WinTools Spyware

Anybody here had to deal with this and actually get it off their computer? I have tried some thing, even something that was specificates!!!! I close one executable and it opens another (there is always 2 wintool executables running)

any suggestions.

Should I try registary entries? I started that, but any specific ones? PlPlus, of course, I would need to turn of the executable otherwise it will just re-write the entries.
3,350 views 10 replies
Reply #1 Top
Sounds more like a Worm/Virus Joe..that isnt ordinary spyware..

Try running an AV scan in safe mode after updating your definitions..

Spyware doesnt usually "Replicate" files..thats a virus..

Zero.
Reply #2 Top
A google search came up with this:
http://www.pchell.com/support/wintools.shtml
http://www.winpatrol.com/db/freesample/wtoolsa.html
http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453093976
http://www.doxdesk.com/parasite/HuntBar.html
http://www.iamnotageek.com/a/wintools.exe.php

Hope it helps.
Reply #3 Top
Just use the entries in Add/Remove Programs.
Works fine.

Otherwise you have to boot into safe mode and delete the files by hand.
They'll be in Program Files/(whatever) and Program Files/Common Files
Reply #4 Top
Oh guys I should have told you.

It puts itself into start up when computer comes on
It runs when computer is on dionostic mode
It has 2 copies of itself as executables
It won't allow files to be deleted (because it is running I would suggest)

I'll try safe mode and see what happens. Add/Remove won't work (at least in my case).

I tried a couple of those solutions Citizen citsym nogard; one in piticular was WinPatrol but there are some links that I haven't tried.

Thanks guys for the help. Maybe I won't have to clean out my sisters computer (I really want to turn her computer into a testing ground for DesktopX themes... if it can run on her slow computer, it will run on anything)
Reply #5 Top
I am in the line too

got the same ... NAV 2005
Reply #6 Top
The programmers of wintools are getting smarter about how it works, including hiding spawners in alternate locations.

MS Antispyware seems to remove it also.
Reply #7 Top
It puts itself into start up when computer comes on


Use msconfig to stop it from running temporarily. If you don't know how, ask.


If that doesn't help. Go to GRC http://www.grc.com/discussions.htm . They have newsgroups dedicated to spyware & people who might be able to give you more help. The reason I'm sending you to the webpage & not the newsgroup is you need to set up a password before you can post. I know it's a pain , but it's a private server & they apparently were having some problems with some people.
Reply #8 Top
It puts itself into start up when computer comes on


Use Spybot Search & Destroy's tool that configures Start-Up entries to disable it from there.

It runs when computer is on dionostic mode


Must be a worm. Try updating Norton and run virus check. Also scan with Ad-Aware and Spybot Search & Destroy for worms.

It won't allow files to be deleted


Try running Task Manager (Ctrl+Alt+Del) and find the processes with the name of this annoying proggie, right-click on the names and select End Process Tree...this should cut the power plug from them,thus allowing you to delete them safely. Also you might as well wanna run a Regedit and hit search and search and delete all registry entries referring to this proggie.

If you have the name of the pest just say it and i'll try to find some info on how to wash it out.

Hope this is of some help.
Reply #9 Top
Couple not-so-simple solutions:

1) Kill all suspicious processes. Then run a spyware remover.

2) Boot from another OS and run a spyware remover from there. This prevents the thing from running at startup, since you're booting from a different OS. Ofcourse you need to have a multi-boot setup for this.

3) Remove the disk and install it as a secondary drive in another machine. Then run the spyware remover.
Reply #10 Top
download "Killbox" and remove it by force with that in safe mode.

If it dosen't want to nuke them live, then set it to replace on boot with a dummy.