WinTools Spyware
Saturday, April 30, 2005 by joeKnowledge | Discussion: WinCustomize Talk
any suggestions.
Should I try registary entries? I started that, but any specific ones? PlPlus, of course, I would need to turn of the executable otherwise it will just re-write the entries.
Reply #2 Saturday, April 30, 2005 8:10 AM
http://www.pchell.com/support/wintools.shtml
http://www.winpatrol.com/db/freesample/wtoolsa.html
http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453093976
http://www.doxdesk.com/parasite/HuntBar.html
http://www.iamnotageek.com/a/wintools.exe.php
Hope it helps.

Reply #3 Saturday, April 30, 2005 8:37 AM
Works fine.
Otherwise you have to boot into safe mode and delete the files by hand.
They'll be in Program Files/(whatever) and Program Files/Common Files
Reply #4 Sunday, May 1, 2005 7:48 AM
It puts itself into start up when computer comes on
It runs when computer is on dionostic mode
It has 2 copies of itself as executables
It won't allow files to be deleted (because it is running I would suggest)
I'll try safe mode and see what happens. Add/Remove won't work (at least in my case).
I tried a couple of those solutions Citizen citsym nogard; one in piticular was WinPatrol but there are some links that I haven't tried.
Thanks guys for the help. Maybe I won't have to clean out my sisters computer (I really want to turn her computer into a testing ground for DesktopX themes... if it can run on her slow computer, it will run on anything)
Reply #6 Sunday, May 1, 2005 11:42 AM
MS Antispyware seems to remove it also.
Reply #7 Sunday, May 1, 2005 12:30 PM
| It puts itself into start up when computer comes on |
Use msconfig to stop it from running temporarily. If you don't know how, ask.
If that doesn't help. Go to GRC http://www.grc.com/discussions.htm . They have newsgroups dedicated to spyware & people who might be able to give you more help. The reason I'm sending you to the webpage & not the newsgroup is you need to set up a password before you can post. I know it's a pain
, but it's a private server & they apparently were having some problems with some people.Reply #8 Monday, May 2, 2005 7:36 AM
| It puts itself into start up when computer comes on |
Use Spybot Search & Destroy's tool that configures Start-Up entries to disable it from there.
| It runs when computer is on dionostic mode |
Must be a worm. Try updating Norton and run virus check. Also scan with Ad-Aware and Spybot Search & Destroy for worms.
| It won't allow files to be deleted |
Try running Task Manager (Ctrl+Alt+Del) and find the processes with the name of this annoying proggie, right-click on the names and select End Process Tree...this should cut the power plug from them,thus allowing you to delete them safely. Also you might as well wanna run a Regedit and hit search and search and delete all registry entries referring to this proggie.
If you have the name of the pest just say it and i'll try to find some info on how to wash it out.
Hope this is of some help.

Reply #9 Monday, May 2, 2005 7:52 AM
1) Kill all suspicious processes. Then run a spyware remover.
2) Boot from another OS and run a spyware remover from there. This prevents the thing from running at startup, since you're booting from a different OS. Ofcourse you need to have a multi-boot setup for this.
3) Remove the disk and install it as a secondary drive in another machine. Then run the spyware remover.
Reply #10 Monday, May 2, 2005 8:20 AM
If it dosen't want to nuke them live, then set it to replace on boot with a dummy.
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #1 Saturday, April 30, 2005 6:49 AM
Try running an AV scan in safe mode after updating your definitions..
Spyware doesnt usually "Replicate" files..thats a virus..
Zero.