WinFixer

WinFixer
WinFixer
Developer(s) Innovative Marketing, Inc.
Development status Shutdown by the United States Government; similar scams may still exist
Operating system Microsoft Windows
Type Scareware
License fraudulent activity
Screenshot of the WinFixer homepage.

WinFixer[n 1] is a family of scareware rogue security programs developed by Winsoftware which claim to repair computer system problems on Microsoft Windows computers if a user purchases the full version of the software. The software is mainly installed without the user's consent.[1] McAfee claims that "the primary function of the free version appears to be to alarm the user into paying for registration, at least partially based on false or erroneous detections."[2] The program prompts the user to purchase a paid copy of the program.[3]

The WinFixer web page (see the image) says it "is a useful utility to scan and fix any system, registry and hard drive errors. It ensures system stability and performance, frees wasted hard-drive space and recovers damaged Word, Excel, music and video files". However, these claims were never verified by any reputable source. In fact, most sources consider this program to actually reduce system stability and performance. The sites went defunct in December 2008 after actions taken by the Federal Trade Commission.

Contents

Installation methods

An example of a WinFixer pop-up dialog box within Opera. Even if the Cancel or Close buttons were clicked to dismiss the box, it would redirect to a WinAntiVirus page anyway, featuring a simulated system scan.

The WinFixer application is known to infect users using the Microsoft Windows operating system, and is browser independent. One infection method involves the Emcodec.E trojan, a fake codec scam. Another involves the use of the Vundo family of trojans.[4]

Typical infection

The infection usually occurs during a visit to a distributing web site using a web browser. A message appears in a dialog box or popup asking the user if they want to install WinFixer, or claiming a user's machine is infected with malware, and requests the user to run a free scan. When the user chooses any of the options or tries to close this dialog (by clicking 'OK' or 'Cancel' or by clicking the corner 'X'), it will trigger a pop-up window and WinFixer will download and install itself, regardless of the user’s wishes.

Initial message prior to infection - a user wishing to avoid infection might wish to disconnect from the Internet before closing the dialog box.

"Trial" offer

A free "trial" offer of this program is sometimes found in pop-ups. If the "trial" version is downloaded and installed, it will execute a "scan" of the local machine, and a couple of non existent Trojans and viruses will be located, but does nothing else. To obtain a quarantine or removal, WinFixer requires the purchase of the program. However, the alleged unwanted bugs are bogus, only serving to persuade the owner to buy the program.

WinFixer application

Once installed, WinFixer frequently launches pop-ups and prompts the user to follow its directions. Because of the intricate way in which the program installs itself into the host computer (including making dozens of registry edits), successful removal may take a fairly long time if done manually. When running, it can be found in the Task manager and stopped, but before long it will re-install and start up again.

WinFixer is also known to modify the Windows Registry, so that it launches automatically after reboot and scans the user's computer.[5]

Firefox popup

The Mozilla Firefox browser is vulnerable to initial infection by WinFixer. Once installed, WinFixer is known to exploit the SessionSaver extension for the Firefox browser. The program causes popups on every startup asking the user to download WinFixer, by adding lines containing the word 'WinFixer' to the prefs.js file.

Removal

The removal process of most rogue malware is often as simple as removing the directory it was originally installed into and then running basic cleanup software on the user's computer.

Unfortunately, simply deleting a directory won't remove WinFixer because it actively undoes whatever the user attempts. Frequently, the procedure that works on one system will not work on another because there are a large number of variants. Some sites provide manual techniques to remove infections that the automated tools can not remove.[6]

Domain ownership

The company that makes WinFixer, Winsoftware Ltd., claims to be based in Liverpool, England (Stanley Street, postcode: 13088.) However, this address has been proven false.[7]

The domain WINFIXER.COM on the whois database shows it is owned by a void company in Ukraine and another in Warsaw, Poland.[8] According to Alexa Internet, the domain is owned by Innovative Marketing, Inc., 1876 Hutson St, Honduras.

According to the public key certificate provided by GTE CyberTrust Solutions, Inc., the server secure.errorsafe.com is operated by ErrorSafe Inc. at 1878 Hutson Street, Belize City, BZ.

Running traceroute on Winfixer domains showed that most of the domains are hosted from servers at setupahost.net, which uses Shaw Business Solutions AKA Bigpipe as their backbone.

Technical information

Technical

WinFixer is closely related to Aurora Network's Nail.exe hijacker/spyware program. In worst-case scenarios, it may embed itself in Internet Explorer and become part of the program, thus being nearly impossible to remove. The program is also closely related to the Vundo trojan. [4][9]

Effects on the public

Class action lawsuit

On September 29, 2006, a San Jose woman filed a lawsuit over WinFixer and related "fraudware" in Santa Clara County Superior Court, however, in 2007 the lawsuit was dropped. In the lawsuit, the plaintiffs charged that the WinFixer software "eventually rendered her computer's hard drive unusable. The program infecting her computer also ejected her CD-ROM drive and displayed Virus warnings." [10][11][12] KTVU (Channel 2 in Oakland, CA) carried a special report. [13]

Ads on Windows Live Messenger

On February 18, 2007, a blog called "Spyware Sucks" had reported that the popular instant messaging application Windows Live Messenger had inadvertently promoted WinFixer by displaying a WinFixer advertisement from one of Messenger's ad hosts. [14] A similar occurrence also was reported on some MSN Groups pages. There were other reports before this one (one from Patchou, the creator of Messenger Plus!), and people had contacted Microsoft about the incidents. Whitney Burk from Microsoft issued this problem in his official statement:

Microsoft was notified of malware that was being served through ads placed in Windows Live Messenger banners. As a result of this notification we immediately investigated the reports and removed the offending ads, as this is a violation of our ad serving policy. We can confirm that the ads are no longer being served by any Microsoft system. We apologize for the inconvenience and are reviewing our ad approval process to reduce the chance of an occurrence such as this happening again. To help customers protect their PCs from malware threats, Microsoft recommends customers follow our Protect your PC guidance at www.microsoft.com/protect.

—Whitney Burk, Microsoft

Federal Trade Commission

On December 2, 2008, the Federal Trade Commission requested and received a temporary restraining order against Innovative Marketing, Inc., ByteHosting Internet Services, LLC, and individuals Daniel Sundin, Sam Jain, Marc D’Souza, Kristy Ross, and James Reno, the creators of WinFixer and its sister products. The complaint alleges that the products' advertising, as well as the products themselves, violate United States consumer protection laws. As of December 2008, this motion has attempted to halt the companies operations, and so halt the distribution of WinFixer and similar products offered by the same companies.[15] However, Innovative Marketing has flouted the court order and is currently being fined $8000 per day in civil contempt.[16]

Notes

  1. ^ Also known under various other names including: WinAntiVirusPro, ErrorSafe, SystemDoctor, WinAntiSpyware, AVSystemCare, WinAntiSpy, Windows Police Pro, Performance Optimizer, StorageProtector, PrivacyProtector, WinReanimator, DriveCleaner, WinspywareProtect, PCTurboPro, FreePCSecure, ErrorProtector, SysProtect, WinSoftware, XPAntivirus, Personal Antivirus, Home Antivirus 20xx, VirusDoctor, Your PC Protector, and ECsecure

References

External links


Wikimedia Foundation. 2010.

Игры ⚽ Нужно решить контрольную?

Look at other dictionaries:

  • Winfixer — 2005 Cet article fait partie de la série Programmes malveillants Virus Cabir MyDoom.A Tchernobyl …   Wikipédia en Français

  • Winfixer 2005 — est un faux utilitaire qui est présenté sur le site de l éditeur comme un logiciel de protection du système ; il réparerait les fichiers corrompus, nettoierait la base de registre, réparerait les erreurs du disque dur, etc. Sommaire 1… …   Wikipédia en Français

  • Drivecleaner — Winfixer 2005 Cet article fait partie de la série Programmes malveillants Virus Cabir MyDoom.A Tchernobyl …   Wikipédia en Français

  • Registry cleaner — A registry cleaner is a type of software utility designed for the Microsoft Windows operating system whose purpose is to remove redundant or unwanted items from the Windows registry. However the necessity and usefullness of registry cleaners is a …   Wikipedia

  • Rogue software — Rogue security software is software that uses malware (malicious software) or malicious tools to advertise or install itself or to force computer users to pay for removal of nonexistent malware. Rogue software will often install a trojan horse to …   Wikipedia

  • Spyware — is a type of malware that can be installed on computers, and which collects small pieces of information about users without their knowledge. The presence of spyware is typically hidden from the user, and can be difficult to detect. Typically,… …   Wikipedia

  • Antivirus software — Antivirus redirects here. For antiviral medication, see Antiviral drug. Antivirus or anti virus software is used to prevent, detect, and remove malware, including but not limited to computer viruses, computer worm, trojan horses, spyware and… …   Wikipedia

  • Scareware — Not to be confused with careware or shareware. Scareware comprises several classes of scam software with malicious payloads, or of limited or no benefit, that are sold to consumers via certain unethical marketing practices. The selling… …   Wikipedia

  • Browser hijacker — A browser hijacker is a form of malware or spyware that replaces the existing internet browser home page, error page, or search page with its own. These are generally used to force hits to a particular website. Morwill Search Morwill Search is a… …   Wikipedia

  • Vundo — Vundo, or the Vundo Trojan (also known as Virtumonde or Virtumondo and sometimes referred to as MS Juan) is a Trojan horse that is known to cause popups and advertising for rogue antispyware programs, and sporadically other misbehavior including… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”