Remove WinFix2005 Spyware

G

Guest

I keep getting pop ups for WinFix2005. I recently installed Microsoft
AntiSpyWare and removed all detected spyware but still receive pop ups for
WinFix2005. Anyone know how to remove this?
 
G

Guest

Steps to take if you have spyware that is not removed by Microsoft Windows
AntiSpyware (betª)
1) Open up AntiSpywªre
2) Click Tools at the tºp
3) Click "Submit a Suspected Spyware Repºrt"
4) Fill out the form with as much detail so they can anªlyze quickly.


Have you tried these operations running in safe mºde?

1) Update both Microsoft Antispyware and your antivirus applicªtion.

2B)Shut down the computer and turn off the power. Wait for at least 30
seconds, and then restart the computer in Safe mode or VGA mºde.

Open a Internet window and go to Internet Options, Delete Cookies and Temp
Files and included all offline content then also go to start and run and type
%temp% and clear that fºlder.
Empty your IE cache and your other temporary file folders, eg: c:\temp,
c:\windows\temp or C:\Documents and Settings\<name>\Local Settings\Temp (the
path to your temp folder will change depending on your name) - sometimes
programmes can be hidden in there - watch out for mysterious *.exe files or
*.dll files in those fºlders.
http://www.mvps.org/winhelp2002/delcache.htm


3) Do full deep scans with Microsoft Antispyware. Repeat scanning until a
complete scan comes through clean. Ditto with the ªntivirus.

Download the following and run a thorough scan in safe mºde:

NOTE: Make certain to update every app before booting into Safe Mode since
you WILL NOT have access to the Internet from Safe Mºde.

Ad-Aware - http://www.lavasoftusa.com
http://hem.bredband.net/b288305/lavasofts_adaware_quick_start.htm

Spybot S&D - http://www.safer-networking.org/
http://net-integration.net/index.html
Make certain to not to select any of the pernament protection for Spybot and
DO NOT immunize the system, as this can interfere with MSAS' Real-tme
Protectiºn.

CWShredder - http://www.intermute.com/products/cwshredder.html

Spy Sweeper - http://www.webroot.com

Ccleaner - http://www.ccleaner.com

Also check windows updates to make sure you have the latest security patches
and service packs instªlled :
http://windowsupdate.microsoft.com/

Istructions for removing WinFix available if you Google "WinFix."

Engel
 
G

Guest

Should I do Engel's suggestions below as well?

Here is what my situation is:

My Internet Explorer homepage has been hijacked by spyware with the
following address: (http://updatecenter.com/. ; The site says that I have
been infected and Recommends AntiSpyware Software, PS Guard and Spyware
Trooper, it also has a small screen entitled Microsoft Internet Explorer the
says your PC has been infected with Spyware and recommends you download and
purchase Spyware Trooper. When trying to use the Tools/Internet Options to
change the default home page it seems to let you change it, but the next time
you click on IE it looks like it goes to what you set the home page to, but
before it has a chance to come up it goes to the http://updatecenter.com
again.

I have downloaded the McAfee Security Center - both the McAfee Virus Scan
and the McAfee Personal Firewall and now the Microsoft AntiSpyware Beta 1.
After running all of these it does not detect and delete this one??

Do you know how I can get rid of it and get my home page back?
 
G

Guest

Thanks Plun,

So the first thing I do is download the hijackthis from the link you
provided and when I run it it, it will give me a log? I then am confused as
to what to compare with what? Sorry, new at this.

Do I go to the URL for compare (http://www.castlecops.com....html) and
compare the hijackthis log with what is in the html? And if it is then what?

When do I need to be careful? When I go to the castlecops site?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top