winfixer is causing a problem - how do I get rid of it?

Posted on 2006-05-09
Last Modified: 2013-12-04
My computer has been infected with Winfixer.  Is it a Trojan Horse?
How do I get rid of it?  With some preliminary attempts at removal, it keeps re-installing itself.  Thanks,
Question by:capreol
    LVL 42

    Expert Comment

    run hijackthis.  it will produce a log.  cut/paste the log into the analyzer.  the analyzer will produce a web page.  at the bottom of that web page analysis results report will be an option to save it.  so save it.  then post a link to that saved page here.
    LVL 48

    Expert Comment

    Hi capreol,

    download this and download the trial version

    run the scan and you should be right
    LVL 47

    Accepted Solution

    Vundo infection usually causes winfixer popups, the entries always show up in hijackthis log, if it's vundo then vundofix should get rid of it.(otherwise let us see a hijackthis log as already suggested, it could be another malware causing it)

    Please download VundoFix.exe to your desktop.
    Double-click VundoFix.exe to run it.
    Put a check next to "Run VundoFix as a task".
    You will receive a message saying vundofix will close and re-open in a minute or less.
    Click OK
    When VundoFix re-opens, click the Scan for Vundo button.
    Once it's done scanning, click the Remove Vundo button.
    You will receive a prompt asking if you want to remove the files, click YES
    Once you click yes, your desktop will go blank as it starts removing Vundo.
    When completed, it will prompt that it will shutdown your computer, click OK.


    Author Comment

    I have run the ewido and it initially found 44 infections.  It removed them and I did a subsequent scan and it found 5 infections.  At one point in the first scan the program indicated that one or two of the infections were in the archive which began with documents and settings.  Then it asked me if I wanted to remove the archive.  At that point I said no because I do not know what removing the archive means.  Does it mean removing other valuable parts of the documents and settings folder??  Anyway, with further scans with ewido it always found 2 infections - therefore it was unable to remove the winfixer malware.  What should I do next?  Thanks,
    LVL 48

    Expert Comment

    did you try rpggamergirl's tool?

    if yes then try disabling system restore as well, i rad once again in a magazine that is should be disabled when trying to kill maware

    anything that ewido find infected you should delete, if its a crucial system file you wont be able to if not then allow it to do its job

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Top 6 Sources for Identifying Threat Actor TTPs

    Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

    In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
    In a recent article here at Experts Exchange (, I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
    Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    13 Experts available now in Live!

    Get 1:1 Help Now