FANDOM


System Tool is a rogue (fake) antivirus program. It is a member of the Win32/Winwebsec family of rogues. It shares its logo with MS Removal Tool and Essential Cleaner, two other rogues in its family.[1]

System-tool

System Tool's interface

Payload

System-tool-desktop

The message System Tool displays on the desktop background

When run, System Tool will hijack the user's desktop background, and replace it with a message that says
YOUR'RE [sic] IN DANGER! YOUR COMPUTER IS INFECTED WITH SPYWARE! 

And then automatically run a scan. System Tool will then proceed to attempt to scare the user into updating their version of System Tool by reporting fake threats that can only be terminated by updating, but whenever this is attempted, it will ask the user to purchase the full version.

Purchasing this product will cause the user's information to be stolen, causing identity theft.

Video

System Tool

System Tool







References

  1. http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Win32%2fWinwebsec#tab=2