"Win Fixer"

B

Butterfly Bill

I somehow downloaded some thing that takes over my Internet Explorer
and demands that I click to download some thing called "Win Fixer". It
ignores my cancels and window closings, and I have to get Zone Alarm to
Stop All Intenet Activity to get it to stop doing popping up more and
more windows. It comes on a few minuutes after I have opens IE. How do
I get rid of this?

-Butterfly Bill
 
P

PA Bear

(This is quite lengthy. Please read it all before doing anything.)
Courtesy of MVP Jim Byrd:

<paste>
Six approaches to removing Winfixer (Vundo). Not all will work on all
variants. It's suggested that you try them in this order.

1 - Feedback from users reports that the Removal Tool here is the most
effective against what is currently the most common variety of this
'malware':
http://forums.mcafeehelp.com/viewtopic.php?t=57049

2 - Symantec has a new Vundo remover:
http://securityresponse.symantec.com/avcenter/FixVundo.exe
http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.removal.tool.html
http://securityresponse.symantec.com/avcenter/venc/data/adware.virtumonde.html#removalinstructions

3 - Courtesy of Dave Lipman:

"Download WinFixerFix.exe from the URL --
http://www.ik-cs.com/programs/virtools/WinFixerFix.exe

On the infected PC...

Execute; WinFixerFix.exe { Note: You must accept the default of
C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your FireWall to enable WGET.EXE to download the needed McAfee
related files.

Execute; c:\mcafee\clean.bat { or Double-click on 'Clean Link' in
c:\mcafee }

A final report in HTML format called C:\mcafee\ScanReport.HTML will be
generated. At the end of the scan, it will be displayed in your browser
(Opera, FireFox or Internet Explorer). It is suggested that you move the
report out of c:\mcafee before performing another scan. It would be a good
idea to scan in Safe Mode and in Normal Mode and save a copy of the HTML
report for each session."

4 - McAfee has a combined automated/manual removal procedure here:
http://vil.nai.com/vil/content/v_127690.htm

5 - Then, courtesy of MVP Suzi Turner and Mosaic1:

"Atribune, a guy in the forums, has a Vundo fix tool as well:

Instructions for use by user as posted in the SpywareWarrior forum:

'Please download VundoFix.exe to your desktop. Here's a link:

http://www.atribune.org/downloads/VundoFix.exe

Double-click VundoFix.exe to extract the files
This will create a VundoFix folder on your desktop.
After the files are extracted, please restart your computer into Safe Mode.

Once in safe mode open the VundoFix folder and double-click on KillVundo.bat

A command window will open and it should look like this:

VundoFix V2.1 by Atri
By pressing enter you agree that you are using this at your own risk

At this point press enter one time.

Next you will see:

Type in the filepath as instructed by the forum staff
Then Press Enter, to continue with the fix.

At this point please type the following file path (make sure to enter it
exactly as below!):
C:\WINDOWS\system32\geeby.dll

Press Enter.

Next you will see:

Please type in the second filepath as instructed by the forum staff

At this point please type the following file path (make sure to enter it
exactly as below!):
C:\WINDOWS\system32\ybeeg.*

Press Enter to continue.

The fix will run then HijackThis will open.
In HijackThis, please place a check next to the following items and click
FIX CHECKED:

O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} -
C:\WINDOWS\system32\geeby.dll
O20 - Winlogon Notify: geeby - C:\WINDOWS\system32\geeby.dll

After you have fixed these items, close Hijackthis.

The fix will tell you to shutdown using the Power button. Hold in your power
button until the computer shuts down. Wait about 15 seconds and then restart
the computer into regular windows.

Chkdsk will run. This is normal. It will take a few minutes and is checking
your file system because of the Bad Shutdown we caused.

Go for free online Virus scans here:

http://housecall.trendmicro.com/housecall/start_corp.asp
http://www.pandasoftware.com/activescan/

Allow them to clean

Panda will have the option to create a log after the scan has finished.
Click
the See Report button. Then click the save Report button. It will be saved
under the name activescan.txt Do that and post that log into your next reply
here.

Run hijackthis and post the new log and the vundofix.txt file from the
vundofix folder into as well.'

The forum helpers have reported this fix from Atribune works. I don't know
about the Symantec tool.

If you'd like to join Spyware Warrior, you could see the thread where the
helpers are discussing this.
Suzi"

Note: Here's some added info relative to the above courtesy of MVP Steve
Wechsler (akaMowGreen):

"the .dll's file name :

C:\WINDOWS\system32\geeby.dll

will be different on different systems. What you can do to identify it
is to scan the system with HijackThis and look at the O2 BHO and/or O20
Winlogon entries to find out it's name. Close all other programs and
browsers prior to scanning with HJT. REMEMBER that there is a hidden file
that will have the name of the .dll spelled backwards. Enter that name when
the VundoFix requests the path to the second file.

6 - Grinler, (Lawrence Abrams, a Security MVP), has another removal method
that can be used if the recommended method fails :
http://www.bleepingcomputer.com/forums/topic18610.html"

Here's the HijackThis info you may need:

Download HijackThis, free, here:
http://209.133.47.200/~merijn/files/HijackThis.exe (Always download a new
fresh copy of HijackThis [and CWShredder also] - It's UPDATED frequently.)
You may also get it here if that link is blocked:
http://www.majorgeeks.com/downloadget.php?id=3155&file=3&evp=3304750663b552982a8baee6434cfc13

There's a good "How-to-Use" tutorial here:
http://computercops.biz/HijackThis.html

In Windows Explorer, click on Tools|Folder Options|View and check "Show
hidden files and folders" and uncheck "Hide protected operating system
files". (You may want to restore these when you're all finished with
HijackThis.)

Place HijackThis.exe or unzip HijackThis.zip into its own dedicated folder
at the root level such as C:\HijackThis (NOT in a Temp folder or on your
Desktop), reboot to Safe mode, start HT then press Scan. Click on SaveLog
when it's finished which will create hijackthis.log. Now click the Config
button, then Misc Tools and click on Generate StartupList.log which will
create Startuplist.txt

Then go to one of the following forums:

Spyware and Hijackware Removal Support, here:
http://forums.spywareinfo.com/
or Jim Eshelman's site here: http://forum.aumha.org/
or Bleepingcomputer here: http://www.bleepingcomputer.com/
or Computer Cops here: http://www.computercops.biz/forums.html
or Tom Coyote here: http://forums.tomcoyote.org/index.php?act=idx
or Net-Integration here: http://net-integration.us/forums/index.php

Register if necessary, then sign in and READ THE DIRECTIONS at the beginning
of the particular site's HiJackThis forum, then copy and paste both files
into a message asking for assistance, Someone will answer with detailed
instructions for the removal of your parasite(s). Be sure you include at
the beginning of your post a description of "What specific
problem(s)/symptoms you're trying to solve" and "What steps you've already
taken."

*******
ONLY IF you've successfully eliminated the malware, you can now make a new,
clean Restore Point and delete any previously saved (possibly infected)
ones. The following suggested approach is courtesy of Gary Woodruff: For XP
you can run a Disk Cleanup cycle and then look in the More Options tab. The
System Restore option removes all but the latest Restore Point. If there
hasn't been one made since the system was cleaned you should manually create
one before dumping the old possibly infected ones.
*******

You probably should consider switching to Sun Java J2SE 5.0 JRE or later
here: http://java.sun.com/j2se/1.5.0/download.jsp (What I use, BTW),
especially since MS will apparently no longer be distributing Java or
providing any support for Java including security fixes after Dec 31, 2007.
BE SURE that you uninstall any prior versions of Sun Java as some,
specifically JRE v. 1.4.2_03, contain a security bug which certain malware,
notably Winfixer/Vundo, are suspected of exploiting. If you did have this
version of Sun Java, JRE v. 1.4.2-03, installed, please post back and tell
us.

When you get things cleaned up, take a look at my Blog, Defending Your
Machine, addy in my Signature below, for some additional curative and
preventive measures you might want to implement to help prevent this type of
thing in the future.
~~
Regards, Jim Byrd, MS-MVP/DTS/AH-VSOP
My Blog, Defending Your Machine, here:
http://DefendingYourMachine.blogspot.com/

</paste>
 
S

SharonS

Use this removal tool for winfixer only run it in safe
mode. If it does not work then you need to run hijackthis and post a log
file. Send your log file to the group listed below as the people here will
freak-out if they see a hjt log file posted here.


Removal Tool - Adware-Virtumundo/WinFixer Popups
http://forums.mcafeehelp.com/viewtopic.php?t=57049
 
B

Butterfly Bill

PA Bear said:
(This is quite lengthy. Please read it all before doing
anything.) Courtesy of MVP Jim Byrd:

<paste>
Six approaches to removing Winfixer (Vundo). Not all will work on
all variants. It's suggested that you try them in this order.

1 - Feedback from users reports that the Removal Tool here is the
most effective against what is currently the most common variety
of this 'malware':
http://forums.mcafeehelp.com/viewtopic.php?t=57049

This one told me that it "wasn't detected"


This one also said it didn't detect it

3 - Courtesy of Dave Lipman:

"Download WinFixerFix.exe from the URL --
http://www.ik-cs.com/programs/virtools/WinFixerFix.exe

On the infected PC...

Execute; WinFixerFix.exe { Note: You must accept the default of
C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow
WGET.EXE to go through your FireWall to enable WGET.EXE to
download the needed McAfee related files.

Execute; c:\mcafee\clean.bat { or Double-click on 'Clean Link'
in c:\mcafee }

A final report in HTML format called C:\mcafee\ScanReport.HTML
will be generated. At the end of the scan, it will be displayed
in your browser (Opera, FireFox or Internet Explorer). It is
suggested that you move the report out of c:\mcafee before
performing another scan. It would be a good idea to scan in Safe
Mode and in Normal Mode and save a copy of the HTML report for
each session."

This one made the computer go beep, then briefly display the DOS prompt
window for a flashing second, then nothing. How long is this supposed
to take? I never saw any browser window after a minute or two.

4 - McAfee has a combined automated/manual removal procedure here:
http://vil.nai.com/vil/content/v_127690.htm

5 - Then, courtesy of MVP Suzi Turner and Mosaic1:

"Atribune, a guy in the forums, has a Vundo fix tool as well:

Instructions for use by user as posted in the SpywareWarrior
forum:

'Please download VundoFix.exe to your desktop. Here's a link:

http://www.atribune.org/downloads/VundoFix.exe

Double-click VundoFix.exe to extract the files
This will create a VundoFix folder on your desktop.
After the files are extracted, please restart your computer into
Safe Mode.

How do you start it in safe mode? The instructions in the Help menu say
to wait for the message "Please select the operating system to startm
and then press F8", but no such message appears.

I know I have the damn thing, even tho the "fixes" tell me I don't.

-Butterfly Bill
 
S

SharonS

Just updated to detect the new variant.Version 1.5. Use this removal tool
for winfixer
only run it in safe mode. If it does not work then run hijackthis and send a
log file to the group listed below. The people in this group will freak-out
if they see a hjt log posted here.


Removal Tool - Adware-Virtumundo/WinFixer Popups
http://forums.mcafeehelp.com/viewtopic.php?t=57049
 
P

Plato

Butterfly said:
I somehow downloaded some thing that takes over my Internet Explorer
and demands that I click to download some thing called "Win Fixer". It

Next time NEVER download or install ANY app that claims to fix ANY
windows problems automagically.
 
B

Butterfly Bill

Jim Byrd said:
Hi Bill - Getting into Windows Safe Mode:
http://www.computerhope.com/issues/chsafe.htm

I press F8, and get not the "Windows Advanced Options Menu" described
therein, but "Select First Boot Device". It goes on to boot apparently
normally (no "Safe Mode" in the corners), no matter what I pick
(Floppy, IDE-O (whatever this is), CDROM, or Network).

I have XP Home Edition, Version 2002, Srevice Pack 2,
Serial # 55277-OEM-0051393-92410

-BB
 
B

Butterfly Bill

Plato said:
Next time NEVER download or install ANY app that claims to fix ANY
windows problems automagically.

I did not tell my computer to download it. I saw my ZoneAlarm window go
crazy and told it to stop all internat access as fast as I could. Yes,
I go for the X on all those kinds of popup windows. But this one
ignored all my cancels and continued even after I had Xed.

Where I think it got in is: I was looking at the contents of my inbox
on the web-mail page of isp.com, as is my habit before I download
anything to my own computer (Tulsa Ballet sends me unsolicited ads with
PDF attachments of MB size, for instance). I told the web-mail window
to display the contents, and that's when the feces impacted the
ventilator. It got in thru the Internet explorer between my legs.

My temporary, and perhaps permanent, solution to the problem today has
been to use Mozilla. It is not affected, nor is Xnews, nor Outlook
Express.

-BB
 
D

David H. Lipman

From: "Butterfly Bill" <[email protected]>

|
| I press F8, and get not the "Windows Advanced Options Menu" described
| therein, but "Select First Boot Device". It goes on to boot apparently
| normally (no "Safe Mode" in the corners), no matter what I pick
| (Floppy, IDE-O (whatever this is), CDROM, or Network).
|
| I have XP Home Edition, Version 2002, Srevice Pack 2,
| Serial # 55277-xxxxxxxxxxxxxxxxxxxxxxxx
|
| -BB

You got into the platform's BIOS boot routines which happen PRIOR to loading the OS and the
OS Safe Mode.

What are you doing posting a Serial Number -- it isn't needed here and posting this data is
in fact a BIG mistake.
 
D

David H. Lipman

From: "Butterfly Bill" <[email protected]>

|
| What is "hijackthis"?
|
| -BB

HiJack This! (HJT) is a program that captures technical aspects of the operating system,
running processes and installed software. It is used to help diagnose malware that software
has problem detecting and or removing. HJT creates a log file with pertinent technical
aspects of the system. You then go to an expert forum and post the log file there and it
will be analyzed by recognized experts.

Download HiJack This! -- http://www.merijn.org/files/hijackthis.zip

http://www.spywareinfo.com/~merijn/

Forums where you can get expert advice for HiJack This! (HJT) logs.
NOTE: Registration is REQUIRED before posting a log
NOTE: Web sites NOT listed in any particular order

http://aumha.net/viewforum.php?f=30
http://www.bleepingcomputer.com/forums/forum22.html
http://www.dslreports.com/forum/security
http://castlecops.com/forum67.html
http://www.wilderssecurity.com/forumdisplay.php?f=24
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://forum.iamnotageek.com/f-130.html
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://boards.cexx.org/viewforum.php?f=1
http://www.malwarebytes.biz/forums/index.php?showforum=5

{ borrowed from the alt.privacy.spyware News Group }
 
U

Uncle Joe

Butterfly Bill said:
I press F8, and get not the "Windows Advanced Options Menu" described
therein, but "Select First Boot Device". It goes on to boot apparently
normally (no "Safe Mode" in the corners), no matter what I pick
(Floppy, IDE-O (whatever this is), CDROM, or Network).

I have XP Home Edition, Version 2002, Srevice Pack 2,
Serial # XXXX-OEM-XXXXXX-XXXXX

-BB

For God's sake--and yours--don't EVER publish serial numbers
in a newsgroup or on the Internet! Very bad practice. Nobody
needs to know your serial numbers except you and the appropriate
software vendors. Good luck with your problem. WinFixer is a
miserable piece of software s**t and its author(s) belong in prison.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top