VIRUS/SPYWARE help please

JC0724

Junior Member
Oct 11, 2008
3
0
0
The virus is called Security System 2009. I am not sure if I have that or more, but here are all the details.

So I come home and I see this virus on my computer. I realize I can't run any of my programs Not Norton(well norton runs but it will not run a full system scan for some reason) or Spy Sweeper. So I have two internal hard drives. One I run windows XP pro and the other Linux Unbuntu. So I log off of XP and into Linux. I hop online and research the virus. So I found a few sites and they all basically say the same thing.

Log in XP in Safe Mode and do one of two things.

Download malwarebyte run it and remove the virus/spyware or manual do it.

So I download malwarebytes anti-malware and install it, but it doesn't run. It installs but it doesn't run, at this point I notice my spy sweeper doesn't run either. So then I try to do it manually.

So I think there are 3 steps here.

1. Stop/Kill the process of the virus/spyware. So i go to task manager, however everysite says it will say system security.exe. I never see this so I just move past this step.

2. Is to search for and find the folders. So in this step the sites show the pathway.

Something like C:/Documents and Settings/application data/All Users/[Random Numbers]/[Random Numbers](something like that). So I found 2 folders that had random numbers for names. Actually 3 but I only deleted 2.

Now here I am not sure if I deleted something important. the two folders I deleted did have the Virus Icons in there but they also had other stuff but it said to delete the folders I think, so I did.

3. To disable start up so I went into msconfig and I noticed those two folder names with random numbers were being called at the start up so I unchecked them.

4. And last step was to delete the Virus/spyware in the Registery This part I thought would be simple but when I to the Registery following the path they gave on the websites I couldn't find the Virus it wasn't there so I skipped this part and restarted.

Now my PC starts up in normal mode I can Hope on the Internet but there are still issues/malware there. Maybe even a virus. I still can't run Spy sweeper or malwarebytes anti-malware.

I run Norton for a full system scan and it only scans like 5 thousands files(not the full system) and it keeps coming up with a packet 200 virus or something that can't be removed.

Also i notice some others don't work like I can't run World of Warcraft anymore.

So if someone can help I would truly appreciate it. Thanks guys for taking the time to read this long long email.
 

bruceb

Diamond Member
Aug 20, 2004
8,874
111
106
Sometimes, you need to rename an antivirus or spyware program, as the virus knows which ones are out there and will stop them from running.
See link here for manual removal of this virus:

http://www.xp-vista.com/spywar...-security-removal-info

System Security 2009 Descriptions:

System Security, also known as System Security 2009, is another deadly counterfeit antispyware application that developed to invade our Internet life. (Do not confuse System Security, which is fake softeware, to AE Software Technologies? System Security 2009 which indeed a legit software). Presumably, System Security is a new verion of Winweb Security, with different name but same destruction. Just like most fake antispywares, System Security simulates the Windows system security alert interface, then issues misleading and exaggerated results to distract and scare the internet users.

System Security 2009 usually installed itself onto your PC without your permission, through Vundo Trojan, Virus or fake software. System Security will display fake system alerts or fake security alerts to trick user to buy the paid version of System Security, in order to remove the potential and reported problems. Not only does it cause your machine to slow down dramatically, it would also put your privacy and data in risk.

Manual System Security Removal Instructions:

Stop System Security Processes:

SystemSecurity.exe
05643921.exe
install.exe

Find and Delete these System Security Files:

systemsecurity.exe
SystemSecurity.lnk
SystemSecurity on the Web.lnk
Uninstall SystemSecurity.lnk
%desktopdirectory%\system security.lnk
%desktopdirectory%\ws\config.udb
%desktopdirectory%\ws\init.udb
%desktopdirectory%\ws\languages\english.lng
%desktopdirectory%\ws\languages\german.lng
%desktopdirectory%\ws\languages\spanish.lng
%desktopdirectory%\ws\systemsecurity.exe
%programs%\system security\system security.lnk
%desktopdirectory%\ws\systemsecurity.exe
05643921.exe
install.exe
%desktopdirectory%\system security 2009.lnk
%programs%\system security\system security 2009 support.lnk
%programs%\system security\system security 2009.lnk

Remove System Security Registry Values:

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run systemsecurity
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 displayicon
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 shortcutpath
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\systemsecurity2009 uninstallstring