Secure Most Provide you most reliable security utilities!
Home Articles File Center Privacy Contact us Links
Now Position: Home>Tech Articles>Emerging Prevalent Pests
How to Remove Unknown BHO Toolbar?
Unknown BHO Description:

A component that Internet Explorer will load whenever it starts, shares IE's memory context, can perform any action on the available windows and modules.

Unknown BHO Automatic Removal:

Using Spyware Doctor to remove Unknown BHO AUTOMATICALLY

Sponsored Links:

Unknown BHO Manual Removal:

Follow these steps to remove Unknown BHO from your machine. Begin by backing up your registry and your system, and/or setting a Restore Point, to prevent trouble if you make a mistake.

  1. Kill these running processes with Task Manager:
    getthis4free.exe
    programfilesdir+\navpass\navpass.exe
    programfilesdir+\system\misc\scrnsvr.exe
    programfilesdir+\system\misc\ufixmx.exe
    programfilesdir+\system\misc\vpinst.exe
    s42ns.exe
    systemroot+\hqr.exe
    systemroot+\preinsmt.exe
    systemroot+\quyrpdch.exe
    systemroot+\system\helper.exe
    systemroot+\system\wtssvit.exe
    systemroot+\system32\epqwnen.exe
    systemroot+\system32\hpdllhost.exe
    systemroot+\system32\ndrv.exe
    systemroot+\system32\orpioqa.exe
    systemroot+\system32\vpataszc.exe
    systemroot+\system32\wtssvit.exe
    systemroot+\temp\lgycy.exe
    wtsit.exe
    zlch.exe
     
  2. Go to the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
    If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\instant access, delete it and reboot the machine immediately.
    If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\ndrv, delete it and reboot the machine immediately.
    If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\taskbar display controls, delete it and reboot the machine immediately.
    If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\uninstal, delete it and reboot the machine immediately.
    If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\wapi, delete it and reboot the machine immediately.
    If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices\image, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\000hpdllhost, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\he3e3fc4, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\hpsysconf, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\iel2cde8, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\image, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\kw3eef76, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\lgycy, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\li01f948, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\navpass, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\nssysconf, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\readdb40, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\rpjzd, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
    \schoolpopshoppingbuddy, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\si91e44b, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\winxpservice, delete it and reboot the machine immediately.
     
  3. Unregister these DLLs with Regsvr32, then reboot:
    apphelp32.dll
    c:\windows\system32\advpyack.dll
    explorer.dll
    mwssrcas.dll
    npmysrch.dll
    profilepath+\application data\iestcrmfrood.dll
    profilepath+\application data\pntrlltsq.dll
    programfilesdir+\active~1\save corn.dll
    programfilesdir+\active~1\way media.dll
    programfilesdir+\okaybi~1\tonsnew.dll
    s4bar.dll
    systemroot+\iems.dll
    systemroot+\madise.dll
    systemroot+\mfcbm32.dll
    systemroot+\mpjkoxef.dll
    systemroot+\nem219.dll
    systemroot+\system32\adpjtif.dll
    systemroot+\system32\cnvffat.dll
    systemroot+\system32\elbs.dll
    systemroot+\system32\fgnkc.dll
    systemroot+\system32\fldbjfh.dll
    systemroot+\system32\fnbko.dll
    systemroot+\system32\fnhfilter.dll
    systemroot+\system32\fxsrcom.dll
    systemroot+\system32\he3e3fc4.dll
    systemroot+\system32\iasrejcst.dll
    systemroot+\system32\iel2cde8.dll
    systemroot+\system32\ihp.dll
    systemroot+\system32\iobmkaa.dll
    systemroot+\system32\ipof.dll
    systemroot+\system32\kjbdcan.dll
    systemroot+\system32\kjpd.dll
    systemroot+\system32\kw3eef76.dll
    systemroot+\system32\lbc.dll
    systemroot+\system32\li01f948.dll
    systemroot+\system32\lplleia.dll
    systemroot+\system32\mdlnp.dll
    systemroot+\system32\mfplay.dll
    systemroot+\system32\mglbh.dll
    systemroot+\system32\nf9.dll
    systemroot+\system32\nzqflswi.dll
    systemroot+\system32\odxmrtp.dll
    systemroot+\system32\pkhoj.dll
    systemroot+\system32\ppmpab.dll
    systemroot+\system32\readdb40.dll
    systemroot+\system32\rhin7.dll
    systemroot+\system32\si91e44b.dll
    systemroot+\system32\vrttofhi.dll
    systemroot+\system32\yieynybd.dll
    webie9.dll
    winnet.dll
     
  4. Remove these registry items (if present) with RegEdit:
    HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\shellbrowser\{e12d3393-0b51-7fae-4fc7-95b9126c23dd}
    HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{7b6020c8-7f87-70b3-1aac-b50f918b8a79}
    HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{e12d3393-0b51-7fae-4fc7-95b9126c23dd}
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\start wingman profiler
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\uninstal
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\wapi
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices\image
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{223405ec-01f9-48a2-bdbb-d519913e2765}
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{28a19c3e-91e4-4bca-a623-baf3c43c4f49}
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{7b6020c8-7f87-70b3-1aac-b50f918b8a79}
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{83dd9741-94b8-4be3-b577-828c752ac215}
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{888419d5-3fc7-4e87-bad9-256147bd9cda}
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{b0b0ba05-b522-49ab-84ca-d0395d268924}
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{e12d3393-0b51-7fae-4fc7-95b9126c23dd}
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{efee6b59-addb-40eb-ba2c-af860f5b42b5}
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0000-0000-8835-3eff76bf2657}
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00000000-0000-47c5-a90f-2cde8f7638db}
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\000hpdllhost
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\he3e3fc4
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\hpsysconf
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\iel2cde8
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\image
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ist service uninstall
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\kw3eef76
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\li01f948
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\nssysconf
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\readdb40
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\rpjzd
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
    \schoolpopshoppingbuddy
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\si91e44b
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\winxpservice
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\xpsystem
    ......
     
  5. Remove these files (if present) with Windows Explorer:
    apphelp32.dll
    c:\windows\system32\advpyack.dll
    explorer.dll
    mwssrcas.dll
    npmysrch.dll
    profilepath+\application data\iestcrmfrood.dll
    profilepath+\application data\pntrlltsq.dll
    programfilesdir+\active~1\jugs mags camp.bin
    programfilesdir+\active~1\save corn.dll
    programfilesdir+\active~1\way media.dll
    programfilesdir+\okaybi~1\tonsnew.dll
    s42ns.exe
    s4bar.dll
    systemroot+\hqr.exe
    systemroot+\iems.dll
    systemroot+\madise.dll
    systemroot+\mfcbm32.dll
    systemroot+\mpjkoxef.dll
    systemroot+\nem219.dll
    systemroot+\preinsmt.exe
    systemroot+\quyrpdch.exe
    systemroot+\system\helper.exe
    systemroot+\system32\adpjtif.dll
    systemroot+\system32\cnvffat.dll
    systemroot+\system32\elbs.dll
    systemroot+\system32\epqwnen.exe
    systemroot+\system32\fgnkc.dll
    systemroot+\system32\fldbjfh.dll
    systemroot+\system32\fnbko.dll
    systemroot+\system32\fnhfilter.dll
    systemroot+\system32\pkhoj.dll
    systemroot+\system32\ppmpab.dll
    systemroot+\system32\readdb40.dll
    systemroot+\system32\rhin7.dll
    systemroot+\system32\si91e44b.dll
    systemroot+\system32\vpataszc.exe
    systemroot+\system32\vrttofhi.dll
    systemroot+\system32\wtssvit.exe
    systemroot+\system32\yieynybd.dll
    webie9.dll
    winnet.dll
    wtstr.exe
    zlch.exe
    ......
     
  6. Remove these directories (if present) with Windows Explorer:
    programfilesdir+\active~1
    programfilesdir+\okaybi~1

Using Spyware Doctor to remove Unknown BHO AUTOMATICALLY. 

More Removal Instructions for Emerging Adware Spyware
More Removal Instructions for More Adware/Spyware Programs
Sign up for free up-to-date messages about your PC's security & privacy:
              Email
Confirm email
     Your Name    
 Anti-Keylogger  Password Pecovery
 Anti-Spam  PC Monitoring
 Anti-Spyware  Personal Firewall
 Anti-Virus  System Tools
 Online Privacy    
PQ DVD to iPod Video Suite
PQ DVD to iPod Video Suite (PQ DVD to iPod + iPod Video Converter) is a One-Click, All-In-One solution to convert DVD, Tivo, DivX, MPEG, WMV, AVI, RealMedia and many more to iPod Video ...
Kaspersky Internet Security
Internet Security processes all incoming and outgoing data on your computer, including email, Internet traffic and network interaction, without the need for additional security applications ...
Cucusoft MPEG/AVI to DVD/VCD/SVCD Converter Pro
It enables you to convert and burn any video file directly to VCD, DVD, SVCD, MPEG1 and MPEG2 format. Pro version included all the features of the lite version ...
FREE Spyware Scan! SpyNoMore
SpyNoMore scans, cleans and blocks spyware as well as any other good anti-spyware product, but with one big advantage, Custom Fix (patent pending). Spyware programs are growing more sophisticated by the day ...
Copyright ©2003-2009 SecureMost.com. All other trademarks are the sole property of their respective owners.