Use HJT tool to fix these entries:
Quote:
O2 - BHO: (no name) - {1AB6932F-92FE-42E6-870C-544AE458EA78} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\nnnlJYrs.dll,#1
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5FFF7437-954A-401D-94B4-4C0CE5CE418A}: NameServer = 85.255.112.60;85.255.112.237 <--this is the hijacker
|
Then get this tool:
-
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Restart in safe mode and use that tool [run as administrator].
One thing, are you still using Symantec Norton Antivirus? It seems to me, it's already been uninstalled, but the other components still there. If so, get the removal tool here:
-
Download and run the Norton Removal Tool
Then get avast home antivirus here:
-
avast! 4 Home Edition - FREE antivirus software - Download
- Install, and run the boot up scheduled scan.
And free registration here:
-
Registration of avast! 4 Home Edition - free antivirus for home non-commercial use
Once you've done everything, please re-upload your HJT log file and also the combofix log.