Home Malware Programs Rogue Anti-Spyware Programs WindoFix

WindoFix

Posted: August 18, 2009

WindoFix is a fake spyware remover that will display fabricated scan reports on computers. Typically, this unwanted program is downloaded manually by an inexperienced user, in an attempt to combat the fake threats that are shown.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 unins000.dat
    2 unins000.exe
    3 WindoFix on the Web.url
    4 WindoFix.exe
    5 WindoFix\\WindoFix.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"WindoFix" = "%ProgramFiles%\WindoFix\WindoFix.exe /fast"HKEY_CURRENT_USER\Software\WindoFixHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{0F464999-9928-4B44-B57E-057033961349}_is1
Loading...