Home Malware Programs Rogue Anti-Spyware Programs Winweb Security 2008

Winweb Security 2008

Posted: November 25, 2008

Threat Metric

Threat Level: 10/10
Infected PCs: 5
First Seen: July 24, 2009
Last Seen: August 3, 2019
OS(es) Affected: Windows

Winweb Security 2008, or Winweb Security, is a fake anti-spyware program that uses fake system messages as a scare tactic. Winweb Security 2008 is a clone of Power Antivirus 2009, Antivirus 2009, Vista Antivirus 2008 and Antivir64. Winweb Security 2008 is often downloaded and installed by a Trojan, through browser security holes, or via other unconventional and unethical mechanisms.

Winweb Security 2008 attempts to get computer users to believe that they must purchase the full version of Winweb Security 2008 to "fix" their computer. Winweb Security 2008 may come from a Trojan infection or a malicious website. Winweb Security 2008 may be difficult to manually remove in some cases.

Aliases

Mal/FakeAV-O [Sophos]Suspicious:W32/Kolweb.d!Gemini [F-Secure]Suspicious file [Panda]TROJ_RENOS.APT [TrendMicro]Downloader.MisleadApp [Symantec]Troj/Fakevir-HW [Sophos]Adware/WinWebSecurity2008 [Panda]Program:Win32/Winwebsec [Microsoft]FakeAlert-WinwebSecurity [McAfee]not-a-virus:FraudTool.Win32.WinwebSecurity.j [Kaspersky]Trojan.Win32.Malware.1 [K7AntiVirus]W32/FakeAlert.AB!tr [Fortinet]FraudTool.Win32.WinwebSecurity.j [F-Secure]Trojan.Generic.1225403 [BitDefender]Agent.AOJQ [AVG]
More aliases (23)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



371143239.exe File name: 371143239.exe
Size: 2.36 MB (2369573 bytes)
MD5: cac57a33850e06e284b2c6030cac4228
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
576829178.exe File name: 576829178.exe
Size: 2.36 MB (2369570 bytes)
MD5: c18bc1e1d92efa0050b33f17e91c7c2b
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1478596346.exe File name: 1478596346.exe
Size: 2.36 MB (2369570 bytes)
MD5: a8e3f0b1bccc7499f9b11ac981fea8d6
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1881679086.exe File name: 1881679086.exe
Size: 2.36 MB (2369570 bytes)
MD5: 93a6b31af97c011088dec95d05fc5773
Detection count: 82
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
562162198.exe File name: 562162198.exe
Size: 2.36 MB (2369570 bytes)
MD5: 8bfb331fc503d7a93e5465e73358162c
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
144089170.exe File name: 144089170.exe
Size: 2.36 MB (2369573 bytes)
MD5: cd88d02908458ef7d407a39f895301d7
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
774105778.exe File name: 774105778.exe
Size: 2.36 MB (2369573 bytes)
MD5: 2de29dac76e2859fca7e182132ee1b89
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1696892500.exe File name: 1696892500.exe
Size: 2.36 MB (2369573 bytes)
MD5: c69a9ed93ef90e1f99589286f5885e86
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1130366974.exe File name: 1130366974.exe
Size: 2.36 MB (2369573 bytes)
MD5: 8caaa248d21e7a665b4aada0f72dba59
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1660584046.exe File name: 1660584046.exe
Size: 2.57 MB (2573349 bytes)
MD5: db291db3dce153a2b1139686d8dea817
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
450939823.exe File name: 450939823.exe
Size: 2.57 MB (2573349 bytes)
MD5: dd4aff78e7563bb99b9af96be553547b
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1902582584.exe File name: 1902582584.exe
Size: 2.36 MB (2369573 bytes)
MD5: 4c18d604bf9fe6ffa108ec7bbbad0a95
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1330376102.exe File name: 1330376102.exe
Size: 2.57 MB (2573349 bytes)
MD5: 4139b6486e51b6769e892e2954adab74
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
AV.exe File name: AV.exe
Size: 540.47 KB (540472 bytes)
MD5: 66497945cd1418e8b10c5939f3e2bfbc
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
1800045027.exe File name: 1800045027.exe
Size: 2.36 MB (2369570 bytes)
MD5: 38473e33f940c8e0f1da321c95d5c667
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%UserProfile%\Application Data\??????????\[NUMBERS].exe

3 Comments

  • Amee says:

    Finally ! a site mentioning winweb 2008 Security! I've been wanting to get rid of it for a couple of days now!Thanks for having such an informative site!You're the first I've seen that has actually mentioned this malware!

  • Whyt Me says:

    And how about the following crap?
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5DF7C9D-6069-4552-8B0C-D02A912FC889}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinwebSecurity

  • do not want says:

    DON\\\'T WANT THIS PROGRAM

Loading...