WinFixer

By Domesticus in Spyware

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 41
First Seen: July 24, 2009
Last Seen: April 10, 2026
OS(es) Affected: Windows

WinFixer is a deceitful application that reports exaggerated scan results, claiming that a PC is infected with numerous malware. After displaying a number of security warnings and irritating pop-ups, WinFixer will convince a user to purchase its "full version" in order to remove all the purportedly detected malware. WinFixer cannot be trusted as it is not able to detect or remove any real malware.

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sophos Mal/EncPk-AA
McAfee New Malware.dq
eSafe SuspiciousR-Mytob6
AntiVir HEUR/Malware
AntiVir ADSPY/WinAntiVi.A.1
Prevx1 Rogue.WinAntiVirus
Panda Application/WinAntiVirus2007
Ikarus not-a-virus:Downloader.Win32.WinFixer.o
F-Prot W32/Adware.WVE
eWido Not-A-Virus.Downloader.Win32.WinFixer.o
ClamAV Adware.Downloader-23
CAT-QuickHeal Downloader.WinFixer.o (Not a Virus)
BitDefender Trojan.Downloader.WinFixer.Z
AVG Potentially harmful program WinFixer.YY
Prevx1 Malware.Gen

SpyHunter Detects & Remove WinFixer

File System Details

WinFixer may create the following file(s):
# File Name MD5 Detections
1. install_sbd_de[1].exe 292739d4882dca2f27548cedc6eafbd7 0
2. installer_en.exe 0b3f8dd90df5a9d7283ab2ce0aef050f 0
3. setup_fr.exe fe1145788e91d3af3bed4a6788f5b76f 0
4. mc.exe dm=http://www.retailchoice.com; ad=http://www.retailchoice.com d6cb8f28090f5bd8d182dfdf4697f9ac 0
5. strpmon.exe dm=http://syslibero.com ad=http://syslibero.com sd=http://napa.syslibero.com 13ba6b9c6e00566ce9cad492643e7b3f 0
6. udcwap.exe 95f88d204efdc83dc15ac76d9d179a5a 0
7. dcsm.exe 4e55c9c40d436668693454d883b78110 0
8. UDC6cw.exe 1c8d3c48d11f8db10daec8818d3702ce 0
9. UDC2006.exe b63b4cb44722ac1e398d8d98e7248abc 0
10. arpl.exe 30973be879616e61e89bca0a5963cbab 0
11. UINST.EXE e9c187a563d1a09a4784a19f2ff5a470 0
12. UERTcw.exe 2bc1aa2033f01f6d2ae92b427068d3a9 0
13. strpmon.exe dm=http://erreurchasseur.com; ad=http://erreurchasseur.com 5695418916dd970d89e2337c9361aceb 0
14. UGDCcw.exe 5aeccee8d7e4282bbe9fdb273bded362 0
15. mav_startupmon.exe b7cb2f8cde97389c7a14c3a595f98fd9 0
16. uwa7pcw.exe f814e80e800dd1008869a2dc2cc88b1e 0
17. setup_es[1].exe 118f47aca75709328ca2f500916b107d 0
18. uga6pcw.exe 2b1599af1d979fc5546b6fafb5ad409e 0
19. udcsdr.exe 77721491373ae3f3c7a9ca3d2dc2e27d 0
20. erscw.exe 5eead3be5a35c4ff647b1785e0e49aa9 0
21. installer_de[1].exe 209191b889c1666823265912dcaaad5d 0
22. install_de[1].exe bc95339e95cef900ab912d83f2f3a4fd 0
23. USDR6cw.exe 892975b9abea85686e50691f684079df 0
24. setup_en[1].exe dce0436953efae3ea0302718b8c0c1e4 0
25. install_en[1].exe 9849091148d9ab6fc5e35704b50eeb06 0
26. newsoftware2007install[1].exe ff63fc6c45107b30f8fc230c4cb996d5 0
More files

Analysis Report

General information

Family Name: Rogue.Winfixer
Signature status: No Signature

Known Samples

MD5: 59f4dd2f4960e552a3b1336bce774cef
SHA1: 646b7be8c77c650e79d50a28db55a23b99708e71
SHA256: A5B11CE1B1BDCAF5AB76E748634B527B11EEDCC2D72D2166AB92CDADE49E9CEE
File Size: 3.80 MB, 3795634 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name Privacy-Care Lab.
File Description OneClick Spyware Expert Setup
File Version 1.17.1.0
Product Name OneClick Spyware Expert
Product Version 1.17.1.0

File Traits

  • ntdll
  • x86

Related Posts

Trending

Most Viewed

Loading...