Home Malware Programs Rogue Anti-Spyware Programs WindowFix

WindowFix

Posted: August 24, 2009

WindowFix is a fake system optimization tool, and is just another name for WindoFix. It masquerades as a useful program, but is nothing of the sort, only seeking to gain your trust. Typically WindowFix states that your computer is infected or has various problems, and then prompts you to purchase the full version in order to combat these imaginary issues.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %common_desktopdirectory%\windofix.lnk
    2 %common_programs%\windofix\uninstall windofix.lnk
    3 %common_programs%\windofix\windofix on the web.url
    4 %common_programs%\windofix\windofix.lnk
    5 %program_files%\windofix\unins000.dat
    6 %program_files%\windofix\unins000.exe
    7 %program_files%\windofix\windofix.exe
    8 windofix.exe
    9 windofixsetup.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\menuorder\start menu2\programs\windofixHKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\menuorder\start menu2\programs\windofix orderHKEY_CURRENT_USER\software\windofixHKEY_CURRENT_USER\software\windofix\windofixHKEY_CURRENT_USER\software\windofix\windofix\settingsHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{0f464999-9928-4b44-b57e-057033961349}_is1{0f464999-9928-4b44-b57e-057033961349}_is1 displayname{0f464999-9928-4b44-b57e-057033961349}_is1 helplink{0f464999-9928-4b44-b57e-057033961349}_is1 inno setup codefile: email{0f464999-9928-4b44-b57e-057033961349}_is1 inno setup codefile: name{0f464999-9928-4b44-b57e-057033961349}_is1 inno setup: app path{0f464999-9928-4b44-b57e-057033961349}_is1 inno setup: icon group{0f464999-9928-4b44-b57e-057033961349}_is1 inno setup: selected tasks{0f464999-9928-4b44-b57e-057033961349}_is1 inno setup: setup version{0f464999-9928-4b44-b57e-057033961349}_is1 inno setup: user{0f464999-9928-4b44-b57e-057033961349}_is1 installdate{0f464999-9928-4b44-b57e-057033961349}_is1 installlocation{0f464999-9928-4b44-b57e-057033961349}_is1 nomodify{0f464999-9928-4b44-b57e-057033961349}_is1 norepair{0f464999-9928-4b44-b57e-057033961349}_is1 publisher{0f464999-9928-4b44-b57e-057033961349}_is1 quietuninstallstring{0f464999-9928-4b44-b57e-057033961349}_is1 uninstallstring{0f464999-9928-4b44-b57e-057033961349}_is1 urlinfoabout{0f464999-9928-4b44-b57e-057033961349}_is1 urlupdateinfo
Loading...