Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner 2009 - Free Scan Now

tattlletale winload keylogger trojan standard in Vista?

microsoft.public.windows.vista.installation setup




Recommended Fix - Fix Vista Errors and Optimize Performance

Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Driver Scanner 2009 - Free Scan Now
Reply
  #1 (permalink)  
Old 01-13-2007
=?Utf-8?B?TWFyaW51cw==?=
 

Posts: n/a
tattlletale winload keylogger trojan standard in Vista?
After installing RC 1 Vista, I noticed using XSOFTSPY that in
windows\system32\winload.EXE a Trojan is mentioned named tattletale. I can
not remove it.

I have understood that Tattletale is used for "parental control", i.e. a
keylogger that should be used by parents to "spy" their children. Easily it
can be used for other usage as well. Xsoftsy call is a severe risk. (I
agree).

My questions
1: Is this a standard element of Vista? or have I installed it by accident
separately?
2: How can I remove this.





Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 01-14-2007
Carey Frisch [MVP]
 

Posts: n/a
Re: tattlletale winload keylogger trojan standard in Vista?
It is not part of Vista..perhaps someone installed it without your knowledge.

PC Tattletale
http://www.pcworld.com/downloads/fil...scription.html

--
Carey Frisch
Microsoft MVP
Windows Shell/User

--------------------------------------------------------------------------------------

"Marinus" <Marinus@discussions.microsoft.com> wrote in message news:9BFE8654-F9FB-44F4-A8A7-6904A2BB8804@microsoft.com...
After installing RC 1 Vista, I noticed using XSOFTSPY that in
windows\system32\winload.EXE a Trojan is mentioned named tattletale. I can
not remove it.

I have understood that Tattletale is used for "parental control", i.e. a
keylogger that should be used by parents to "spy" their children. Easily it
can be used for other usage as well. Xsoftsy call is a severe risk. (I
agree).

My questions
1: Is this a standard element of Vista? or have I installed it by accident
separately?
2: How can I remove this.





Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 01-14-2007
John Barnes
 

Posts: n/a
Re: tattlletale winload keylogger trojan standard in Vista?
How have you tried to remove it? You should check your startup programs to
at least keep it from starting. Have you tried stopping it in Task Manager
and then uninstalling it?


"Marinus" <Marinus@discussions.microsoft.com> wrote in message
news:9BFE8654-F9FB-44F4-A8A7-6904A2BB8804@microsoft.com...
> After installing RC 1 Vista, I noticed using XSOFTSPY that in
> windows\system32\winload.EXE a Trojan is mentioned named tattletale. I
> can
> not remove it.
>
> I have understood that Tattletale is used for "parental control", i.e. a
> keylogger that should be used by parents to "spy" their children. Easily
> it
> can be used for other usage as well. Xsoftsy call is a severe risk. (I
> agree).
>
> My questions
> 1: Is this a standard element of Vista? or have I installed it by accident
> separately?
> 2: How can I remove this.
>
>
>
>
>


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 01-14-2007
Peter M
 

Posts: n/a
Re: tattlletale winload keylogger trojan standard in Vista?
Can we say "false positive"? I dl'd this program, ran it, and it claimed
winload.exe was a trojan and also claimed i had a trojan/adware in my
hostfile..... hmmm only entry in my host file is loopback. Another program
deleted like many other so called spyware scanners I've tried. I wouldn't
pay for it.

"Marinus" <Marinus@discussions.microsoft.com> wrote in message
news:9BFE8654-F9FB-44F4-A8A7-6904A2BB8804@microsoft.com...
> After installing RC 1 Vista, I noticed using XSOFTSPY that in
> windows\system32\winload.EXE a Trojan is mentioned named tattletale. I
> can
> not remove it.
>
> I have understood that Tattletale is used for "parental control", i.e. a
> keylogger that should be used by parents to "spy" their children. Easily
> it
> can be used for other usage as well. Xsoftsy call is a severe risk. (I
> agree).
>
> My questions
> 1: Is this a standard element of Vista? or have I installed it by accident
> separately?
> 2: How can I remove this.
>
>
>
>
>


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 01-14-2007
Richard Urban
 

Posts: n/a
Re: tattlletale winload keylogger trojan standard in Vista?
Winload.exe is a part of the Vista RTM operating system. You will find two
instances of it on your computer.

One will be in C:\Windows\System32 and is 918k

The other is in C:\Windows\System32\Boot and is 918k

Both are dated Thursday, ‎November ‎02, ‎2006, ‏‎07:42:32

--


Regards,

Richard Urban
Microsoft MVP Windows Shell/User
(For email, remove the obvious from my address)

Quote from George Ankner:
If you knew as much as you think you know,
You would realize that you don't know what you thought you knew!



"Marinus" <Marinus@discussions.microsoft.com> wrote in message
news:9BFE8654-F9FB-44F4-A8A7-6904A2BB8804@microsoft.com...
> After installing RC 1 Vista, I noticed using XSOFTSPY that in
> windows\system32\winload.EXE a Trojan is mentioned named tattletale. I
> can
> not remove it.
>
> I have understood that Tattletale is used for "parental control", i.e. a
> keylogger that should be used by parents to "spy" their children. Easily
> it
> can be used for other usage as well. Xsoftsy call is a severe risk. (I
> agree).
>
> My questions
> 1: Is this a standard element of Vista? or have I installed it by accident
> separately?
> 2: How can I remove this.
>
>
>
>
>


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 01-14-2007
Richard Urban
 

Posts: n/a
Re: tattlletale winload keylogger trojan standard in Vista?
Winload.exe is a part of the Vista RTM operating system. You will find two
instances of it on your computer.

One will be in C:\Windows\System32 and is 918k

The other is in C:\Windows\System32\Boot and is 918k

Both are dated Thursday, ‎November ‎02, ‎2006, ‏‎07:42:32



--


Regards,

Richard Urban
Microsoft MVP Windows Shell/User
(For email, remove the obvious from my address)

Quote from George Ankner:
If you knew as much as you think you know,
You would realize that you don't know what you thought you knew!



"Carey Frisch [MVP]" <cnfrisch@nospamgmail.com> wrote in message
news:30F99664-9677-44DC-99B9-A2BD48737E44@microsoft.com...
> It is not part of Vista..perhaps someone installed it without your
> knowledge.
>
> PC Tattletale
> http://www.pcworld.com/downloads/fil...scription.html
>
> --
> Carey Frisch
> Microsoft MVP
> Windows Shell/User
>
> --------------------------------------------------------------------------------------
>
> "Marinus" <Marinus@discussions.microsoft.com> wrote in message
> news:9BFE8654-F9FB-44F4-A8A7-6904A2BB8804@microsoft.com...
> After installing RC 1 Vista, I noticed using XSOFTSPY that in
> windows\system32\winload.EXE a Trojan is mentioned named tattletale. I
> can
> not remove it.
>
> I have understood that Tattletale is used for "parental control", i.e. a
> keylogger that should be used by parents to "spy" their children. Easily
> it
> can be used for other usage as well. Xsoftsy call is a severe risk. (I
> agree).
>
> My questions
> 1: Is this a standard element of Vista? or have I installed it by accident
> separately?
> 2: How can I remove this.
>
>
>
>
>


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 01-14-2007
Richard Urban
 

Posts: n/a
Re: tattlletale winload keylogger trojan standard in Vista?
Additionally, many forms of malware take on the name of a valid Windows
system file. If you find a similarly named file in another location - it is
a trojan, malware or virus.

--


Regards,

Richard Urban
Microsoft MVP Windows Shell/User
(For email, remove the obvious from my address)

Quote from George Ankner:
If you knew as much as you think you know,
You would realize that you don't know what you thought you knew!



"Richard Urban" <richardurbanREMOVETHIS@hotmail.com> wrote in message
news:%23K5WIG$NHHA.140@TK2MSFTNGP04.phx.gbl...
> Winload.exe is a part of the Vista RTM operating system. You will find two
> instances of it on your computer.
>
> One will be in C:\Windows\System32 and is 918k
>
> The other is in C:\Windows\System32\Boot and is 918k
>
> Both are dated Thursday, ‎November ‎02, ‎2006, ‏‎07:42:32
>
> --
>
>
> Regards,
>
> Richard Urban
> Microsoft MVP Windows Shell/User
> (For email, remove the obvious from my address)
>
> Quote from George Ankner:
> If you knew as much as you think you know,
> You would realize that you don't know what you thought you knew!
>
>
>
> "Marinus" <Marinus@discussions.microsoft.com> wrote in message
> news:9BFE8654-F9FB-44F4-A8A7-6904A2BB8804@microsoft.com...
>> After installing RC 1 Vista, I noticed using XSOFTSPY that in
>> windows\system32\winload.EXE a Trojan is mentioned named tattletale. I
>> can
>> not remove it.
>>
>> I have understood that Tattletale is used for "parental control", i.e. a
>> keylogger that should be used by parents to "spy" their children. Easily
>> it
>> can be used for other usage as well. Xsoftsy call is a severe risk. (I
>> agree).
>>
>> My questions
>> 1: Is this a standard element of Vista? or have I installed it by
>> accident
>> separately?
>> 2: How can I remove this.
>>
>>
>>
>>
>>

>


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 01-14-2007
Rick Rogers
 

Posts: n/a
Re: tattlletale winload keylogger trojan standard in Vista?
Hi Richard,

OP's problem is that their anti-spyware program is out of date and not up to
snuff for Vista. It is misidentifying the legitimate winload.exe file with
the one provided by the PC Tattletale malware.

I just knew this was going to start happening when they used the file name
of known malware for the system bootloader.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Windows help - www.rickrogers.org

"Richard Urban" <richardurbanREMOVETHIS@hotmail.com> wrote in message
news:%23KqRSG$NHHA.5016@TK2MSFTNGP04.phx.gbl...
> Winload.exe is a part of the Vista RTM operating system. You will find two
> instances of it on your computer.
>
> One will be in C:\Windows\System32 and is 918k
>
> The other is in C:\Windows\System32\Boot and is 918k
>
> Both are dated Thursday, ‎November ‎02, ‎2006, ‏‎07:42:32
>
>
>
> --
>
>
> Regards,
>
> Richard Urban
> Microsoft MVP Windows Shell/User
> (For email, remove the obvious from my address)
>
> Quote from George Ankner:
> If you knew as much as you think you know,
> You would realize that you don't know what you thought you knew!
>
>
>
> "Carey Frisch [MVP]" <cnfrisch@nospamgmail.com> wrote in message
> news:30F99664-9677-44DC-99B9-A2BD48737E44@microsoft.com...
>> It is not part of Vista..perhaps someone installed it without your
>> knowledge.
>>
>> PC Tattletale
>> http://www.pcworld.com/downloads/fil...scription.html
>>
>> --
>> Carey Frisch
>> Microsoft MVP
>> Windows Shell/User
>>
>> --------------------------------------------------------------------------------------
>>
>> "Marinus" <Marinus@discussions.microsoft.com> wrote in message
>> news:9BFE8654-F9FB-44F4-A8A7-6904A2BB8804@microsoft.com...
>> After installing RC 1 Vista, I noticed using XSOFTSPY that in
>> windows\system32\winload.EXE a Trojan is mentioned named tattletale. I
>> can
>> not remove it.
>>
>> I have understood that Tattletale is used for "parental control", i.e. a
>> keylogger that should be used by parents to "spy" their children. Easily
>> it
>> can be used for other usage as well. Xsoftsy call is a severe risk. (I
>> agree).
>>
>> My questions
>> 1: Is this a standard element of Vista? or have I installed it by
>> accident
>> separately?
>> 2: How can I remove this.
>>
>>
>>
>>
>>

>


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 01-14-2007
=?Utf-8?B?TWFyaW51cw==?=
 

Posts: n/a
Re: tattlletale winload keylogger trojan standard in Vista?
Hi all,

I've learned a lot. I've even managed to change the owner of the
(system)file, necessary to delete it. Actually I have deleted all the
Winload-files (diffrent creation-date), so the system did not boot anymore.
Never mind, this is "testing" and the installationpackage was obvious
manipulated and not trustable in any way.

Thanks a lot for all answers.

Marinus



"Richard Urban" wrote:

> Additionally, many forms of malware take on the name of a valid Windows
> system file. If you find a similarly named file in another location - it is
> a trojan, malware or virus.
>
> --
>
>
> Regards,
>
> Richard Urban
> Microsoft MVP Windows Shell/User
> (For email, remove the obvious from my address)
>
> Quote from George Ankner:
> If you knew as much as you think you know,
> You would realize that you don't know what you thought you knew!
>
>
>
> "Richard Urban" <richardurbanREMOVETHIS@hotmail.com> wrote in message
> news:%23K5WIG$NHHA.140@TK2MSFTNGP04.phx.gbl...
> > Winload.exe is a part of the Vista RTM operating system. You will find two
> > instances of it on your computer.
> >
> > One will be in C:\Windows\System32 and is 918k
> >
> > The other is in C:\Windows\System32\Boot and is 918k
> >
> > Both are dated Thursday, ‎November ‎02, ‎2006, ‏‎07:42:32
> >
> > --
> >
> >
> > Regards,
> >
> > Richard Urban
> > Microsoft MVP Windows Shell/User
> > (For email, remove the obvious from my address)
> >
> > Quote from George Ankner:
> > If you knew as much as you think you know,
> > You would realize that you don't know what you thought you knew!
> >
> >
> >
> > "Marinus" <Marinus@discussions.microsoft.com> wrote in message
> > news:9BFE8654-F9FB-44F4-A8A7-6904A2BB8804@microsoft.com...
> >> After installing RC 1 Vista, I noticed using XSOFTSPY that in
> >> windows\system32\winload.EXE a Trojan is mentioned named tattletale. I
> >> can
> >> not remove it.
> >>
> >> I have understood that Tattletale is used for "parental control", i.e. a
> >> keylogger that should be used by parents to "spy" their children. Easily
> >> it
> >> can be used for other usage as well. Xsoftsy call is a severe risk. (I
> >> agree).
> >>
> >> My questions
> >> 1: Is this a standard element of Vista? or have I installed it by
> >> accident
> >> separately?
> >> 2: How can I remove this.
> >>
> >>
> >>
> >>
> >>

> >

>
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 03-31-2008
smeesh
 

Posts: n/a
RE: tattlletale winload keylogger trojan standard in Vista?
I think I have a similar/maybe related problem and would appreciate if
someone could help me. I did an upgrade from XP to Vista Home basic on my
sons computer. It does not have a DVD drive so had to install from 5 CD's.
I put the parental lock on as the computer is in his room and wanted to have
some control on what is viewed (and doing homework rather than
chatting/surfing)!! ;oP

All seemed to be working fine. My son then got to the computer and removed
Grand Theft Auto. The computer no longer starts - he assures me this is all
he did.

It gives the error winload.exe missing or corrupt (yadda, yadda, yadda). It
tells me to reinsert disc and restart. I do this and it wont read the CD. I
have checked boot sequence and it is CD first.

Now what? Please help or provide some ideas as I just cant afford to pay to
fix this one.

thanks in advance

"Marinus" wrote:

> After installing RC 1 Vista, I noticed using XSOFTSPY that in
> windows\system32\winload.EXE a Trojan is mentioned named tattletale. I can
> not remove it.
>
> I have understood that Tattletale is used for "parental control", i.e. a
> keylogger that should be used by parents to "spy" their children. Easily it
> can be used for other usage as well. Xsoftsy call is a severe risk. (I
> agree).
>
> My questions
> 1: Is this a standard element of Vista? or have I installed it by accident
> separately?
> 2: How can I remove this.
>
>
>
>
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: do I have a keylogger or not? Dale microsoft.public.windows.vista.general 1 04-02-2007 18:46
Ask for Vista DVD to run winload =?Utf-8?B?UGF0?= microsoft.public.windows.vista.general 0 02-28-2007 22:54
Winload Error Gary MCSE microsoft.public.windows.vista.general 0 02-28-2007 19:48
Is PC Tattletale (keylogger) part of vista parental control software? T5 microsoft.public.windows.vista.general 4 02-20-2007 13:51
Winload error - please advise =?Utf-8?B?VGlt?= microsoft.public.windows.vista.installation setup 3 12-13-2006 13:19




All times are GMT +1. The time now is 22:32.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com and Win7Heads.com.


Funny Commercials to make you laugh :-)

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120