WiredWX Hobby Weather ToolsLog in

 


I've been infected with Winbluesoft

4 posters

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

  • Double-click the launch.exe or cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, just let it cure whatever it finds...
    o Now, go to Settings >> Change Settings
    o Go to Actions tab >> under Objects section, change the settings to below
    Infected objects - Cure
    Incurable objects - Report
    Suspicious objects - Report
    o Don't change any other settings
  • Start the scan again. This time, choose Complete Scan
  • Click the green arrow button at the right, and the scan will start.
  • After the scan finished, click Select all
  • Click on Cure and choose Report incurable (means take no actions.. Don't "move", or "rename" or "delete")
  • When the scan has finished, in the menu, click File and choose Save report list
  • Save the report to your Desktop. The report will be called DrWeb.csv
  • Post DrWeb.csv in your next reply (Open it as Notepad).. Do NOT reboot the computer yet..

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
Dr. Web CureIt wouldn't run. Nothing happened, I didn't even get the 'Process Terminated...' message from Winbluesoft.

Something new I did notice was that my Spybot S&D TeaTimer popped up with this info:
Category: System Startup User Entry
Change: Key Changed

Entry: setup2.exe

Old Data: C:\WINDOWS\System32\setup2.exe
New Data: setup2.exe


Should I allow or deny this change?

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
I need you to boot in safe mode with networking and do the following:




  • Download combofix from here
    Link 1
    Link 2
1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:

I've been infected with Winbluesoft - Page 2 CF_download_FF

I've been infected with Winbluesoft - Page 2 CF_download_rename

3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.
See HERE for how to disable your AV..

  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
I can't get into Setup to try to boot into Safe Mode. When I try to enter Setup while the infected computer is booting up it asks for a password to access Setup. I've never set a password, so I'm guessing Winbluesoft did it.

I've tried several default and back door passwords that I've found, but none of them have worked. I've also tried a couple of BIOS password crackers, but they haven't been able to run.

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
Can you download anything from anywhere?

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
Yes, I'm currently using the other computer I have which is not infected. I've been downloading from this uninfected computer and using a USB drive to transfer to the infected computer.

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
Tell me if you can run the following:


Download OTListIt2 by OldTimer to your Desktop.

  • Close all windows and double click OTListIt2.exe
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up - OTListIt2.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
  • You may need to use two posts to get it all.

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
That wasn't able to run either.
I was actually able to delete the C:\Windows\System32\setup2.exe file though, which I was unable to do earlier.

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
I'm able to run .exe files now! I used one of the regfix.inf suggested in another Winbluesoft thread and now I can run programs. I'm posting this from the infected computer.

I was able to run hijackthis. Here's the log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:58:33 AM, on 6/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe
C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\Common Files\Sonic Shared\cinetray.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Safari\Safari.exe
C:\Documents and Settings\Pete\Desktop\13.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [setup2.exe] C:\WINDOWS\system32\setup2.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [setup2.exe] C:\WINDOWS\system32\setup2.exe (User 'Default user')
O4 - Startup: Sonic CinePlayer Quick Launch.lnk = ?
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Post-it®️ Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8182 bytes

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
Hello.

I notice that you have Spybot's TeaTimer running. While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes. So please disable TeaTimer by doing the following:
1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
You can reenable TeaTimer once your system is clean.

Please make sure Teatimer is disable before we do this, otherwise this fix will fail.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O4 - HKUS\S-1-5-18\..\Run: [setup2.exe] C:\WINDOWS\system32\setup2.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [setup2.exe] C:\WINDOWS\system32\setup2.exe (User 'Default user')


  • Press "Fix Checked"
  • Close Hijack This.

Next,

  • Download combofix from here
    Link 1
    Link 2

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:

    I've been infected with Winbluesoft - Page 2 CF_download_FF

    I've been infected with Winbluesoft - Page 2 CF_download_rename

    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See HERE for how to disable your AV. (AVG8)
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    I've been infected with Winbluesoft - Page 2 Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes

    I've been infected with Winbluesoft - Page 2 Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
Here's the combofix log:

ComboFix 09-05-31.06 - Pete 06/01/2009 10:41.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.625 [GMT -5:00]
Running from: c:\documents and settings\Pete\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\windows\10216not5a9vzrus345.ocx
c:\windows\1029no5-a-virus5bz.cpl
c:\windows\10334hzc9tooled5.dll
c:\windows\104095zy492.exe
c:\windows\105939roj2z7.exe
c:\windows\1059b5ckdoor67z.exe
c:\windows\10805ot-a-9irus4zd.ocx
c:\windows\10ebspz59re1333.exe
c:\windows\10z5s59al858.bin
c:\windows\10z969py19e5.cpl
c:\windows\1147spy5are2z639.exe
c:\windows\11599viruz7.ocx
c:\windows\1170b5zkdoor9599.bin
c:\windows\118959zoj520.ocx
c:\windows\118cspa5sz219.cpl
c:\windows\11938hacktzol795.bin
c:\windows\11956vizus7a15.dll
c:\windows\11f15pyware229z.exe
c:\windows\125119pz7205.cpl
c:\windows\12599trojz29.ocx
c:\windows\126925pambot73z.bin
c:\windows\129eadd5arz600.dll
c:\windows\12d7down9zad5r3176.ocx
c:\windows\12z75hackto9l193.bin
c:\windows\131865zrm2d9.dll
c:\windows\135cszyware491.dll
c:\windows\135z0ha59tool7c5.ocx
c:\windows\13757wormz92.bin
c:\windows\139539pambzt2e8.dll
c:\windows\139569roz76d.dll
c:\windows\13z92t5oj381.bin
c:\windows\140099pambotz5f.cpl
c:\windows\14051ha9ktzol2c.exe
c:\windows\14499hacktool2b5z.bin
c:\windows\1449z5orm784.exe
c:\windows\1476z5irus917.bin
c:\windows\1488zno9-a-vi5us39c.bin
c:\windows\14950spazb5t56a.ocx
c:\windows\1497zpambot588.bin
c:\windows\14a95ir22z3.exe
c:\windows\14z735py99a.bin
c:\windows\15079troj6bz.bin
c:\windows\15238virus99z.ocx
c:\windows\15261worz9d5.exe
c:\windows\1528zvi5us93d.bin
c:\windows\1529thzeat9922.bin
c:\windows\153369zrm684.cpl
c:\windows\15392not-a5viruszbd.cpl
c:\windows\15392worm42z9.cpl
c:\windows\15453sp94d6z.cpl
c:\windows\15589not-a-5iru9589z.bin
c:\windows\1582vzr15759.bin
c:\windows\159bdownlo9derz251.bin
c:\windows\159bs9arse47z.bin
c:\windows\15c5szarse1919.exe
c:\windows\16394hackt95l21cz.bin
c:\windows\164z6n95-a-virus69c.exe
c:\windows\166065zrm192.cpl
c:\windows\16839vi5zs594.dll
c:\windows\1697zvirus145.exe
c:\windows\17095hazkt5ol2dc.ocx
c:\windows\17152viruzd9.exe
c:\windows\17259zpambot5a9.ocx
c:\windows\17442s5a9bzt44b.dll
c:\windows\17730szam9o54bc.exe
c:\windows\17869hreat25z29.dll
c:\windows\178bt9reaz16415.dll
c:\windows\17e6add95ze2128.ocx
c:\windows\18085virz929f.dll
c:\windows\181999p5z9d.exe
c:\windows\18506not-z-9irus70f.bin
c:\windows\18650s5azb9t70f.cpl
c:\windows\18675v5ru9zd6.ocx
c:\windows\189125rzj9a1.dll
c:\windows\18caback9ozr2455.ocx
c:\windows\1905thi9z7.cpl
c:\windows\19095virz55a3.cpl
c:\windows\19295roj3zb.bin
c:\windows\193a5pzware2425.bin
c:\windows\1941zorm4519.exe
c:\windows\19519zp9mbot8f.exe
c:\windows\1965zackt9ol4d8.dll
c:\windows\1967doznlo5der2810.bin
c:\windows\196cbackdoz51987.exe
c:\windows\1983zor5194.exe
c:\windows\19891noz-a-virus1af5.cpl
c:\windows\198z59r380.bin
c:\windows\19979zot-a-v5rus1a7.bin
c:\windows\1997zvirus35b.bin
c:\windows\19dcaddwzre54639.bin
c:\windows\1a87s9zrs542.dll
c:\windows\1c72th5ezt20959.ocx
c:\windows\1c95stzal103.cpl
c:\windows\1cc3adz5are9312.bin
c:\windows\1d5c9hief2643z.ocx
c:\windows\1d6fsparze985.dll
c:\windows\1db05i9295z.exe
c:\windows\1dd69hief1522z.ocx
c:\windows\1e8do5nloadez14369.dll
c:\windows\1f56vir8z19.bin
c:\windows\1ff3d5wnloadzr2429.ocx
c:\windows\1ffezt5a92202.ocx
c:\windows\1z0dspars912045.dll
c:\windows\1z1e9teal1455.exe
c:\windows\1z322s95a.exe
c:\windows\1z470vi5us9ea.bin
c:\windows\1z545s95450.ocx
c:\windows\1z7699orm65c.exe
c:\windows\1z82795rus527.ocx
c:\windows\1z93n9t-a-v5rus489.bin
c:\windows\1za5addware19899.exe
c:\windows\200955orz3889.exe
c:\windows\201329ot-a-5irus4f9z.exe
c:\windows\202239irus7z5.dll
c:\windows\2034spzwa9e2056.ocx
c:\windows\209819izus35e.ocx
c:\windows\209csparse199z5.cpl
c:\windows\209z7worm556.dll
c:\windows\20f9downloaderz885.cpl
c:\windows\20z68not-a-9iru5167.ocx
c:\windows\20zcspars59519.cpl
c:\windows\210385zcktool359.dll
c:\windows\21155zi5us259.bin
c:\windows\214015orz6569.ocx
c:\windows\216z9t5oj5b6.cpl
c:\windows\217znot-a-v5r9s734.exe
c:\windows\219bthrezt198195.cpl
c:\windows\21z5spy9are1846.cpl
c:\windows\21z75wo9539a.ocx
c:\windows\22047spzmb9t4255.cpl
c:\windows\2205sparze2139.exe
c:\windows\222fstea59352z.dll
c:\windows\223spaz5e1999.dll
c:\windows\2244azdw5re13599.cpl
c:\windows\22699not9a-vzr5s193.ocx
c:\windows\22758hzc5tool599.cpl
c:\windows\22758t5oj9ez.dll
c:\windows\22805haz9toolce.bin
c:\windows\23251zr5j994.bin
c:\windows\23471zor965b.bin
c:\windows\235dsparse952z.ocx
c:\windows\23705pazbot9c.ocx
c:\windows\23759yware18z2.bin
c:\windows\2390znot-a-viru52d.dll
c:\windows\23dcspaz5e659.dll
c:\windows\2416zhr9at5995.dll
c:\windows\24257spa95ot2zf.dll
c:\windows\24344zor9756.ocx
c:\windows\24407szy79d5.exe
c:\windows\24599notz5-virus4da.dll
c:\windows\246bbackdoo9z9265.ocx
c:\windows\247z9vir5s598.bin
c:\windows\24845v9rus2z15.ocx
c:\windows\24870s5ambo976z.exe
c:\windows\24998hacktzol51f5.cpl
c:\windows\24b9threaz59380.exe
c:\windows\25052not-9-5irusza2.ocx
c:\windows\25098hacktool39cz.cpl
c:\windows\250z1hacktool596.ocx
c:\windows\25160vir9s5zb.dll
c:\windows\25336trz53d69.ocx
c:\windows\25399zpy2b1.cpl
c:\windows\2539zspy3b7.exe
c:\windows\253cback9oor5z45.exe
c:\windows\253zbackdoor9665.ocx
c:\windows\2540zwor945f5.bin
c:\windows\2546szyware9921.cpl
c:\windows\25475h9cktooz15.bin
c:\windows\25560sp9mbot76z.exe
c:\windows\255789py1bbz.dll
c:\windows\25594worm3z59.dll
c:\windows\2559spy9a5e21z2.bin
c:\windows\25869pywa5e734z.ocx
c:\windows\25956wo9z156.dll
c:\windows\2596z5r9j477.dll

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
c:\windows\2596zir6595.dll
c:\windows\259fzir9316.bin
c:\windows\259spamb5z69b.exe
c:\windows\25aadownzoad5r839.exe
c:\windows\25z89vi5us679.dll
c:\windows\26210ha9kzo5l1f.exe
c:\windows\2625sparse1297z.bin
c:\windows\263z69a5ktool4a6.dll
c:\windows\26459hazktool9d5.dll
c:\windows\26531szambo95ec.dll
c:\windows\26622spamz9t33a5.ocx
c:\windows\2695dz59loader1721.cpl
c:\windows\26985s5ambot7z6.dll
c:\windows\2698backdz5r1961.ocx
c:\windows\270015rojz49.exe
c:\windows\27268spzmb9t5d5.ocx
c:\windows\2750backdo9r2584z.exe
c:\windows\2753zw9rm1e1.cpl
c:\windows\275fzddware15939.dll
c:\windows\2795bazkdoor1297.bin
c:\windows\27b5spy9zre3035.ocx
c:\windows\27edbac9zoor350.exe
c:\windows\27f5zp95se1715.exe
c:\windows\27z59o5m7cb.cpl
c:\windows\2821tzoj9a55.dll
c:\windows\28419orm25z.bin
c:\windows\28850troz699.exe
c:\windows\288czpy9are1549.bin
c:\windows\28z91spam5ot3e9.dll
c:\windows\29014wzrm1c59.ocx
c:\windows\2908sp93fz5.ocx
c:\windows\2916095z-a-virus468.ocx
c:\windows\29190v5zus184.bin
c:\windows\29199noz-a-v5rus4fa.cpl
c:\windows\29236spazbo9665.exe
c:\windows\293ste5l9z9.dll
c:\windows\29491spy57dz.ocx
c:\windows\29499wozm1b95.cpl
c:\windows\2952thiez9065.exe
c:\windows\29559szambot956.cpl
c:\windows\2955spywzr5569.dll
c:\windows\295ddownzoader9321.ocx
c:\windows\29620zpy550.dll
c:\windows\29678v9z5s53f.bin
c:\windows\297at5izf3039.cpl
c:\windows\299165pz4e9.ocx
c:\windows\29979z5am9ot29c.cpl
c:\windows\29e3downloade5z409.ocx
c:\windows\29z05sp9159.ocx
c:\windows\29z57h5cktool64e.ocx
c:\windows\2bz0backdo5r25779.ocx
c:\windows\2c2abazk59or3150.ocx
c:\windows\2d1baczdoo99735.cpl
c:\windows\2z03s9ambot605.ocx
c:\windows\2z076not-a-vi5us39e.ocx
c:\windows\2z155parse21129.ocx
c:\windows\2z2a5pyware9149.bin
c:\windows\2z38addwa95684.bin
c:\windows\2z505w9rm7f7.exe
c:\windows\2z6319irus85.cpl
c:\windows\2z651hackt5o9261.bin
c:\windows\2z67st9al2625.cpl
c:\windows\2z95virus59.exe
c:\windows\2z965hief2605.cpl
c:\windows\2zf9vir4205.cpl
c:\windows\301v5z1897.ocx
c:\windows\302z3v5rus7969.ocx
c:\windows\302z95irus4d.cpl
c:\windows\30394zo5956e.cpl
c:\windows\3056thi9z109.dll
c:\windows\30a8spa5ze2988.dll
c:\windows\30ha95tzol2e6.bin
c:\windows\30z49s5y90.ocx
c:\windows\30z76troj4945.dll
c:\windows\30zft95ef2880.bin
c:\windows\31008not5a-viruz944.dll
c:\windows\3135th9efz231.exe
c:\windows\31755pzwar91546.cpl
c:\windows\31a7ste9l57z.dll
c:\windows\31ezth5eat19904.bin
c:\windows\32099viruz25.exe
c:\windows\323z5hack9ool2f5.cpl
c:\windows\323z9hackto5l55c.bin
c:\windows\3245zspambo56f79.cpl
c:\windows\32749troz755.dll
c:\windows\3412w95m50z.bin
c:\windows\3416zpa9bot225.exe
c:\windows\349zv5rus9ba.bin
c:\windows\350adown95zder3235.exe
c:\windows\3535addzare953.ocx
c:\windows\3539spz9bot5af.ocx
c:\windows\353h5ckzool67c9.cpl
c:\windows\3545v9r671z.cpl
c:\windows\354baddwarez6149.cpl
c:\windows\3565zpy299.ocx
c:\windows\35911zroj1ae.exe
c:\windows\3595zackdo9r545.exe
c:\windows\3599zi91992.ocx
c:\windows\35fzteal9047.cpl
c:\windows\361et9reat51764z.cpl
c:\windows\3639addware57z.ocx
c:\windows\3664v5r90z0.cpl
c:\windows\369zspy15f.dll
c:\windows\36fthr9zt23854.exe
c:\windows\36zath9ef451.cpl
c:\windows\379ftz5eat29468.exe
c:\windows\387cszars52494.dll
c:\windows\3919vizu5768.dll
c:\windows\39441s5z13a.dll
c:\windows\3974zparse1695.bin
c:\windows\398zspyw9r598.ocx
c:\windows\39c5szarse30575.dll
c:\windows\39z3tro549d.ocx
c:\windows\3a3z9ir435.ocx
c:\windows\3a8fdzwnload5r691.bin
c:\windows\3b9ct5reaz6500.bin
c:\windows\3badzte9l685.dll
c:\windows\3bstzal18659.cpl
c:\windows\3c99zddware1265.cpl
c:\windows\3d11v5z9209.dll
c:\windows\3d79spazse5615.ocx
c:\windows\3d9t5iefz8579.dll
c:\windows\3e5dt5iez359.dll
c:\windows\3e6b9ckd5orz699.ocx
c:\windows\3fb6zteal5419.bin
c:\windows\3z0535r9j5d6.dll
c:\windows\3z05b5ckdoo91583.dll
c:\windows\3z070troj594.exe
c:\windows\3z106hacktoo519b.cpl
c:\windows\3z22downloader9895.cpl
c:\windows\3z51059cktool672.exe
c:\windows\3z545troj4e09.bin
c:\windows\3zb6spyware5191.dll
c:\windows\3zbdv5r32759.exe
c:\windows\4065viz5s729.bin
c:\windows\40755py9zb.dll
c:\windows\40z6spa59e2254.dll
c:\windows\4104virzs595.dll
c:\windows\4177hackzool935.dll
c:\windows\41z5sparse649.bin
c:\windows\41z7add59re2627.cpl
c:\windows\4284a59zare2447.exe
c:\windows\43a9spaz5e1242.cpl
c:\windows\4438steal9z5.ocx
c:\windows\44539hiefz361.ocx
c:\windows\44625hief9z35.ocx
c:\windows\4498addware1518z.cpl
c:\windows\45209ackdoor1z75.dll
c:\windows\4539zi9698.cpl
c:\windows\45975zr2135.dll
c:\windows\45b9bzckd9or2403.cpl
c:\windows\45bczddware26695.bin
c:\windows\45c9parz5112.dll
c:\windows\45f19teaz2.ocx
c:\windows\45z9ste592399.exe
c:\windows\46235z9ef502.exe
c:\windows\4659thief1659z.ocx
c:\windows\4673downloadez2955.cpl
c:\windows\469evi52z9.dll
c:\windows\473bdownlzader19885.bin
c:\windows\485fthreat22z599.bin
c:\windows\48zackt9ol551.exe
c:\windows\4955vi9uz715.dll
c:\windows\495dthreat5031z.bin
c:\windows\495zsteal1050.ocx
c:\windows\49a9spyware452z.cpl
c:\windows\49d65parse909z.cpl
c:\windows\49dcthiez553.exe
c:\windows\49f6downloa9erz505.cpl
c:\windows\49z6spambo512a.exe
c:\windows\4a0dthi5f11z9.exe
c:\windows\4a54virz8985.cpl
c:\windows\4abd9p5rsz1185.exe
c:\windows\4ac9addware201z5.dll
c:\windows\4b85zief9795.exe
c:\windows\4b9fzhief1657.dll
c:\windows\4bfdd5wnloade91z42.exe
c:\windows\4c09zhreat5525.ocx
c:\windows\4d73bac59ozr927.exe
c:\windows\4e6fspzrse92585.ocx
c:\windows\4e89thief16z5.exe
c:\windows\4ea8spzrs9565.cpl
c:\windows\4efzaddwa9e485.cpl
c:\windows\4f2fzackdo951756.bin
c:\windows\4f49pa5sz404.dll
c:\windows\4z21spy39c5.cpl
c:\windows\4z53sparse19049.cpl
c:\windows\4z5thief1191.exe
c:\windows\4z68backd59r2065.ocx
c:\windows\4z785pyware9189.cpl
c:\windows\4ze9thi5f453.exe
c:\windows\500n59za-virusc3.exe
c:\windows\5018spam9ot592z.bin
c:\windows\5025tzie955.exe
c:\windows\5045downlz9der1495.cpl
c:\windows\50a7ba9kdoor952z.exe
c:\windows\50bc9ownl5adzr3055.ocx
c:\windows\50c69ir1876z.exe
c:\windows\50e4sz5war9263.ocx
c:\windows\5117spazse379.cpl
c:\windows\5118virz9d7.ocx
c:\windows\51498vir9sz34.bin
c:\windows\515z1spam9ot7a9.bin
c:\windows\516ebackdoo9z295.exe
c:\windows\5192worm95z.bin
c:\windows\5195zspambot379.ocx
c:\windows\5199zt5al2028.ocx
c:\windows\52352wo9m5z1.bin
c:\windows\5239back5zor1940.bin
c:\windows\52624zpambo9110.bin
c:\windows\5265st9al5z5.bin
c:\windows\5275sp9zad.bin
c:\windows\527downloa9zr1568.bin
c:\windows\529athrzat51242.bin
c:\windows\52b2s9yware2z49.bin
c:\windows\52f1steal199z.ocx
c:\windows\53d8bac5doorz794.exe
c:\windows\5409b5ckdoor2999z.dll
c:\windows\5412st5az9956.cpl
c:\windows\5416szar9e314.ocx
c:\windows\5423h5ckzool56f9.dll
c:\windows\546459roj5f1z.exe
c:\windows\5494viruz1e1.bin
c:\windows\54954virus7z5.ocx
c:\windows\54c9addwzre1984.ocx
c:\windows\55169zrus1a4.dll
c:\windows\5540b9ckdoor1z70.cpl
c:\windows\55452szy6f9.dll
c:\windows\554ebaczdoor892.cpl
c:\windows\5555w9rz1c7.exe
c:\windows\5559sp55az.exe
c:\windows\555cbazkdoor9015.ocx
c:\windows\556az9ea51226.ocx
c:\windows\5572s59z2.exe

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
c:\windows\5595spz74b.cpl
c:\windows\55c8zpy5are31709.ocx
c:\windows\55eazir914.cpl
c:\windows\55f1do5zload9r2487.dll
c:\windows\55f2virz9629.ocx
c:\windows\55f39teaz2482.ocx
c:\windows\55fzv9r1556.bin
c:\windows\55z0a9dware1335.cpl
c:\windows\562z2spy509.dll
c:\windows\56385zi9f2643.dll
c:\windows\56870wormz029.cpl
c:\windows\56915py3z3.ocx
c:\windows\56971not-a-viruz582.bin
c:\windows\56a1dowzloa9er13085.cpl
c:\windows\56zbsparse15209.dll
c:\windows\573499zrm227.exe
c:\windows\5734troj968z.ocx
c:\windows\573zirus39c9.dll
c:\windows\57819roj2z.exe
c:\windows\5786backdo9r1z81.cpl
c:\windows\57ca9ownloaderz42.cpl
c:\windows\57e4download9z1476.dll
c:\windows\581zbackdoo5590.dll
c:\windows\58455ha9ktooz40c.bin
c:\windows\5851spy989z.ocx
c:\windows\58755spam9oz296.cpl
c:\windows\5896zspy99e.bin
c:\windows\58azspywa95773.ocx
c:\windows\58c5downl9adzr65.cpl
c:\windows\58d4thiz936.dll
c:\windows\58fs9zrse960.dll
c:\windows\5901downloaderz9135.bin
c:\windows\5913vzr39625.bin
c:\windows\59321not-a-vzrus9d4.dll
c:\windows\5944vi5zs4e7.cpl
c:\windows\5952backdoor2z30.exe
c:\windows\5952virus6z7.exe
c:\windows\59557wormz6d9.bin
c:\windows\5956not9a-viruz355.ocx
c:\windows\595ha9kzool1d7.exe
c:\windows\5975tzreat26755.dll
c:\windows\5995vir2z14.dll
c:\windows\59a5addwzre1050.dll
c:\windows\59abspywzre2595.exe
c:\windows\59cbvir15z1.dll
c:\windows\59estzal1255.dll
c:\windows\59z8spy7b5.exe
c:\windows\5a56t9iefz946.ocx
c:\windows\5aa29ddware2z72.ocx
c:\windows\5b15doznload9r318.ocx
c:\windows\5b2fd9znloader2753.dll
c:\windows\5bc5thi9f3155z.cpl
c:\windows\5bcat5rea9297z8.ocx
c:\windows\5bzaad9ware5356.dll
c:\windows\5c17addwarz529.bin
c:\windows\5c1fzownloader57329.dll
c:\windows\5c31spa5se3921z.bin
c:\windows\5c62zpa9se147.exe
c:\windows\5cecback9oor1453z.exe
c:\windows\5d50thz9f1703.cpl
c:\windows\5d53vir1z599.ocx
c:\windows\5d6ev5r9z79.cpl
c:\windows\5e9f9zars51939.ocx
c:\windows\5ed5downlozder3099.bin
c:\windows\5ezdsteal9107.bin
c:\windows\5f23thrzat95789.exe
c:\windows\5f59vir512z.exe
c:\windows\5f5ethi596z.ocx
c:\windows\5f99szeal21105.bin
c:\windows\5faedown9oader2z91.exe
c:\windows\5fdcspyw9rez743.exe
c:\windows\5ff0steaz19719.cpl
c:\windows\5z1d59r836.ocx
c:\windows\5z38vir2297.dll
c:\windows\5z6not-a-vi9u544d.ocx
c:\windows\5z9109py6f4.dll
c:\windows\5z969py77d.bin
c:\windows\5z9ste5l2897.cpl
c:\windows\5zc05pa9se2920.exe
c:\windows\6048wo9m355z.dll
c:\windows\61eddownzoad9r31535.bin
c:\windows\6297zo9m15.dll
c:\windows\63925pzmbot9ad.exe
c:\windows\6450ha5ktz9l388.bin
c:\windows\64c7addwzr94885.exe
c:\windows\650f9hizf3083.dll
c:\windows\6544sp9rs554z.ocx
c:\windows\6576addwar9478z.ocx
c:\windows\658fdownloadzr2229.dll
c:\windows\65cf9irz075.bin
c:\windows\65zddownloader7879.cpl
c:\windows\6627z9r2895.dll
c:\windows\6659addwzre22449.ocx
c:\windows\66ast9zl5122.cpl
c:\windows\66b3viz9635.bin
c:\windows\66b6addz9re945.cpl
c:\windows\6705thief2922z.exe
c:\windows\6707s9ywa5e1941z.bin
c:\windows\6746zo5nlo9der514.ocx
c:\windows\679e9zw5loader1378.dll
c:\windows\67dazh5e91443.cpl
c:\windows\67f2zp9w5re538.dll
c:\windows\67z99te5l2450.bin
c:\windows\6818zr9j46e5.cpl
c:\windows\6855tzief2690.ocx
c:\windows\6924addza5e549.ocx
c:\windows\6957azdware665.exe
c:\windows\696downlozde52674.cpl
c:\windows\696not9azv5rus6ec.ocx
c:\windows\699abackdozr1509.exe
c:\windows\699zs5eal1219.cpl
c:\windows\69c59ow5zoader1559.exe
c:\windows\69e25zr1565.dll
c:\windows\69z4s9ea52190.exe
c:\windows\6b05s9eal158z.ocx
c:\windows\6cathiez2579.ocx
c:\windows\6d13spywa9e27z5.ocx
c:\windows\6d93z5eal83.cpl
c:\windows\6e29th5eat1z856.bin
c:\windows\6e70zpa5s9545.cpl
c:\windows\6e82vir5993z.bin
c:\windows\6eb99iz589.exe
c:\windows\6ed8zddwar5966.bin
c:\windows\6f6zth9e51392.dll
c:\windows\6fczdownloader15895.cpl
c:\windows\6fz9addwar52155.dll
c:\windows\6z8bthreat319325.cpl
c:\windows\7042spy5arz934.bin
c:\windows\70fbzhre9t59268.cpl
c:\windows\70z9vir1535.cpl
c:\windows\716dd5wnlzader13669.bin
c:\windows\718ct5zef24599.bin
c:\windows\71bbspars52z91.bin
c:\windows\71bdbac5dzor499.bin
c:\windows\7265h9ckzoo5319.dll
c:\windows\7494addwar5148z.ocx
c:\windows\7500a9dwa5e25z9.bin
c:\windows\752sz9e3.ocx
c:\windows\7594spyware3z95.dll
c:\windows\759zbackdoor80.cpl
c:\windows\75caadzware1339.cpl
c:\windows\75e5dzwn9o5der2539.exe
c:\windows\75e95ddwzre3166.exe
c:\windows\75zbt9ief1376.dll
c:\windows\75zethie9775.cpl
c:\windows\7659thiz92984.bin
c:\windows\76a5spa5ze9092.ocx
c:\windows\76b995ckzoor29.cpl
c:\windows\774fth9ef2z835.exe
c:\windows\7759stealz395.ocx
c:\windows\77a1stezl5091.bin
c:\windows\77z3thre5t94881.exe
c:\windows\782cz59eat16295.ocx
c:\windows\784959arse15z1.ocx
c:\windows\7850a9dware3z27.bin
c:\windows\78589irz529.cpl
c:\windows\7895vizus9b.bin
c:\windows\790a5ir887z.cpl
c:\windows\791szamb9t158.bin
c:\windows\7924notza-virus5385.cpl
c:\windows\7938steal3z85.bin
c:\windows\7958d9zn5oader340.cpl
c:\windows\795troj5a9z.ocx
c:\windows\79665zt-a-virus299.dll
c:\windows\79779roz3945.exe
c:\windows\7a1bs9eal95z.cpl
c:\windows\7a7z5rea913508.dll
c:\windows\7b1dadd5are95z5.dll
c:\windows\7ba9addzare5505.dll
c:\windows\7d18download9rz1015.bin
c:\windows\7d49t5reat249z3.dll
c:\windows\7d5ethiez2903.dll
c:\windows\7f93addza9e2855.cpl
c:\windows\7fathie5z609.dll
c:\windows\7z25hac5tool190.exe
c:\windows\7z4st9al21895.ocx
c:\windows\7z59addware1069.exe
c:\windows\80z39orm7485.dll
c:\windows\81zw5rm5b9.bin
c:\windows\8205n9t-a5vizus3b4.bin
c:\windows\8335virus965z.dll
c:\windows\8392spy5z5.cpl
c:\windows\8432sp9m5ot5a7z.ocx
c:\windows\8499z95ktool2b8.ocx
c:\windows\8524zot-a-9irus618.exe
c:\windows\8525zpy5ed9.cpl
c:\windows\85499roz432.ocx
c:\windows\855zhreat21919.cpl
c:\windows\8590sz56a2.bin
c:\windows\85dbackdoor2z19.exe
c:\windows\8959spy76z.exe
c:\windows\90488haczt5ol138.cpl
c:\windows\90b9spars55z7.ocx
c:\windows\914zth5eat11492.exe
c:\windows\9167zworm5de.cpl
c:\windows\91755zy229.bin
c:\windows\91967not-a-vi5uz790.dll
c:\windows\91bfbaz5door1943.ocx
c:\windows\923zv59us15e.bin
c:\windows\92623zor5551.bin
c:\windows\92625hazktool4db.bin
c:\windows\9284zspambo542.exe
c:\windows\92dback59or17z9.ocx
c:\windows\92e5downlzader1019.ocx
c:\windows\9318sza9bot565.bin
c:\windows\93300w5rz30d.exe
c:\windows\935espzware24225.exe
c:\windows\939zhrea512771.ocx
c:\windows\93dzdownlo5der1976.cpl
c:\windows\943d5wnloadez9504.cpl
c:\windows\94613w5zm709.dll
c:\windows\948h9cktzol54d.ocx
c:\windows\9495virus434z.exe
c:\windows\94994woz5553.bin
c:\windows\9502trojdz.exe
c:\windows\9515t5iez505.ocx
c:\windows\95160spazbot35.dll
c:\windows\951z5virus51d.ocx
c:\windows\95231spamzot8d.bin
c:\windows\9532notza-virus646.dll
c:\windows\9535thzeat28355.dll
c:\windows\955935ormz.dll
c:\windows\955zpambot7d9.exe
c:\windows\9575virusz929.ocx
c:\windows\9595ezl998.cpl
c:\windows\95b9stea53z33.exe
c:\windows\95fdtzreat275695.cpl
c:\windows\95ffthiez798.bin
c:\windows\9714s59mbzt1c4.ocx
c:\windows\9744spambotz8d5.bin
c:\windows\978a5dw9rz3043.exe
c:\windows\980zw5rm136.cpl
c:\windows\9819sp54baz.exe
c:\windows\983aa5dwarz375.dll
c:\windows\98bth5ef765z.bin
c:\windows\991downloaderz025.cpl
c:\windows\992z5ackdoor3120.bin
c:\windows\993515roz24a.bin
c:\windows\994sp5rsz2099.dll
c:\windows\99667viru52z6.cpl
c:\windows\9980thr5az12154.exe
c:\windows\99dfth5ef925z.dll
c:\windows\99z9s5ambot2ab9.bin
c:\windows\9a5cstezl3170.ocx
c:\windows\9b69a5dware39z.dll
c:\windows\9c0zspywar5323.exe
c:\windows\9c25downzoader754.exe
c:\windows\9c30spywaze19645.cpl
c:\windows\9cc5t5ief192z.bin
c:\windows\9ceavzr2505.cpl
c:\windows\9d4zvir30625.bin
c:\windows\9d5es5eal9z6.bin
c:\windows\9d91threa52736z.exe
c:\windows\9e0bdzwnload5r3033.exe
c:\windows\9e6cdoznloade53235.bin
c:\windows\9e89st5alz144.exe
c:\windows\9z05pyware343.exe
c:\windows\9z3565roj68e.dll
c:\windows\9z7spy21a5.ocx
c:\windows\9z905py628.bin
c:\windows\9zca5dware851.bin
c:\windows\a909hizf55.bin
c:\windows\a95s5zware2248.exe
c:\windows\abthre9t553z2.bin
c:\windows\acfdzwn9oader3051.exe
c:\windows\b98s9eaz4415.cpl
c:\windows\c62dzwnloa5er1459.bin
c:\windows\c8zthie91085.exe
c:\windows\d885hzea922625.dll
c:\windows\e32viz1579.cpl
c:\windows\e8zadd9are5608.bin
c:\windows\e8zthre5t4926.exe
c:\windows\e959h5zf2427.ocx
c:\windows\e9aspywa5e3z41.bin
c:\windows\f0dste9lz55.ocx
c:\windows\f33szyw59e743.exe
c:\windows\ffc95dware3z89.dll
c:\windows\system32\10717spz569.cpl
c:\windows\system32\10951spy492z.dll
c:\windows\system32\1099ztroj9e45.bin
c:\windows\system32\114045acktozl7f69.ocx
c:\windows\system32\11562spambzt149.exe
c:\windows\system32\11584ziru985.ocx
c:\windows\system32\115bspyw5ze15439.exe
c:\windows\system32\11749not-a-v5zu99e.bin
c:\windows\system32\1184z9or569b.dll
c:\windows\system32\11968spazbot25a.cpl
c:\windows\system32\11f9thief589z.dll
c:\windows\system32\11z78hack5ool3fa9.exe
c:\windows\system32\128505azk9ool2d.exe
c:\windows\system32\129119pam5ot143z.dll
c:\windows\system32\12915v5rus6ez.dll
c:\windows\system32\1297zwo9539f.bin
c:\windows\system32\13271hacktooz25b9.exe
c:\windows\system32\13379wo5m6z8.ocx
c:\windows\system32\13500sp93b5z.exe
c:\windows\system32\13519tr5jz9.ocx
c:\windows\system32\137965pambotzbc.cpl
c:\windows\system32\13989not5z-virus712.bin
c:\windows\system32\13a5spyw9re1z15.bin
c:\windows\system32\14019spambot5z2.dll
c:\windows\system32\14077tr9j2z5.dll
c:\windows\system32\14495a9kdozr458.cpl
c:\windows\system32\14661s9y58z.bin
c:\windows\system32\14787notza-v5rus99f.cpl
c:\windows\system32\14917z9cktool2195.bin
c:\windows\system32\149515zy41b.exe
c:\windows\system32\15283hac9to5z122.cpl
c:\windows\system32\1528thiez1939.bin
c:\windows\system32\152z5hac9tool747.exe
c:\windows\system32\15395spz4899.bin
c:\windows\system32\15465ackto9lz98.ocx
c:\windows\system32\154z8spy695.bin
c:\windows\system32\15507zroj2f9.exe
c:\windows\system32\15600spam95z69f.bin
c:\windows\system32\1562z9py1a7.exe
c:\windows\system32\1565zsp9mbot3fa.exe
c:\windows\system32\15709teaz5108.bin
c:\windows\system32\1571tro96z05.ocx
c:\windows\system32\15855szy985.bin
c:\windows\system32\1589s9arsz1405.dll
c:\windows\system32\15945v5rus5z3.ocx
c:\windows\system32\1597zs9546d.dll
c:\windows\system32\1598zot-a-vir5s9ae.exe
c:\windows\system32\15bz9ir3273.ocx
c:\windows\system32\15c5addw9re2z05.exe
c:\windows\system32\15dzdownloader24859.dll
c:\windows\system32\15e8dzwnload9r5708.ocx
c:\windows\system32\15f5dow9lzader3028.exe
c:\windows\system32\15fzadd59re1914.exe
c:\windows\system32\1609spywaze525.bin
c:\windows\system32\16200no9-a-vir5s65z.exe
c:\windows\system32\16238wormz95.ocx
c:\windows\system32\1655zhac9tool658.dll
c:\windows\system32\165azpa59e1433.ocx
c:\windows\system32\168965irus1z9.ocx
c:\windows\system32\168z5spy79b5.exe
c:\windows\system32\1699s5z37b.cpl
c:\windows\system32\1747159zj25c.exe
c:\windows\system32\1771sz5rse2189.ocx
c:\windows\system32\17755sp59z4.dll
c:\windows\system32\17792trz54c2.exe
c:\windows\system32\177et9zea514634.dll
c:\windows\system32\17z29pywa5e148.exe
c:\windows\system32\17z2d9wn5oader2948.ocx
c:\windows\system32\180185zcktool4a9.ocx
c:\windows\system32\181bzdd5are1959.dll
c:\windows\system32\18425hackz9ol290.bin
c:\windows\system32\1859hazktool955.bin
c:\windows\system32\185worz9525.exe
c:\windows\system32\18959szy5e6.dll
c:\windows\system32\18962not-a-v5rus50z.dll
c:\windows\system32\18a3threat94z55.exe
c:\windows\system32\18z4spywa5e1819.ocx
c:\windows\system32\1906worm9ze5.cpl
c:\windows\system32\19081trojz55.dll
c:\windows\system32\19135troz79.dll
c:\windows\system32\1915roj9z3.ocx
c:\windows\system32\19245hreatz8066.bin
c:\windows\system32\19289spy55fz.cpl
c:\windows\system32\193585orm1z7.exe
c:\windows\system32\19450nzt-5-virus2c9.cpl
c:\windows\system32\19490h5cktoolz91.cpl
c:\windows\system32\194995zy56b.ocx
c:\windows\system32\195559roz545.bin
c:\windows\system32\1955spyware1z05.bin
c:\windows\system32\1955zspy99c.cpl
c:\windows\system32\195879py4z6.cpl
c:\windows\system32\19677t9oj1z5.exe
c:\windows\system32\19685not-a5vzrus4b9.bin
c:\windows\system32\19750spamzot551.dll
c:\windows\system32\19853not5a-vi9uz529.exe
c:\windows\system32\1990z5r2705.dll
c:\windows\system32\19a6b59kdoor2318z.ocx
c:\windows\system32\19c5viz26449.cpl
c:\windows\system32\19z15roj4579.cpl
c:\windows\system32\1a4a9hizf2451.exe
c:\windows\system32\1b92zow5loader911.exe
c:\windows\system32\1bd5addw9re1z50.ocx
c:\windows\system32\1c1fdo9nlzader3255.bin

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
c:\windows\system32\1c95addware925z.exe
c:\windows\system32\1d7ethr9at2z755.cpl
c:\windows\system32\1de659iefz729.dll
c:\windows\system32\1e4fthi9z559.bin
c:\windows\system32\1e50spzware10839.dll
c:\windows\system32\1eadz5ea9750.exe
c:\windows\system32\1f37thief9z53.exe
c:\windows\system32\1f3a9aczdoo52054.dll
c:\windows\system32\1f43z9yware75.bin
c:\windows\system32\1fee5zr5349.cpl
c:\windows\system32\1fzethi5f5519.exe
c:\windows\system32\1z385pywa9e129.dll
c:\windows\system32\1z5csp9rse1913.ocx
c:\windows\system32\1z695troj545.bin
c:\windows\system32\1z6bth9eat385.cpl
c:\windows\system32\1z755troj195.ocx
c:\windows\system32\1za9vir5719.cpl
c:\windows\system32\20053spambzt6a69.ocx
c:\windows\system32\200z9orm465.ocx
c:\windows\system32\20245wo9mz5a.cpl
c:\windows\system32\203z5worm295.exe
c:\windows\system32\20550spazbot3bc9.exe
c:\windows\system32\20599spamzot12d5.exe
c:\windows\system32\20849v5rus689z.dll
c:\windows\system32\20869azk5oor3237.exe
c:\windows\system32\20977ha5ktool629z.bin
c:\windows\system32\209z5pyware7.ocx
c:\windows\system32\210z2vir9sb5.cpl
c:\windows\system32\21160w9rm535z.ocx
c:\windows\system32\2122do5n9ozder1264.dll
c:\windows\system32\21387sp5m9ot3z5.cpl
c:\windows\system32\21389tzo5579.dll
c:\windows\system32\21495not-az5irus279.ocx
c:\windows\system32\215z8wo9mc5.exe
c:\windows\system32\22115hackzo9l43c.exe
c:\windows\system32\22190nzt-a-virus555.dll
c:\windows\system32\2238zsp5965.bin
c:\windows\system32\22395szy10f.ocx
c:\windows\system32\224705z9us333.dll
c:\windows\system32\22470s9a5bot2z9.exe
c:\windows\system32\22509v9rus535z.bin
c:\windows\system32\229265pambzt9b.cpl
c:\windows\system32\22b7t9zef5599.ocx
c:\windows\system32\22z199pamb5t505.dll
c:\windows\system32\231559roj1z6.dll
c:\windows\system32\23492wo5z39c.dll
c:\windows\system32\23525zor9676.bin
c:\windows\system32\23728noz-a-virus95e.bin
c:\windows\system32\23745virzs2139.dll
c:\windows\system32\23z99ir5994.cpl
c:\windows\system32\24571viru5795z.bin
c:\windows\system32\24591spambzt521.dll
c:\windows\system32\249895pyz12.bin
c:\windows\system32\2500z5y2a9.ocx
c:\windows\system32\25117h9cktooz5e5.exe
c:\windows\system32\25118hz9ktool7d15.ocx
c:\windows\system32\2519dz9nlo5der129.cpl
c:\windows\system32\25205pa9sz2631.dll
c:\windows\system32\2527hazktoo9565.exe
c:\windows\system32\2535noz9a-virus299.dll
c:\windows\system32\253es5ywzre1299.dll
c:\windows\system32\25473zpy79d5.ocx
c:\windows\system32\25560zpy395.cpl
c:\windows\system32\25617spam9o5z76.dll
c:\windows\system32\25715zroj599.exe
c:\windows\system32\2573zs5y7949.ocx
c:\windows\system32\2575295rmz45.dll
c:\windows\system32\258519acktooz6f.ocx
c:\windows\system32\25942hacktz5l359.ocx
c:\windows\system32\25987spz358.cpl
c:\windows\system32\25a4s9arsez671.exe
c:\windows\system32\25adthreatz9438.cpl
c:\windows\system32\25e8st5al1697z.ocx
c:\windows\system32\25fethreat24092z.ocx
c:\windows\system32\25z8addw5re2091.exe
c:\windows\system32\25zdvir18579.ocx
c:\windows\system32\26195hacztool7ae.cpl
c:\windows\system32\26195noz-a-virus5e4.cpl
c:\windows\system32\26352trojz9b.bin
c:\windows\system32\264cz5eal26509.exe
c:\windows\system32\265349izus3f8.exe
c:\windows\system32\26595not-azviru97c.exe
c:\windows\system32\267fzhi9f9985.bin
c:\windows\system32\27104v9ruz15b5.cpl
c:\windows\system32\27899tr9z15d.exe
c:\windows\system32\27929h95ktoolz4a.ocx
c:\windows\system32\27999troj5z59.bin
c:\windows\system32\279ezp5rse2789.bin
c:\windows\system32\27a19pa5ze1510.ocx
c:\windows\system32\27e39own5oadzr91.ocx
c:\windows\system32\27z8sp5r9e1510.bin
c:\windows\system32\280725zrm5569.exe
c:\windows\system32\281znot-a-viru9325.bin
c:\windows\system32\2880hackt95z60c.exe
c:\windows\system32\29165spa5boz1df9.exe
c:\windows\system32\292629pzmbot6d5.cpl
c:\windows\system32\29385i9uz1ba.bin
c:\windows\system32\2940thzeat25969.exe
c:\windows\system32\2942859rusc6z.cpl
c:\windows\system32\294eaddzare5307.dll
c:\windows\system32\29583zacktool59b.cpl
c:\windows\system32\295905rojz97.exe
c:\windows\system32\29668viru935cz.dll
c:\windows\system32\29722zro56d4.bin
c:\windows\system32\297775roj3zf.exe
c:\windows\system32\29805sp547z.dll
c:\windows\system32\29846sz552b.dll
c:\windows\system32\29868woz95495.cpl
c:\windows\system32\2986addw9re21z5.ocx
c:\windows\system32\29902spa9b5t577z.exe
c:\windows\system32\29911hacztool9f5.ocx
c:\windows\system32\29940s5y7z9.cpl
c:\windows\system32\29966not-5-virzs66a.ocx
c:\windows\system32\2996z5ac9tool302.dll
c:\windows\system32\29e3addware11z5.bin
c:\windows\system32\29z58vi5us1d29.ocx
c:\windows\system32\2a43downloadzr395.exe
c:\windows\system32\2a75st9alz846.dll
c:\windows\system32\2c0ft9reat3z561.bin
c:\windows\system32\2ccdzownl5ader9669.cpl
c:\windows\system32\2e95back5oor1z98.dll
c:\windows\system32\2e95vzr1595.dll
c:\windows\system32\2f25thi9f1545z.bin
c:\windows\system32\2f7zaddw5r92277.exe
c:\windows\system32\2z072tro5229.bin
c:\windows\system32\2z0e95dware1.exe
c:\windows\system32\2z289hacktoo955b.bin
c:\windows\system32\2z452t5oj295.bin
c:\windows\system32\2z679hack5ool759.ocx
c:\windows\system32\2z989vir5s93.ocx
c:\windows\system32\2zspar591597.ocx
c:\windows\system32\3052vi9155z.bin
c:\windows\system32\30639not9z-5irus37d.exe
c:\windows\system32\30z25troj579.exe
c:\windows\system32\31145parsez913.bin
c:\windows\system32\3115zw9rm75b.cpl
c:\windows\system32\31829t5o9zb1.dll
c:\windows\system32\31z55not-a9virus601.ocx
c:\windows\system32\31z8wo9m525.cpl
c:\windows\system32\32030t9oz551.bin
c:\windows\system32\32069wo9518z.cpl
c:\windows\system32\3232tzief20995.dll
c:\windows\system32\32391spamb9t5z5.ocx
c:\windows\system32\32495spy24z.bin
c:\windows\system32\32556h59kzool210.bin
c:\windows\system32\32561troz2569.exe
c:\windows\system32\32636tro9zc5.ocx
c:\windows\system32\32915hacktzo527a.dll
c:\windows\system32\3294zacktoo5295.dll
c:\windows\system32\32abvir9z56.ocx
c:\windows\system32\32eedownloa9er571z.bin
c:\windows\system32\3309not-a5vizus9e5.ocx
c:\windows\system32\3339threa91105z.dll
c:\windows\system32\3359t9ie51060z.bin
c:\windows\system32\34125zckdoor9309.bin
c:\windows\system32\341zadd5are519.exe
c:\windows\system32\3499vi530z8.exe
c:\windows\system32\34b9vir36z5.cpl
c:\windows\system32\34z09iru53bc.cpl
c:\windows\system32\34z4spa95otc5.bin
c:\windows\system32\353zthie91816.bin
c:\windows\system32\355athr5a918z06.cpl
c:\windows\system32\3576not-a5viru91z4.dll
c:\windows\system32\357bsp9wa5e2z38.dll
c:\windows\system32\35eethief95z3.exe
c:\windows\system32\3665z9oj7b4.cpl
c:\windows\system32\3718thr5atz9009.dll
c:\windows\system32\3719addwzre525.ocx
c:\windows\system32\37615pa9zot635.ocx
c:\windows\system32\3795not-a-5irus74z.dll
c:\windows\system32\37f9ba5kdooz150.ocx
c:\windows\system32\38d15zars92315.dll
c:\windows\system32\38f9downlo5dez2443.cpl
c:\windows\system32\39156zroj529.bin
c:\windows\system32\3955vir504z.bin
c:\windows\system32\396zspywar582.ocx
c:\windows\system32\39dc5tealz3999.exe
c:\windows\system32\39ebacz5oor1257.bin
c:\windows\system32\3a80zteal9596.ocx
c:\windows\system32\3aa2ba59door1z13.ocx
c:\windows\system32\3affbackd9o5z915.ocx
c:\windows\system32\3b2th9ea518506z.dll
c:\windows\system32\3c4zaddw5re10219.dll
c:\windows\system32\3df8ztea5944.dll
c:\windows\system32\3e1cspywaz92395.ocx
c:\windows\system32\3e49thief51z4.cpl
c:\windows\system32\3e93ba5kdoor2z28.dll
c:\windows\system32\3fc5z9eal1554.bin
c:\windows\system32\3fze9tea51957.dll
c:\windows\system32\3z5cbac9d5or2718.dll
c:\windows\system32\3z5dthief69.dll
c:\windows\system32\3z75ad9ware3037.bin
c:\windows\system32\3z89spywa5e1402.bin
c:\windows\system32\3z939p5ware3125.cpl
c:\windows\system32\3z94spy598.dll
c:\windows\system32\405cs9arse1z505.dll
c:\windows\system32\4093spa5se3084z.cpl
c:\windows\system32\41275ot-a-zirus191.exe
c:\windows\system32\41cav9r735z.ocx
c:\windows\system32\41dbbackd9zr2559.bin
c:\windows\system32\424z5ackdoor1409.cpl
c:\windows\system32\4289steal1z85.exe
c:\windows\system32\429edownlo5d9r1z53.cpl
c:\windows\system32\4354zhreat218269.ocx
c:\windows\system32\44zaba9kdo5r950.ocx
c:\windows\system32\4503addzare597.ocx
c:\windows\system32\4529thiefz069.cpl
c:\windows\system32\4555trojz9.ocx
c:\windows\system32\459f5ownz9ader1402.bin
c:\windows\system32\45czth9eat2768.ocx
c:\windows\system32\45d5steaz1498.cpl
c:\windows\system32\4625spy9aze30865.ocx
c:\windows\system32\46605orm4z9.bin
c:\windows\system32\4675ste9z62.ocx
c:\windows\system32\46919acktool64z5.bin
c:\windows\system32\4696troj59bz.dll
c:\windows\system32\47e7vi959z.cpl
c:\windows\system32\47fdstz9l5505.ocx
c:\windows\system32\47z7vir9s65.ocx
c:\windows\system32\4824wzrm695.cpl
c:\windows\system32\4829downzo9de5372.exe
c:\windows\system32\4916zpyware8985.exe
c:\windows\system32\4986vi5396z.exe
c:\windows\system32\49a3th95az7029.ocx
c:\windows\system32\49b6spyw5r97z9.ocx
c:\windows\system32\49z9steal5152.bin
c:\windows\system32\4a96sparse1755z.cpl
c:\windows\system32\4azt59ef43.ocx
c:\windows\system32\4bd7th5zf23999.cpl
c:\windows\system32\4c53st9al290z.exe
c:\windows\system32\4d0thre593z531.ocx
c:\windows\system32\4da9s9yware151z.exe
c:\windows\system32\4dd5sp9rse689z.cpl
c:\windows\system32\4dzbv9r3150.cpl
c:\windows\system32\4e55stea92351z.ocx
c:\windows\system32\4e6dsparze9095.cpl
c:\windows\system32\4e84t5i9z2330.exe
c:\windows\system32\4ea2t9iez995.dll

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
c:\windows\system32\4fe8threaz11952.cpl
c:\windows\system32\4z599hreat22525.exe
c:\windows\system32\4z75s95766.ocx
c:\windows\system32\4z85ack9oor2825.dll
c:\windows\system32\4z85troj3d9.ocx
c:\windows\system32\4z975parse1166.cpl
c:\windows\system32\4z99ste5l199.exe
c:\windows\system32\4zb3downloa9er26075.bin
c:\windows\system32\4zbc9tea51946.exe
c:\windows\system32\4zcc9ir5364.dll
c:\windows\system32\4zee5tea91659.exe
c:\windows\system32\502bspa5sz990.exe
c:\windows\system32\502ezownlo9der1525.exe
c:\windows\system32\5032not-a95irzs318.exe
c:\windows\system32\504cvir359z.ocx
c:\windows\system32\505at9reat2099z.dll
c:\windows\system32\505downloaz9r286.exe
c:\windows\system32\505z8spambot3d99.cpl
c:\windows\system32\50765spz229.ocx
c:\windows\system32\5090spambzt533.dll
c:\windows\system32\5094zot-a-virus9f5.dll
c:\windows\system32\5097backdoor26z8.exe
c:\windows\system32\509ha5kzool69e.cpl
c:\windows\system32\50a5thie9z869.ocx
c:\windows\system32\50bstz9l3098.cpl
c:\windows\system32\50d5sp9zse1348.ocx
c:\windows\system32\50z8hacktoo925a.bin
c:\windows\system32\51219vi9us6az.dll
c:\windows\system32\5159downloadez984.dll
c:\windows\system32\5169sparsez45.exe
c:\windows\system32\516bt9ief159z5.ocx
c:\windows\system32\5243s5y9aze2710.dll
c:\windows\system32\525czddware5948.bin
c:\windows\system32\5274szyware14159.cpl
c:\windows\system32\528zwo5m89.bin
c:\windows\system32\52f9sparse15z8.dll
c:\windows\system32\5309pambzt109.dll
c:\windows\system32\531fvzr32495.bin
c:\windows\system32\5340addwzre5659.dll
c:\windows\system32\534virz93.bin
c:\windows\system32\537edownloazer595.cpl
c:\windows\system32\539cv9z1365.bin
c:\windows\system32\5412hacktoo53fz9.bin
c:\windows\system32\54659wozm59e.bin
c:\windows\system32\549spyware95z.exe
c:\windows\system32\54b9spyza9e855.exe
c:\windows\system32\54d59ownloadzr3052.exe
c:\windows\system32\54e39ackdozr4765.ocx
c:\windows\system32\55145ot-a9virus59z.bin
c:\windows\system32\55155tr9z229.ocx
c:\windows\system32\5519not-a-virus50z.ocx
c:\windows\system32\551zworm4999.exe
c:\windows\system32\55280worm97dz.cpl
c:\windows\system32\5541hacktoolz93.exe
c:\windows\system32\555z6vi9us105.ocx
c:\windows\system32\55936not-a9zirus321.exe
c:\windows\system32\55ecthrzat5692.bin
c:\windows\system32\55ze9parse5288.ocx
c:\windows\system32\563thie52z9.bin
c:\windows\system32\5651sparze19919.cpl
c:\windows\system32\56736tr9j65z.ocx
c:\windows\system32\5680backzoor2195.exe
c:\windows\system32\568a9ownloa5erz255.cpl
c:\windows\system32\5692wzrm495.exe
c:\windows\system32\569z8virus1ea.dll
c:\windows\system32\56a09ir18z3.exe
c:\windows\system32\56b8v59z612.exe
c:\windows\system32\56d5thief2319z.bin
c:\windows\system32\5725h9cktool52z.dll
c:\windows\system32\5759tealz035.ocx
c:\windows\system32\576zsteal3049.ocx
c:\windows\system32\57984zirus2e9.ocx
c:\windows\system32\5799down5oadzr965.cpl
c:\windows\system32\579bvirz075.dll
c:\windows\system32\57e4spywarz9859.ocx
c:\windows\system32\5809zparse1401.ocx
c:\windows\system32\584zth9ef2310.bin
c:\windows\system32\585fspyw9re25z3.dll
c:\windows\system32\5890vzr195.ocx
c:\windows\system32\589ezack9o5r2815.bin
c:\windows\system32\58b5zhreat39871.bin
c:\windows\system32\59139zt-a-5irus4b5.cpl
c:\windows\system32\593cdownloaderz155.exe
c:\windows\system32\5945troj9zf.bin
c:\windows\system32\5962zspambot498.cpl
c:\windows\system32\596429roj32cz.exe
c:\windows\system32\5965troz30d9.dll
c:\windows\system32\5968baczdo5r85.cpl
c:\windows\system32\596z2worm188.ocx
c:\windows\system32\597z5virus43a.cpl
c:\windows\system32\5980spzrse3219.bin
c:\windows\system32\5983zirus2d2.dll
c:\windows\system32\5986addwaz91100.exe
c:\windows\system32\5987spywaz51909.ocx
c:\windows\system32\5991thre5tz583.exe
c:\windows\system32\5991vi52z36.ocx
c:\windows\system32\5992spamboza29.dll
c:\windows\system32\59e3back9oor16z4.bin
c:\windows\system32\59ethief35z5.dll
c:\windows\system32\5a3spy9are155z.exe
c:\windows\system32\5a5bviz5791.ocx
c:\windows\system32\5a7ft59eatz990.ocx
c:\windows\system32\5a95t9zef1667.ocx
c:\windows\system32\5ac2spyw9re2z68.dll
c:\windows\system32\5b7baddw5rez29.ocx
c:\windows\system32\5b92downloader191z5.dll
c:\windows\system32\5b9ddo9nload5r17z4.ocx
c:\windows\system32\5c0zstea91138.cpl
c:\windows\system32\5c95sp5warez659.exe
c:\windows\system32\5c9bvir2331z.bin
c:\windows\system32\5c9szar9e3046.exe
c:\windows\system32\5cc4zackdoo9326.cpl
c:\windows\system32\5cz1downloade9121.dll
c:\windows\system32\5d37do5nloadzr20449.bin
c:\windows\system32\5d9aazdwa9e2632.ocx
c:\windows\system32\5df4spzrs91665.dll
c:\windows\system32\5df9downloazer2535.exe
c:\windows\system32\5dz0bac59oor2068.cpl
c:\windows\system32\5e91th59f948z.dll
c:\windows\system32\5e94thzeat98859.cpl
c:\windows\system32\5eb1tzie9122.bin
c:\windows\system32\5ee3sp9zse1779.cpl
c:\windows\system32\5ez1spy5ar92304.ocx
c:\windows\system32\5ezs9eal741.dll
c:\windows\system32\5f1b9zief2600.dll
c:\windows\system32\5f4fadzwa9e885.cpl
c:\windows\system32\5f99threat1z673.cpl
c:\windows\system32\5fbad5wnloa9er26z2.cpl
c:\windows\system32\5ff9szea51830.dll
c:\windows\system32\5z829ownload5r654.ocx
c:\windows\system32\607cdowzl95der2179.cpl
c:\windows\system32\60a0zownl9ader2025.dll
c:\windows\system32\60e9spyw5re243z.bin
c:\windows\system32\60fctz5e91519.ocx
c:\windows\system32\61929pazbot5765.cpl
c:\windows\system32\6293downlz5de91636.bin
c:\windows\system32\6310zpa9b5t1f.dll
c:\windows\system32\6315zdd9are50.ocx
c:\windows\system32\6320t5ief2769z.exe
c:\windows\system32\6354baczdoor3569.dll
c:\windows\system32\63czs5eal6569.bin
c:\windows\system32\643559wnloadez3087.dll
c:\windows\system32\645zspywar92513.cpl
c:\windows\system32\6520thi9z1559.bin
c:\windows\system32\654bzhief2975.ocx
c:\windows\system32\655e9teal845z.ocx
c:\windows\system32\655spywarez910.exe
c:\windows\system32\65f9spywzre2909.cpl
c:\windows\system32\65zes9eal30.bin
c:\windows\system32\6651bzckdoor2859.ocx
c:\windows\system32\6759sparze2335.dll
c:\windows\system32\6779szy37b5.exe
c:\windows\system32\67z0steal5898.dll
c:\windows\system32\685adownloade96z8.ocx
c:\windows\system32\688asz5al9164.dll
c:\windows\system32\695cvi5193z.dll
c:\windows\system32\6981thizf1185.dll
c:\windows\system32\6985st9al2z87.bin
c:\windows\system32\6a04thz9at28405.ocx
c:\windows\system32\6a51baczdoor12319.cpl
c:\windows\system32\6a95steal5620z.dll
c:\windows\system32\6b15spa5se249z9.bin
c:\windows\system32\6b6dspars9111z5.cpl
c:\windows\system32\6b7espar9e15z0.cpl
c:\windows\system32\6cz4thie928945.cpl
c:\windows\system32\6ea35ackdoo93z01.dll
c:\windows\system32\6eb9azdwa5e2289.cpl
c:\windows\system32\6ez295eal1414.bin
c:\windows\system32\6z1thre5t114549.exe
c:\windows\system32\6z25w5r994.ocx
c:\windows\system32\6z4s9eal555.bin
c:\windows\system32\6z54s9yf5.bin
c:\windows\system32\6z75s9eal65.cpl
c:\windows\system32\6z82ad9w5re3038.ocx
c:\windows\system32\6z99tr5j71e.dll
c:\windows\system32\7091zp5r9e2625.exe
c:\windows\system32\70d4t5rezt9974.cpl
c:\windows\system32\726as5z9are3241.dll
c:\windows\system32\7299tzief2564.exe
c:\windows\system32\7353szeal9255.bin
c:\windows\system32\742fspyz9re3556.bin
c:\windows\system32\74515ackdooz26049.dll
c:\windows\system32\7560sparse9607z.cpl
c:\windows\system32\7595steal476z.exe
c:\windows\system32\770not-a-9izu5773.bin
c:\windows\system32\7782s9azbot555.exe
c:\windows\system32\77s9ywar5981z.bin
c:\windows\system32\787z9roj2a15.exe
c:\windows\system32\78z059eal2184.ocx
c:\windows\system32\78z5s5y35a9.exe
c:\windows\system32\78z5sparse9964.cpl
c:\windows\system32\790zdow9loader355.dll
c:\windows\system32\79185hiefz96.cpl
c:\windows\system32\7959spzmbot229.ocx
c:\windows\system32\795zt5reat16532.bin
c:\windows\system32\7995wor914z.ocx
c:\windows\system32\79dzsp95are567.exe
c:\windows\system32\7b8fthiez9956.cpl
c:\windows\system32\7b969ownlzader2415.dll
c:\windows\system32\7bzbthief2950.dll
c:\windows\system32\7c5f5hreaz13298.bin
c:\windows\system32\7c86sp5rsez898.dll
c:\windows\system32\7d5baddware90z6.dll
c:\windows\system32\7e025ze9l2554.cpl
c:\windows\system32\7e51adzware9571.dll
c:\windows\system32\7e56do59lozder2084.bin
c:\windows\system32\7e59bac9door103z5.bin
c:\windows\system32\7e76spars915z7.exe
c:\windows\system32\7effthre5t9780z.dll
c:\windows\system32\7fd0zhreat30569.dll
c:\windows\system32\7z2cth5e93024.dll
c:\windows\system32\7z465irusbd9.bin
c:\windows\system32\7z49thie5975.dll
c:\windows\system32\7z58downl5ader9445.exe
c:\windows\system32\7z81sp5ware1629.cpl
c:\windows\system32\7z95addwar9509.cpl
c:\windows\system32\7za8downl5ader9427.cpl
c:\windows\system32\7zcct5i9f2141.cpl
c:\windows\system32\8055sp91z5.exe
c:\windows\system32\82739otz5-virus307.exe
c:\windows\system32\8305t9az1376.ocx
c:\windows\system32\8351zorm9335.bin
c:\windows\system32\8531s9y22az.bin
c:\windows\system32\853backd5o92960z.cpl
c:\windows\system32\8559haczt9ol354.dll
c:\windows\system32\85759roj1f6z.ocx
c:\windows\system32\863spzwa95203.exe
c:\windows\system32\870z9y2845.cpl
c:\windows\system32\8715vi5zs5f9.dll
c:\windows\system32\8798vizus5b9.ocx
c:\windows\system32\8890tzo5937.cpl
c:\windows\system32\89895orz357.cpl
c:\windows\system32\8dc59zware775.bin
c:\windows\system32\9004not-a-vz5us5eb.cpl
c:\windows\system32\90076spamzot553.cpl
c:\windows\system32\903baddware1z59.exe
c:\windows\system32\90557hacktool1z6.dll
c:\windows\system32\9059zr2125.ocx
c:\windows\system32\905z1spy535.dll
c:\windows\system32\90709hacktooz755.ocx
c:\windows\system32\9123not-a-vzrus750.exe
c:\windows\system32\9153spa5se75z.cpl
c:\windows\system32\9167tro57z2.ocx
c:\windows\system32\91907worm5ze.dll
c:\windows\system32\91925virzs2c.exe
c:\windows\system32\91dbaz5door985.bin
c:\windows\system32\92845pambot672z.ocx
c:\windows\system32\934caddwzre1195.cpl
c:\windows\system32\9358szywa5e656.exe
c:\windows\system32\942zsp529d.exe
c:\windows\system32\94353wo5z502.exe
c:\windows\system32\9457worm9bz.cpl
c:\windows\system32\949925zrusff.ocx
c:\windows\system32\95281spz621.cpl
c:\windows\system32\9530wzrm932.dll

descriptionI've been infected with Winbluesoft - Page 2 EmptyRe: I've been infected with Winbluesoft

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum