We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

winwebsecurity????

245

Comments

  • fedupnow
    fedupnow Posts: 931 Forumite
    Hi All

    It's not the combifix itself that puts me off it's the other recovery thing. I have printed and read the instructions and if the combifix does damage something I honestly don't think I am competent enough to do the 'recovery' bit.

    It's not popping up or anything.... it's only that I KNOW it is there.

    I really wish I didn't.

    I have to search for the two things that remain in c docs and settings\allusers\application data\winwebsecurity. When I try to delete it says access is denied - make sure the disk is not full or write-protectedand that the file is not currently in use.

    I have ran spybot soooo many times - nothing.

    I have tried ctl alt del to delete any winweb from the processes - but it just isn't there, the closest thing I can find is winlogon.exe - I daren't delete that.

    Ahhh shucks
  • Marty_J
    Marty_J Posts: 6,594 Forumite
    fedupnow wrote: »
    I have to search for the two things that remain in c docs and settings\allusers\application data\winwebsecurity. When I try to delete it says access is denied - make sure the disk is not full or write-protectedand that the file is not currently in use.

    I have ran spybot soooo many times - nothing.

    I have tried ctl alt del to delete any winweb from the processes - but it just isn't there, the closest thing I can find is winlogon.exe - I daren't delete that.

    Ahhh shucks

    As I suggested previously, try restarting in safe mode and deleting it.
  • fedupnow wrote: »
    Hi All

    It's not the combifix itself that puts me off it's the other recovery thing. I have printed and read the instructions and if the combifix does damage something I honestly don't think I am competent enough to do the 'recovery' bit.

    I have tried ctl alt del to delete any winweb from the processes - but it just isn't there, the closest thing I can find is winlogon.exe - I daren't delete that.

    Ahhh shucks

    The recovery things a built in safety feature - it did not feature at one time - Loads of people have run it - the choice however is yours.

    Do Not remove winlogon.exe.

    Try deleting the files is safe mode as already suggested and also post a Hijack log.
  • Airwolf1
    Airwolf1 Posts: 1,266 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    My suggestion and/or advice is my own and it is up to you if you follow it, please check the advice given before acting on it.
  • Here some instructions for the above;

    Please run the F-Secure Online Scanner

    Note: This Scanner is for Internet Explorer Only!
    • Follow the Instruction here for installation.
    • Accept the License Agreement.
    • Once the ActiveX installs, Click Full System Scan
    • Once the download completes, the scan will begin automatically.
    • The scan will take some time to finish, so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    Click the Show Report button and Copy & Paste the entire report in your next reply.
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I suspect if you wait a few days then Malwarebytes will get rid of it , but in the meantime I would do NO secure transactions like banking , no entering usernames/passwords for web sites etc as thereis a VERY high chance that the whole security on the PC is compromised

    personally I would run combifix now and be safe , nothing else is liable to touch it and it will show us what files have been recently added so we can remove the offending crap
    Ex forum ambassador

    Long term forum member
  • Airwolf1
    Airwolf1 Posts: 1,266 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    This site may help, instructions to remove it are about a third of the way down. As I've not got the problem, I can't try it.
    My suggestion and/or advice is my own and it is up to you if you follow it, please check the advice given before acting on it.
  • The use of Avenger would appear to be over kill to me, especially to kill a run key and a Browser Hijack, OTMoveIt3 will do the job.

    Having said all that it would help to see a log of some format to establish the rogue files.

    It also mentions using superantispyware.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.2K Work, Benefits & Business
  • 600.8K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.