GF's computer hit with System Tool 2.20

Iron Woode

Elite Member
Super Moderator
Oct 10, 1999
31,304
12,819
136
I need some advice in removing this thing.

she is also on dial-up. :(

MBAM can't remove it and Avira can't either.

I believe it may be a rootkit infection.

Windows XP.
 

pcslookout

Lifer
Mar 18, 2007
11,959
157
106
I need some advice in removing this thing.

she is also on dial-up. :(

MBAM can't remove it and Avira can't either.

I believe it may be a rootkit infection.

Windows XP.

Hitman Pro to the rescue! Used as my backup plan and second scanner! Works 99% of the time!
 

Lemon law

Lifer
Nov 6, 2005
20,984
3
0
The point being, once you can correctly identify what ails your computer, one is way ahead of the game. Because you can google the "system tool 2.20 infection" and get pages and pages of various removal tools.

So for chuckles and grins I did just that, and just clicked om one random link.

http://www.cleanpcguide.com/remove-system-tool-2-20-how-to-remove-system-tool-2-20/

Which claims spyware doctor can do as well as hitman, and I am somewhat willing to bet further search would find removal tools not linked to any specific programs that can do the job even better.

But OP, don't let grass grow under your feet, system tools 2.20 disables your GF's entire
security defenses, and if she continues to access the internet while all her computer security fails to function, she can catch all forms of very hard to identify malware that
makes system tools mild in comparison.
 

pcslookout

Lifer
Mar 18, 2007
11,959
157
106
The point being, once you can correctly identify what ails your computer, one is way ahead of the game. Because you can google the "system tool 2.20 infection" and get pages and pages of various removal tools.

So for chuckles and grins I did just that, and just clicked om one random link.

http://www.cleanpcguide.com/remove-system-tool-2-20-how-to-remove-system-tool-2-20/

Which claims spyware doctor can do as well as hitman, and I am somewhat willing to bet further search would find removal tools not linked to any specific programs that can do the job even better.

But OP, don't let grass grow under your feet, system tools 2.20 disables your GF's entire
security defenses, and if she continues to access the internet while all her computer security fails to function, she can catch all forms of very hard to identify malware that
makes system tools mild in comparison.

It is not portable like Hitman Pro can be.
 

astark

Junior Member
Dec 19, 2010
1
0
0
MBAM should remove it, though your GF will have to disable System Tool before
scanning. She might need updating before scan.
To disable System tool, try entering one of its codes (they change rarely) here are around ten of them : http://www.2-viruses.com/remove-system-tool
If it does not work, reboot into safe mode and do a scan.
 

Iron Woode

Elite Member
Super Moderator
Oct 10, 1999
31,304
12,819
136
1. I had her scan with MBAM in safe-mode and it can't remove it.

2. I told her to turn off the PC until I am able to go over there.

3. I will try Hitman Pro on it and see what happens.
 

MadScientist

Platinum Member
Jul 15, 2001
2,183
63
91
If Hitman Pro does not work, try this.
1. Boot into Safe Mode with networking, download and run rkill. If rkill.exe does not run try one of its variants. DO NOT reboot. If you have to reboot, you will have to run rkill again.
http://www.bleepingcomputer.com/forums/topic308364.html

I have found that MBAM will not detect certain rootkill malware.

2. If this is a rootkit infection, download and run TDSSKILLER
http://support.kaspersky.com/viruses/solutions?qid=208280684

3. Update MBAM and run it again.

4. If still infected run Combofix. Back up all your important files first before running Combofix.
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
 

Iron Woode

Elite Member
Super Moderator
Oct 10, 1999
31,304
12,819
136
update 1:

I just got home with her PC, because I worked all day today.

Now I will attempt to remove this crap.
 

Iron Woode

Elite Member
Super Moderator
Oct 10, 1999
31,304
12,819
136
Update 2:

Hitman Pro removed it in about 20 mins.

everything else seems ok.
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,056
199
116
I'd recommend also scanning it with an online scanner and a AV Boot cd just to be sure.