System Tool - How to remove

System tool (also you can find it named System tool 2011, System Tool 2.20) is the fake antivirus which should be known for you if interested in fake anti-spywares because it hails from the same family as the “famous” Security Tool. Both programs are useless in the detection and removal of any cyber threat because they are created for only stealing the money. It’s done by simply “finding” viruses and then aggressively asking the money for their removal.  As you should have already realised, you should NEVER purchase System Tool because you will end up with more viruses on your PC. It has no real full version and it can not remove any viruses as it claims.

System Tool is spread by worms, trojans, drive-by downloads and faked freeware/shareware installs. There is a high chance to get this parasite if you install Adobe flash or reader updates from third party sources and not from makers website. Sometimes it is very hard to tell how you got System Tool installed on your machine as it may also come with some file downloads or be downloaded by other trojan infections. After Installation, this parasite starts acting classically and displays various alerts and popups trying to scare users into scanning PC and then paying for its full version. These alerts look like this :

System Tool Warning
Your PC is infected with dangerous viruses. Activate antivirus protection to prevent data loss and avoid the theft of your credit card details.
Click here to activate protection.

System Tool Warning
Intercepting programs that may compromise your private and harm your system have been detected on your PC.
Click here to remove them immediately with System Tool.

Security Monitor: WARNING!
Attention: System detected a potential hazard (TrojanSPM/LX) on your computer that may infect executable files. Your private information and PC safety is at risk. To get rid of unwanted spyware and keep your computer safe you need to update your current security software.
Click Yes to download official intrusion detection system (IDS software).

Warning: Your computer is infected
Windows has detected spyware infection!
Click this message to install the last update of Windows security software…

System Tool 2011 might also change your background to image that warns about infections :

Warning!
Your’re in Danger!
Your Computer is infected with Spyware!

All you do with your computer is stored forever in your hard disk. When you visit sites, send emails… All your actions are logged. And it is impossible to remove them with standard tools. Your data is still available for forensics, and in some cases

For your boss, your friends, your wife, your children. Every site you or somebody or even something, like spyware, opened in your browsers, with all the images, and all the downloaded and maybe later removed movies or mp3 songs – ARE STILL THERE and could break your life!

Secure yourself right now!
Removal all spyware from your PC!

Additionally, it will block the execution of some of the programs while executing them. You will get a message like this :

Warning!
Application cannot be executed. The file cmd.exe is infected.
Please activate your antivirus software.

All these warnings should be ignored because the removal of some files reported by System Tool may damage your computer. Paying for System Tool will not solve any problems, but will result in giving away your Credit card details to rogues.If you have already paid for it, contact your credit card company to dispute the charges.

System Tool will block the launching of legitimate processes and prevent one from visiting certain websites. This means that once you will try executing programs like task manager, command prompt or similar, you will get a SystemTool popup which will tell that program is infected and the program will not launch. However, you can overcome that problem by renaming the executable to other names, as some of the programs are allowed, or using safe mode. Additionally, usually you can launch task manager during the login process to windows: System Tool launches at later stages and it will not stop programs already working.

As it must have been turned out, you should never pay for System Tool – it is a scam, and you will not get a full working version despite paying. It will only bombard you with tons of annoying system scanners, alerts, and notification that will announce dangerous activity detected. Do NOT leave this parasite on PC: it is a sign of infection with trojans, which might download other parasites and compromiser the system further. Thus you have to remove SystemTool from PC and not ignore the popups. Follow the instructions below.

Special removal instructions for System Tool

To remove System Tool, you might need to overcome the malware protection from executing other files. You have several options for that :
1. Reboot, and while being logged in, press ctrl+shift+esc to launch task manager. As long as System Tool is not active, you will be able to start the task manager and stop its process after launch.
2. Try running Msconfig and disabling all unclear startup entries from these locations mentioned in this System Tool removal guide. Reboot
3. Try renaming files you want to launch to xxxx.com or similar names. Typically, most of the parasites block only .exe files
4. Try this key WNDS-S0DF5-GS5E0-FG14S-2DF8G to disable the malware (check the window where it asks for license )
Some other keys (recovered by panda labs)
WNDS-TGN15-RFF29-AASDJ-ASD65
WNDS-U94KO-LF4G4-1V8S1-2CRFE
WNDS-6W954-FX65B-41VDF-8G4JI
WNDS-G84H6-S854F-79ZA8-W4ERS
WNDS-TTUYJ-7UO54-G561H-J1D6F
WNDS-A1SDF-6AS4D-RF5RE-79G84
WNDS-A1SDF-RY4E8-7U98D-F1GB2
WNDS-5SRTS-AEHUF-YA54S-D6F35
WNDS-P9685-4H41A-DSW3A-2R64T
WNDS-2AE32-1VFC2-B6894-G67YU
WNDS-4TS8R-D6F5D-4JH8T-U4JK5
WNDS-FGS5D-649RG-4S53D-412SF
WNDS-452S3-ER00F-TSE35-S8FSD
WNDS-SERFH-2642S-F04SD-64FG1
WNDS-F40SA-1ER5H-4FG5D-F8412
WNDS-5D1V2-XB0D5-JT1TY-97DS3
WNDS-4BGY2-JY4KO-IT98Y-7HJ43
WNDS-G8FB6-1V87S-DRT1S-63SRG
WNDS-HFVDR-9844O-U54DA-5TBSC
WNDS-89OF7-7324R-5SAD4-TG68U
WNDS-JUYH3-24GHJ-HGKSH-FKLSD

Even if you stop seeing System Tool symptoms, the infection still might be here, so I recommend scanning with SpyHunter and deleting all the trojan downloaders and other malware that allowed System Tool infection to infect your PC. Having a good Anti-Malware tool like full versions of SpyHunter or Malwarebytes Anti-Malware prevent majority of parasites like System Tool.

Automatic Malware removal tools

Download Spyhunter for Malware detection
(Win)

Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions,

Download Combo Cleaner for Malware detection
(Mac)

Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy ,

Manual removal

Removal guides in other languages

44 responses to “System Tool

  1. Hello- I have tried several different virus removal tools including spyware doctor. I’ll start up in safemode with networking because I can’t get the programs to run otherwise, but even when they do run they either find nothing or the they find a few relatively harmless things like cookies.

    At this point is it best to try to remove it manually- or would it be beneficial to wipe my computer and just start over?

  2. I just downloaded and ran spyware doctor. The scan lasted almost 3 hours, and found numerous infections that I fixed. I rebooted, and the problems are still there??? Now what??

  3. Patric: Contact pc tools support or try hitman pro – it is good against rootkits that can stop Spyware Doctor from removing some of infections sucessfully.

  4. Im using a laptop at the moment cause system tool wont let me get on the internet on my PC, so theres no way i can download any products online so is there a product i could buy at a store not off the net that will help me rid this virus?

  5. Josh: Try using the key first to disable its popups. Then disable proxy and you should be able to access internet. scan with various anti-malware tools.

  6. Oh yeah, make sure you download all the most recent updates before running the programs.

    Also, if you can’t get Explorer to run on teh infected computer download all programs onto a flash drive on another uninfected computer. Then plug into infected computer in safe mode, cut and paste .exe programs off flash drive to infected computer and run.

  7. System tool makes a shortcut on your desktop. Right click it => open location.
    i found two files. One can be deleted, the other one can be renamed. When you reboot, system tool cant open and you ca remove the other file as well and your computer at least behaves normally again.

  8. Boot to safe mode and run system restore. Pick a date before you got the trojan.
    When it reboots you will be free of the trojan.

  9. I had a problem using the method outlined above. I could not stop the process in task manager fast enough to prevent system tool from activating. I tried the following method instead. it was much simpler and only took 10 minutes to completely remove system tool from my laptop.

    1)start in safe mode
    2)backup any document, movie music, etc files that were added or modified in the last several days prior to the infection.
    3)click windows start icon on the left side of the task bar.
    4)type “system restore”in the search field.
    5)restore to a point prior to the infection.
    DONE!!

    no trying to beat system tool startup in task manager, no downloading additional files, no scanning, no searching for rogue files, no traces of system tool left on your computer, and best of all….

    Its SIMPLE, its QUICK, and its COMPLETELY THOROUGH!!

  10. Mikedelta: Actually, system restore does not remove the files and it might miss some startup entries. Scanning is advisable after restore as well.

  11. hello, my husband has this system tool on his laptop, i would be able to do everything that is said above but the only problem is there isnt any visable file that i can find its hidden. ive updated my spybot and i downloaded the spydoctor thing but itjust wants me to but it…is there anyway that i can get this off?

  12. @admin
    The problem lay on my setting on my computer. I downladed and ran Spyware Doctor. I think I still had problems, but I logged on on my wife’s area and downlaoded Norton Internet Security 2011 and did a complete scan. This took a long time but the problem seems to be solved. We had Norton 360 but let the licence lapse – a cautionary tale.

  13. i just left my computer shut off for 4 days then it does not ATTACK SINCE IT IS A ROUGE VIRUS then install malwarebytes and use avg after that i had avg and malwarebytes on there it would not let me update so i removed all of the shortcuts and anything i could find on search a rouge is useless if it cannot have internet access it on it how can it spam if it has no way possible? after those few days it resets itself so you can update EVERYTHING!!!then kill it with your malware program then use the anti virus since it is now free to update no need to change anything.

  14. Restart your computer in safe mode (f8 – on boot up)
    Select system restore from your control panel
    Restore back at least 15 days.

    Viola…gone no muss no fuss no reprogramming no special software to buy and install. If you have a malware remover, just to be safe run it after restoring your system to locate any possible threads.

  15. I have just “adopted” Active System Tool and am getting many of the banners that you indicate. Am am smart but not super computer literate. Should I attempt the reboot instructions and if not what is my smart choice?

  16. OK I got the sysyems tool telling me SZServer.exe is infected I have tried everything nothing is downloading and really getting irritated by this I can get online but cant play my games offline can u help me please.

    Thanks

  17. Itried to get rid of this system tool but i have obviously doon something wrong i cant get my system to start up in reg or safe mode it is disabling my keyboard

  18. I got System Tool by downloading porn videos off a website and if I try any way to remove it in normal mode it is impossible. Can anyone contact someone that is an expert and just give me steps to get rid of this virus once and for all? I really want this virus to be gone forever from my laptop.

  19. well, this is the 2nd time it infcted me… (different computers)
    so, i traced the trojan downloaders IP and sent system tool back at where i got it

  20. how was you able to do that I tried malbyte it didn’t show in there I went into the registry it only showed one file I deleted that restated the computer it was still there@jason

  21. Hey I have a Windows 7 Starter Laptop, I cant open any programs or do safe mode or system restore, any ideas, please I need help!

  22. Thanks So Much For The Really Useful Information!!! It Had Really Helped Me A Lot… I Got Rid Of That Troublesome Spyware Program! 🙂 Thank You Again. >.<
    Hey Guys, You Should Really Download: – Malwarebytes Anti-Malware
    – Spy Doctor
    – KillBox
    They Really Helped… Hope Programs Proved Useful Too! ^.^

  23. thx alot.
    this page helped.
    i use spybot S&D for removing.
    The biggest prop was to stop the exe.
    Pics the rmb on your desktop on the sys tool app to find the correct nameof the process.
    After 5 times reboot i stopped it.
    thx a lot

  24. Removing System Tool takes quite a bit of time. The method i used was restarting it..and press escape be4 the computer starting windows. And then Press f2 i think for system recovery..and it will be alot easier to go from there. Lol the only problem you might have with this method is that if you don’t have a back up for your computer, you will lose important information. Which I didn’t have any Lol..thank god. But try that anyhow.

  25. Go and DL RKill. This can be done in Safe Mode w/ Networking. Once DL’d and installed, this turd of a program can’t stop RKill from starting and shutting it the hell down. Then you can go through the lengthy process of removing it.

  26. @Maineiac
    i did as suggested above and it worked i then forgot to delete my cookies and within a hour it was back,i have then gone back into system restore and redide again changed to a date i did not have the trogon but i am getting a message saying system could not restore to these changes and no changes have been made help!

  27. Tony Roe: System restore is (usually) temporally solution. In all cases after system restore you have to scan PC for trojans, rootkits or unremoved parts of malware.

  28. I have had systen tool attack twice,had mcaffee antivirus first time,and have had regzooka and spyzooka,also now using system mecanic,none have stopped system tool so far,seems to me someone who sells antivirus would be able to stop it but the best way to stop it i have found so far is to use system restore,i have e-mailed system mecanic to ask if there is a way to configure to stop it,still waiting,but right now i wonder who really design it,could it have been one of the antivirus company’s.

  29. Michael: System mechanic and regzooka is not anti-malware programs nor antivirus. I would not recommend Spyzooka at all. Try common anti-malware solutions : Spyware Doctor, Hitman Pro, Malwarebytes, superantispyware, emsisoft anti-malware, etc.

  30. Easiest removal is:
    -start in safe mode
    – open windows explorer
    – change the view to show all files and folders even system protected
    – browse through the program files for a folder with random letters for the name, inside you’ll see a single exe file
    – copy the name of the file then delete the whole folder
    – search the registry for the name and delete all instances
    – reboot and install Spybot or Malware bytes and do a full scan.
    – voila

  31. who ever created this virus is sick. If you are out there i am going to hunt you down and find you. I will be the bane of your life, until i find you, and beat you down….

    be afraid…..very afraid

  32. It is as easy as 123 to remove. When you start up your computer, imediately press F8 key. When the menue appears, scroll down to “Directory Services Restore Mode.” The rest is easy; just restore to an earlier date. Make sure it is a date before the virus entered your system and it will be gone. Your computer will be back to normal.

  33. Rob: Read comments above. This will not fix all versions of malware and does not remove all trojans that install system tool in first place. You should scan your PC.

  34. Thanks for the tips, still DOS mode is the best.
    While starting windows, press F8 and wait until the Safe Mode Window comes.
    Then… search for the weird .exe filename, by typing dir *.exe /p/s (to find .exe files within the system)
    Then… while files are flashing, look for the file that suspect you. Try to look for dates and time nearest in the event when the System Tool start showing or any unusual long filenames (like what I have encountered: bIeGpIo18101.exe)
    Go to the directory and delete it including the directory.
    Then restart your computer.
    Its like magic!

  35. @Mikedelta
    THANK YOU, THANK YOU, THANK YOU!!!!
    This method worked great and like you said,
    only took about 10 minutes. I am a techno-boob
    and it was very easy for me. I didn’t even know
    how to restart in safe mode, but a quick Google search
    and I was on my way.

Leave a Reply to MS Removal Tool - how to remove Cancel reply

Your email address will not be published. Required fields are marked *