WinFixer2005 unremovable!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mskabialka, Sep 30, 2005.

  1. mskabialka

    mskabialka Private E-2

    I need to get rid of WinFixer2005

    I know the file which is the problem:
    c:\windows\$N72CA~1\bak.dll which Ewido identifies as having Spyware:Virtumonde, which is Winfixer, however I am totally unable to get rid of this. It hides itself in safe mode with command prompt, and can't be killed in any other mode as it is a running process. I have done all of the following to no avail.

    1: Disable System Restore

    2: Network Security Service
    Workstation Netlogon Service
    Remote Procedure Call (RPC) Helper
    None of these was running, so left alone

    3: Enable viewing of hidden files and folders and extensions

    4: Only Sophos Antivirus running

    5: Downloading Tools;
    Ad-Aware SE
    Ad-Aware VX2 Cleaner Plug-In
    CCleaner
    Spybot
    SpywareBlaster
    McAfee AVERT Stinger
    CWShredder
    Kill2me
    about:Buster
    HSRemove

    Scanning And Cleaning Steps: Could not get to Internet in "safe mode with networking support", so ran in normal mode:
    do an online scan at Bitdefender
    do an online scan at RavAntivirus

    Safe Mode:
    run McAfee AVERT Stinger

    So disconnect from the internet now and close all browsers and any other applications you have running now and then continue with step 2 below.

    2: Clean Your Hard Drive; Run CCleaner
    3: Ad-Aware SE (Ad-Aware VX2 Cleaner Plug-In) and Spybot.

    4: CWShredder
    Kill2me
    about:Buster (every version I found of this had an error: Runtime error '5': invalid procedure call or argument but I don't have about:blank or HomeSearchAssistent hijacks)
    HSRemove.


    OPTIONAL Steps: require you reboot back to normal mode.

    1: Don't have "Only the Best" aka "HSA" HIJACKER

    2: Scan With Hijack This



    May I post my HijackThis log for help and assistance?
    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. mskabialka

    mskabialka Private E-2

    Here is the log.
    Another problem I have besides Winfixer is that whenever I go to the Windows update site it only finds and downloads the Genuine Validation Tool, over and over, and won't go to the next step of finding current patches, etc.

    Thanks,
    Mich
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your copy of Windows valid and licensed to you? Do you have WinXP CD with a license key on it?

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.

    Please print these instructions out for use in Safe Mode.

    Please download VundoFix.exe to your desktop.
    • Double-click VundoFix.exe to extract the files
    • This will create a VundoFix folder on your desktop.
    • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
    • You will first be presented with a warning and a list of forums to seek help at. Iit should look like this
    • At this point press enter one time.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\$N72CA~1\bak.dll

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • Next you will see:
    • At this point please type the following file path (make sure to enter it exactly as below!):

    C:\WINDOWS\$N72CA~1\kab.*

    • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
    • The fix will run then HijackThis will open.
    • In HiJackThis, please place a check next to the following items and click FIX CHECKED:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\$N72CA~1\bak.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O20 - Winlogon Notify: bak - C:\WINDOWS\$N72CA~1\bak.dll

    • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
    • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
    • Now please attach a new HJT log from normal mode.
     
    Last edited: Sep 30, 2005
  5. mskabialka

    mskabialka Private E-2

    This PC was new from Dell within the year, and has a valid Windows XP CD and key number.

    I have attached the hijack this log; the items in question seem to be gone from the log, and no Winfixer or Ewido warnings (only the demo version) of virtumonde so far!

    So that leaves the Windows update problem, and another I forgot about until I rebooted; each time it reboots I get this Status Main error (screenshot attached), which may be from the Brother printer. I am fixing this PC at another location so do not have the printer attached.

    Thanks again
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're log is now clean. Have you tried Windows update after doing these fixes?

    Note: Both your Windows Update problem and Status Monitor problem for your printer are topics better discussed in the Software Forum.
     
  7. mskabialka

    mskabialka Private E-2

    Thanks so much for the help with removing WinFixer. I have tried Windows Update since the repair and have the same problem. I will follow your advice and post to the software forum for the other problems.
    Thanks again.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let me know how things go over there by posting back here with any status.

    You should also check out the below to help keep your system clean:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds