PDA

View Full Version : Winfixer 2005


jells
09-18-2005, 05:00 PM
I have this winfixer thing on my comp, driving me mental..Ive scanned with spybot, adaware, norton, trend housecalls etc..nothing works. Ive googled this and the results are telling me to download Hijack This and create a folder, run that and log the results...I'm not very computer literate, I'm wondering if there is another way to get rid of this..I have Windows XP Home.
Any help would be appreciated.
Thanks !

mander
09-18-2005, 09:22 PM
If you have already uninstalled it through add/remove programs, try this handy little utility to remove it from the registry. www.ccleaner.com

Let us know how you make out.

mitch
09-18-2005, 11:04 PM
Manual Removal http://www.spywaredb.com/remove-winfixer/
Also says Spy Sweeper will work (there is a trial version)
http://www.webroot.com/consumer/products/spysweeper/index.html?rc=3601&ac=winfixer

frostyone
09-19-2005, 09:10 AM
Well jells, that's a real nasty.
There are a few different variants of winfixer.

If you have windows xp
Microsoft anti-spyware with the latest updates will take care of some variants.
Download microsoft anti-spyware, update the definitions and then scan.
http://www.microsoft.com/athome/security/spyware/software/default.mspx
--------
If you have another variant, yes you will have to use hijack this. To at least begin to remove it.

Easist way:

Here is a link to hijack this setup.
This program will automatically set it up properly for you
DIRECT DOWNLOAD:
http://www.thespykiller.co.uk/files/HJTsetup.exe

Download the program, desktop is fine.
Run the program.
Accept the default locations.
(It will setup hjt on C: program files)

You should place a checkmark in the box for the shortcut icon on the desktop.

When you double click the icon, the program will open.

You will choose "scan and save a log file"
( it only takes a minute)
A second window will open in notepad ,automatically, with the results.
You will copy and paste those results in a forum
-------

jells
09-19-2005, 04:43 PM
Im trying all your suggestions, thank you for your help..I will let you know how it works out.

jells
09-23-2005, 12:32 AM
Frosty your advice to do the following:
If you have windows xp
Microsoft anti-spyware with the latest updates will take care of some variants.
Download microsoft anti-spyware, update the definitions and then scan.
http://www.microsoft.com/athome/sec...re/default.mspx
Did the trick, its gone and all is well...Thank you all for your help, much appreciated.

skalek
11-10-2005, 07:23 PM
This post will help you remove it:

How To Remove Winfixer / Virtumonde / Msevents / Trojan.vundo.b (http://www.bleepingcomputer.com/forums/topic18610.html)

BillD
11-10-2005, 08:07 PM
None of the above fixes worked for me, and had to use the symantec virtuomondo tool, that frostyone provided a link for to remove it.

frostyone
11-10-2005, 09:20 PM
That's why it really helps when people like BillD and jells post back to say what worked and it's appreciated.

These variants change constantly.
What will work at one time, will not at another time.

When jells posted in September, the symantec removal tool was next to useless.
Manual removal was difficult, but microsoft anti-spyware had just updated and was reported to work well, and did.

A little later in November, when BillD had a problem ,microsoft anti-spyware no longer worked for the newer variants.
Symantec's removal tool, however, had just underwent several major updates at the end of October.
(It's last update was 3 days ago, Nov 7.)
Right now it is the preferred method.
That might change.


The spyware variants , change , evolve so rapidly.

It's important to look at dates and why feedback is so necessary.
---

There seems to be suspicion arising that Winfixer, virtumondo are using a flaw in old versions of sun java to get in.

Problem is that when you update your sun java the old versions remain on your computer, and are suspected of remaining exploitable.

It's recommened that any old versions of sun java be removed using add/remove programs.

CalamityJane is taking a poll of those infected by Virtumondo/winfixer to see if that could be the entry point and provides info on it:

Winfixer/ Vundo / Virtumonde Victims : Please Read

Multiple Choice Poll
Which version of Sun Java is installed?

We have noticed a large number of Winfixer/ Vundo / Virutmonde Victims have an older version of Sun Java (v. J2SE 1.4.2_03) installed in Add/Remove Programs in the Control Panel. Other older or newer versions may also be installed, however, we are wanting to know if you have this version on your system.
http://www.dslreports.com/forum/remark,14738046~days=9999