Hi,
Trojan (virus) file. Follow these "relatively" simple removal steps:
Restart in Safe mode by hitting F8 as Windows first begins to load on boot.
Logon as administrator.
Start/search/files and folders, look for jdfkhbej.exe and delete it wherever
it is found.
Start/run regedit, expand the + signs to look under these keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
Look in the right hand pane for the string or strings that load that file.
Delete just those strings that contain the reference. Do not delete other
strings or the keys from the left pane. Close the registry editor when
completed, make sure you check all strings.
Go to the Control Panel/System/System Restore tab. Check the box to "Turn
off system restore on all drives". Click apply/ok. This will remove all
restore points, however you don't want them back as some or all of them will
contain the virus depending upon how recently you got infected.
Restart the system normally. Go back to the Control Panel/System and restart
System Restore.
Update your antivirus software.
--
Best of Luck,
Rick Rogers, aka "Nutcase" - Microsoft MVP
Associate Expert - WindowsXP Expert Zone
Windows help -
www.rickrogers.org
smiley188 said:
For the past few days, whenever i've tried shutting down my Windows XP
program, i keep getting an error message that a file - jdfkhbej.exe is still
running and the pop up asks if i want to cancel the shut down command or
continue with it and lose any unsaved data. I'm worried that this strange
file is a virus or something of that nature. I did a search - there are 2 of
these files, one in the c:/windows/prefetch directory and the other in the
c:/windows/system32 directory. Any ideas what this file is? I would like to
delete it but am afraid that i may delete something that sd be there in the
first place....thanks!!