One of our computers was infected with a lovely gem of a product called “WinWeb Security” - not affiliated with winweb.com, this is a program the installs itself and pretends to be an antivirus program, telling you your computer is infected with a wide variety of issues. When you attempt to use the program, you are only able to if you pay $49.99. Unfortunately, this program does NOT clean up your computer, it actually installs vicious trogans, spyware and viruses and royally screws the computer and user up.
After spending 6 hours last night and 4 hours this morning fixing this problem (my personal/work computer is pretty darn secure so I don’t have a lot of experience with these things!), I am compelled to write a post to assist anyone else having this problem.
Symptoms of the problem: Unable to visit any spyware removal websites, unable to install or run any removal or anti virus programs, popups saying you are infected, pop ups that appear to be advertising pop ups (even using Firefox), Google search results not going to the actual website but to go.google.com/example, and the WinWeb “Security” program icon/window on your computer. There may be others but those are the main ones I experienced.
How this happened: Lax security on your computer most likely. The computer involved (not my own) had the Firewall disabled and someone who was not the normal user went to a variety of ….. bad ….. websites, without that without firewall in place, the program was able to easily infect many areas of the hard drive.
How to fix it: Basically, 3 main things: Firewall your computer, get a (free) antivirus program, and a (free) malware removal program. This isn’t going to cost you anything if you are a Windows user. 2 websites (listed below in references) were instrumental in assisting me get rid of this problem, and if you are infected, you won’t be able to view the websites, so I will link them but give the run down on how I fixed it, which will also streamline the process. Expect to spend hours on this, but it’ll be boring so have a book or knitting handing.
Step 1. Make sure your Firewall is ACTIVE. In XP with the classic menu, Start>Settings>Control Panel>WIndows Firewall. Make sure it is on, then go to the exceptions tab and uncheck anything you don’t recognize. If you are unable to get to a website or play a game (make sure it’s a honest site!), you can go back and recheck as needed. Then in the Control Panel, go to Add/Remove Programs and uninstall WinWeb Security if it is there (it wasn’t in mine)
Step 2. Go to downloads.com and download Avira AntiVir Personal Install, but don’t run yet (disable it if it tries to run, as well as any other virus checkers). Now download Malwarebytes Anti-Malware. Install this program, and allow an icon to be placed on your desktop. Right click on the Malwarebytes icon and select Properties, then click on the Find Target button. A window will open with the icon highlighted. Right click on this icon and rename it to *anything* (I named mine lalalala), then launch it by double clicking it. WinWeb is VERY sneaky and makes these programs not work. By renaming it, it will run.
Step 3. With Malwarebytes open, select Quick Scan first, before anything else. It’ll take a while, get the book or knitting out. Let it quarantine the files it finds, delete them, then restart your computer. When it’s back up, run Malwarebytes again, but go to the Update tab and update the program. Do another Quick Scan, restart again. Repeat one more time.
Step 4. With the computer restarted, you’re still going to have WinWeb trying to get into your computer’s pants. Deleting virus ridden registry entries is next. Go to Start>Run and in the space provided, type “regedit” - without the “” quotes of course - and a window will come up with all your computer’s registry files. There are 3 to remove (I only had 2 of them, but make sure anyway):
1. HKEY_CLASSES_ROOT\CLSID\{D5DF7C9D-6069-4552-8B0C-D02A912FC889}
2. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5DF7C9D-6069-4552-8B0C-D02A912FC889}
3. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “WinwebSecurity”
For example, to remove number 1, find and open the HKEY_CLASSES_ROOT folder, then find and open the CLSID folder, the find the {D5DF7C9D-6069-4552-8B0C-D02A912FC889} folder (easiest way is to look for the D5D and make sure the ending is the 889). Don’t open this folder, just right click and delete the whole thing. Do the same with number 2 and 3. Restart your computer.
Step 5. Run Malwarebytes but do a Full Scan time, then run the Avira program. Update the program if it asks you to, then let it run. You need to stick close because each time it finds an infection it’ll ask you what to do with it (select quarantine). Once this program is done, go to the administation tab>quarantine and delete all the quarnatined files, then restart your computer. You should now be WinWeb free. If you aren’t, shoot me an email and I’ll see if I can help, but only if you’ve ALREADY done everything listed here, or are willing to bring me your computer and pay me to fix it!
References:
http://www.bleepingcomputer.com/malware-removal/remove-winweb-security
http://forums.cnet.com/5208-6132_102-0.html?forumID=32&threadID=300720&start=0&tag=forum-w;forums06
http://www.download.com/Avira-AntiVir-Personal-Free-Antivirus/3000-2239_4-10322935.html?tag=mncol
http://www.malwarebytes.org/