Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

how do you remove the "system tools hoax" software

Posted on 2011-02-14
11
Medium Priority
?
814 Views
Last Modified: 2012-05-11
This seems to be a new program pretending to be an antivirus program. It is a scam, but it hijacks the computer and there seems to be no way to see the virus or stop it from runnning.  McAfee is totally ignorant of it and wants $90 to "try" to remove it.  Is there any other way to get rid of this hoax?
0
Comment
Question by:dean_stephens
11 Comments
 
LVL 8

Expert Comment

by:moonie42
ID: 34890530
Refer to:
http://www.computersecurityarticles.info/malware/system-tool-2011/

General recommendations:
-Backup your data
-Disable System Restore
-Install/update Malwarebytes Antimalware
-Run full scan in Malwarebyte
-Reboot into Safe Mode
-Re-run Malwarebytes
-Reboot
0
 
LVL 4

Expert Comment

by:RobertParten
ID: 34890614
If this is a 32 bit Windows 7 machine you can attempt to run

combofix

HOwever, I would recommend running a good clenup utility as well:

http://www.stevengould.org/index.php?option=com_content&task=view&id=15&Itemid=69

Will clean up a lot of that crap that is sitting around, do that before you run a scan. In the worst case scenario you can download sysinternals procexp and find the culprit file and "echo" it out and render it useless. I can offer further detail if you want.
0
 

Author Comment

by:dean_stephens
ID: 34890621
I already own McAfee.  Why will they not help me remove the virus?  If it has been around since 2008 it cannot be that hard to get rid of.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 9

Expert Comment

by:bz43
ID: 34890657
Here is a link that says don't disable system restore until after you run the scans:
http://www.experts-exchange.com/Software/Internet_Email/Anti-Virus/A_1934-Viruses-in-the-System-Volume-Information-System-Restore.html

Here is a link that says to run scans in normal mode NOT safe mode, if you can:
http://forums.malwarebytes.org/index.php?showtopic=17334&st=0&p
0
 

Author Comment

by:dean_stephens
ID: 34900531
@moonie42 - The software you linked to will not install since it requires you install in normal mode and the virus will allow nothing to run in normal mode.  Only safe mode can be used.
@ bz43 - ditto
@RobertParton - All I get when I try to find Combofix is a link to Registry Mechanic.  I assume I am doing something wrong but I cannot figure out how to find the program. Do you have a link perhaps.  

I am really gettting frustrated with this.  

McAfee has given me a link to a program called "stinger', which ran to completion and did not find the virus or remove it.  I am still stuck with nothing but safe mode.  Normal mode is infected with the "System Tools" hoax and nothing seems to work.
0
 

Author Comment

by:dean_stephens
ID: 34901223
I am being told by both McAfee and Norton that this virus can only be removed manually at a cost of $99.  Does anyone know any other option?
0
 
LVL 9

Accepted Solution

by:
bz43 earned 2000 total points
ID: 34902111
I asked the moderators to add some antivirus zones to your question.  Right now the only zone it's in is "Windows 7".  More people should read it when the zones are updated.  Or see if you can add some zones to this question like: Anti-Virus, Anti-Spyware, Internet Security, Latest Threats.

There is a bootable disk called the VIPRE Rescue Program at http://live.sunbeltsoftware.com/
Maybe, from another non-infected computer, download that and run it on the infected PC.

This thread might be about your infection.  I'm not sure.  Please read it at:
http://supportforums.sunbeltsoftware.com/messageview.aspx?catid=76&threadid=6712

Only download Combofix from the following website:
http://www.bleepingcomputer.com/download/anti-virus/combofix

Tutorial on how to use combofix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
0
 

Author Closing Comment

by:dean_stephens
ID: 34903458
Thank you so much.
0
 
LVL 9

Expert Comment

by:bz43
ID: 34908061
You're welcome.  Were you able to remove the virus?
0
 

Author Comment

by:dean_stephens
ID: 34954037
Yes.
0
 

Author Comment

by:dean_stephens
ID: 34954065
For clarification, the details on the second thread you posted

http://supportforums.sunbeltsoftware.com/messageview.aspx?catid=76&threadid=6712


allowed me to find the virus manually and delete enough of it to get the standard anti virus to remove the rest.
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are many software programs on offer that will claim to magically speed up your computer. The best advice I can give you is to avoid them like the plague, because they will often cause far more problems than they solve. Try some of these "do it…
IF you are either unfamiliar with rootkits, or want to know more about them, read on ....
This Micro Tutorial will go in depth within Systems and Security in Windows 7 and will go into detail regarding Action Center, Windows Firewall, System, etc. This will be demonstrated using Windows 7 operating system.
This Micro Tutorial will give you a basic overview of Windows Live Photo Gallery and show you various editing filters and touches to photos you can apply. This will be demonstrated using Windows Live Photo Gallery on Windows 7 operating system.
Suggested Courses

577 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question