05-19-2010 01:04 PM - last edited on 05-19-2010 03:22 PM by shannons
I am having the same problem. I have run the hijack this program and have attached the log. Could you please let me know which files I should delete? I would appreciate any help you can give me.
[edit: Clarified subject.]
05-19-2010 03:36 PM
Now start Hijackthis and you will see beside each entry a little box that you can tick the entries you want.
With Hijackthis tick / check these entries below, look carefully there are actually 2 O4 entries to tick it's not a typo below
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int
O4 - HKLM\..\Run: [dojpfhit] C:\Documents and Settings\User\Local Settings\Application Data\xjmmxands\cvnwuvatssd.exe
O4 - HKCU\..\Run: [dojpfhit] C:\Documents and Settings\User\Local Settings\Application Data\xjmmxands\cvnwuvatssd.exe
Now Click the "Fix Checked" button. That should remove those entries.
Now restart the PC, the rogue should not start up on the restart.
Next, check the Internet Connections so that the Proxy is NOT selected, see the link below