Monday, November 21, 2011

Remove Windows Fix virus

Windows Fix (WindowsFix) is a kind of fake computer tool that, unlike most of the similar counterfeits, do not run after viruses. Why, other counterfeits do not run after them as well, but they pretend to prosecute computer infections – unlike the fake under review, which only pretends to detect and repair performance error.
Such tactic is not a brand new fraud, as well as the performance booster in question is a remake of popular template that already exists in hundreds of variants and under the same number of names.
However, the program is quite unique. In any case, special technique is required to successfully remove Windows Fix, which is slightly but different from those to be applied for its nearest relatives, System Fix and Computer Fix.
Click here to run free scan and ensure removal of Windows Fix advertisement virus and other trojans, worms, rootkits etc as detected by the examination tool that applies description based comparative methods as well as the most advanced heuristic techniques.

Windows Fix snapshot:



Manual removal guide:
Delete infected files:

%AllUsersProfile%\~
%AllUsersProfile%\~
%AllUsersProfile%\
%AllUsersProfile%\.exe
%AppData%\Microsoft\Internet Explorer\Quick Launch\Windows Fix.lnk
%Desktop%\
Computer Fix.lnk
%StartMenu%\Programs\
Windows Fix\
%StartMenu%\Programs\
Windows Fix\System Fix.lnk
%StartMenu%\Programs\
Windows Fix\Uninstall System Fix.lnk
%Temp%\smtmp\
%Temp%\smtmp\1
%Temp%\smtmp\1
%Temp%\smtmp\2
%Temp%\smtmp\3
%Temp%\smtmp\4
Delete infected registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘Yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ‘0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer “NoDesktop” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ‘0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = ‘0′

No comments: