WinTools registry entries unable to be deleted

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by RLS2005, Mar 11, 2005.

  1. RLS2005

    RLS2005 Private E-2

    I have a Win 2000 machine that is infected with some WinTools issues. Specificly I am unalbe to complete a CounterSpy scan due to a registry entry HKLM/SW/WinTools that cannot be deleted. Should I reinstall WinTools and then uninstall then run COunterSpy or what might you suggest.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try running CounterSpy in safe mode. Isn't CounterSpy actually a copy of GiantAntiSpyware which is now Microsoft AntiSpyware. If so perhaps you would be better off removing CounterSpy and using Microsoft AntiSpyware. If you are still having problems, follow the steps below.

    To help us to best help you, please follow the steps below closely and in the order given and do not skip anything. If you have any difficulty, please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better. Don't be afraid to ask for additional help if you don't understand something!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENTto your next message. (Do NOT copy/paste the log into your post).
     
  3. RLS2005

    RLS2005 Private E-2

    Well, Dr.C, I have proceeded with the suggested safe mode and with everything off and used Microsoft Antispy beta and it proceeds okay till I hit the registry scan then after about 1000 lines scanned it s l o w s down and stops. I then get a window explaining that virtual memory is low and I should increase my page file size (now at 768) then everything stops. I can use task manager to end the program but the items found in the files scan are NOT removed since the program never completed the scan. (Side note...Microsoft please add the abitiy to remove what is found even when you abort the scan....). I will capture my log and attach for your review later today.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have run ALL the other steps from the READ ME FIRST before proceding to a HijackThis log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds