Wednesday, November 19, 2008

WinTools Adware

Removing WinTools
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

Visible Symptoms:
Files in system folders:
[%PROGRAM_FILES_COMMON%]\WinTools\WSup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsB.dll
[%PROFILE_TEMP%]\tb_setup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WSup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsB.dll
[%PROFILE_TEMP%]\tb_setup.exe

How to detect WinTools:

Files:
[%PROGRAM_FILES_COMMON%]\WinTools\WSup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsB.dll
[%PROFILE_TEMP%]\tb_setup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WSup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsB.dll
[%PROFILE_TEMP%]\tb_setup.exe

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{87067f04-de4c-4688-bc3c-4fcf39d609e7}
HKEY_CLASSES_ROOT\CLSID\{87766247-311C-43B4-8499-3D5FEC94A183}
HKEY_CLASSES_ROOT\clsid\{a8deb4a5-d9ef-4d21-b4f6-921475004e7d}
HKEY_CLASSES_ROOT\wtoolsb.resprotocol
HKEY_CURRENT_USER\software\wintools
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\wintools
HKEY_LOCAL_MACHINE\software\wintools
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\wintoolssvc
HKEY_CLASSES_ROOT\clsid\{87766247-311c-43b4-8499-3d5fec94a183}
HKEY_CLASSES_ROOT\wsg.wsgobj

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservicesonce

Removing WinTools:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Agent.asu Trojan Cleaner
Remove CashDialer Adware
Lizards.Tail Spyware Removal
CWS.Svcinit Trojan Removal instruction
Remove BettInet Trojan

No comments: