Forum Home
Press F1
 
Thread ID: 95578 2008-12-10 21:59:00 I have Malware, Help! rybear4513 (14398) Press F1
Post ID Timestamp Content User
727498 2008-12-10 21:59:00 I have the Winweb malware on my Alienware laptop - Service pack 2

Everything I have done here I have done in Safemode and Regularmode

I have tried system restore in safe and regular mode - neither seem to work, I get to the "click next, this may take a moment" after I have selected my restore point and I click next and nothing happens, no matter how many times I click next nothing will happen, no matter how long I wait, but if I hit cancel System restore the window closes right down with no problem .

I have installed ZoneAlarm, A Squared, AVG, and etc . . . None seem to work . A squared found about 9 threats which I deleted - they were trojans, back door trojans, etc . . . But still WinWeb runs fine . I did Download Malwarebytes and Spyware Doctor but neither will install .

I have tried searching my hard drive for Winweb and all the different file names that are listed on the internet but none will show search results on my PC . I have also tried the classic CTRL ALT DELETE and ending the process but with 30-40 processes running it is near to impossible to tell which is Winweb because Winweb seems to be disguised .

I am truly stumped - I have a lot of important information on this PC that I need to save .

How much does Geeksquad charge to fix something like this?

I am really trying to avoid reformating my hard drive .

Help is appreciated, thanks!
rybear4513 (14398)
727499 2008-12-10 22:03:00 Have you tried Microsoft's malware removal tool (www.microsoft.com)?
It's a basic step, but if you havn't then I sugggest you try.

What are the symptoms and effects of this malware? I ran a google search but it appears to me as being a program to remove malware??

Best of luck
Curbd (13334)
727500 2008-12-10 22:06:00 download malwarebytes (http://www.malwarebytes.org/) and see if that helps.

cheers
GameJunkie (72)
727501 2008-12-10 22:06:00 Disable system restore, reboot, then try malwarebytes again

Try trojan remover below as well. Update it first, scan, then select all options under utilities as well
Speedy Gonzales (78)
727502 2008-12-10 22:07:00 download malwarebytes (http://www.malwarebytes.org/) and see if that helps.

cheers

He did, it didnt install
Speedy Gonzales (78)
727503 2008-12-10 22:09:00 He did, it didnt install


woops:D

didn't see that in his post, lol
GameJunkie (72)
727504 2008-12-10 22:14:00 By the looks of it malwarebytes should remove it

Here (www.bleepingcomputer.com)

Disabling system restore may let you install it

Or get ccleaner (www.ccleaner.com) run it, go to tools/startup, then delete the startup entries for it, reboot then try to install malwarebytes

Just make sure the entries in startup, belong to it
Speedy Gonzales (78)
727505 2008-12-11 01:56:00 Have you tried Microsoft's malware removal tool (www.microsoft.com)?
It's a basic step, but if you havn't then I sugggest you try.

What are the symptoms and effects of this malware? I ran a google search but it appears to me as being a program to remove malware??

Best of luck

The effect is anytime I try to search the web it will redirect whatever link i click to some spam site

It also seems to have put a a Trojan Downloader and Tracker onto my computer

It freezes my computer often, so really trying to do anything on it is a pain

I'm going to try Disable System Restore to see if that works...I'll let you all know

Thanks
rybear4513 (14398)
727506 2008-12-11 02:00:00 Its rogue software, it says it removes malware, when in fact it does jack

It installs more crap on your system. Its like Antivirus 2008 / 2009
Speedy Gonzales (78)
727507 2008-12-11 03:04:00 If the malware is stopping you from going to sites and downloading the removal tools, Click on this (download.bleepingcomputer.com) -- Its a direct download of Malwarebytes, that should come through. Install and run in full scan mode - after disabling System Restore.

Once run, then get Spyware Terminator, as well as Spybot S&D from my sig, install and run as well in full scan mode.
wainuitech (129)
1 2