03-30-2006, 06:45 PM | #1 (permalink) |
WaterDog
|
Winfixer, Virtumonde
where the heck do i keep getting this from? i got rid of it afew weeks ago and it's back.... it's pissing me off, i havn't downloaded any files recently, just browsing forums mostly... macafee is on full throttle, i have it set to alert me with everything, the macafeee popups let me approve or decline all cookies...
this is really making me mad, i can't get rid of it anyone know if this might be linked to images displayed on forums or links with putfile.com or anything like that?
__________________
...AquaFox... |
03-31-2006, 12:55 AM | #2 (permalink) |
Crazy
Location: PA
|
heh, the last time I tried to remove winfixer, I ended up reformatting, however after a search there appears to be a couple utilities to remove this program. You said McAfee is on full throttle, is it a complete internet security, or just anti-virus? If it's just AV, it won't stop things like winfixer from getting on your machine.
Try downloading this and see if it helps for WinFixer: http://winfixerremovers.org/?gclid=C...A2k64Q#compare Or try this link here: http://www.bleepingcomputer.com/forums/topic18610.html A quick overview shows step by step instructions for removing that garbage. Good luck! |
03-31-2006, 08:08 AM | #3 (permalink) |
WaterDog
|
macafee has virus, firewall, and privacy services
i think i got rid of it with the one free download, it's been a half an hour and no sign soo soo far soo good when i scan my entire hard drive with macafee or adaware, it tends to get hung up on certain files and will not fully scan it, i've let it sit overnight with it still getting stuck... i think i might need to reflormat sooner or later too
__________________
...AquaFox... |
03-31-2006, 10:02 AM | #4 (permalink) |
beauty in the breakdown
Location: Chapel Hill, NC
|
Look in the registry, in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify. If you have a key in there that is 5 letters long, usually with at least on character that is repeated once (but NOT cscdll), that is the file that's causing you so much trouble. But here's the trick--because it is part of the winlogon process, you can't delete it from Windows, even in safe mode. Boot using Knoppix or something like that and delete the file by that name (whatever.dll) from C:\Windows\System32. Then reboot into windows and remove that registry key.
Virtumonde is a sonofabitch. We see it all the time at work.
__________________
"Good people do not need laws to tell them to act responsibly, while bad people will find a way around the laws." --Plato |
03-31-2006, 10:58 AM | #5 (permalink) | |
WaterDog
|
Quote:
the little removal tool i got seemed to have removed it, i don't see any other 5 letter folder things listed in that folder other than cscdll does anyone know where this bug comes from? all i've downloaded recently was a couple WMV vids from putfile and other random uploaders
__________________
...AquaFox... |
|
03-31-2006, 11:36 PM | #6 (permalink) |
Go Cardinals
Location: St. Louis/Cincinnati
|
Whoever made that shit deserves a kick in the balls. I have fixed it off a couple friends computers, but let me say, it is the WORST virus i have seen thus far. I mean it is a pesky bitch that just doesn't give up.
__________________
Brian Griffin: Ah, if my memory serves me, this is the physics department. Chris Griffin: That would explain all the gravity. |
04-02-2006, 10:26 AM | #7 (permalink) | |
beauty in the breakdown
Location: Chapel Hill, NC
|
Quote:
__________________
"Good people do not need laws to tell them to act responsibly, while bad people will find a way around the laws." --Plato |
|
04-02-2006, 11:06 AM | #8 (permalink) |
Go Cardinals
Location: St. Louis/Cincinnati
|
The most annoying this is that on the computers that I fix, there are no anti-spyware programs installed, no anti-virus programs, they use internet explorer and about 3 different file-sharing applications.
__________________
Brian Griffin: Ah, if my memory serves me, this is the physics department. Chris Griffin: That would explain all the gravity. |
Tags |
virtumonde, winfixer |
|
|