Hi,
1) Kill the following processes (From Task Manager):
C:\Documents and Settings\All Users\Application Data\17167654\17167654.exe
C:\Documents and Settings\All Users\Application Data\97177646\97177646.exe
2) Delete the following Files (Unknown & Looks malicious):
C:\Documents and Settings\All Users\Application Data\17167654\17167654.exe
C:\Documents and Settings\All Users\Application Data\97177646\97177646.exe
3) Delete the following Registry Keys (Unknown & Looks malicious):
O4 - HKLM\..\Run: [17167654] C:\Documents and Settings\All Users\Application Data\17167654\17167654.exe
O4 - HKLM\..\Run: [97177646] C:\Documents and Settings\All Users\Application Data\97177646\97177646.exe
4) Delete the following BHO using ToolbarCop:
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
http://windowsxp.mvps.org/
5) Upload the mentioned executables to:
http://vil.nai.com/vil/sub
http://virustotal.com
6) Download & Run CCleaner to wipe any related temp/junk files:
http://www.ccleaner.com/do
7) Reboot Windows in "Safe Mode" and run a full virus scan
8) Run Hijackthis again and attach the log file for additional reviewing
A Symantec Certified Specialist @ your service
Main Topics
Browse All Topics





by: LANm0nk3yPosted on 2009-05-15 at 23:52:43ID: 24401513
Remove System security 2009 from your system. Download spybot search and destroy, and also adaware. Reboot your system in safemode with networking. Insall those two, and update the definitions. Scan them there, another one you should try is http://malwarebytes.org/.