Go
HERE and run this removal tool.
Then follow the rest of the instructions below.
Boot into safe mode. See how HERE.
http://www.bleepingcomputer.com/forums/tutorial61.html
Turn off system restore.(XP/ME only) See how HERE.
http://www.bleepingcomputer.com/forums/tutorial56.html
In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.
http://www.bleepingcomputer.com/forums/tutorial62.html
Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.
Click on the processes tab and end process for(if there).
Isass.exe
<Note the spelling. Not to be confused with lsass.exe. This nasty is spelled with an I and not L.
hanguard.exe
BBJ.exe
Close task manager.
Click start/run and type regsvr32 /u C:\WINDOWS\System32\hKeyword.dll into the run box and press the enter key. Note the space between the 2 and the forward slash and again between the u and c.
Click start/run and type regsvr32 /u C:\WINDOWS\SYSTEM32\AsntDll.dll into the run box and press the enter key. Note the space between the 2 and the forward slash and again between the u and c.
Click start/run and type regsvr32 /u C:\WINDOWS\System32\vbsys2.dll into the run box and press the enter key. Note the space between the 2 and the forward slash and again between the u and c.
Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).
R3 - URLSearchHook: Translate Class - {350279C2-C2B0-457B-9A16-1A5DB2EE88AF} - C:\WINDOWS\System32\hKeyword.dll
O3 - Toolbar: V3 - {9E3849D6-41EF-4B2F-86B7-632EF90758E4} - "C:\Program Files\Ahnlab\V3\V3Bar.dll" (file missing)
O4 - HKCU\..\Run: [hansetup] C:\WINDOWS\System32\hanguard.exe
O4 - HKCU\..\Run: [BHPw3gh0] "C:\WINDOWS\pchealth\BBJ.exe"
Fix all 016-DPF entries.
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: asnt3 - C:\WINDOWS\SYSTEM32\AsntDll.dll
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll
Click on the fix checked button.
Close HJT.
Locate and delete the following
bold files and/or directories(if there).
C:\WINDOWS\System32\
vbsys2.dll
C:\WINDOWS\SYSTEM32\
AsntDll.dll
C:\WINDOWS\pchealth\
BBJ.exe
C:\WINDOWS\System32\
hanguard.exe
C:\WINDOWS\System32\
hKeyword.dll
Reboot into normal mode and turn system restore back on.
Post a fresh HJT log.
Regards Howard