Jump to content


Photo

TvmBho.dll & I don't know how to get rid it


  • Please log in to reply
6 replies to this topic

#1 Cain

Cain

    Member

  • Full Member
  • Pip
  • 28 posts

Posted 12 June 2004 - 06:26 PM

I got this thing got TV Media in my parents computer and I don't know how to get rid of it. There is also a lot of other junk that I found using HiJackthis and I don't know what to get rid of. Please help.

Thanks

Logfile of HijackThis v1.97.7
Scan saved at 12:41:39, on 2004-6-12
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\sysupd.exe
C:\Program Files\Common files\updater\wupdater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\VBouncer\VirtualBouncer.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\gooduser\My Documents\HijackThis.exe

R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {00000EF1-0786-4633-87C6-1AA7A44296DA} - C:\WINDOWS\System32\ATPART~1.DLL
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ????? - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [srsryx] C:\WINDOWS\srsryx.exe
O4 - HKLM\..\Run: [mjuxuz] C:\WINDOWS\mjuxuz.exe
O4 - HKLM\..\Run: [ojkzmrcb] C:\WINDOWS\ojkzmrcb.exe
O4 - HKLM\..\Run: [uxwp] C:\WINDOWS\uxwp.exe
O4 - HKLM\..\Run: [qzwpotyh] C:\WINDOWS\qzwpotyh.exe
O4 - HKLM\..\Run: [gnsxqz] C:\WINDOWS\gnsxqz.exe
O4 - HKLM\..\Run: [dwj] C:\WINDOWS\dwj.exe
O4 - HKLM\..\Run: [bmfyxwp] C:\WINDOWS\bmfyxwp.exe
O4 - HKLM\..\Run: [tabefej] C:\WINDOWS\tabefej.exe
O4 - HKLM\..\Run: [hwjwryr] C:\WINDOWS\hwjwryr.exe
O4 - HKLM\..\Run: [mvobql] C:\WINDOWS\mvobql.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [ronahkj] C:\WINDOWS\ronahkj.exe
O4 - HKLM\..\Run: [xwjeh] C:\WINDOWS\xwjeh.exe
O4 - HKLM\..\Run: [lozqnkb] C:\WINDOWS\lozqnkb.exe
O4 - HKLM\..\Run: [pgfkt] C:\WINDOWS\pgfkt.exe
O4 - HKLM\..\Run: [jwlonir] C:\WINDOWS\jwlonir.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\RunOnce: [_UnwiseDMO] cmd.exe /c del C:\WINDOWS\System32\ATPartners.dll
O4 - HKLM\..\RunOnce: [_UnwiseDMO_] cmd.exe /c del C:\WINDOWS\System32\im64.dll
O4 - HKCU\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\RunOnce: [DeleteISTbar] rundll32.exe advpack.dll,DelNodeRunDLL32 "C:\Program Files\ISTbar\istbar.dll"
O4 - Startup: NTUSER.DAT
O4 - Startup: NTUSER.DAT.LOG
O4 - Startup: ntuser.ini
O4 - Startup: dpusys.ini
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg...t/c381/chat.cab
O16 - DPF: {012F24D4-6A26-11D3-AA0F-0000E8212478} (WisImage Class) - http://219.133.31.212/wisimage.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg...v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...s/yinst0401.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...81/mcinsctl.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8124.9246412037
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,19/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ol_v1-0-3-0.cab

#2 billiebob

billiebob

    Caperjack

  • Retired Staff - Helper
  • PipPipPip
  • 248 posts

Posted 12 June 2004 - 06:50 PM

You have a bit more than Media tv ,lets start with these programs

Might I suggest Ad-Aware and Spybot & Hijackthis .

Download the latest version of Ad-Aware at ADAWARE

Download SPYBOT

How to setup Ad-Aware and Spy-Bot S&D
http://www.zerosrealm.com/scanning.php

And after that, please do the following:
Run the free online virus scan in my signature .

#3 billiebob

billiebob

    Caperjack

  • Retired Staff - Helper
  • PipPipPip
  • 248 posts

Posted 12 June 2004 - 06:50 PM

Also a trip to windows updates is needed for critical updates and SP1's
WINDOWS UPDATES

Post a fresh hijackthis log

Edited by billiebob, 12 June 2004 - 06:51 PM.


#4 Cain

Cain

    Member

  • Full Member
  • Pip
  • 28 posts

Posted 12 June 2004 - 09:20 PM

Okay for some reason when I ran the update to get the SP1, the installer for the update didn't install due to some language problems. It said in chinese that it can't run the installation. Here is the new log and thanks for the help.

Logfile of HijackThis v1.97.7
Scan saved at 19:17:40, on 2004-6-12
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\sysupd.exe
C:\WINDOWS\ojkzmrcb.exe
C:\WINDOWS\uxwp.exe
C:\WINDOWS\qzwpotyh.exe
C:\WINDOWS\gnsxqz.exe
C:\WINDOWS\dwj.exe
C:\WINDOWS\bmfyxwp.exe
C:\WINDOWS\tabefej.exe
C:\WINDOWS\hwjwryr.exe
C:\WINDOWS\mvobql.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\ronahkj.exe
C:\WINDOWS\xwjeh.exe
C:\WINDOWS\lozqnkb.exe
C:\WINDOWS\pgfkt.exe
C:\WINDOWS\jwlonir.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\AdDestroyer\AdDestroyer.exe
C:\WINDOWS\System32\conime.exe
C:\PROGRA~1\HEWLET~1\hpis\common\MOTIVE~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\gooduser\My Documents\HijackThis.exe

R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ????? - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [srsryx] C:\WINDOWS\srsryx.exe
O4 - HKLM\..\Run: [mjuxuz] C:\WINDOWS\mjuxuz.exe
O4 - HKLM\..\Run: [ojkzmrcb] C:\WINDOWS\ojkzmrcb.exe
O4 - HKLM\..\Run: [uxwp] C:\WINDOWS\uxwp.exe
O4 - HKLM\..\Run: [qzwpotyh] C:\WINDOWS\qzwpotyh.exe
O4 - HKLM\..\Run: [gnsxqz] C:\WINDOWS\gnsxqz.exe
O4 - HKLM\..\Run: [dwj] C:\WINDOWS\dwj.exe
O4 - HKLM\..\Run: [bmfyxwp] C:\WINDOWS\bmfyxwp.exe
O4 - HKLM\..\Run: [tabefej] C:\WINDOWS\tabefej.exe
O4 - HKLM\..\Run: [hwjwryr] C:\WINDOWS\hwjwryr.exe
O4 - HKLM\..\Run: [mvobql] C:\WINDOWS\mvobql.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [ronahkj] C:\WINDOWS\ronahkj.exe
O4 - HKLM\..\Run: [xwjeh] C:\WINDOWS\xwjeh.exe
O4 - HKLM\..\Run: [lozqnkb] C:\WINDOWS\lozqnkb.exe
O4 - HKLM\..\Run: [pgfkt] C:\WINDOWS\pgfkt.exe
O4 - HKLM\..\Run: [jwlonir] C:\WINDOWS\jwlonir.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: NTUSER.DAT.LOG
O4 - Startup: ntuser.ini
O4 - Startup: dpusys.ini
O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg...t/c381/chat.cab
O16 - DPF: {012F24D4-6A26-11D3-AA0F-0000E8212478} (WisImage Class) - http://219.133.31.212/wisimage.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg...v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...s/yinst0401.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...81/mcinsctl.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8124.9246412037
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,19/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ol_v1-0-3-0.cab

#5 billiebob

billiebob

    Caperjack

  • Retired Staff - Helper
  • PipPipPip
  • 248 posts

Posted 13 June 2004 - 05:34 AM

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary.

#6 billiebob

billiebob

    Caperjack

  • Retired Staff - Helper
  • PipPipPip
  • 248 posts

Posted 13 June 2004 - 10:30 AM

Did you run Spy-bot and Ad-aware .

#7 billiebob

billiebob

    Caperjack

  • Retired Staff - Helper
  • PipPipPip
  • 248 posts

Posted 13 June 2004 - 03:36 PM

Have Hijack This fix the following by placing a check in the appropriate

boxes and selecting fix checked. Make sure all browser and all Windows

Explorer windows are closed before fixing.


O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} -

C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL

O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe

O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe

O4 - HKLM\..\Run: [srsryx] C:\WINDOWS\srsryx.exe

O4 - HKLM\..\Run: [mjuxuz] C:\WINDOWS\mjuxuz.exe

O4 - HKLM\..\Run: [ojkzmrcb] C:\WINDOWS\ojkzmrcb.exe

O4 - HKLM\..\Run: [uxwp] C:\WINDOWS\uxwp.exe

O4 - HKLM\..\Run: [qzwpotyh] C:\WINDOWS\qzwpotyh.exe

O4 - HKLM\..\Run: [gnsxqz] C:\WINDOWS\gnsxqz.exe

O4 - HKLM\..\Run: [dwj] C:\WINDOWS\dwj.exe

O4 - HKLM\..\Run: [bmfyxwp] C:\WINDOWS\bmfyxwp.exe

O4 - HKLM\..\Run: [tabefej] C:\WINDOWS\tabefej.exe

O4 - HKLM\..\Run: [hwjwryr] C:\WINDOWS\hwjwryr.exe

O4 - HKLM\..\Run: [mvobql] C:\WINDOWS\mvobql.exe


O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe

O4 - HKLM\..\Run: [ronahkj] C:\WINDOWS\ronahkj.exe

O4 - HKLM\..\Run: [xwjeh] C:\WINDOWS\xwjeh.exe

O4 - HKLM\..\Run: [lozqnkb] C:\WINDOWS\lozqnkb.exe

O4 - HKLM\..\Run: [pgfkt] C:\WINDOWS\pgfkt.exe

O4 - HKLM\..\Run: [jwlonir] C:\WINDOWS\jwlonir.exe


O4 - HKLM\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe

O4 - HKCU\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe

O4 - Startup: NTUSER.DAT

O4 - Startup: NTUSER.DAT.LOG

O4 - Startup: ntuser.ini

O4 - Startup: dpusys.ini


Now reboot into safe mode and delete the following files and folders if

found .


C:\WINDOWS\sysupd.exe....delete file


C:\Program Files\TV Media\....delete folder

C:\WINDOWS\srsryx.exe....delete file

C:\WINDOWS\mjuxuz.exe....delete file

C:\WINDOWS\ojkzmrcb.exe....delete file

C:\WINDOWS\uxwp.exe....delete file

C:\WINDOWS\qzwpotyh.exe....delete file

C:\WINDOWS\gnsxqz.exe....delete file

C:\WINDOWS\dwj.exe....delete file

C:\WINDOWS\bmfyxwp.exe....delete file

C:\WINDOWS\tabefej.exe....delete file

C:\WINDOWS\hwjwryr.exe....delete file

C:\WINDOWS\mvobql.exe....delete file



C:\WINDOWS\ronahkj.exe....delete file

C:\WINDOWS\xwjeh.exe....delete file

C:\WINDOWS\lozqnkb.exe....delete file

C:\WINDOWS\pgfkt.exe....delete file

C:\WINDOWS\jwlonir.exe....delete file




to delete the above files and folder you will need to do the following
go to
Show hidden

files & folders


"Fix Checked"...Reboot to SAFE mode to delete files
How to start computer

in safe mode


reboot computer and post a new log

Edited by billiebob, 13 June 2004 - 03:50 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button