Spybot will not remove Win32BHO.je

NoSweatMan

New member
Running Spybot 1.5.2
XP Professional 5.1.2600 SP 2 Build 2600

Spybot identifyed Win32BHO.je as a Malware threat,
identifiedon the Search & Distroy results with register key as (SBI $426E0B56) Browser helper object
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Exployer\Browser Helper Objects\{DF47DD37-4A93-8E. . .

When I tried fix (remove) it, I get a warning that states . . .
"some problems couldn't be fixed; the reason could be that the associated files are still in use (in memory). This could be fixed after a restart.
May Spybot-S&D run on your next system restart?"

I tried that option, but it appears to be cyclical with the same results.

I tried to log the error, but I got an error "Invalid argument to date encode". I couldn't even cut & paste the information.

I looked at Spybot Tools & it appears that one of the BHO's "e404 helper" has the same CLSID.

I tried running Kaspersky, but Windows crashes with a blue screen before it get very far in the scan.
Because of this, I thought attempting hijack might be a waste of time.

Windowss also crashes when I try to run Norton Security Scan and also when I try to launch FireFox. iexplorer seemed to function properly, after I unchecked the Internet Advanced browser Option "Enable third-party browser extensions"

The only other information I can give you is that I do see a
c:\Program Files\Helper directory, but i cannot delete it.

I hope this helps.

If I need to provide more information, just let me know.

Any help would be appreciated.
 
Hi NoSweatMan

Click here to download HJTInstall.exe
  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT use the AnalyseThis button, its findings are dangerous if misinterpreted.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
 
Hi Shaba,

I'm sorry but I just couldn't wait for a reply, so since I needed my computer I reformated & reloaded XP.

Through this process I have learn a great deal by reading this form.

Thank you so much for your reply.
 
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.
 
Back
Top