Winwebsec

Winwebsec is a category of malware that targets the users of Windows operating system and produce fake claims as genuine anti-malware software, then demand payment to provide fixes to ficticious problems.

Winwebsec

These are programs that generate misleading alerts and false detections in order to convince users to purchase illegitimate security software. Some of these programs, including Win32/Winwebsec, may display product names or logos of some well known companies like Microsoft in an attempt to impersonate some genuine products of legitimate companies.

The software shows popup that claim to scan for malware, and displays fake warnings similar to:

They then show a message to the user that they need to pay money to activate the software in order to remove these threats which actually doesn't exist. These malwares may display a dialog that looks similar to Windows Security Center or it may have names like Live Security Platinum or Security Shield. The GUI varies from variant to variant.

Variants

  • Smart Protection 2012
  • Security Sphere 2012
  • Security Shield
  • Win 8 Security System
  • System Progressive Protection
  • Live Security Platinum
  • Personal Shield Pro
  • Smart Fortress 2012

Removal

Few variants of this malware can be removed by using software and tools like McAfee Stinger or Microsoft Windows Malicious Software Removal Tool. Most variants of this malware prevents the user from accessing internet browsers and programs with names like chrome.exe, firefox.exe, iexplore.exe, opera.exe and safari.exe. Users infected with this virus may have to boot the computer into advance boot options like safe mode to diagnose these virus variants. The continuously changing nature of these viruses makes it hard for security software to detect and remove them.

Annotation/Proposal: dismount the drive, install it in an external (USB) case and open the infected drive as external USB drive on another computer. Thus, all files on the infected drive can be viewed, deleted, etc. For security reason, disable "autoplay" for this USB drive first.

Similar Articles

  • Rogue security software
  • Social engineering (security)
  • List of rogue security software
  • Scareware