Bundleware . WinFixer 2005 (Summary)
Software Name: WinFixer 2005
Company Name:
Product Name: WinFixer 2005
Classification: Bundleware
Website: http://www.winfixer.com
Brief:
Can come silently installed and detects false threats to entice end-users to purchase the software.
IMPORTANT!
Some of the Bundleware.WinFixer 2005 components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of WinFixer 2005
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
WinFixer 2005 might create following folders (and inject its files inside
the folders):
- %COMMON_PROGRAMS%\WinFixer 2005
- %PROGRAM_FILES_COMMON%\WinSoftware
- %PROGRAM_FILES%\WinFixer 2005
- %APPDATA%\WinSoftware
- %COMMON_APPDATA%\WinSoftware
- %COMMON_APPDATA%\WinSoftware\WinAntiVirus*
- %COMMON_PROGRAMS%\WinAntiVirus 200*
- %COMMON_PROGRAMS%\WinFixer*
- %APPDATA%\WinSoftware\WinAntiVirus*
- %PROGRAM_FILES_COMMON%\WinAntiVirus*
- %PROGRAM_FILES%\WinFixer*
- %PROGRAM_FILES%\WinAntiVirus*
- %PROGRAM_FILES%\WinFixer_200*
- %PROGRAM_FILES%\*WinFixer*
- %PROGRAM_FILES%\*WinFixer*200*
WinFixer 2005 might create following files (some of the files might be
loaded in memory while the software is running):
- %PROFILE%\Local Settings\Temp\WinFixer2005ScannerSetup.exe
- %PROGRAM_FILES%\WinFixer 2005\Install.exe
- %PROGRAM_FILES%\WinFixer 2005\sr.exe
- %PROGRAM_FILES%\WinFixer 2005\Updater.exe
- %PROGRAM_FILES%\WinFixer 2005\WFX5.exe
- %SYSTEM%\df_kme.exe
- %SYSTEM%\drivers\df_kmd.sys
- %WINDOWS%\Downloaded Program Files\UWFX5R*.exe
- %WINDOWS%\Downloaded Program Files\*\UWA5*.exe
- %DESKTOP%\Install WinAntiVirus*.lnk
- %DESKTOP%\WinAntiVirus*.lnk
- %DESKTOP%\WinFixer*.lnk
- %PROFILE%\Local Settings\Temp\UWA5PNetInstaller.exe
- %PROFILE%\Local Settings\Temp\UWFX5LP*.exe
- %PROFILE%\Local Settings\Temp\WinAntiVirus*.exe
- %PROFILE%\Local Settings\Temp\WINAVInstaller.log
- %PROFILE%\Local Settings\Temp\WinFixer*.exe
- %PROGRAM_FILES_COMMON%\WinSoftware\CrXML.dll
- %PROGRAM_FILES_COMMON%\WinSoftware\PCheck.dll
- %PROGRAM_FILES_COMMON%\WinSoftware\VapFM.exe
- %PROGRAM_FILES_COMMON%\WinSoftware\VAPSpy.sys
- %PROGRAM_FILES%\WinAntiVirus 2005 Trial\*.*
- %PROGRAM_FILES%\WinFixer 200*\*.*
- %PROGRAM_FILES%\WinAntiVirus 2006\*.*
- %PROGRAM_FILES%\WinAntiVirus 2006 Trial\*.*
- %PROGRAM_FILES%\WinAntiVirus 2005\*.*
- %PROGRAM_FILES%\WinFixer200*\*.*
- %SYSTEM%\ssttu.dll
- %WINDOWS%\Downloaded Program Files\UWFX*Installer.exe
- %WINDOWS%\Downloaded Program Files\UWFX*.exe
- %PROGRAM_FILES%\WinFixer_200*\*.*
- %PROGRAM_FILES%\WinFixer*\*.*
- %SYSTEM%\nnnll.dll
WinFixer 2005 is often accompanied by the following tracking cookies:
- *.winantivirus.com
- *.winfixer.com
WinFixer 2005 might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\Interface\{B9DFCF32-B679-4CAD-B7FC-518A48CE3922}
- HKEY_CLASSES_ROOT\Interface\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
- HKEY_CLASSES_ROOT\Interface\{CBEEF194-EBC5-4758-9B51-AC34FC135E70}
- HKEY_CLASSES_ROOT\Interface\{CD3604CC-2B95-43EE-AFC9-E7444C21BE1C}
- HKEY_CLASSES_ROOT\Interface\{D21040FE-0A57-4FAB-8ED2-F0E653E55809}
- HKEY_CLASSES_ROOT\Interface\{D7A2488E-53E4-4EDD-AEAA-F24778BEB100}
- HKEY_CLASSES_ROOT\Interface\{D7A6DF8D-B6CF-4C27-8E99-ECA2CE370EA7}
- HKEY_CLASSES_ROOT\Interface\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
- HKEY_CLASSES_ROOT\Interface\{F6C1582E-B11C-4724-B8F6-240457EF1D2A}
- HKEY_CLASSES_ROOT\Interface\{FB787D5E-0C7C-4BAB-B45D-20325FB886DB}
- HKEY_CLASSES_ROOT\MMFixCtrl.CoFixEngine
- HKEY_CLASSES_ROOT\MMFixCtrl.CoFixEngine.1
- HKEY_CLASSES_ROOT\TypeLib\{0E9F6AC0-A21A-4591-910F-E2C6F3CA094C}
- HKEY_CLASSES_ROOT\TypeLib\{4DCEEA42-794D-4855-9ECC-20DCF5F4FEA7}
- HKEY_CLASSES_ROOT\TypeLib\{6A077841-5016-42C8-92C8-F2D6B865BCD1}
- HKEY_CLASSES_ROOT\TypeLib\{AD70AC89-F460-4E7E-B5A5-7EAF7E207736}
- HKEY_CLASSES_ROOT\TypeLib\{B6625280-8CD8-4632-97C0-83CEC12A49A3}
- HKEY_CLASSES_ROOT\TypeLib\{F458ADAE-D53B-4859-B99F-9FA127791278}
- HKEY_CLASSES_ROOT\TypeLib\{FC76A5B8-DB35-4F3E-8B9A-BF0EEA098D64}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WFX5_is1
- HKEY_LOCAL_MACHINE\SOFTWARE\WinSoftware
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\df_kmd.sys
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\df_kmd.sys
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\df_kmd
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\df_kmd
- HKEY_USERS\*\Software\WinSoftware
- HKEY_USERS\*\Software\WinSoftware\WinFixer 2005
- HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{F919FBD3-A96B-4679-AF26-F551439BB5FD}
- HKEY_CLASSES_ROOT\AppID\compcln.dll
- HKEY_CLASSES_ROOT\AppID\FFWraper.DLL
- HKEY_CLASSES_ROOT\AppID\FixCore.DLL
- HKEY_CLASSES_ROOT\AppID\MMFixCtrl.DLL
- HKEY_CLASSES_ROOT\AppID\{25A3C995-10C8-474B-A167-99460AB4AB2B}
- HKEY_CLASSES_ROOT\AppID\{287A2BAD-6590-4EFF-9BBC-494385664A73}
- HKEY_CLASSES_ROOT\AppID\{290B5B73-4963-4BA1-9D2D-07CB566CB7FA}
- HKEY_CLASSES_ROOT\AppID\{E8928E69-C050-42A9-8884-94DE85E888A2}
- HKEY_CLASSES_ROOT\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
- HKEY_CLASSES_ROOT\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
- HKEY_CLASSES_ROOT\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
- HKEY_CLASSES_ROOT\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
- HKEY_CLASSES_ROOT\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
- HKEY_CLASSES_ROOT\CLSID\{53ABACCB-434C-4756-A02B-8C2A3F29FB7D}
- HKEY_CLASSES_ROOT\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
- HKEY_CLASSES_ROOT\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
- HKEY_CLASSES_ROOT\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
- HKEY_CLASSES_ROOT\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
- HKEY_CLASSES_ROOT\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
- HKEY_CLASSES_ROOT\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
- HKEY_CLASSES_ROOT\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
- HKEY_CLASSES_ROOT\CLSID\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
- HKEY_CLASSES_ROOT\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
- HKEY_CLASSES_ROOT\CompCleanCore.AppCleaner
- HKEY_CLASSES_ROOT\CompCleanCore.AppCleaner.1
- HKEY_CLASSES_ROOT\CompCleanCore.CCQuickScan
- HKEY_CLASSES_ROOT\CompCleanCore.CCQuickScan.1
- HKEY_CLASSES_ROOT\CompCleanCore.FileCleaner
- HKEY_CLASSES_ROOT\CompCleanCore.FileCleaner.1
- HKEY_CLASSES_ROOT\CompCleanCore.InetCleaner
- HKEY_CLASSES_ROOT\CompCleanCore.InetCleaner.1
- HKEY_CLASSES_ROOT\CompCleanCore.RegCleaner
- HKEY_CLASSES_ROOT\CompCleanCore.RegCleaner.1
- HKEY_CLASSES_ROOT\CompCleanCore.SystemCleaner
- HKEY_CLASSES_ROOT\CompCleanCore.SystemCleaner.1
- HKEY_CLASSES_ROOT\df_fixer.Fixer
- HKEY_CLASSES_ROOT\df_fixer.Fixer.1
- HKEY_CLASSES_ROOT\df_proxy.DriverManipulate
- HKEY_CLASSES_ROOT\df_proxy.DriverManipulate.1
- HKEY_CLASSES_ROOT\FFCom.FlFixer
- HKEY_CLASSES_ROOT\FFWraper.FFEnginWraper
- HKEY_CLASSES_ROOT\FFWraper.FFEnginWraper.1
- HKEY_CLASSES_ROOT\FixCore.MMFixCore
- HKEY_CLASSES_ROOT\FixCore.MMFixCore.1
- HKEY_CLASSES_ROOT\Interface\{08C71FB1-1E66-4D22-9F32-4C045A451306}
- HKEY_CLASSES_ROOT\Interface\{1CE1C25B-F8B4-4974-99D2-5D4AE96B9900}
- HKEY_CLASSES_ROOT\Interface\{35096C29-3507-4ABE-B6D8-C7CC881BE020}
- HKEY_CLASSES_ROOT\Interface\{38F743A2-210F-49DE-9B79-DCD501CED284}
- HKEY_CLASSES_ROOT\Interface\{3EEC290D-FC13-4C83-803D-4802651EEB61}
- HKEY_CLASSES_ROOT\Interface\{41A5BBF6-3C9D-4CF9-9A99-32DD37CC290B}
- HKEY_CLASSES_ROOT\Interface\{4E4F38D9-8736-41AE-B192-E829AE194398}
- HKEY_CLASSES_ROOT\Interface\{66484903-09F4-4330-927D-1F6C214221AC}
- HKEY_CLASSES_ROOT\Interface\{7FA14AD6-D8E5-465F-9BD1-A37E26C1A74F}
- HKEY_CLASSES_ROOT\Interface\{9E984934-CD94-4763-9DBC-618E483D4B7F}
- HKEY_CLASSES_ROOT\Interface\{B115BD8E-B008-46F4-B8B6-3405EB325C3C}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtstt
- HKEY_CLASSES_ROOT\AntiVirus.AntiVirus
- HKEY_CLASSES_ROOT\AntiVirus.AntiVirus.1
- HKEY_CLASSES_ROOT\AntiVirusTrayCOM.AntiVirusTray
- HKEY_CLASSES_ROOT\AntiVirusTrayCOM.AntiVirusTray.1
- HKEY_CLASSES_ROOT\AppID\AntiVirus.DLL
- HKEY_CLASSES_ROOT\AppID\CheckProduct2.DLL
- HKEY_CLASSES_ROOT\AppID\Quarantine.EXE
- HKEY_CLASSES_ROOT\AppID\VapFM.EXE
- HKEY_CLASSES_ROOT\AppID\{406B7088-1E9D-48C4-B7B2-4FF9738997AB}
- HKEY_CLASSES_ROOT\AppID\{62B74DC2-2C6F-4DAE-9E39-FFFB8018C47B}
- HKEY_CLASSES_ROOT\AppID\{8C65AEF6-E413-4314-815B-82717A3F1603}
- HKEY_CLASSES_ROOT\AppID\{989ADB33-3EE9-4A36-8113-76D1B79B606B}
- HKEY_CLASSES_ROOT\AVExplorer.ExplorerAntiVirus
- HKEY_CLASSES_ROOT\AVExplorer.ExplorerAntiVirus.1
- HKEY_CLASSES_ROOT\AVLog.AntiVirusLog
- HKEY_CLASSES_ROOT\AVLog.AntiVirusLog.1
- HKEY_CLASSES_ROOT\AVScheduler.AVScheduler
- HKEY_CLASSES_ROOT\AVScheduler.AVScheduler.1
- HKEY_CLASSES_ROOT\CheckProduct2.CheckProduct
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinAntivirus
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVScheduler
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VAPSpy
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinAntivirus
- HKEY_USERS\*\Software\WinSoftware\WinAntiVirus 200*
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8DBF02DA-4360-4A7E-BEA1-347B87816327}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6DD0BC06-4719-4BA3-BEBC-FBAE6A448152}
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7697DB96-5DA3-44F2-BC97-AD35E5F4CEDC}
- HKEY_CLASSES_ROOT\CLSID\{8DBF02DA-4360-4A7E-BEA1-347B87816327}
- HKEY_CLASSES_ROOT\MSEvents.MSEvents
- HKEY_CLASSES_ROOT\MSEvents.MSEvents.1
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BAE99AF-A9F7-4f7e-9C72-2C1CC81BE0FF}
- HKEY_CLASSES_ROOT\CheckProduct2.CheckProduct.1
- HKEY_CLASSES_ROOT\CLSID\{025C9956-0606-4583-BC40-633904FF6D77}
- HKEY_CLASSES_ROOT\CLSID\{11D14DA6-FCAA-405E-B014-E5920F922AC1}
- HKEY_CLASSES_ROOT\CLSID\{1BD800A1-1C40-47E6-99A1-22B04DAB2CE0}
- HKEY_CLASSES_ROOT\CLSID\{26EA10BD-85B6-4052-9300-59AAC07E84EF}
- HKEY_CLASSES_ROOT\CLSID\{4E34AB3C-05D2-438E-A408-06CB9467038D}
- HKEY_CLASSES_ROOT\CLSID\{5F4C4961-505D-4DA5-B770-BF3D860C0207}
- HKEY_CLASSES_ROOT\CLSID\{8AA798D6-FA74-43D3-8121-321B21CB9C3B}
- HKEY_CLASSES_ROOT\CLSID\{8ACF7E80-3254-4F9A-9D11-39E10E04973A}
- HKEY_CLASSES_ROOT\CLSID\{BAD54733-5051-485E-B8F0-8A78BEBD80FC}
- HKEY_CLASSES_ROOT\CLSID\{C427B3E3-28DC-4001-9590-D99B6776119B}
- HKEY_CLASSES_ROOT\CLSID\{FEB5C757-2F1D-4939-A069-42564648403B}
- HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\ExplorerAntiVirus
- HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\ExplorerAntiVirus
- HKEY_CLASSES_ROOT\Interface\{025C9956-0606-4583-BC40-633904FF6D77}
- HKEY_CLASSES_ROOT\Interface\{11D14DA6-FCAA-405E-B014-E5920F922AC1}
- HKEY_CLASSES_ROOT\Interface\{1BD800A1-1C40-47E6-99A1-22B04DAB2CE0}
- HKEY_CLASSES_ROOT\Interface\{27967FBC-694B-41A6-8CCE-30E59292350E}
- HKEY_CLASSES_ROOT\Interface\{3AC2E7AC-1E90-4DE8-BD4F-B58275133F82}
- HKEY_CLASSES_ROOT\Interface\{4F79D1C5-24F9-4E59-8022-604D4B41D5CA}
- HKEY_CLASSES_ROOT\Interface\{5D65F8B9-6C63-4227-AB90-04E8D2B87C31}
- HKEY_CLASSES_ROOT\Interface\{66BA5DC6-BBA9-470F-A68D-37CCD9AB6788}
- HKEY_CLASSES_ROOT\Interface\{82B9A1FB-6B6B-47D2-8CED-B9A494F26F48}
- HKEY_CLASSES_ROOT\Interface\{C0A3779C-3345-4150-BD63-C399EB32661E}
- HKEY_CLASSES_ROOT\Quarantine.QuarantineImpl
- HKEY_CLASSES_ROOT\Quarantine.QuarantineImpl.1
- HKEY_CLASSES_ROOT\VapFM.CreationNotifier
- HKEY_CLASSES_ROOT\VapFM.CreationNotifier.1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TWA5_is1
- HKEY_LOCAL_MACHINE\SOFTWARE\WinSoftware\WinAntiVirus 200*
- HKEY_LOCAL_MACHINE\SOFTWARE\WinSoftware\WinFixer 200*
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\AVScheduler
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\WinAntivirus
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\AVScheduler
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\WinAntivirus
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AVScheduler
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VAPSpy
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinAntivirus
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVScheduler
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\df_kmd.sys
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinAntivirus
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AVScheduler
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\df_kmd.sys
- HKEY_LOCAL_MACHINE\SOFTWARE\Winfixer*
- HKEY_LOCAL_MACHINE\SOFTWARE\*Winfixer*
- HKEY_LOCAL_MACHINE\SOFTWARE\*Winfixer*200*
- HKEY_USERS\*\Software\Winfixer*
- HKEY_USERS\*\Software\*Winfixer*200*
- HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifypmkjj
WinFixer 2005 might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\WinSoftware\CrXML.dll*
- HKEY_USERS\*\Control Panel\MMCPL|AVcpl
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 200*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|UWFX*
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5LP_0001_0715
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls|AVcpl
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Extended Properties\{305CA226-D286-468e-B848-2B2E8E697B74} 2|*\WinAntiVirus 200*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|FNI.UWA5P
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|AVTray
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\WinSoftware\*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Winfixer_2005
WinFixer 2005 might create registry values with following data:
n/a
WinFixer 2005 might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for WinFixer 2005 free of charge
|