I have runned CCleaner, and ComboFix. Here is the log file.
Main Topics
Browse All TopicsHello!
When i opened my computer, the antivirus software (NOD32) installed on my PC prompted me that the executable "rncsys32.exe" is loaded into memory. I had the option to delete the file located in Start > Programs > Startup.
Is it enough to let antivirus handle this threat or should i manually check and remove certain files or registry entryes?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hi,
c:\windows\system32\ter
It's possible that a file infector was or is still at work there, as Combofix had deleted legit files and that usually happens with virut or sality.
Also run the system with DrWebCureIt,
http://www.freedrweb.com/
T
Business Accounts
Answer for Membership
by: rpggamergirlPosted on 2009-06-22 at 01:05:24ID: 24680463
Just let your antivirus delete or quarantine it, the other files are in the temp folders so you might also like to run temp folder cleaners like CCleaner ot ATF Cleaner. The registry files your antivirus should also remove anyway.
Or run MalwareBytes and or Combofix and show us the logs.
es.org/mba m.php
ingcompute r.com/sUBs /ComboFix. exe
Download Malwarebytes' Anti-Malware to your desktop, check for the tool's Updates before running a scan.
http://www.malwarebyt
Please download ComboFix by sUBs:
http://download.bleep
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
If needed, here's the Combofix tutorial which includes the installation of the Recovery Console: gcomputer. com/combof ix/how-to- use-combof ix
http://www.bleepin