how do you remove the "system tools hoax" software

Posted on 2011-02-14
Last Modified: 2012-05-11
This seems to be a new program pretending to be an antivirus program. It is a scam, but it hijacks the computer and there seems to be no way to see the virus or stop it from runnning.  McAfee is totally ignorant of it and wants $90 to "try" to remove it.  Is there any other way to get rid of this hoax?
Question by:dean_stephens
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

ID: 34890530
Refer to:

General recommendations:
-Backup your data
-Disable System Restore
-Install/update Malwarebytes Antimalware
-Run full scan in Malwarebyte
-Reboot into Safe Mode
-Re-run Malwarebytes

Expert Comment

ID: 34890614
If this is a 32 bit Windows 7 machine you can attempt to run


HOwever, I would recommend running a good clenup utility as well:

Will clean up a lot of that crap that is sitting around, do that before you run a scan. In the worst case scenario you can download sysinternals procexp and find the culprit file and "echo" it out and render it useless. I can offer further detail if you want.

Author Comment

ID: 34890621
I already own McAfee.  Why will they not help me remove the virus?  If it has been around since 2008 it cannot be that hard to get rid of.
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Expert Comment

ID: 34890657
Here is a link that says don't disable system restore until after you run the scans:

Here is a link that says to run scans in normal mode NOT safe mode, if you can:

Author Comment

ID: 34900531
@moonie42 - The software you linked to will not install since it requires you install in normal mode and the virus will allow nothing to run in normal mode.  Only safe mode can be used.
@ bz43 - ditto
@RobertParton - All I get when I try to find Combofix is a link to Registry Mechanic.  I assume I am doing something wrong but I cannot figure out how to find the program. Do you have a link perhaps.  

I am really gettting frustrated with this.  

McAfee has given me a link to a program called "stinger', which ran to completion and did not find the virus or remove it.  I am still stuck with nothing but safe mode.  Normal mode is infected with the "System Tools" hoax and nothing seems to work.

Author Comment

ID: 34901223
I am being told by both McAfee and Norton that this virus can only be removed manually at a cost of $99.  Does anyone know any other option?

Accepted Solution

bz43 earned 500 total points
ID: 34902111
I asked the moderators to add some antivirus zones to your question.  Right now the only zone it's in is "Windows 7".  More people should read it when the zones are updated.  Or see if you can add some zones to this question like: Anti-Virus, Anti-Spyware, Internet Security, Latest Threats.

There is a bootable disk called the VIPRE Rescue Program at
Maybe, from another non-infected computer, download that and run it on the infected PC.

This thread might be about your infection.  I'm not sure.  Please read it at:

Only download Combofix from the following website:

Tutorial on how to use combofix:

Author Closing Comment

ID: 34903458
Thank you so much.

Expert Comment

ID: 34908061
You're welcome.  Were you able to remove the virus?

Author Comment

ID: 34954037

Author Comment

ID: 34954065
For clarification, the details on the second thread you posted

allowed me to find the virus manually and delete enough of it to get the standard anti virus to remove the rest.

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Internet Explorer 11.0 fails to open 34 87
Windows Features blank 4 37
TLS 1.0 & Windows 7 - How to disable? 16 131
Chocolatey with PowerShell is not working again 2 42
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
This Micro Tutorial will give you a basic overview of Windows Live Photo Gallery and show you various editing filters and touches to photos you can apply. This will be demonstrated using Windows Live Photo Gallery on Windows 7 operating system.

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question