i accidentally installed WinBlueSoft on my comp and cant get it off how do i go about removing it...im also an idiot when it comes to computers so can i get so in-depth directions
Kettsueyes 0 Newbie Poster
Dani AI
Generated
Quick note following original post and ’s recommended scans: WinBlueSoft is a classic fake-AV/rogueware that often blocks or resets real scanners and leaves persistent startup items. The advice to run Malwarebytes and produce a HijackThis log is the right first step; the material below covers next-stage actions and safe fallbacks when scanners are blocked or the infection returns.
Common next steps that are safe and non-destructive:
- Start Windows in Safe Mode (Safe Mode with Networking if downloads are needed) so fewer malicious components run. Microsoft documents how to start in Safe Mode here: Start your PC in Safe Mode.
- If a scanner will not run, use a process-killer tool such as RKill to stop rogue processes so scanners can complete (RKill — BleepingComputer).
- After processes are stopped, run a full scan with Malwarebytes (as suggested) and an adware cleaner such as AdwCleaner to remove browser and PUP remnants (AdwCleaner).
If the program persists after scans:
- Use Autoruns to find and remove entries the malware created in Run keys, services, scheduled tasks, and drivers. Autoruns shows exactly what starts on boot and where it is defined: Autoruns — Sysinternals.
- Inspect Scheduled Tasks, the hosts file, and common folders (Program Files, AppData, Documents and Settings) for folders or executables whose names reference WinBlue or similar. Export any registry keys before editing and prefer deleting startup entries via Autoruns rather than manual registry edits.
When to escalate: a rescue/boot disk scan or a clean reinstall is faster and safer for heavily infected systems. For guided removals and examples of FakeAV cleanups, see the BleepingComputer Virus Removal forum: .
Practical cautions: do not pay or supply personal data to the rogue, back up personal files first, and avoid tools or fixes from unknown sites. Per , the Malwarebytes and HijackThis logs remain the most useful diagnostics for responders.
crunchie 990 Most Valuable Poster Team Colleague Featured Poster
Hi and welcome to the Daniweb forums :).
==========
Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Download the update from here if you have problems.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
Make sure that you restart the computer.
===============
Download HijackThis Executable from here. Save it to your desktop.
Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option of where to save it. Save it to desktop where it is easy to access. Open the log file and then go to the format Tab and make sure that wordwrap is unchecked. Copy the entire contents of the file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.