System Tool Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by misterbojangles, Mar 6, 2011.

  1. misterbojangles

    misterbojangles Private E-2

    My Wife's laptop from school has become infected with System Tool which is asking her to pay to clean up Spyware infections.

    I've read the thread here http://forums.majorgeeks.com/showthread.php?t=233857 and cannot run the Rkill Application as System Tool blocks it. System Tool blocks most applications from running.

    XP Profesional SP3 on a Toshiba. I do not have admin access to this laptop and the 'Read and Run Me' steps may be impossible.

    Sophos antivirus is installed but appears to be disabled and cannot be turned on and does not appear in Windows security Centre.

    Any help gratefully accepted.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have run Rkill first hand on several PCs having this infection without a problem. However perhaps you have a different form. Try booting in safe mode and doing the below.


    Please download and run the below tool namedRkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are a few different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    If you are having problems running Rkill, you can download iExplore.exe or eXplorer.exe, which are renamed copies of Rkill.com, and try them instead.

    Once you've gotten one of them to run then try to immediately run the following.

    Now run this: Using Malwarebytes Anti-Malware
     
  3. misterbojangles

    misterbojangles Private E-2

    Thank you.
    I think i got Rkill to work in Safe Mode With Networking - access denied appeared a lot in the command box.

    I could not run Malwarebites as I do not have Admin rights. Looks like i will have to leave it for the IT 'Professionals' at my wife's school to mess about tomorrow.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are booting in safe mode then you are using an admin account and should have admin rights. If you are seeing errors about rights, you did not get the malware shutdown which is what Rkill normally does. As I stated, I have used this many times without a problem.

    Is there another user account? If so, try booting to it and running a full scan with Malwarebytes and other tools on this second account. Then come back to the infected account.


    See if you can run regedit also see if MSconfig runs.
     
  5. misterbojangles

    misterbojangles Private E-2

    I couldn't install Malwarebytes after I downloaded it.

    I restarted in Normal Mode and the System Tool appeared to have been disabled and I had full access to everything again, so i assume the Rkill worked. Sophos Antivirus was active again and I could run a scan, but not take any action... because I didn't have admin rights :confused

    My wife has her laptop back and the IT guys at her school can take it from here. Thank you very much for your help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Then you should be able to run MBAM and the rest of our cleaning process now to finish things off. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds