Bit of a computer issue ...

For tech wizards and n00bs alike. Questions, answers, or just general hoo-haa.

Moderator: Moderators

Post Reply
Message
Author
User avatar
Neoscryer
Citizen
Posts: 54
Joined: Wed Jul 02, 2008 6:04 am
Location: USA
Fav. Twokinds Character: Natani

Bit of a computer issue ...

#1 Post by Neoscryer »

Okay. I don't know how this happened (honestly, I haven't been to any dangerous sites lately ... my brother must've been looking for porn again. Ugh)

Anyway, this spyware/malware called 'WinWeb Security' is downloaded now, popping up bull claims that I have like fifteen Trojans on my computer and I HAVE to buy their product to fix it about once a minute. I'm not an idiot, I know that's a load of crap. But it's a little more than that. I can't use Google, I have to use the direct link otherwise the damned thing re-directs me to sites that are probably only making this worse. I can't open the virus protection I DO have, and manually searching for this program in my files would take hours I don't have.

And I can't seem to download any of the removal programs I have found. ... Help? :(
Image

FastChapter
The Inkwell Coyote
Posts: 9458
Joined: Wed Aug 09, 2006 9:28 pm

Re: Bit of a computer issue ...

#2 Post by FastChapter »

If you've got something that's preventing you from downloading virus protection, anti-spyware, and the like... and it's actively hijacking your browsers, you need to restart your computer in SAFE MODE (smash F8 as it reboots) and try running your antivirus then.

If you still can't do it, reinstall windows and make sure you reformat your hard drive in the process. I'd try saving what vital files you can to a jump drive or something, but be 100% sure you aren't moving infections onto it as well.

User avatar
Demus
Templar
Posts: 386
Joined: Thu Jul 17, 2008 3:09 pm
Location: My own little fortress...
Contact:

Re: Bit of a computer issue ...

#3 Post by Demus »

Google to the rescue!

Of course, first you could try eliminating the process via task manager, which should set your internet free for at least a short amount of time.

Second, I don't trust the removal programs either, so I'd suggest the manual way. Someone has found those files for you already, you see :3
WinWebSecurity2008 Removal instructions wrote:Delete registry values:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "WinwebSecurity"
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\Browser Helper Objects\{D5DF7C9D-6069-4552-8B0C-D02A912FC889}

Delete files:
c:\\Documents and Settings\\All Users\\Application Data\\WinwebSecurity\\config.udb
c:\\Documents and Settings\\All Users\\Application Data\\WinwebSecurity\\init.udb
c:\\Documents and Settings\\All Users\\Application Data\\WinwebSecurity\\WinwebSecurity.exe
c:\\Documents and Settings\\All Users\\Application Data\\WinwebSecurity\\Languages\\English.lng

Delete directories:
C:\Documents and Settings\All Users\Application Data\WinwebSecurity
Although I'm not sure how to deal with registry values... Somebody who has smarts, please?
Image
The shapeshifting cliché!

User avatar
avwolf
Templar Inner Circle
Posts: 7006
Joined: Wed Jan 17, 2007 5:33 pm
Location: Nebraska, USA
Contact:

Re: Bit of a computer issue ...

#4 Post by avwolf »

Demus wrote:Although I'm not sure how to deal with registry values... Somebody who has smarts, please?
Start->Run
Regedit
In the Registry editor that pops up, choose Edit->Search and then paste in the key you want to find. Otherwise you can troll the tree structure of the registry to find the key and delete it.

Be careful! Mucking about in the registry and deleting things you don't know you want to delete is a bad idea. Only delete those registry entries you know are bad.

Another thing to check for is the proxy settings for your computer/IE (under Control Panels: Internet Options) and possibly also Firefox. It's either using a local proxy to redirect all your traffic or it's changed your HOSTS file (in C:\WINDOWS\system32\drivers\etc it's the file called "hosts"). That's a plaintext file without an extension that should probably only have one line that doesn't start with '#'

Code: Select all

127.0.0.1         localhost
If there are any other lines in that file below that line, they're probably evil and should be deleted. Don't be surprised if your malware readds them if it's still running though.

-- Bugger, Fast! --
A reformat? He got some malware, he wasn't hacked! That might just be a bit of overkill. :P
Image

User avatar
Neoscryer
Citizen
Posts: 54
Joined: Wed Jul 02, 2008 6:04 am
Location: USA
Fav. Twokinds Character: Natani

Re: Bit of a computer issue ...

#5 Post by Neoscryer »

avwolf wrote:
Demus wrote:Although I'm not sure how to deal with registry values... Somebody who has smarts, please?
Start->Run
Regedit
In the Registry editor that pops up, choose Edit->Search and then paste in the key you want to find. Otherwise you can troll the tree structure of the registry to find the key and delete it.

Be careful! Mucking about in the registry and deleting things you don't know you want to delete is a bad idea. Only delete those registry entries you know are bad.

Another thing to check for is the proxy settings for your computer/IE (under Control Panels: Internet Options) and possibly also Firefox. It's either using a local proxy to redirect all your traffic or it's changed your HOSTS file (in C:\WINDOWS\system32\drivers\etc it's the file called "hosts"). That's a plaintext file without an extension that should probably only have one line that doesn't start with '#'

Code: Select all

127.0.0.1         localhost
If there are any other lines in that file below that line, they're probably evil and should be deleted. Don't be surprised if your malware readds them if it's still running though.

-- Bugger, Fast! --
A reformat? He got some malware, he wasn't hacked! That might just be a bit of overkill. :P
Okay start>run ... I got that, but in the run menu, there isn't an 'edit' button. Err, am I doing something wrong?

'She', by the way. Sorry, I'm a little picky about that. :P

*EDIT* Oh, and no "Application Data" either.
Image

User avatar
Demus
Templar
Posts: 386
Joined: Thu Jul 17, 2008 3:09 pm
Location: My own little fortress...
Contact:

Re: Bit of a computer issue ...

#6 Post by Demus »

Write "regedit" and press enter.
Av mentioned it, but seems to have slipped past your eyes ^^
Image
The shapeshifting cliché!

User avatar
Neoscryer
Citizen
Posts: 54
Joined: Wed Jul 02, 2008 6:04 am
Location: USA
Fav. Twokinds Character: Natani

Re: Bit of a computer issue ...

#7 Post by Neoscryer »

Demus wrote:Write "regedit" and press enter.
Av mentioned it, but seems to have slipped past your eyes ^^
Ahh, I'm sorry.
Image

User avatar
avwolf
Templar Inner Circle
Posts: 7006
Joined: Wed Jan 17, 2007 5:33 pm
Location: Nebraska, USA
Contact:

Re: Bit of a computer issue ...

#8 Post by avwolf »

Neoscryer wrote:'She', by the way. Sorry, I'm a little picky about that. :P
My apologies. I'll remember in the future.

I think Demus covered the regedit issue.
Neoscryer wrote:*EDIT* Oh, and no "Application Data" either.
Application Data is a hidden directory. In your open directory (folder), go to Tools->Folder Options. Then under the "View" tab, look for the radio button for "Show hidden files and folders." Select that option, click "Apply" and then click "Okay." You should be able to see Application Data now. It'll be sort of ghosted to mark it as hidden, but you should have no problem getting into it to delete what needs removed.
Image

User avatar
Neoscryer
Citizen
Posts: 54
Joined: Wed Jul 02, 2008 6:04 am
Location: USA
Fav. Twokinds Character: Natani

Re: Bit of a computer issue ...

#9 Post by Neoscryer »

avwolf wrote: Application Data is a hidden directory. In your open directory (folder), go to Tools->Folder Options. Then under the "View" tab, look for the radio button for "Show hidden files and folders." Select that option, click "Apply" and then click "Okay." You should be able to see Application Data now. It'll be sort of ghosted to mark it as hidden, but you should have no problem getting into it to delete what needs removed.
Okay ... now I have the Application Data, but no Winweb. And the registry editor just brought me to my brother's Starcraft files. Er, I'm failing at this. I'm sorry guys.
Image

User avatar
avwolf
Templar Inner Circle
Posts: 7006
Joined: Wed Jan 17, 2007 5:33 pm
Location: Nebraska, USA
Contact:

Re: Bit of a computer issue ...

#10 Post by avwolf »

You can walk through the registry using the tree navigation on the left side. Try using that to get to the keys you're looking for.

HKEY_LOCAL_MACHINE...Run will have a lot of values there, make sure you don't accidentally delete any you don't want to delete (I'd right click on the specific entry in the right side and choose delete from the context menu, personally).

You could try searching your registry for "Winweb." It's a safe bet that pretty much anything you find can be deleted.

I don't know what's in the Application Data directory on your system, so I can't really offer any suggestions there, other than to also check the Application Data for your specific user as well as "All Users."
Image

User avatar
Neoscryer
Citizen
Posts: 54
Joined: Wed Jul 02, 2008 6:04 am
Location: USA
Fav. Twokinds Character: Natani

Re: Bit of a computer issue ...

#11 Post by Neoscryer »

Thank you all - it's gone now. I was getting really sick of it.
Image

User avatar
avwolf
Templar Inner Circle
Posts: 7006
Joined: Wed Jan 17, 2007 5:33 pm
Location: Nebraska, USA
Contact:

Re: Bit of a computer issue ...

#12 Post by avwolf »

Excellent news. I hope we were at least some sort of help.

-- Edit --
I apparently experienced a typing fail there. Missing letters have been restored.
Image

FastChapter
The Inkwell Coyote
Posts: 9458
Joined: Wed Aug 09, 2006 9:28 pm

Re: Bit of a computer issue ...

#13 Post by FastChapter »

:P I just hit the big red panic button whenever my computers hiccup.

*glitch* OVERRIDE THE OPERATING SYSTEM AND HIT DELETE!!

User avatar
Demus
Templar
Posts: 386
Joined: Thu Jul 17, 2008 3:09 pm
Location: My own little fortress...
Contact:

Re: Bit of a computer issue ...

#14 Post by Demus »

I still get nightmares about my computer's condition couple years back.

Found out I had loose cable on hard-drive.

I formatted it anyway.
Image
The shapeshifting cliché!

Post Reply