<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>WinFixer</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/WinFixer"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-WinFixer rootpage-WinFixer skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">WinFixer</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */
.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}
/* end https://en.wikipedia.org/ */
</style><table class="infobox vcard"><caption class="infobox-title fn org">WinFixer</caption><tbody><tr><td colspan="2" class="infobox-image"></td></tr><tr><td colspan="2" class="infobox-image"><span typeof="mw:File"></span><div class="infobox-caption">Screenshot of the WinFixer homepage</div></td></tr><tr><th scope="row" class="infobox-label"><div style="display: inline-block; line-height: 1.2em; padding: .1em 0;">Type of site</div></th><td class="infobox-data"><a href="Scareware" title="Scareware">Scareware</a></td></tr><tr><th scope="row" class="infobox-label">Available in</th><td class="infobox-data">English</td></tr><tr><th scope="row" class="infobox-label">Owner</th><td class="infobox-data"><a href="Innovative_Marketing" title="Innovative Marketing">Innovative Marketing</a></td></tr><tr><th scope="row" class="infobox-label">Commercial</th><td class="infobox-data">No</td></tr><tr><th scope="row" class="infobox-label">Registration</th><td class="infobox-data">Not required</td></tr><tr><th scope="row" class="infobox-label">Current status</th><td class="infobox-data category">Shut down by the United States federal government</td></tr><tr><th scope="row" class="infobox-label"><div style="display: inline-block; line-height: 1.2em; padding: .1em 0;">Content license</div></th><td class="infobox-data">Not protected by copyright laws; see <i><a href="Ex_turpi_causa_non_oritur_actio" title="Ex turpi causa non oritur actio">ex turpi causa non oritur actio</a></i></td></tr></tbody></table>
<p><b>WinFixer</b><sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>a<span class="cite-bracket">]</span></a></sup> was a family of <a href="Scareware" title="Scareware">scareware</a> <a href="Rogue_software" class="mw-redirect" title="Rogue software">rogue security programs</a> developed by Winsoftware which claimed to repair computer system problems on <a href="Microsoft_Windows" title="Microsoft Windows">Microsoft Windows</a> computers if a user purchased the full version of the software. The software was mainly installed without the user's consent.<sup id="cite_ref-fsecure_2-0" class="reference"><a href="#cite_note-fsecure-2"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> <a href="McAfee" title="McAfee">McAfee</a> claimed that "the primary function of the free version appears to be to alarm the user into paying for registration, at least partially based on false or erroneous detections."<sup id="cite_ref-mcafee_3-0" class="reference"><a href="#cite_note-mcafee-3"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> The program prompted the user to purchase a paid copy of the program.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p><p>The WinFixer web page (see the image) said it "is a useful utility to scan and fix any system, registry and hard drive errors. It ensures system stability and performance, frees wasted hard-drive space and recovers damaged Word, Excel, music and video files."
However, these claims were never verified by any reputable source. In fact, most sources considered this program to actually reduce system stability and performance. The sites went defunct in December 2008 after actions taken by the <a href="Federal_Trade_Commission" title="Federal Trade Commission">Federal Trade Commission</a>.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Installation_methods">Installation methods</h2></div>
<p>The WinFixer application was known to infect users using the <a href="Microsoft_Windows" title="Microsoft Windows">Microsoft Windows</a> <a href="Operating_system" title="Operating system">operating system</a>, and was browser independent. One infection method involved the <a href="Emcodec" title="Emcodec">Emcodec.E</a> <a href="Trojan_horse_(computing)" title="Trojan horse (computing)">trojan</a>, a <a href="Fake_codec" class="mw-redirect" title="Fake codec">fake codec</a> scam. Another involves the use of the <a href="Vundo" title="Vundo">Vundo</a> family of trojans.<sup id="cite_ref-bleepingcomputer.com_5-0" class="reference"><a href="#cite_note-bleepingcomputer.com-5"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Typical_infection">Typical infection</h3></div>
<p>The infection usually occurred during a visit to a distributing website using a web browser. A message appeared in a <a href="Dialog_box" title="Dialog box">dialog box</a> or popup asking the user if they wanted to install WinFixer, or claimed a user's machine was infected with <a href="Malware" title="Malware">malware</a>, and requested the user to run a free scan. When the user chose any of the options or tried to close this dialog (by clicking 'OK' or 'Cancel' or by clicking the corner 'X'), it would trigger a <a href="Pop-up_window" class="mw-redirect" title="Pop-up window">pop-up window</a> and WinFixer would download and install itself, regardless of the user's wishes.
</p>
<div class="mw-heading mw-heading3"><h3 id=""Trial"_offer">"Trial" offer</h3></div>
<p>A free "trial" offer of this program was sometimes found in pop-ups. If the "trial" version was downloaded and installed, it would execute a "scan" of the local machine and a couple of non-existent <a href="Trojan_horse_(computing)" title="Trojan horse (computing)">trojans</a> and viruses would be "discovered", but no further action would be undertaken by the program. To obtain a quarantine or removal, WinFixer required the purchase of the program.<sup id="cite_ref-AAA_6-0" class="reference"><a href="#cite_note-AAA-6"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> However, the alleged unwanted bugs were bogus, only serving to persuade the owner to buy the program.
</p>
<div class="mw-heading mw-heading3"><h3 id="WinFixer_application">WinFixer application</h3></div>
<p>Once installed, WinFixer frequently launched pop-ups and prompted the user to follow its directions. Because of the intricate way in which the program installed itself into the host computer (including making dozens of registry edits), successful removal would have taken a fairly long time if done manually. When running, its <a href="Process_(computing)" title="Process (computing)">process</a> could be found in the <a href="Task_manager" title="Task manager">task manager</a> and be stopped, but would automatically relaunch itself after a period of time.
</p><p>WinFixer was also known to modify the <a href="Windows_Registry" title="Windows Registry">Windows Registry</a> so that it started up automatically with every reboot, and scanned the user's computer.<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Firefox_popup">Firefox popup</h3></div>
<p>The <a href="Mozilla_Firefox" class="mw-redirect" title="Mozilla Firefox">Mozilla Firefox</a> browser was vulnerable to initial infection by WinFixer. Once installed, WinFixer was known to exploit the SessionSaver extension for the <a href="Firefox" title="Firefox">Firefox</a> browser. The program caused popups on every startup asking the user to download WinFixer, by adding lines containing the word 'WinFixer' to the prefs.js file.
</p>
<div class="mw-heading mw-heading3"><h3 id="Removal">Removal</h3></div>
<p>Removal of WinFixer proved difficult because it actively undid whatever the user attempted. Frequently, procedures that worked on one system would not work on another because there were a large number of variants. Some sites provided manual techniques to remove infections that automated cleanup tools could not remove.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Domain_ownership">Domain ownership</h2></div>
<p>The company that made WinFixer, Winsoftware Ltd., claimed to be based in Liverpool, England (Stanley Street, postcode: 13088.) However, this address was proven to be false.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>
</p><p>The domain WINFIXER.COM on the <a href="WHOIS" title="WHOIS">whois</a> database showed it was owned by a void company in <a href="Ukraine" title="Ukraine">Ukraine</a> and another in <a href="Warsaw" title="Warsaw">Warsaw</a>, <a href="Poland" title="Poland">Poland</a>.<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> According to <a href="Alexa_Internet" title="Alexa Internet">Alexa Internet</a>, the domain was owned by Innovative Marketing, Inc., 1876 Hutson St, Honduras.
</p><p>According to the <a href="Public_key_certificate" title="Public key certificate">public key certificate</a> provided by <a href="GTE" title="GTE">GTE</a> <a href="Cybertrust" class="mw-redirect" title="Cybertrust">CyberTrust Solutions</a>, Inc., the server <i>secure.errorsafe.com</i> was operated by ErrorSafe Inc. at 1878 Hutson Street, Belize City, BZ.
</p><p>Running traceroute on Winfixer domains showed that most of the domains were hosted from servers at setupahost.net, which used Shaw Business Solutions AKA Bigpipe as their backbone.
</p>
<div class="mw-heading mw-heading2"><h2 id="Technical_information">Technical information</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Technical">Technical</h3></div>
<p>WinFixer was closely related to Aurora Network's Nail.exe hijacker/spyware program. In worst-case scenarios, it would embed itself in Internet Explorer and become part of the program, thus being nearly impossible to remove. The program was also closely related to the <a href="Vundo" title="Vundo">Vundo</a> trojan.<sup id="cite_ref-bleepingcomputer.com_5-1" class="reference"><a href="#cite_note-bleepingcomputer.com-5"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Variants">Variants</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Windows_Police_Pro">Windows Police Pro</h3></div>
<p>Windows Police Pro was a variant of WinFixer.<sup id="cite_ref-Long_12-0" class="reference"><a href="#cite_note-Long-12"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> David Wood wrote in <a href="Microsoft_TechNet" title="Microsoft TechNet">Microsoft TechNet</a> that in March 2009, the Microsoft Malware Protection Center saw ASC Antivirus, the virus' first version. Microsoft did not detect any changes to the virus until the end of July that year when a second variant, Windows Antivirus Pro, appeared. Although multiple new virus versions have since appeared, the virus has been renamed only once, to Windows Police Pro. Microsoft added the virus to its <a href="Malicious_Software_Removal_Tool" title="Malicious Software Removal Tool">Malicious Software Removal Tool</a> in October 2009.<sup id="cite_ref-Wood_13-0" class="reference"><a href="#cite_note-Wood-13"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p><p>The virus generated numerous persistent popups and messages displaying false scan reports intended to convince users that their computers were infected with various forms of malware that do not exist. When users attempted to close the popup message, they received <a href="Confirmation_dialog_box" class="mw-redirect" title="Confirmation dialog box">confirmation dialog boxes</a> that switched the "Purchase full version" and "Continue evaluating" buttons.<sup id="cite_ref-Wood_13-1" class="reference"><a href="#cite_note-Wood-13"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> Windows Police Pro generated a counterfeit <a href="Windows_Security_Center" class="mw-redirect" title="Windows Security Center">Windows Security Center</a> that warned users about the fake malware.<sup id="cite_ref-Abrams_14-0" class="reference"><a href="#cite_note-Abrams-14"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p><p><a href="Bleeping_Computer" title="Bleeping Computer">Bleeping Computer</a> and the syndicated "Propeller Heads" column recommended using <a href="Malwarebytes'_Anti-Malware" class="mw-redirect" title="Malwarebytes' Anti-Malware">Malwarebytes' Anti-Malware</a> to remove Windows Police Pro permanently.<sup id="cite_ref-Wood_13-2" class="reference"><a href="#cite_note-Wood-13"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Propeller_Heads_15-0" class="reference"><a href="#cite_note-Propeller_Heads-15"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> <a href="Microsoft_TechNet" title="Microsoft TechNet">Microsoft TechNet</a> and <a href="Softpedia" title="Softpedia">Softpedia</a> recommended using <a href="Microsoft" title="Microsoft">Microsoft</a>'s <a href="Malicious_Software_Removal_Tool" title="Malicious Software Removal Tool">Malicious Software Removal Tool</a> to get rid of the malware.<sup id="cite_ref-Wood_13-3" class="reference"><a href="#cite_note-Wood-13"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Oiaga_16-0" class="reference"><a href="#cite_note-Oiaga-16"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Effects_on_the_public">Effects on the public</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Class_action_lawsuit">Class action lawsuit</h3></div>
<p>On September 29, 2006, a <a href="San_Jose%2C_California" title="San Jose, California">San Jose</a> woman filed a lawsuit over WinFixer and related "fraudware" in <a href="Santa_Clara_County" class="mw-redirect" title="Santa Clara County">Santa Clara County</a> Superior Court; however, in 2007 the lawsuit was dropped. In the lawsuit, the plaintiffs charged that the WinFixer software "eventually rendered her computer's hard drive unusable. The program infecting her computer also ejected her CD-ROM drive and displayed Virus warnings."<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Ads_on_Windows_Live_Messenger">Ads on Windows Live Messenger</h3></div>
<p>On February 18, 2007, a blog called "Spyware Sucks" reported that the popular <a href="Instant_messaging" title="Instant messaging">instant messaging</a> application <a href="Windows_Live_Messenger" class="mw-redirect" title="Windows Live Messenger">Windows Live Messenger</a> had inadvertently promoted WinFixer by displaying a WinFixer advertisement from one of Messenger's <a href="Ad_serving" class="mw-redirect" title="Ad serving">ad hosts</a>.<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> A similar occurrence was also reported on some <a href="MSN_Groups" title="MSN Groups">MSN Groups</a> pages. There were other reports before this one (one from Patchou, the creator of <a href="Messenger_Plus!" title="Messenger Plus!">Messenger Plus!</a>), and people had contacted Microsoft about the incidents. Whitney Burk from Microsoft issued this problem in his official statement:
</p>
<style data-mw-deduplicate="TemplateStyles:r1244412712">
/* start https://en.wikipedia.org/ */
.mw-parser-output .templatequote{overflow:hidden;margin:1em 0;padding:0 32px}.mw-parser-output .templatequotecite{line-height:1.5em;text-align:left;margin-top:0}@media(min-width:500px){.mw-parser-output .templatequotecite{padding-left:1.6em}}
/* end https://en.wikipedia.org/ */
</style><blockquote class="templatequote"><p><i>Microsoft was notified of malware that was being served through ads placed in Windows Live Messenger banners. As a result of this notification we immediately investigated the reports and removed the offending ads, as this is a violation of our ad serving policy. We can confirm that the ads are no longer being served by any Microsoft system. We apologize for the inconvenience and are reviewing our ad approval process to reduce the chance of an occurrence such as this happening again. To help customers protect their PCs from malware threats, Microsoft recommends customers follow our Protect your PC guidance at <a rel="nofollow" class="external text" href="https://www.microsoft.com/protect">www.microsoft.com/protect</a>.</i></p></blockquote><div class="templatequotecite"><p style="display: inline; padding-left: 2.3em;">— Whitney Burk, <a href="Microsoft" title="Microsoft">Microsoft</a></p></div>
<div class="mw-heading mw-heading3"><h3 id="Federal_Trade_Commission">Federal Trade Commission</h3></div>
<p>On December 2, 2008, the <a href="Federal_Trade_Commission" title="Federal Trade Commission">Federal Trade Commission</a> requested and received a <a href="Temporary_restraining_order" class="mw-redirect" title="Temporary restraining order">temporary restraining order</a> against Innovative Marketing, Inc., ByteHosting Internet Services, LLC, and individuals Daniel Sundin, <a href="Jain_Shaileshkumar" title="Jain Shaileshkumar">Sam Jain</a>, Marc D’Souza, Kristy Ross, and James Reno, the creators of WinFixer and its sister products. The complaint alleged that the products' advertising, as well as the products themselves, violated United States consumer protection laws.<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup> However, Innovative Marketing flouted the court order and was fined $8,000 per day in civil contempt.<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</p><p>On September 24, 2012, Kristy Ross was fined $163 million by the Federal Trade Commission for her part in this.<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
The article goes on to say that the WinFixer family of software was simply a con but does not acknowledge that it was in fact a program that made many computers unusable.
</p>
<div class="mw-heading mw-heading2"><h2 id="Notes">Notes</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-lower-alpha">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text">Also known under various other names, including AVSystemCare, DriveCleaner, ECsecure, ErrorProtector, ErrorSafe, FreePCSecure, Home Antivirus 20xx, PCTurboPro, Performance Optimizer, Personal Antivirus, PrivacyProtector, StorageProtector, SysProtect, SystemDoctor, VirusDoctor, WinAntiSpy, WinAnti<a href="Spyware" title="Spyware">Spyware</a>, WinAntiVirusPro, Windows Police Pro, WinReanimator, WinSoftware, WinspywareProtect, XPAntivirus and Your PC Protector.</span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-fsecure-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-fsecure_2-0">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.f-secure.com/sw-desc/winfixer.shtml">"Winfixer"</a>. F-secure.com<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-mcafee-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-mcafee_3-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=135733">"Computer Virus Attacks, Information, News, Security, Detection and Removal | McAfee"</a>. Us.mcafee.com<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20080324121728/http://www.symantec.com/security_response/writeup.jsp?docid=2005-120121-2151-99&tabid=1">"WinFixer"</a>. Symantec. Archived from <a rel="nofollow" class="external text" href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-120121-2151-99&tabid=1">the original</a> on March 24, 2008<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-bleepingcomputer.com-5"><span class="mw-cite-backlink">^ <a href="#cite_ref-bleepingcomputer.com_5-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-bleepingcomputer.com_5-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.bleepingcomputer.com/malware-removal/remove-vundo-virtumonde">"How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo"</a>. Bleepingcomputer.com<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-AAA-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-AAA_6-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFVincentas2013" class="citation news cs1">Vincentas (July 6, 2013). <a rel="nofollow" class="external text" href="http://www.spywareloop.com/infections/w/winfixer">"WinFixer in SpyWareLoop.com"</a>. <i>Spyware Loop</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2013-07-28</span></span>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20071118122531/http://www.stopbadware.org/reports/reportdisplay?reportname=winfixer">"WinFixer 2005, WinFixer 2006"</a>. <i>www.stopbadware.org</i>. Archived from <a rel="nofollow" class="external text" href="http://www.stopbadware.org/reports/reportdisplay?reportname=winfixer">the original</a> on November 18, 2007.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://mc-computing.com/Parasites/WinFixer_parasite.html">"WinFixer Virus Manual Removal - Vundo Variant"</a>. 2006.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20070709232750/http://castlecops.com/t132998-quot_winfixer_quot_virus_quot_winsoftware_quot_crime_rin.html">""winfixer" virus "winsoftware" crime rin"</a>. Archived from <a rel="nofollow" class="external text" href="http://castlecops.com/t132998-quot_winfixer_quot_virus_quot_winsoftware_quot_crime_rin.html">the original</a> on 2007-07-09.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.dnsstuff.com/tools/whois.ch?ip=http://www.winantivirus.com/">"DNS tools - Manage Monitor Analyze - DNSstuff"</a>. <i>www.dnsstuff.com</i>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20070930122058/http://www.trojanguide.com/spydet_2339_vundo.html">"Vundo"</a>. Archived from <a rel="nofollow" class="external text" href="http://www.trojanguide.com/spydet_2339_vundo.html">the original</a> on September 30, 2007<span class="reference-accessdate">. Retrieved <span class="nowrap">February 26,</span> 2006</span>.</cite></span>
</li>
<li id="cite_note-Long-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-Long_12-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFLong2009" class="citation news cs1">Long, Daniel (2009-10-02). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20091004090328/http://www.pcauthority.com.au/News/157350,fake-antivirus-5-software-titles-you-should-definitely-not-install.aspx">"Fake Antivirus: 5 software titles you should definitely NOT install"</a>. <i>PC & Tech Authority</i>. <a href="Nextmedia" title="Nextmedia">nextmedia</a>. Archived from <a rel="nofollow" class="external text" href="http://www.pcauthority.com.au/News/157350,fake-antivirus-5-software-titles-you-should-definitely-not-install.aspx">the original</a> on 2009-10-04<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-12-02</span></span>.</cite></span>
</li>
<li id="cite_note-Wood-13"><span class="mw-cite-backlink">^ <a href="#cite_ref-Wood_13-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-Wood_13-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-Wood_13-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-Wood_13-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFWood2009" class="citation news cs1">Wood, David (2009-10-13). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20130106223412/http://blogs.technet.com/b/mmpc/archive/2009/10/13/scanti-ly-clad-another-rogue-stripped-by-msrt.aspx">"Scanti-ly Clad - Another Rogue Stripped by MSRT"</a>. <a href="Microsoft_TechNet" title="Microsoft TechNet">Microsoft TechNet</a>. Archived from <a rel="nofollow" class="external text" href="http://blogs.technet.com/b/mmpc/archive/2009/10/13/scanti-ly-clad-another-rogue-stripped-by-msrt.aspx">the original</a> on 2013-01-06<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-11-13</span></span>.</cite></span>
</li>
<li id="cite_note-Abrams-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-Abrams_14-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFAbrams2009" class="citation news cs1">Abrams, Lawrence (2009-09-01). <a rel="nofollow" class="external text" href="http://www.bleepingcomputer.com/virus-removal/remove-windows-police-pro">"Remove Windows Police Pro (Removal Guide)"</a>. <a href="Bleeping_Computer" title="Bleeping Computer">Bleeping Computer</a>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20090903140340/http://www.bleepingcomputer.com/virus-removal/remove-windows-police-pro">Archived</a> from the original on 2009-09-03<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-11-15</span></span>.</cite></span>
</li>
<li id="cite_note-Propeller_Heads-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-Propeller_Heads_15-0">^</a></b></span> <span class="reference-text"><cite class="citation news cs1"><a rel="nofollow" class="external text" href="http://docs.newsbank.com/s/InfoWeb/aggdocs/AWNB/12B53B7F6DC5C600/0D0CB57AB53DF815">"Getting rid of malware"</a>. <i><a href="Coeur_d'Alene_Press" title="Coeur d'Alene Press">Coeur d'Alene Press</a></i>. Propeller Heads. 2009-10-11<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-11-11</span></span>.</cite></span>
</li>
<li id="cite_note-Oiaga-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-Oiaga_16-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFOiaga2009" class="citation news cs1">Oiaga, Marius (2009-10-15). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20141111033646/http://archive.news.softpedia.com/news/Windows-Antivirus-Pro-Tackled-by-the-Microsoft-Malicious-Software-Removal-Tool-124423.shtml">"Windows Antivirus Pro Tackled by the Microsoft Malicious Software Removal Tool"</a>. <a href="Softpedia" title="Softpedia">Softpedia</a>. Archived from <a rel="nofollow" class="external text" href="http://archive.news.softpedia.com/news/Windows-Antivirus-Pro-Tackled-by-the-Microsoft-Malicious-Software-Removal-Tool-124423.shtml">the original</a> on 2014-11-11<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-11-11</span></span>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite id="CITEREFJeremy_Kirk2007" class="citation magazine cs1">Jeremy Kirk (March 8, 2007). <a rel="nofollow" class="external text" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9012579">"Lawyer sleuths out mystery around 'Winfixer'"</a>. <i>Computerworld</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2014-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.mercurynews.com/ci_8668679?nclick_check=1">"Malware victim tries in vain to punish its source - San Jose Mercury News"</a>. <i>Mercurynews.com</i>. 23 March 2008<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.theinternetpatrol.com/lawsuit-filed-against-winfixer-aka-errorsafe-winantispyware-winantivirus-systemdoctor-and-drivecleaner">"Lawsuit Filed Against Winfixer (a/k/a ErrorSafe, WinAntiSpyware, WinAntiVirus, SystemDoctor and DriveCleaner)"</a>. The Internet Patrol. 9 March 2007<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20080705081003/http://msmvps.com/blogs/spywaresucks/archive/2007/02/18/591493.aspx">"WARNING: Winfixer and Errorsafe being distributed via MSN Messenger banner advertisements - Spyware Sucks"</a>. <i>msmvps.com</i>. Archived from <a rel="nofollow" class="external text" href="http://msmvps.com/blogs/spywaresucks/archive/2007/02/18/591493.aspx">the original</a> on July 5, 2008.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.ftc.gov/opa/2008/12/winsoftware.shtm">"Court Halts Bogus Computer Scans"</a>. <a href="Federal_Trade_Commission" title="Federal Trade Commission">Federal Trade Commission</a> (<a href="United_States" title="United States">United States</a>). December 10, 2008<span class="reference-accessdate">. Retrieved <span class="nowrap">2008-12-11</span></span>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.theregister.co.uk/2008/12/24/scareware_mongers_fined/">"Accused Scareware mongers held in contempt of court"</a>. The Register (<a href="United_Kingdom" title="United Kingdom">United Kingdom</a>). December 24, 2008<span class="reference-accessdate">. Retrieved <span class="nowrap">2008-12-24</span></span>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite id="CITEREFIonescu2012" class="citation web cs1">Ionescu, Daniel (October 3, 2012). <a rel="nofollow" class="external text" href="http://www.techhive.com/article/2011046/scareware-con-artist-fined-163-million-by-ftc.html">"Scareware con artist fined $163 million by FTC"</a>. techhive.com<span class="reference-accessdate">. Retrieved <span class="nowrap">2012-10-03</span></span>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.ftc.gov/os/caselist/0723137/121002winfixeropinion.pdf">"Winfixer Opinion"</a> <span class="cs1-format">(PDF)</span>. US Federal Trade Commission. September 24, 2012<span class="reference-accessdate">. Retrieved <span class="nowrap">2012-10-03</span></span>.</cite></span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="http://vil.mcafeesecurity.com/vil/content/v_135733.htm">McAfee's Entry on WinFixer</a></li>
<li><a rel="nofollow" class="external text" href="https://web.archive.org/web/20051208113316/http://securityresponse.symantec.com/avcenter/venc/data/winfixer.html">Symantec’s Entry on WinFixer and removal instructions</a></li>
<li><a rel="nofollow" class="external text" href="https://web.archive.org/web/20060206085954/http://securityresponse.symantec.com/avcenter/venc/data/errorsafe.html">Symantec's entry on ErrorSafe - a sister spyware application</a></li>
<li><a rel="nofollow" class="external text" href="https://www.ftc.gov/os/caselist/0723137/081202innovativemrktgcmplt.pdf">FTC complaint</a></li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-01-13" href="https://en.wikipedia.org/wiki/?title=WinFixer&oldid=1269192248">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>