Link to home
Start Free TrialLog in
Avatar of Richard Christensen
Richard Christensen

asked on

winfixer is causing a problem - how do I get rid of it?

My computer has been infected with Winfixer.  Is it a Trojan Horse?
How do I get rid of it?  With some preliminary attempts at removal, it keeps re-installing itself.  Thanks,
capreol
Avatar of zephyr_hex (Megan)
zephyr_hex (Megan)
Flag of United States of America image

run hijackthis.  it will produce a log.  cut/paste the log into the analyzer.  the analyzer will produce a web page.  at the bottom of that web page analysis results report will be an option to save it.  so save it.  then post a link to that saved page here.
hijackthis:http://www.majorgeeks.com/download3155.html
analyzer:  http://www.hijackthis.de
Hi capreol,

download this
www.ewido.net and download the trial version

run the scan and you should be right
ASKER CERTIFIED SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Richard Christensen
Richard Christensen

ASKER

I have run the ewido and it initially found 44 infections.  It removed them and I did a subsequent scan and it found 5 infections.  At one point in the first scan the program indicated that one or two of the infections were in the archive which began with documents and settings.  Then it asked me if I wanted to remove the archive.  At that point I said no because I do not know what removing the archive means.  Does it mean removing other valuable parts of the documents and settings folder??  Anyway, with further scans with ewido it always found 2 infections - therefore it was unable to remove the winfixer malware.  What should I do next?  Thanks,
capreol
did you try rpggamergirl's tool?

if yes then try disabling system restore as well, i rad once again in a magazine that is should be disabled when trying to kill maware

anything that ewido find infected you should delete, if its a crucial system file you wont be able to if not then allow it to do its job