WiredWX Hobby Weather ToolsLog in

 


Help, done everything for winbluesoft

3 posters

descriptionHelp, done everything for winbluesoft EmptyHelp, done everything for winbluesoft

more_horiz
So i have purchased and downloaded spyhunter. When i scanned my pc it found some Dll and some rogue files of winbluesoft...but its still on my comp. I ran an adaware scan but errors keep occuring when i perform them.

I have removed winblusoft in "add/remove" i have also ran msconfig to stop it from starting up but still the virus has not subsided...wut else can i do


thanks

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
Please download the current version of HijackThis from HERE

  • Double click and run the installer.
  • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
  • After installing, you should get the user agreement, press accept and Hijack This will run.
  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
my Hijack This wont open up. I get the option of installing it...but after that nothing pops up. I click the desktop icon and still nothing occurs

i have the choice of either Run or Save when i click the link you gave me to download it

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
Guess the blocker.dll is present here. Lets try this out on it, see if it knows about IceSword yet. Goofy

Please download Ice Sword from HERE

  1. Download the zip to your desktop and extract it.
  2. Open the Ice Sword folder and then launch IceSword.exe.
  3. When IceSword opens, it will randomly rename itself, so the malware shouldn't notice it.
  4. Does it stay open? let me know. Don't do anything with it just yet.

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
god daym this winbluesoft is a little b****

i extracted it, when i did though it didnt change the name it stayed as iceswrd and when i opened it it gave a message

intialized failed, error code 3

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
Hello.
I need to know what OS your running. There is two versions of IceSword. One for XP, another for Vista.

If your running Vista, I've given you the wrong link. LMBO or ROFL

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
I'm running windows xp

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
Darn.

Please download the Pocket Killbox from HERE

1. Open the Killbox.
2. Does it stay open?

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
yes it stays open thank god lol

gives me and option to Full path of file to delete

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
I know.

2. Under "Full path of file to delete", copy and paste in the following:

C:\Windows\system32\blocker.dll

3. Then switch the option from "Standard file kill", to "Delete on reboot"
4. Press the Red X to delete the file.
5. It will ask if you want to make a backup of the file we deleted, select Yes to the prompt.
6. Now it will ask to reboot, so please do so.

Then after reboot, run Hijack This

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
Alrigh i'm able to do all of that except its not asking me to create a back up file. but i am able to delete on reboot and reboot my comp but i stopped the reboot before to make sure if i cant create a back up file is a problem

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
Okay, doesn't matter anyway, I know the file is malicious.
Reboot the machine so Killbox can delete the file.

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
kk i deleted on reboot, my compter didnt reboot it told me

"pendingFileRenameOperations Registery data has been removed by external process"

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
Hmm.
Reboot anyway, see if you can run programs like normal now.

If not, re-run the Killbox, but don't stop the reboot this time.

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
i Still have the security alerts for winbluesoft saying my comp is infected..i re-ran the kill box but again when i clikc the option delte on reboot and press the RED X button it gave me the same message as b4..kinda looks like an error msg saying PeningFileRename Operations Regiustry Data has been removed by external process. I have a choice in the kill box to do single files or all files? Again my PC didnt auto restart after pressing the RED X button

descriptionHelp, done everything for winbluesoft EmptyRe: Help, done everything for winbluesoft

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum