There are some malicious files that need to be removed now! Okay, run HijackThis and click the button
Do a system scan only. It will scan the system and display the results. Now, select (put a checkmark) the items mentioned below:
Code:
O4 - HKLM\..\Policies\Explorer\Run: [Altap] tskstsh
O4 - HKUS\S-1-5-19\..\RunOnce: [Set] fuset.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [Set] fuset.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [Set] fuset.exe (User 'SYSTEM')
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
Once all the above entries are selected, click the
Remove Selected button.
Close HijackThis after performing the above step. Now, delete following files if they are present in your system:
Code:
C:\WINDOWS\system32\tskstsh.exe
C:\WINDOWS\system32\tscupgrd.exe
C:\Program.exe
fuset.exe
You need to search for the file
fuset.exe as its path is not known. And, you may also need to make Windows to show hidden files/folders, if you are not able to see above mentioned files.
Reboot the system after deleting those files. Download MalwareBytes' Anti-Malware(
http://www.malwarebytes.org/mbam.php ) and install it. Run a complete system scan using MalwareBytes Anti-Malware and remove any malicious item it may find.
After this, post a new HijackThis log.