyware tool because detects numerous false infections and displays a lot of fake security alerts in order to scare you into thinking your computer in danger. It hopes that you will then purchase its full version. But you should know, System Tool is unable to detect or remove any viruses, trojans, worms nor will be protect you from legitimate future security threats. Thus, you need to remove this malware from your computer as soon as possible.

SystemTool is distributed through the use of malware that pretends to be flash updates, or even video codecs required to watch an online movie. Once started, it will configure itself to run automatically when Windows starts. Next, the rogue will perform a system scan and report numerous infections to make you think that your computer is infected with trojans, spyware and other malware. Then it will prompt you to pay for a full version of System Tool to remove these threats. Of course, all of these infections are fake and don’t actually exist on your computer. So you can safely ignore them.

While SystemTool is running, it blocks the ability to run any programs, including legitimate antivirus and antispyware applications. The following warning will be shown when you try to run any program:

Application cannot be executed. The file {file name} is infected.
Please activate your antivirus software.

More over, System Tool will display a lot of false security alerts and nag screens. Some of the alerts:

System Tool Warning
Intercepting program that may compromise your privacy and
harm your system have been detected on your PC.
Click here to remove them immediately with System Tool

System Tool
WARNING 23 infections found!!!

System Tool Warning
Some critical system files of your computer were modified by
malicious program. It may cause system instability and data
loss.

SystemTool will also replace your current Windows background with a fake security warning that states:

Warning!
Your’re in Danger!
Your Computer is infected with Spyware!

Of course, all of these warnings and alerts are a fake and like scan false results should be ignored!

If your computer is infected with SystemTool, then most importantly, do not purchase it! Uninstall the rogue from your PC as soon as possible. Use the removal guide below to remove System Tool and any associated malware from the system for free.

Symptoms in a HijackThis Log

O4 – HKCU\..\RunOnce: [{RANDOM}] C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe

Automatic removal instructions for System Tool

Step 1. Reboot your computer in Safe mode with networking

Restart your computer.

After hearing your computer beep once during startup, start pressing the F8 key on your keyboard. On a computer that is configured for booting to multiple operating systems, you can press the F8 key when the Boot Menu appears.

Instead of Windows loading as normal, Windows Advanced Options menu appears similar to the one below.

safe-mode-how-to
Windows Advanced Options menu

When the Windows Advanced Options menu appears, select Safe mode with networking and then press ENTER.

Step 2. Remove SystemTool and any associated malware

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer for System Tool infection. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

System Tool remover
Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove System Tool. MalwareBytes Anti-malware will now remove all of associated SystemTool files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Step 3. Reset HOSTS file

System Tool will change the Windows system HOSTS file so you need reset this file with the default version for your operating system.

Please download OTM by OldTimer from here and save it to desktop. Run OTM, copy, then paste the following text in “Paste Instructions for Items to be Moved” textarea (under the yellow bar):

:Commands
[resethosts]

Click the red Moveit! button. Close OTM.

SystemTool removal notes

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Note 3: your current antispyware and antivirus software let the infection through ? Then you may want to consider purchasing the FULL version of MalwareBytes Anti-malware to protect your computer in the future.

System Tool creates the following files and folders

C:\Documents and Settings\All Users\Application Data\{RANDOM}
C:\Documents and Settings\All Users\Application Data\{RANDOM}\{RANDOM}.exe.

SystemTool creates the following registry keys and values

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\{RANDOM}

Malware removal Rogue Anti Spyware

 Previous Post

Remove antispyway.com hijacker and Antivirus Action malware

Next Post 

How to remove AntiVirus Solution 2010 (Uninstall instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

260 Comments

  1. Lucky
    ― February 27, 2011 - 11:33 am  Reply

    Many thanks!! God bless u! 🙂

  2. becky
    ― February 27, 2011 - 12:47 pm  Reply

    THANKS SO MUCH! These instructions saved my life. I followed them exactly and now this computer is fine! THANK YOU!

  3. Mary Collyer
    ― February 27, 2011 - 1:49 pm  Reply

    Patrik

    I ran Malwarebytes but System Tool hadn’t gone so I have done a scan using HijackThis (as per an earlier post by you dated 16 December 2010). The only line I can find that features the words ‘RunOnce’ is as follows:

    HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

    Am I safe to delete this (it’s not the same as the example you give)? Is there anything else I should be looking for?

    Thanks for your help.

  4. daniel
    ― February 27, 2011 - 3:09 pm  Reply

    brilliant!!

  5. Bert
    ― February 27, 2011 - 5:11 pm  Reply

    This was amazing. This really helped me and if my friends or somebody I know runs into a virus or problem, I will, without a doubt, direct them here.

  6. Katie Duffy
    ― February 27, 2011 - 5:30 pm  Reply

    YESSS SYSTEM TOOL IS DEAD :”D now i will remember too scan my computer regularly….. then mum won’t kill me.
    Thank Youuu!!!

  7. Heather
    ― February 27, 2011 - 8:30 pm  Reply

    How can I get onto the Internet in safe mode so that I can download the malware programs? I have an aircard for internet access, and that doesn’t work now.

  8. Kay
    ― February 27, 2011 - 10:30 pm  Reply

    Thank you so much Patrick!!! Your instructions were easy to follow as well as execute. The only challenge I am having is resetting the HOSTS. I had the same problem as Andrew above. I read the reply you posted on 1/8 to Andrew and tried to follow the instruction there. However I could not find the etc file once I got to Window–>System32–>drivers. How do I reset the HOSTS? I want to follow to completion and make sure that I can do as much as I can from preventing this from happening again. Your help is much appreciated.

  9. eV x RAPIDZzz
    ― February 28, 2011 - 2:10 am  Reply

    you dont have to start it with safe networking just recover your computer and thanks for everything but make sure we spread these into messages and emails to save peoples computers and laptop

  10. angie
    ― February 28, 2011 - 8:52 am  Reply

    hi i have tried the malware but as i can not connect to internet had to down load on another computer did the update but when loading om infedted computer it says it still needs updating so its not finding system tools at all just going round and round in circles here plzzzzzzzzzz help me :O(
    oh also tried you hyjack this but cant make head or tails of that :O(

  11. Patrik (Myantispyware admin)
    ― February 28, 2011 - 10:10 am  Reply

    Chelsie, try scan your computer with Kaspersky virus removal tool.

  12. Patrik (Myantispyware admin)
    ― February 28, 2011 - 10:13 am  Reply

    T, try boot your computer in Last good configuration.

  13. Patrik (Myantispyware admin)
    ― February 28, 2011 - 10:19 am  Reply

    Mary, looks like the line is ok. Start a new topic in our forum and post your HijackThis log into it. I will help you to check your PC.

  14. Nicky
    ― February 28, 2011 - 12:38 pm  Reply

    Thank you for this life-saver. I am a complete luddite but even I have followed your instructions no problem. Perhaps you could be a little clearer about the problems many of us have experienced running OTM, but apart from that fantastic!

  15. Kat
    ― February 28, 2011 - 3:46 pm  Reply

    Hi Thanks so much for all your help! I opened in safe mode as per the advise. Then I got confused by all the instructions so I just logged onto the internet and used Microsofts instructions on performing a system restore. Its all sorted now thanks 🙂

  16. Hari
    ― February 28, 2011 - 5:19 pm  Reply

    Worked like a charm. Thank you!

  17. Duxuk
    ― March 1, 2011 - 1:42 pm  Reply

    I used malwarebytes after pressing F8 repeatedly whilst booting up the laptop. It wasn’t too difficult even for a technophobe like me. Worked a treat and the whole nightmare of being hit by a virus has got me to seriously look at my future security.

  18. sarah
    ― March 1, 2011 - 2:40 pm  Reply

    i got infected with the system tool rubbish and it wouldnt let me do anything at all then it turned off my laptop altogether and on startup i used safemode to load and it found no threats. now i have managed to get back online and dont seem to be getting the system tool popups but i know they will come back-how to i search for the infected files to remove them completely?? thanks !!

  19. Jon
    ― March 2, 2011 - 8:56 am  Reply

    Thank you very much, worked perfectly!

  20. hanky
    ― March 2, 2011 - 1:08 pm  Reply

    omg. i don’t know how to thank you.
    :O :O :O
    i am so suprised it really works, that damned virus is just gone now 😀
    thank you x 1000!

  21. hanky
    ― March 2, 2011 - 1:17 pm  Reply

    i’ll do anything to support this website from now by the way, thankyouthankyouthankyou!

  22. Curt
    ― March 2, 2011 - 5:11 pm  Reply

    fantastic! worked like a charm!
    thank u malwarebytes’!

    btw- i wish someone could “return the favor” to the fellas’ over at system tool?

  23. Don
    ― March 3, 2011 - 2:55 pm  Reply

    I didn’t have any luck with Spybot, but I downloaded Malware Bytes, ran a full scan, and I believe it works. I had to reboot after the scan as it told me to do, and my computer seems to be fine, that damned system tool didn’t show up, and my taskbar appears normal. Fingers crossed!!

  24. haig
    ― March 3, 2011 - 10:28 pm  Reply

    please watch my YouTube video to that I have made to remove system tool
    youtube.com/watch?v=7xIOgAU5OCQ

    1) Unplug your PC
    2) Plug it back in and power it up
    3) You will be asked how you want to power your PC back up. Select “Safe Mode with Networking”.
    4) After your PC finishes booting (note that you don’t see the bad background anymore) open up a command prompt (running “cmd” in “Search Programs and Files” on the bottom of the menu that comes up when you select “Start” in Windows 7 works).
    5) Run “C:Windowssystem32
    egedt32.3xe”
    6) Look for registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOnce
    and click on it.
    7) There will be two keys. One will be “default”. One won’t. Write the one that isn’t down. I had “C:ProgramData MdOtQz3816 MdOtQz3816.exe”, but it’s different for everyone.
    After you write that key down exactly, delete it and close the program.
    9) Back in the command prompt window do a “cd” to that path. Note that if you do a directory listing of the root directory (i.e., “cd ” and then “dir *.*”) you WON’T SEE ProgramData. Don’t worry – it’s a hidden directory. If you run “cd ProgramData” it’ll work.
    10) “cd” to the directory that was shown in the directory key.
    11) Delete it’s contents.
    12) Perform “cd ..”. That brings you back up into “C:ProgramData”. Remove the directory. In the example I’m using run “rmdir fMdOtQz3816″.
    13) Now bring up Internet Explorer (yes, even if you normally run some other browser).
    14) From the menu bar and the subsequent pop-up windows, select “Tools”, then “Internet Options”, then the tab “Connections”, then the button “LAN Settings”.
    15) You’ll see a check box for Proxy Settings. If it’s checked, uncheck it. Close that all up.
    16) Back in the command prompt window, go to “C:Windowssystem32driversetc”. There should be a hosts file. Edit it (“edit hosts”) and edit it so that there’s only one line and it says “127.0.0.1 localhost”. You can separate “127.0.0.1″ and “localhost” with either a space, a few spaces or a tab, it doesn’t matter.
    17) Close everything up and reboot your machine. If it asks when it comes back up, tell it to start Windows normally. You’re done

  25. John
    ― March 3, 2011 - 10:58 pm  Reply

    Thank you my friend, may God bless you immensley for such detailed procedure. Works like a charm and that nusense is gone!!!! Thank you!!!!

  26. Jim
    ― March 4, 2011 - 1:28 am  Reply

    Thank you. I ran malwarebytes and it seems to have corrected the problem. I am hesitant to re-set the HOSTS file as I don’t want to have to re-load printer drivers. How necessary is it do re-set the HOSTS file? Can I assume everything’s ok if I go a few days without further problem?

  27. Patrik (Myantispyware admin)
    ― March 4, 2011 - 8:34 am  Reply

    Heather, you need use “Safe mode with networking”.

  28. Patrik (Myantispyware admin)
    ― March 4, 2011 - 8:37 am  Reply

    angie, try the instructions that i have posted above (answer to broigel and Jason,omment by Patrik — January 1, 2011).

  29. Patrik (Myantispyware admin)
    ― March 4, 2011 - 9:01 am  Reply

    sarah, update your antivirus and perform a full scan.

  30. Patrik (Myantispyware admin)
    ― March 4, 2011 - 9:22 am  Reply

    Jim, if computer works fine, no any redirects (google, yahoo, etc), then, I think, you HOSTS file is ok and you can skip last step.

« Previous 1 … 5 6 7 8 9 Next »

Leave a Reply Cancel reply

New Guides

Natural Glyco Blood Support Reviews, Scam or Legit, Don’t Fall for the Hype!
The Xledcoin.com Elon Musk Scam, TAKE Promo Codes as a Trap
The XBITHUMB.com Elon Musk Scam, Fake ELON31 Promo Code Rip-off
Sonedex.top Elon Musk Scam, Fake STOX Promo Codes
scam alert
Eloneu.com’s Bitcoin Promo Code Scam: What to Know

Follow Us

Search

Useful Guides

How to remove browser hijacker virus (Chrome, Firefox, IE, Edge)
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
ads by adware
How to remove Adware from Windows 10 (Virus removal guide)
adwcleaner
AdwCleaner – Review, How to use, Comments
Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide

Recent Guides

Remove antispyway.com hijacker and Antivirus Action malware
How to remove ThinkPoint (Uninstall instructions)
How to remove antispytag.com browser hijacker
How to remove System Defragmenter (Uninstall instructions)
How to remove Smart Engine (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.