Malware

Rogue:Win32/Winwebsec removal guide

Malware Removal

The Rogue:Win32/Winwebsec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue:Win32/Winwebsec virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify UAC prompt behavior
  • Attempts to modify user notification settings

How to determine Rogue:Win32/Winwebsec?


File Info:

crc32: 8913ED6E
md5: 111fc7d82191876ea87a7683451c02fe
name: 111FC7D82191876EA87A7683451C02FE.mlw
sha1: 4f5849be0aadb8b3dd7398822c9144c5d9db5123
sha256: 4e117a1dfe9f2decdad78be3ec59e3b19302baff683d6f8f2fe4b122976a0131
sha512: 28ceb267372579dd270a9174e5597b1fba5f5e9e2d651c1de53775a24152779e384c22fb6854f3ff4edc7e7bdd65fa869f5848766249b8133e5dd5b3fe7a9b9f
ssdeep: 12288:SRObekMjd2UXxIM0bWfKqV4anwfsi9bT3Q38z9wgUT5b+8iG:0Obeky2mX0bB61nwf9AM6gUT5xiG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Rogue:Win32/Winwebsec also known as:

BkavW32.Common.58D4DD98
DrWebTrojan.Fakealert.41063
MicroWorld-eScanGen:Variant.Delf.212
FireEyeGeneric.mg.111fc7d82191876e
McAfeeRansom-FEY!111FC7D82191
CylanceUnsafe
VIPRETrojan.Win32.FakeAV.rr (v)
AegisLabTrojan.Win32.Badur.4!c
SangforVirus_Suspicious.Win32.Sality.ae
BitDefenderGen:Variant.Delf.212
K7GWAdware ( 004cce391 )
K7AntiVirusAdware ( 004cce391 )
BitDefenderThetaAI:Packer.1693FF7114
CyrenW32/A-91f55188!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Winwebsec.PGVLBM
TrendMicro-HouseCallHT_FAKEAV_EI0901DE.UVPM
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaAdWare:Win32/SystemSecurity.9d6c8881
NANO-AntivirusTrojan.Win32.FakeAV.cwecch
RisingRogue.Winwebsec!8.B21 (CLOUD)
Ad-AwareGen:Variant.Delf.212
TACHYONTrojan/W32.Badur.769536
SophosMal/FakeAV-KL
ComodoApplication.Win32.Winwebsec.A@57i387
F-SecureHeuristic.HEUR/AGEN.1110398
TrendMicroHT_FAKEAV_EI0901DE.UVPM
McAfee-GW-EditionRansom-FEY!111FC7D82191
EmsisoftGen:Variant.Delf.212 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1110398
KingsoftWin32.Troj.Badur.fz.(kcloud)
MicrosoftRogue:Win32/Winwebsec
ArcabitTrojan.Delf.212
SUPERAntiSpywareTrojan.Agent/Gen-Winwebsec
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Delf.212
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.C234061
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Delf.212
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2229267305
ESET-NOD32a variant of Win32/Adware.SystemSecurity.AP
TencentMalware.Win32.Gencirc.10b4919a
YandexTrojan.Badur!Sh9cUUpW8+o
IkarusTrojan.Win32.FakeAV
eGambitGeneric.Malware
FortinetW32/FakeAV.KL!tr
WebrootW32.Rogue.Gen
PandaTrj/Genetic.gen
Qihoo-360Win32/Trojan.447

How to remove Rogue:Win32/Winwebsec?

Rogue:Win32/Winwebsec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment