# Need Help Removing Insidious Winfix Spyware

**URL:** <https://boards.straightdope.com/t/need-help-removing-insidious-winfix-spyware/335865>\
**Category:** Factual Questions\
**Created:** [December 16, 2005, 4:40am UTC](https://boards.straightdope.com/t/need-help-removing-insidious-winfix-spyware/335865 "2005-12-16T04:40:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Torgo](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Torgo](https://boards.straightdope.com/u/Torgo)\
**Post date:** [December 16, 2005, 4:40am UTC](https://boards.straightdope.com/t/need-help-removing-insidious-winfix-spyware/335865/1 "2005-12-16T04:40:40Z")

</div>

Yikes, I’ve got this S/W from hell on my work computer from some company called Winfix and I cannot get rid of it. Spybot doesn’t detect it, I’ve deleted my temporary files and all my cookies and it’s still there. Any suggestions would be appreciated.

---

<div class="post-metadata">

**Author:** ![Ponster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ponster/32/17081_2.png) [@Ponster](https://boards.straightdope.com/u/Ponster)\
**Post date:** [December 16, 2005, 10:28am UTC](https://boards.straightdope.com/t/need-help-removing-insidious-winfix-spyware/335865/2 "2005-12-16T10:28:43Z")

</div>

You probably know already but there seem to be a couple of different ways to get rid of it…  
[http://forums.spywareinfo.com/lofiversion/index.php/t58173.html](http://forums.spywareinfo.com/lofiversion/index.php/t58173.html)

[http://www.howtofixcomputers.com/bb/ftopic136241-0-asc-30.html](http://www.howtofixcomputers.com/bb/ftopic136241-0-asc-30.html)

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [December 16, 2005, 1:35pm UTC](https://boards.straightdope.com/t/need-help-removing-insidious-winfix-spyware/335865/3 "2005-12-16T13:35:41Z")

</div>

Ah, yes. Vundo. I’ve written up some instructions here: [http://www.siena.edu/antivirus/viruses/vundo.asp](http://www.siena.edu/antivirus/viruses/vundo.asp). They are not for prime time, since there have been some changes in the tools since I wrote it, but it will show you what to look for (O20 - Winlogon Notify: jkhhi - C:\WINDOWS\system32&lt;random characters\>.dll in your hijackthis log) and a procedure that does work if followed carefully.
