WiniBlueSoft manual removal:
Kill processes:
WiniBlueSoft.exe 13951spzmb9t5a2.exe 14041hackt5zl99.exe uninstall.exe 19524spyze9.exe 19991not-a-v5rzs1c9.exe 19z43hacktoo965f.exe A0070788.exe ijjistarter2.exe HDExtrem.exe
Delete registry values:HKEY_CURRENT_USER\Software\WiniBlueSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WiniBlueSoft
HKEY_LOCAL_MACHINE\SOFTWARE\WiniBlueSoft
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "setup2.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WiniBlueSoft"
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{bd19cc12-f8a2-475c-846b-0af337b47940}\NameServer
Unregister DLLs:111znot-a-v5rus998.dll 11797tzoj595.dll 12946sz5mbot79c.dll 129cvir1z58.dll 12bbszy5ar91941.dll 19945hzcktool65b.dll
Delete files:always_skip.xml data.bin License.txt main_config.xml uninstall.exe WiniBlueSoft.exe WiniBlueSoft.lnk Homepage.lnk Uninstall.lnk WiniBlueSoft.lnk 102959roz2b45.ocx 10325virusz955.ocx 10355h9eat227z2.cpl 111znot-a-v5rus998.dll 115z1vi9us3e85.ocx 11797tzoj595.dll 1197addwaze16915.ocx 127b95ief305z.ocx 12946sz5mbot79c.dll 129cvir1z58.dll 12bbszy5ar91941.dll 13323w95mz1b.ocx 135zvir1929.cpl 1393z5or9df.ocx 13951spzmb9t5a2.exe 14041hackt5zl99.exe 19199hackt5zl7a1.bin 19524spyze9.exe 19544spy6fbz.ocx 19945hzcktool65b.dll 19991not-a-v5rzs1c9.exe 19z43hacktoo965f.exe HDExtrem.exe 1a59dow9lozder1735.ocx 1b20z9a5se2186.bin S-5-4-33-100030900-100005361-100010101-6637.com My Music.url My Pictures.url My Video.url My Documents.url
Delete directories:c:\Program Files\WiniBlueSoft Software
c:\Program Files\WiniBlueSoft Software\WiniBlueSoft
c:\Documents and Settings\All Users\Start Menu\Programs\WiniBlueSoft
C:\WINDOWS\system32\gaopdxcounter
it is also related to this winibluesoft crap.
Post Comment: