Here is what I got from
Symantec.
Personal Security virus will modify Windows Registry and add the following entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run “Personal Security”
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_LOCAL_MACHINE\SOFTWARE\5FFB10D58FFCF482208906E6A889FD56
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Internet Settings\5.0\User Agent\post platform “WinTSI 01.12.2009″
The threat will drop the following malicious files:
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Security.lnk
%UserProfile%\Desktop\Personal Security.lnk
%Program Files%\Personal Security
%Program Files%\Personal Security\personalsecurity.exe
%Program Files%\Common Files\Personal Security Uninstall
%Program Files%\Common Files\Personal Security Uninstall\Uninstall.lnk
%Documents and Settings%\All Users\Start Menu\Personal Security
%Documents and Settings%\All Users\Start Menu\Personal Security\Computer Scan.lnk
%Documents and Settings%\All Users\Start Menu\Personal Security\Help.lnk
%Documents and Settings%\All Users\Start Menu\Personal Security\Personal Security.lnk
%Documents and Settings%\All Users\Start Menu\Personal Security\Registration.lnk
%Documents and Settings%\All Users\Start Menu\Personal Security\Sec Center.lnk
%Documents and Settings%\All Users\Start Menu\Personal Security\Settings.lnk
%Documents and Settings%\All Users\Start Menu\Personal Security\Update.lnk
%WINDOWS%\system32\win32extension.dll