Newbie dot Org HomePage
Visit one of our web buddies
WEBSHOTS will not uninstall
Amarie

01/23/04
I installed Webshots, and now my computer is running slow & freezing. I'm unable to do a restart, or a shut down from the start menu, and It won't let me CRTL ALT DELETE, when this happens.
I have to hit the power button to shut it down.

I went in to do an uninstall, when it pulled up I tried the automatic uninstall 1st, it turned everything white and froze. I tried it 2 more times with the same thing happening. I tried twice to uninstall using the custom feature, it's doing the same thing. It will not uninstall-Help!

Amarie

01/23/04
Hi Amarie. Webshots installs spyware on your computer (NewDot.net and/or WebHancer). The program needs to be uninstalled from your computer and don't ever download it again...

Ok. You need to go look in Control Panel, Add/Remove Programs, if you see anything on Webshots, NewDot.net, or NewNet, or WebHancer ; if so, uninstall. Then you need to download SpyBot Search and Destroy (which is a free spyware removal tool), update it and run it. Tell us how things are going after that.

Don't believe Webshots is bad? Read this :

http://info-center.ccit.arizona.edu/~ccitinfo/newsletters/march2002/problems_with_webshots.html

Mark

01/23/04
Oopsss... I wrote your name instead of mine... please overlook!
Mark

01/23/04
Just to make sure you get SpyBot and run it properly, here's a link with a "tutorial" that should help you and others with this great little program.

http://tutorials.nerocom.us/spybot/

Good luck!

AMARIE

01/23/04
Hi, and Thank you.

Add/Remove Programs aren't showing anything for NewDot.net, NewNet or WebHancer.

Infact it hasn't even showed Webshots since, the 1st time I tried to uninstall it. Since then I've had to go in and pull up the folder and try uninstall it. But I still get the same thing, it turns the screen completely white and freezes, without finishing.

I've had spybot and ad-ware both for awhile, I did run them and here is what they have found.
Ad-Ware---
Data Miner-Mediaplex
Data Miner-Infusion
Data Miner-gateway user@atdmt(2).txt

Spybot---
AVENUE A, INC.

I also checked it W/ HouseCall and they found---
5 TROJ WINPUP.B in C:\_RESTORE\TEMP\
17 TROJ WINPUP.B in C:\_RESTORE\ARCHIVES\
9 TROJ WINPUP.B in C:\WINDOWS\SYSTEM\
TROJ WINPUP.B in C:\Program Files\puu.exe
TROJ WINPUP.B in C: Program Files\Over.exe

A friend of mine recommended that I try Trojan remover since the housecall found these, but When I downloaded Trojan Remover it is finding Nothing, at all.

Since I don't have a paid subscription w/webshots I'm unable to go through them for any help...

Thanks again

li

01/23/04
here are Description and removal instructions:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_WINPUP.B

or to doublecheck first:

You can check a single file here at Kaspersky:
http://www.kaspersky.com/remoteviruschk.html

or run another online scan, say here:
http://www3.ca.com/virusinfo/virusscan.aspx
or here:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Fixing the trojan is the first step.

AMARI

01/23/04
Hi, again, Not to be a pain, But I think I may have screwed up! I went into my search for files and folders and typed in everything that HOUSECALL Found on the 1st scan and I deleted them.
While I was doing that I was looking around other folders and when I came back on to do another HouseCall Scan, its no longer picking up the ones that showed before, but it appears to be picking up things Ive accessed since, then.

I had clicked on my adobe acrobat folder and I ran spybot again- & now this is showing up on the housecall scans.

TROJ WINPUP.B C:\WINDOWS|SYSTEM\dobeA.exe

C:\WINDOWS|SYSTEM\pybot.S

I had also Opened my recycle bin
and Housecall is showing
C:\RECYCLED\DC19exe
C:\RECYCLED\DC18exe

Should Housecall be picking up all these things and showing them as A TROJ WINPUP.B.
Im completely confused as to what to do next..
Any help appreciated

Mark

01/23/04
Ok Amarie, you need to take a deep breath...

I'm guessing you're running Windows ME. You will need to deactivate System Restore before you attempt any more deletions. The bugger is in Restore, therefore protected by Windows, and will come back, and back, etc... Shutting down Restore is essential here (for ME and XP).

Do the Housecall scan again. Post back.

BTW, Winpup is a bitch to remove... this may need a little more work!

Amarie

01/25/04
Your right, I have windows ME, I went in and turned off system restore, and started in safemode and was able to get rid of the rest.
After all that my uninstall finally worked and got rid of the webshots, completely.

My housecall scans are finally free of anything.

I do have one more ? concerning the winpup B. according to housecall, you get it from 1 website- the websites name isn't familiar to me or my husband, could it have possibly came from a site other than the one housecall listed it as being from?

THANKS AGAIN- You've been of great help!

Mark

01/25/04
Hi Amarie. Glad to see you're clean! About the reference from Trend-Micro (housecall) : I think that the source may be the one site in question, but that URL can be thrown at you from multilple sources (forced popups, etc...) making it impossible to trace to a specific site that you or any other user may have visited. Don't worry, it happens to all of us at one point or another... You can check some articles, listed on Newbie homepage, concerning security settings in your browser and safe surfing practices... couldn't hurt to learn a little more on how malware hits, and how to protect yourself a little more.


© Copyright 1998-2004 Newbie dot Org -- All rights reserved --



This site maintained by Galaxy Website Design


--|--