A few more to delete now that I can see them
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.
O20 - Winlogon Notify: winysd32 - winysd32.dll (file missing)
Now
close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
________________________
Please download the OTMoveIt
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\ur.dat
C:\Program Files\wt3d.ini
C:\WINDOWS\SYSTEM32\winysd32.dll Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply with a new Hijack log.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
________________
Plus 3 files that are suspicious need to be checked out
Jotti File Submission:- Please go to Jotti's malware scan
- Copy and paste the following file path into the "File to upload & scan"box on the top of the page:
- C:\WINDOWS\system32\6618C5C771.sys
- Click on the submit button
Then repeat for the next two files
C:\WINDOWS\system32\B79B2158C1.sys
C:\WINDOWS\system32\C158219BB7.sys- Please post the results in your next reply.