First time here? Check out the FAQ!
x

What is ywnmon32 because I get invisible ads?

0 votes
asked by (120 points)
edited by

Somehow I got some noise from background without any program running. I checked by processes, and to my knowledge, I don't remember how I got ywnmon32.exe? I want this off, please tell me how.

2 Answers

0 votes
answered by (140 points)

ywnmon32.exe has much to do with browsers and it comes in with random third-party programs, mostly are web applications like toolbar, extensions, it can be also distributed by malicious domain, that’s why you don’t know where it comes from and when it comes in. ywnmon32.exe should be removed as services or processes like explorer.exe has been detected to be badly influenced.

Running anti-virus programs is not sufficient as internal services have been influenced and those programs were created to deal with vicious things only. You have to:

1. access Running Tasks to help locate the service name and thelocation of ywnmon32.

All Apps > Accessories > System Tools > System Information > Software Environment > Running Tasks.

2. use command to access system service window and end the service associated with ywnmon32 according to the “path to executables”.

3.reveal all hidden items to remove Temp files and the items generated by ywnmon32.

C:\WINDOWS\Temp
C:\Users[user name]\AppData\Local\Temp\
C:\Documents and Settings[user name]\Local Settings\Temp
C:\Documents and Settings[user name]\Local Settings\Temporary Internet File

Here are the locations you have to locate the related items according to the creation day:

%SystemDriver%\
%PROGRAMFILES%\
C:\Windows
C:\Windows
C:\Program Files\
C:\windows\system32\
C:\users\user\appdata\local\
C:\Users[your username]\Documents\
C:\users[username]\appdata\locallow\

If you don’t know how to do the steps exactly, more detailed steps are available.

0 votes
answered by (264k points)

This is actually a trojan application which means the computer is infected with viruses and other bad content. I immediately recommend downloading Combofix through the application page at Software Informer. Copy the application on a USB flash drive (it's recommended to download it on another computer) then reboot the PC and press F8 until the servie menu appears. Select Safe Mode (WITHOUT NETWORKING) and boot to Windows. Insert the drive, then launch the executable file. Let it scan and at the end the computer will reboot itself. By now the trojan should be removed automatically from your computer.

Your answer

Your name to display (optional):
Privacy: Your email address will only be used for sending these notifications.
Anti-spam verification:
To avoid this verification in future, please log in or register
...