WiniBlueSoft manual removal:
Kill processes:
WiniBlueSoft.exe 13951spzmb9t5a2.exe 14041hackt5zl99.exe uninstall.exe 19524spyze9.exe 19991not-a-v5rzs1c9.exe 19z43hacktoo965f.exe A0070788.exe ijjistarter2.exe HDExtrem.exe
Delete registry values:HKEY_CURRENT_USER\Software\WiniBlueSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WiniBlueSoft
HKEY_LOCAL_MACHINE\SOFTWARE\WiniBlueSoft
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "setup2.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WiniBlueSoft"
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{bd19cc12-f8a2-475c-846b-0af337b47940}\NameServer
Unregister DLLs:111znot-a-v5rus998.dll 11797tzoj595.dll 12946sz5mbot79c.dll 129cvir1z58.dll 12bbszy5ar91941.dll 19945hzcktool65b.dll
Delete files:always_skip.xml data.bin License.txt main_config.xml uninstall.exe WiniBlueSoft.exe WiniBlueSoft.lnk Homepage.lnk Uninstall.lnk WiniBlueSoft.lnk 102959roz2b45.ocx 10325virusz955.ocx 10355h9eat227z2.cpl 111znot-a-v5rus998.dll 115z1vi9us3e85.ocx 11797tzoj595.dll 1197addwaze16915.ocx 127b95ief305z.ocx 12946sz5mbot79c.dll 129cvir1z58.dll 12bbszy5ar91941.dll 13323w95mz1b.ocx 135zvir1929.cpl 1393z5or9df.ocx 13951spzmb9t5a2.exe 14041hackt5zl99.exe 19199hackt5zl7a1.bin 19524spyze9.exe 19544spy6fbz.ocx 19945hzcktool65b.dll 19991not-a-v5rzs1c9.exe 19z43hacktoo965f.exe HDExtrem.exe 1a59dow9lozder1735.ocx 1b20z9a5se2186.bin S-5-4-33-100030900-100005361-100010101-6637.com My Music.url My Pictures.url My Video.url My Documents.url
Delete directories:c:\Program Files\WiniBlueSoft Software
c:\Program Files\WiniBlueSoft Software\WiniBlueSoft
c:\Documents and Settings\All Users\Start Menu\Programs\WiniBlueSoft
C:\WINDOWS\system32\gaopdxcounter
Post Comment:
Attention: Use this form only if you have additional information about WiniBlueSoft parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Comments from visitors:
1. by dirk_flail. 2009-06-24 09:06:36
it is also related to this winibluesoft crap.