Unsolved

This post is more than 5 years old

Community Manager

 • 

56.9K Posts

 • 

232.1K Points

18266

October 22nd, 2005 19:00

Vundo/WinFixer2005 Fix

(1)
* Run the VirtumundoBeGone.exe tool
* Click Save- Desktop- Save
* Close all running programs (including your Internet Browser)
* Double-click VirtumundoBeGone.exe on the desktop
* Click Run if asked
(If you get a blue screen error, just reboot)
* Click Start
* Click Yes

(2)
* Run the FixVundo tool
* Click Save- Desktop- Save
* Close all running programs (including your Internet Browser)
* Double-click FixVundo.exe on the desktop
* Click Run if asked
* Click Start
Important: Do not launch any new applications while the tool is running!
* When finished, click Start. The result will be displayed
* Click OK to close the box
* When finished, restart the computer
* Run the removal tool again and restart the system to ensure that the system is clean. Then, run your virus checker

Message Edited by DELL-ChrisM on 11-11-2005 12:15 PM


DELL-Chris M (old account)

#IWork4Dell

November 11th, 2005 17:00

Am I suppose to follow these directions to fix the WinFixer 2005 virus? I am not too good with computers, so sorry to bother you.
Sincerely,
 Jennifer

3 Posts

November 11th, 2005 17:00

all I can say is that one of my staff followed the directions and it worked. The staff is not an expert.

3 Posts

November 14th, 2005 22:00

Chris,

I used your method of removing the winfixer problem.  I can't thank you enough.  The blue screen freaked me out at the end though.  So I rebooted the machine and the MS event object was gone.  I ran MS AntiSpyware and it couldn't find it again.  I also ran the McAfee  virus scan too.  Negative results.

Now how do I pervent it from happening again?  I think one of my kids caused it accidently. 

1 Message

November 15th, 2005 02:00

Through an error in the spyware, I was able to obtain an IP address for malicious code that I think is a part of Winfixer/Virtumondo. The IP address is 202.67.220.227 - registered to
mntner:       MAINT-HKNET-NT
upd-to:       dnstech@hknet.com
upd-to:       ray@hknet.com
descr:        Maintainer of HKNet
admin-c:      DA56-AP
tech-c:       RC429-AP
referral-by:  APNIC-HM
auth:         CRYPT-PW apE1Rklobh1.g
changed:      mfcho@hknet.com 20050103
mnt-by:       MAINT-HKNET-NT
source:       APNIC
person:       DNS Administrator
address:      15/F., Tower2, Ever Gain Plaza,
address:      88 Container Port Road,
address:      Kwai Chung, N.T.,
address:      Hong Kong
country:      HK
phone:        +852 2110 3663
fax-no:       +852 2110 9746
e-mail:       dnstech@hknet.com
nic-hdl:      DA56-AP
mnt-by:       MAINT-HKNET-NT
changed:      dnstech@hknet.com 20020725
source:       APNIC
person:       Ray Chan
nic-hdl:      RC429-AP
e-mail:       ray@hknet.com
address:      15/F
address:      Evergain Plaza II
address:      88 Container Port Road
address:      Kwai Chung
address:      N.T.
address:      Hong Kong
phone:        +852-2110-3388
fax-no:       +852-2110-0241
country:      HK
changed:      mfcho@hknet.com 20050103
mnt-by:       MAINT-NEW
source:       APNIC
Anybody have any ideas how to shut them down?

1 Message

November 15th, 2005 22:00

chris-

if this works, i'll have my mom send you a box of cookies.

seriously, this winfixer/vundo thing is getting ridiculous.  what makes this virus/spyware so tough to eliminate?  i've been dealing with this for about a week on my home computer, and i've thrown a bunch of antivirus programs at it, with no results, including trend's and microsoft's.  they find the viruses/spyware, say they removed them, but when i reboot and rescan, they are still there.  i can't believe that has been going on for months and the major antivirus companies haven't solved this attack yet.  is it because they mutate or hide in the registry where the antivirus software cannot get to?  i'm thankful that many expert individuals volunteer their time and talents helping us neophytes on a case by case basis to solve our problems, but what happens in the future when we get hit with dozens of these things at the same time?  how will we handle them then?  it's 2005, we spend good money on antivirus programs and operating systems, and i can't do a simple thing like get on my computer at home and access the internet because of a virus that's been around for months and can't remove after trying with at least 4 different antivirus programs.  if this isn't a wakeup call, i don't know what it.

by the way, when i go home tonight to try your solutions, should i run them in safe or regular mode?  does it make a difference?

thanks again

terry 

November 16th, 2005 05:00

Chris, I just want to thank you so much for the directions to get rif of the winfixer2005. My computer is working super well right now...THANKSSS!!!!!!!!!!!!!!!
Sincerely,
 Vi4jenn

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 16th, 2005 18:00

apofreak:
 
by its very design, VirtumundoBeGone is expected to generate a " BLUE SCREEN error"... a.k.a, BLUE SCREEN OF DEATH error/crash.   What happened after you rebooted the system?   are you still getting the WinFixer popups? ---- or have they stopped?   the best thing for you to do now is to start a new thread of your own, here in the HiJackThis forum, and post both your VirtumundoBeGone log, as well as your HiJackThis log.

 

Message Edited by ky331 on 11-16-2005 05:13 PM

1 Message

November 16th, 2005 18:00

Hi, I'm a WinFix victim and am going nuts with this evil thing. I followed the directions at the beginning of this thread but upon running VirtumundoBeGone.exe my computer froze... I rebooted and the next time I ran it, the whole screen went blank and gave me a dos message of a fatal error, system shut down, etc.  Why would this VirtumundoBeGone.exe work for some but crash mine ? And what else can I do to get rid of this evil spyware ?

5 Posts

November 16th, 2005 19:00

Hi,
I have followed your instructions to clear winfixer 2005 (at least Norton, MS antispyware and ewido have told me so). However, whenever I start my computer, there is a popup windows saying Winfixer 2005 service is currently not available. How can I get rid of this please?
Thanks

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 16th, 2005 19:00

there are several different versions/variations of WInFixer.  by far, the most common type is based on a Vundo/Virtumundo trojan, and in these cases, VirtumundoBeGone has been tremendously successful.
 
However, there are at least three other "types" of WinFixer problems:  
the various "installers", SurfAccuracy, and the yet-undermined ("stealth") versions. 
If you have one of these alternative versions, the ONLY way for you to proceed is to generate and post a HiJackThis log, starting a new thread of your own, in the HiJackThis forum.

3 Posts

November 16th, 2005 19:00

This is the read out when I ran the fix for virtumondo/winfixer problem

- Starting Process...
[11/14/2005, 18:24:32] - Looking for Browser Helper Object [MSEvents Object]
[11/14/2005, 18:24:32] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/14/2005, 18:24:32] - 2: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess
[11/14/2005, 18:24:32] - 3: {B313D637-F405-4052-AC37-E2119AB3C8F8} - MSEvents Object
[11/14/2005, 18:24:32] - Found MSEvents Object!
[11/14/2005, 18:24:32] - File location: C:\WINDOWS\system32\awvvs.dll
[11/14/2005, 18:24:32] - Attempting to kill C:\WINDOWS\system32\awvvs.dll
[11/14/2005, 18:24:32] - Terminating Process: RUNDLL32.EXE
[11/14/2005, 18:24:32] - Terminating Process: IEXPLORE.EXE
[11/14/2005, 18:24:32] - Disabling Automatic Shell Restart
[11/14/2005, 18:24:32] - Terminating Process: EXPLORER.EXE
[11/14/2005, 18:24:33] - Suspending the NT Session Manager System Service
[11/14/2005, 18:24:33] - Terminating Windows NT Logon/Logoff Manager
[11/14/2005, 18:24:33] - Re-enabling Automatic Shell Restart
[11/14/2005, 18:24:33] - Renaming C:\WINDOWS\system32\awvvs.dll -> C:\WINDOWS\system32\awvvs.dll.vir
[11/14/2005, 18:24:33] - File successfully renamed!
[11/14/2005, 18:24:33] - Removing Registry references to {B313D637-F405-4052-AC37-E2119AB3C8F8}
[11/14/2005, 18:24:33] - Adding Internet Explorer Protection (Kill ActiveX) for {B313D637-F405-4052-AC37-E2119AB3C8F8}
[11/14/2005, 18:24:33] - Removing Winlogon Notify Entry: awvvs
[11/14/2005, 18:24:33] - BHO list has been changed! Starting over...
[11/14/2005, 18:24:33] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/14/2005, 18:24:33] - 2: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess
[11/14/2005, 18:24:33] - Finished searching for [MSEvents Object]
[11/14/2005, 18:24:33] - Finishing up...
[11/14/2005, 18:24:33] - Enabling Automatic Reboot on STOP Error.
[11/14/2005, 18:24:33] - Attempting to Restart via STOP error (Blue Screen!)

I am so glad this thing is gone!


 

November 16th, 2005 20:00

Hi. I have winfixer 2005....it is HORRIBLE!!!! I really want to use this method, because everyone says it works...but I am afraid that I will lose data....My computer loses data easily, and if I do this, will I lose anything?
 
 

November 16th, 2005 22:00

I'm having a hard time getting rid of this thing also.....I've tried the advice but I couldn't locate the exact files listed... I found some similiar but not the ones listed
Heres the reads
 
Logfile of HijackThis v1.99.1
Scan saved at 4:13:08 PM, on 11/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\cmd.exe
C:\Documents and Settings\Shana Wickersham\Desktop\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Bho - {27704612-ACFC-4349-8429-B765B25CCB24} - C:\WINDOWS\system32\gpcwypwj.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: PAVWAIT.DLL
O20 - Winlogon Notify: awvtq - C:\WINDOWS\system32\awvtq.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Panda PAVFNSVR (PAVFNSVR) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PavFnSvr.exe
O23 - Service: Panda PAVPROT (PAVPROT) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavprot.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavsrv51.exe
O23 - Service: Panda Preventium+ Service (PREVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\Prevsrv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
 

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 17th, 2005 01:00

WinfixerKiller
 
I've taken the liberty of re-posting your log here:
 
 
it's rather late here now... if no one else gets there first, i'll do my best to reply there tomorrow.
 
 
To everyone else reading this thread:
 
The purpose of this thread was to inform the community of a general fix that could be applied to this problem.   If you need more individualized help,  you should start a NEW thread of your own, in the HiJackThis forum.  
 
Please do *NOT* post any more HiJackThis logs in this particular thread.  

Message Edited by ky331 on 11-16-2005 11:29 PM

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 17th, 2005 01:00

sprite

i don't know why your computer "loses data" (easily or otherwise)... trying this fix (other than the scare of seeing the BLUE SCREEN crash) should not lose any data (unless you're "losing" it anyway, by some other means).  

you can try this fix, if you wish... OR if you want to play-it extra-safe, generate and post your HiJackThis log, starting a separate thread of your own.   by doing so, we can check your log, to determine precisely which version of WinFixer you have, and advise you accordingly.

No Events found!

Top