Make a note of this. Saved me some time investigating myself. Just like the fake scan results and warning messages, you should not be alarmed with this message as they just tactics that the malware writer is using to try and scare Your're in Danger! Check This Out

My computer now loads fine. www. Running XP I got infected last night and struggled for hours to clear it out.I noted that it was "squeezing" the time it allowed me on the Internet searching for answers/ideas February 19, 2011 at 5:23 AM Anonymous said...

Alternate System Tool removal instructions using HijackThis or Process Explorer (in Normal mode): 1. February 27, 2011 at 11:49 AM Richard said... We now need to delete the C:\Windows\System32\Drivers\etc\HOSTS file.

I didn't know how to do that Safe Mode stuff (I have Vista) so I tried Malwarebytes and it said I had 164 infected files. OR you may download Process Explorer and end System Tool process: [SET OF RANDOM CHARACTERS].exe, i.e. If you find that your computer has been infected with this rogue program then please uninstall System Tool from your computer as soon as possible. That's when I got the first hint I had a problem...

This post was just tweeted to me. THEN I ran the SUPERAntiSpyware free edition sotware that was alreasdy installed on the computer. The warning message that you will see is: Warning: Your computer is infected Windows has detected spyware infection! http://www.2-spyware.com/remove-system-tool.html I rebooted in safe mode, then did a system restore.

Click here to activate protection. Be assured that nothing is going to "break your life". I downloaded a couple of antivirus software but they either charge or can't fix it. It works fine, now, but all the fake viruses planted on the computer are still there somewhere, I am sure.

I don't understand the Ashok method. https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=SystemTool It indicates that a scan is in progress and that several threats, including trojans, worms, and dialers, have been detected. If you have already purchased it, the please contact your credit card company and dispute the charges. During a seemingly inactive phase, the rogue modifies your security settings so it can run undetected.

This infection changes your Windows settings to use a proxy server that will not allow you to browse any pages on the Internet with Internet Explorer or update security software.

I don't go to a lot of websites so I am rather confused. A typical path is C:Documents and SettingsAll UsersApplication Data. - %DesktopDirectory% is a variable that refers to the file system directory used to physically store file objects on the desktop. Your data is still available for forensics, and in some cases For your boss, your friends, your wife, your children. http://mseedsoft.com/system-tool/system-tool-2011-please-help.html can anyone help for vista please?

You should now be in the Internet Options screen as shown in the image below. The file cmd.exe is infected. Thanks for saving me mucho bucks.

I have removed "SYSTEM TOOL 2011" from two different computers (so far).

c:\documents and settings\all users\application Data\[Folder name with weired name]\foldername.exe. I think I managed to get rid of it by using one of the activation codes. I started the full scan anyway and hope it is updated enough to capture this nasty virus. (So far, I see it shows 21 infected objects.)Of course, this comes at the Remember, knowledge is the most powerful weapon.

Member Posts: 211 im a malware killer Re: Need help in removing System Tool 2011 malware « Reply #2 on: December 12, 2010, 07:17:17 PM » you can also use a OMG thankss sooo much it removed it... Loading... navigate here Thanks Ashok, worked for me too.

Secure yourself right now! i cant find the folder.. Is anybody has a miracle solution,? January 29, 2011 at 6:14 PM Anonymous said...

Running Vista (unfortunately)and I had to search for my C:\programdata folder from the start menu as it would not show up in my c drive normally. Double-click on the icon on your desktop named mb3-setup-1878.1878-

Activate antivirus protection to prevent data loss and avoid the theft of your credit card details. Ask us a question remove it now remove it now Reimage is a tool to detect malware.You need to purchase full version to remove infections. UPDATE: you can register System Tool 2011 by using these codes: (This should make the removal procedure a lot easier) WNDS-S0DF5-GS5E0-FG14S-2DF8G WNDS-JUYH3-24GHJ-HGKSH-FKLSD WNDS-89OF7-7324R-5SAD4-TG68U WNDS-HFVDR-9844O-U54DA-5TBSC WNDS-G8FB6-1V87S-DRT1S-63SRG WNDS-4BGY2-JY4KO-IT98Y-7HJ43 WNDS-5D1V2-XB0D5-JT1TY-97DS3 WNDS-F40SA-1ER5H-4FG5D-F8412 WNDS-SERFH-2642S-F04SD-64FG1 WNDS-S0DF5-GS5E0-FG14S-2DF8G WNDS-452S3-ER00F-TSE35-S8FSD search: C:\ProgramData\glbKINd13400 delete then empty recycle bin January 31, 2011 at 9:09 PM eubie137 said...

Working... February 28, 2011 at 11:02 PM Anonymous said... Afterwards...do a sytem restore and go back 3 weeks. (to be safe)And it wouldn't hurt to download Avast anti virus software. Every site you and somebody or even something, like spyware, opened in your browsers, with all the images, and all the downloaded and maybe later removed movies or mp3 songs -

I also use regedit and removed all the references to the "random letter" file.The MalwareByte program did not detect System tools 2011, but found some others. OTL will now runDouble-click on the Custom Scans box and a message box will popup asking if you want to load a custom scan from a fileSelect Scan.txt that you downloadedClick I highlighted it and deleted it.