Please do the following;
Please run HiJackThis again.
Place a checkmark next to the following entries;
R3 - URLSearchHook: (no name) - {66B30261-9AF5-E170-D3FE-C16946FBDB94} - C:\WINDOWS\system32\ymnsd.dll (file missing)
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvwac.dll,startup
O4 - HKLM\..\Run: [xobghic.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\xobghic.dll,mbvwpdg
O4 - HKCU\..\Run: [Rnuu] "C:\PROGRA~1\ICROSO~1\winlogon.exe" -vt ndrv
O4 - HKCU\..\Run: [Rydijdmf] C:\Program Files\Common Files\??mantec\msdtc.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
Once you have the checkmark next to all of the above then click the FIX button.
Exit HJT.
Next go to this link;
Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
- The program will launch and then begin downloading the latest definition files:
- Once the files have been downloaded click on NEXT
- Now click on Scan Settings
- In the scan settings make sure that the following are selected:
- Scan using the following Anti-Virus database:
- Extended (if available otherwise Standard)
- Scan Options:
- Scan Archives
Scan Mail Bases- Click OK
- Now under select a target to scan:
- Select My Computer
- This program will start and scan your system.
- The scan will take a while so be patient and let it run.
- Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop.
- Copy and paste that information in your next post with another HJT log.


Reply With Quote