WinTools Spyware

Saturday, April 30, 2005 by joeKnowledge | Discussion: WinCustomize Talk

Anybody here had to deal with this and actually get it off their computer? I have tried some thing, even something that was specificates!!!! I close one executable and it opens another (there is always 2 wintool executables running)

any suggestions.

Should I try registary entries? I started that, but any specific ones? PlPlus, of course, I would need to turn of the executable otherwise it will just re-write the entries.
Double Zero
Reply #1 Saturday, April 30, 2005 6:49 AM
Sounds more like a Worm/Virus Joe..that isnt ordinary spyware..

Try running an AV scan in safe mode after updating your definitions..

Spyware doesnt usually "Replicate" files..thats a virus..

Zero.
citsym nogard
Reply #2 Saturday, April 30, 2005 8:10 AM
A google search came up with this:
http://www.pchell.com/support/wintools.shtml
http://www.winpatrol.com/db/freesample/wtoolsa.html
http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453093976
http://www.doxdesk.com/parasite/HuntBar.html
http://www.iamnotageek.com/a/wintools.exe.php

Hope it helps.
Doomgaze
Reply #3 Saturday, April 30, 2005 8:37 AM
Just use the entries in Add/Remove Programs.
Works fine.

Otherwise you have to boot into safe mode and delete the files by hand.
They'll be in Program Files/(whatever) and Program Files/Common Files
joeKnowledge
Reply #4 Sunday, May 1, 2005 7:48 AM
Oh guys I should have told you.

It puts itself into start up when computer comes on
It runs when computer is on dionostic mode
It has 2 copies of itself as executables
It won't allow files to be deleted (because it is running I would suggest)

I'll try safe mode and see what happens. Add/Remove won't work (at least in my case).

I tried a couple of those solutions Citizen citsym nogard; one in piticular was WinPatrol but there are some links that I haven't tried.

Thanks guys for the help. Maybe I won't have to clean out my sisters computer (I really want to turn her computer into a testing ground for DesktopX themes... if it can run on her slow computer, it will run on anything)
BX
Reply #5 Sunday, May 1, 2005 11:31 AM
I am in the line too

got the same ... NAV 2005
Doomgaze
Reply #6 Sunday, May 1, 2005 11:42 AM
The programmers of wintools are getting smarter about how it works, including hiding spawners in alternate locations.

MS Antispyware seems to remove it also.
citsym nogard
Reply #7 Sunday, May 1, 2005 12:30 PM
It puts itself into start up when computer comes on


Use msconfig to stop it from running temporarily. If you don't know how, ask.


If that doesn't help. Go to GRC http://www.grc.com/discussions.htm . They have newsgroups dedicated to spyware & people who might be able to give you more help. The reason I'm sending you to the webpage & not the newsgroup is you need to set up a password before you can post. I know it's a pain , but it's a private server & they apparently were having some problems with some people.
Cyberworld
Reply #8 Monday, May 2, 2005 7:36 AM
It puts itself into start up when computer comes on


Use Spybot Search & Destroy's tool that configures Start-Up entries to disable it from there.

It runs when computer is on dionostic mode


Must be a worm. Try updating Norton and run virus check. Also scan with Ad-Aware and Spybot Search & Destroy for worms.

It won't allow files to be deleted


Try running Task Manager (Ctrl+Alt+Del) and find the processes with the name of this annoying proggie, right-click on the names and select End Process Tree...this should cut the power plug from them,thus allowing you to delete them safely. Also you might as well wanna run a Regedit and hit search and search and delete all registry entries referring to this proggie.

If you have the name of the pest just say it and i'll try to find some info on how to wash it out.

Hope this is of some help.
craeonics
Reply #9 Monday, May 2, 2005 7:52 AM
Couple not-so-simple solutions:

1) Kill all suspicious processes. Then run a spyware remover.

2) Boot from another OS and run a spyware remover from there. This prevents the thing from running at startup, since you're booting from a different OS. Ofcourse you need to have a multi-boot setup for this.

3) Remove the disk and install it as a secondary drive in another machine. Then run the spyware remover.
Doomgaze
Reply #10 Monday, May 2, 2005 8:20 AM
download "Killbox" and remove it by force with that in safe mode.

If it dosen't want to nuke them live, then set it to replace on boot with a dummy.

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01