WINFIXER Popups won't go away!

Discussion in 'Malware Help (A Specialist Will Reply)' started by heatherjean, Nov 18, 2005.

  1. heatherjean

    heatherjean Private E-2

    I keep getting these annyoing winfixer popups every 5 minutes, even when you close the popup window, another one pops up! I have never dealt with anything like this before. My computer seems to be running much slower as well. I think this is some kind of freaky virus or something. I tried all your instructions on malware removal first, and i'm still getting them! Someone please help me to get rid of this thing. thanks :mad:
     
  2. heatherjean

    heatherjean Private E-2

    Oh, also by the way, this only happens when I use Internet Explorer. But even when I don't use it, my pc still is running slow.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you look at the Special Removal Procedures thread that was listed in the READ & RUN ME. See the reference to Virtumonde aka WinFixer.
     
  4. heatherjean

    heatherjean Private E-2

    No, i just read the read me and run first post sorry. I did try all of that. I'll check that one and post again. :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The link is in the READ ME & RUN. See step 6.
     
  6. heatherjean

    heatherjean Private E-2

    OMG, it worked! Thank you so much, all those stupid winfixer popups have stopped and my pc is running faster now :) I also bought that Spy Sweeper program, it's great! :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Yes SpySweeper is excellent. Are you sure everything is now fixed?
     
  8. heatherjean

    heatherjean Private E-2

    Well, i've IE open for quiet awhile now, and I haven't had any popups. :) I did all of the things to get rid of it while I was in safe mode, and I rebooted and I still don't see anything. It seems as if it's gone, I pray it is. Is there a way to check to be sure?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. heatherjean

    heatherjean Private E-2

    Ok chas, done :) Thanks for helping :)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the directions in that link for HJT. You did not install it properly and also you have some items running that should not be:

    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Documents and Settings\Ms. Heather Jean\Local Settings\Temp\HijackThis.exe <--- this is where we request that it not be installed

    Is the below something you installed? It is normally considered a Trojan.

    O4 - Global Startup: palstart.exe
     
  12. heatherjean

    heatherjean Private E-2

    I'm sorry, my bad. I need to learn to follow exact directions instead of trying to rush through everything :( I made the HJT folder and ran it from there. I closed down everything before I ran it. I hope it's ok this time. I think the palstart.exe belongs to a program that i've been using for years called Paltalk. I thought the program was safe. :rolleyes:
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may be! There could be a baddie that uses the same name. If you are sure it is okay just leave it be.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: MSEvents Object - {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - C:\WINDOWS\system32\pmkhi.dll (file missing)
    O3 - Toolbar: (no name) - {11359F4A-B191-42D7-905A-594F8CF0387B} - (no file)
    O20 - Winlogon Notify: pmkhi - C:\WINDOWS\system32\pmkhi.dll (file missing)
    O23 - Service: AntiVir Service (AntiVirService) - Unknown owner - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\PROGRAM FILES\AVPERSONAL

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
    The O23 Service may need a special procedure to remove. We will see.
     
  14. heatherjean

    heatherjean Private E-2

    Ok thanks Chas, I did that. :) Here's the new log, i'd be so lost without your help! ;)
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Looks clean now. So how are things working?

    If everything is okay, it is time to check this out: How to Protect yourself from malware!

    Also as a long term solution you should decide whether you want Spy Sweeper or MS Antispyware installed and running. I would not leave them both running because they do use a load of system rsources. If you purchased (or plan to) Spy Sweeper, I would keep it. Otherwise it is only a trial and expires in 14 days from installation.
     
  16. heatherjean

    heatherjean Private E-2

    I'm so happy to hear that! Dayum spyware was driving me crazy :mad: Everything is working fine :) No more popups at all and every time I run Spy Sweeper the results are clean. Thank you so much again and have a wonderful holiday! :)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Make sure you enjoy the holidays malware free and work thru that link I gave you in my last message.
     
  18. heatherjean

    heatherjean Private E-2

    I will be sure to do that! :) Peace
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds