Mini tool partition wizard a threat?

Page 1 of 2 12 LastLast

  1. Posts : 823
    W11 pro 64 beta channel

    Mini tool partition wizard a threat?

    I have Mini Tool Partition Wizard on all my pc's. When I opened the free version on this pc, it prompted me to update to the latest version which was not unexpected, and as I went through the update process which was exactly the same as updates in the past, Windows Security killed it dead. Trying to find out more, I couldn't find any reference to the actual name of the program. Any thoughts?
      My Computers

  2. Posts : 8,104
    windows 10

    Upload the installer to VirusTotal see what it makes of it
      My Computer

  3. Posts : 823
    W11 pro 64 beta channel
    Thread Starter

    I can't, the program has vanished from my machine, I even looked in control panel. Tomorrow, I will open up the program in another of my pc's and see if the same thing happens.
      My Computers

  4. 1PW
    Posts : 370


    Please read the last community remark.
      My Computers

  5. Posts : 1,621
    Windows 10 Home

    Tinmar49, exactly where did that download come from? MiniTool Partition Wizard, both free and fee, are available from MiniTool web site www . / partition-manager / partition-wizard-home . html.
    I suspect the other version is in a quarantine bucket in one or more of the security programs you use. Most allow restore, however, you might be better off to download and use the one directly from MiniTool.
      My Computer

  6. Posts : 823
    W11 pro 64 beta channel
    Thread Starter

    I have found threat references on Windows security, and have followed the instructions to scam and remove them . This took four short scans, now there are no threats detected.
    I will now follow Roland's link and re install the program.
    I was just opening the MTPW and followed the prompt to update when this happened, and the update proceeded exactly the same as frequent earlier updates of the program have gone. I scan frequently using the full Windows Security scans, and their offline scans, in addition to Malwarebytes free. The last scans were done on the same day as the problems arised.

    - - - Updated - - -

    Having reinstalled MTPW from Roland's link, and unticked a lot of unwanted extras as it proceeded, the program opened as normal and my disc drives showed up as expected. Windows Security immediately showed two potential threats.
    I ran Malwarebytes and two addware related items showed up, which I quarantined. A further scan with W S was clear.

    - - - Updated - - -

    I have just run MTPW and their other program, Shadowmaker, without any interruptions from WS, so, hopefully things may have settled down. I will now try an offline scan and see what happens.

    - - - Updated - - -

    Since promising to try the Windows offline scan, I have tried and failed four times to get it to start, a full scan worked ok
      My Computers

  7. Posts : 1,621
    Windows 10 Home

    Tinmar, thanks for your very informative update! I did not know so many extra"goodies" came with that program! If Windows Security labeled the threats, can you tell us those names?
      My Computer

  8. Posts : 823
    W11 pro 64 beta channel
    Thread Starter

    The Windows Security flagged the following programs:

    PVA : Win32/install core

    PVA : Win 32/relavent knowledge

    Malwarebytes found two pups :

    Adware. premier opinion (folder)

    Adware. premier opinion (file)

    These are either not allowed, or quarantined and MTPW still works as expected. Since the first part of this post, I have successfully run an offline scan which was clear.

    I have just turned on my laptop, which doesn't get used much, run MTPW and as expected, the latest version was offered. When running through the install process, I noticed what at first glance was the EULA but was something else and unchecked it. However, I am running Malwarebytes on the laptop at present and there are 20 threats, each with the title "Adware Premier".
    Last edited by tinmar49; 20 Jan 2020 at 13:59.
      My Computers

  9. Posts : 4
    Windows 10 Pro

    Surprisingly, I've been using it for so long without knowing it's malicious software. But anyway, it has helped me partition hard drives quite quickly and for free. The latest report from VirusTotal records it as 25/70 points.


    Free Automated Malware Analysis Service - powered by Falcon Sandbox
    "System Destruction" - "Opens the file with access rights to deletion"
    "Opens many files with write access (often an indicator of complete system infection)"
    "Opens the Windows Kernel Security Device Driver (KsecDD)"

    …. that evently has been removed

    Thank you.

    - - - Updated - - -

    More details on Joe Sandbox's Analysis:

    Verdict: MAL
    Score: 42/100
    Classification: mal42.spyw.evad.winEXE@39/497@20/10
    Domains: MiniTool Software | Best Partition Manager & Data Recovery [Software] Google MiniTool Partition Wizard | Best partition magic alternative for Windows PC and Server
    Hosts: omegle

    HTML Report: Automated Malware Analysis - Joe Sandbox Cloud Basic
    PDF Report: Automated Malware Analysis - Joe Sandbox Cloud Basic
    Executive Report: Automated Malware Analysis - Joe Sandbox Cloud Basic
    Incident Report:
      My Computer

  10. Posts : 23,229
    Win 10 Home ♦♦♦19045.4291 (x64) [22H2]


    Here's a dropbox link to MTPW 12.1 - free (this is my copy)

    Dropbox - Partition Wizard 12.1 - - Simplify your life

    Here the Virustotal results... (it's 100% clean)


    After it's installed, before running the program, block these two files in your firewall.
    Then it can't update or call home.

    Mini tool partition wizard a threat?-image1.png
      My Computer


  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 22:16.
Find Us

Windows 10 Forums