Unsolved
This post is more than 5 years old
Community Manager
•
56.9K Posts
•
232.1K Points
0
18266
October 22nd, 2005 19:00
Vundo/WinFixer2005 Fix
(1)
* Run the VirtumundoBeGone.exe tool
* Click Save- Desktop- Save
* Close all running programs (including your Internet Browser)
* Double-click VirtumundoBeGone.exe on the desktop
* Click Run if asked
(If you get a blue screen error, just reboot)
* Click Start
* Click Yes
(2)
* Run the FixVundo tool
* Click Save- Desktop- Save
* Close all running programs (including your Internet Browser)
* Double-click FixVundo.exe on the desktop
* Click Run if asked
* Click Start
Important: Do not launch any new applications while the tool is running!
* When finished, click Start. The result will be displayed
* Click OK to close the box
* When finished, restart the computer
* Run the removal tool again and restart the system to ensure that the system is clean. Then, run your virus checker
* Run the VirtumundoBeGone.exe tool
* Click Save- Desktop- Save
* Close all running programs (including your Internet Browser)
* Double-click VirtumundoBeGone.exe on the desktop
* Click Run if asked
(If you get a blue screen error, just reboot)
* Click Start
* Click Yes
(2)
* Run the FixVundo tool
* Click Save- Desktop- Save
* Close all running programs (including your Internet Browser)
* Double-click FixVundo.exe on the desktop
* Click Run if asked
* Click Start
Important: Do not launch any new applications while the tool is running!
* When finished, click Start. The result will be displayed
* Click OK to close the box
* When finished, restart the computer
* Run the removal tool again and restart the system to ensure that the system is clean. Then, run your virus checker
Message Edited by DELL-ChrisM on 11-11-2005 12:15 PM
DELL-Chris M (old account)
#IWork4Dell
No Events found!


vi4jennifer
3 Posts
0
November 11th, 2005 17:00
dhkennedy
3 Posts
0
November 11th, 2005 17:00
der Kaiser
3 Posts
0
November 14th, 2005 22:00
Chris,
I used your method of removing the winfixer problem. I can't thank you enough. The blue screen freaked me out at the end though. So I rebooted the machine and the MS event object was gone. I ran MS AntiSpyware and it couldn't find it again. I also ran the McAfee virus scan too. Negative results.
Now how do I pervent it from happening again? I think one of my kids caused it accidently.
smilenow
1 Message
0
November 15th, 2005 02:00
terrytheman
1 Message
0
November 15th, 2005 22:00
chris-
if this works, i'll have my mom send you a box of cookies.
seriously, this winfixer/vundo thing is getting ridiculous. what makes this virus/spyware so tough to eliminate? i've been dealing with this for about a week on my home computer, and i've thrown a bunch of antivirus programs at it, with no results, including trend's and microsoft's. they find the viruses/spyware, say they removed them, but when i reboot and rescan, they are still there. i can't believe that has been going on for months and the major antivirus companies haven't solved this attack yet. is it because they mutate or hide in the registry where the antivirus software cannot get to? i'm thankful that many expert individuals volunteer their time and talents helping us neophytes on a case by case basis to solve our problems, but what happens in the future when we get hit with dozens of these things at the same time? how will we handle them then? it's 2005, we spend good money on antivirus programs and operating systems, and i can't do a simple thing like get on my computer at home and access the internet because of a virus that's been around for months and can't remove after trying with at least 4 different antivirus programs. if this isn't a wakeup call, i don't know what it.
by the way, when i go home tonight to try your solutions, should i run them in safe or regular mode? does it make a difference?
thanks again
terry
vi4jennifer
3 Posts
0
November 16th, 2005 05:00
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
November 16th, 2005 18:00
Message Edited by ky331 on 11-16-2005 05:13 PM
apofreak
1 Message
0
November 16th, 2005 18:00
biancopet
5 Posts
0
November 16th, 2005 19:00
I have followed your instructions to clear winfixer 2005 (at least Norton, MS antispyware and ewido have told me so). However, whenever I start my computer, there is a popup windows saying Winfixer 2005 service is currently not available. How can I get rid of this please?
Thanks
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
November 16th, 2005 19:00
der Kaiser
3 Posts
0
November 16th, 2005 19:00
This is the read out when I ran the fix for virtumondo/winfixer problem
- Starting Process...
[11/14/2005, 18:24:32] - Looking for Browser Helper Object [MSEvents Object]
[11/14/2005, 18:24:32] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/14/2005, 18:24:32] - 2: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess
[11/14/2005, 18:24:32] - 3: {B313D637-F405-4052-AC37-E2119AB3C8F8} - MSEvents Object
[11/14/2005, 18:24:32] - Found MSEvents Object!
[11/14/2005, 18:24:32] - File location: C:\WINDOWS\system32\awvvs.dll
[11/14/2005, 18:24:32] - Attempting to kill C:\WINDOWS\system32\awvvs.dll
[11/14/2005, 18:24:32] - Terminating Process: RUNDLL32.EXE
[11/14/2005, 18:24:32] - Terminating Process: IEXPLORE.EXE
[11/14/2005, 18:24:32] - Disabling Automatic Shell Restart
[11/14/2005, 18:24:32] - Terminating Process: EXPLORER.EXE
[11/14/2005, 18:24:33] - Suspending the NT Session Manager System Service
[11/14/2005, 18:24:33] - Terminating Windows NT Logon/Logoff Manager
[11/14/2005, 18:24:33] - Re-enabling Automatic Shell Restart
[11/14/2005, 18:24:33] - Renaming C:\WINDOWS\system32\awvvs.dll -> C:\WINDOWS\system32\awvvs.dll.vir
[11/14/2005, 18:24:33] - File successfully renamed!
[11/14/2005, 18:24:33] - Removing Registry references to {B313D637-F405-4052-AC37-E2119AB3C8F8}
[11/14/2005, 18:24:33] - Adding Internet Explorer Protection (Kill ActiveX) for {B313D637-F405-4052-AC37-E2119AB3C8F8}
[11/14/2005, 18:24:33] - Removing Winlogon Notify Entry: awvvs
[11/14/2005, 18:24:33] - BHO list has been changed! Starting over...
[11/14/2005, 18:24:33] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
[11/14/2005, 18:24:33] - 2: {5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess
[11/14/2005, 18:24:33] - Finished searching for [MSEvents Object]
[11/14/2005, 18:24:33] - Finishing up...
[11/14/2005, 18:24:33] - Enabling Automatic Reboot on STOP Error.
[11/14/2005, 18:24:33] - Attempting to Restart via STOP error (Blue Screen!)
I am so glad this thing is gone!
spriteandcola
6 Posts
0
November 16th, 2005 20:00
WinfixerKiller
1 Message
0
November 16th, 2005 22:00
Scan saved at 4:13:08 PM, on 11/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\cmd.exe
C:\Documents and Settings\Shana Wickersham\Desktop\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Bho - {27704612-ACFC-4349-8429-B765B25CCB24} - C:\WINDOWS\system32\gpcwypwj.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: PAVWAIT.DLL
O20 - Winlogon Notify: awvtq - C:\WINDOWS\system32\awvtq.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Panda PAVFNSVR (PAVFNSVR) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PavFnSvr.exe
O23 - Service: Panda PAVPROT (PAVPROT) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavprot.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavsrv51.exe
O23 - Service: Panda Preventium+ Service (PREVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\Prevsrv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
November 17th, 2005 01:00
Message Edited by ky331 on 11-16-2005 11:29 PM
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
November 17th, 2005 01:00
sprite
i don't know why your computer "loses data" (easily or otherwise)... trying this fix (other than the scare of seeing the BLUE SCREEN crash) should not lose any data (unless you're "losing" it anyway, by some other means).
you can try this fix, if you wish... OR if you want to play-it extra-safe, generate and post your HiJackThis log, starting a separate thread of your own. by doing so, we can check your log, to determine precisely which version of WinFixer you have, and advise you accordingly.