Er du sikker på at det ikke er MScgsys.exe, MSgcsys.exe eller MSfcsys.exe? Læs her:
"
http://www.helpbytes.co.uk/removal.php Removal Instructions
Details
If your Yahoo! Instant Messenger automatically sends out IMs to your buddies with links, you're likely infected with this.
What is it?
The following I have now found in the package:
TrojanDownloader.Win32.Small.fz & TrojanDownloader.Win32.Small.gx
These are trojans which download programs from the internet. They are FSG packed and infect your PC initially, they are known to spread via posting their URLs in chat services. TrojanClicker.Win32.Small.pThis generates clicks on porn websites with affiliate IDs in order to generate the author some revenue. Trojan.Win32.SaonetThe actual trojan thats adds the internet explorer item.
How to Remove
Find the Files
1) Start, Find>>All Files and Folders. Look in C:\
XP: Start, search, All Files and Folders.
2) Search for this: "MS*sys.exe".
http://www.hn-ams.org/forum/images/attach/jpg.gif remfind.jpg (
http://www.hn-ams.org/forum/attachment.php?attachmentid=2740&stc=1)
3) It may find some files. IMPORTANT: We are only interested in the files containing 7 letters(excluding .exe).
Known filenames:
MScgsys.exe, MSgcsys.exe, MSfcsys.exe
One of the files will be about 11000 in size (11kb) and another about 3000 in size(3kb).
Locations: C:\ and/or C:\windows\system
MSgsys if you have it is clean, don't delete it.
Stop the Process - Delete the Files
4) Press ctrl+alt+del once. Make sure you're on the process list.
http://www.hn-ams.org/forum/images/attach/jpg.gif remctrl.jpg (
http://www.hn-ams.org/forum/attachment.php?attachmentid=2739&stc=1)
5) Look for any of the files you found above in the list. For each one found (with or without .exe) click it then click end task.
6) Delete the files, you can do this from the find screen. Leave them in recycle bin.
Search for msup.exe like above. If you find it, delete all occurunces.
Remove the Registry Entries:
7) Now, start, run, type regedit. Expand down the left:
HKEY_LOCAL_MACHINE
Software
Microsoft
CurrentVersion
click Run
8) Look for, and delete the following:
http://www.hn-ams.org/forum/images/attach/jpg.gif remreg.jpg (
http://www.hn-ams.org/forum/attachment.php?attachmentid=2742&stc=1)
IMClass (Data: c:\ or c:\windows\ plus one of the files found above). One of the files above (command as above). msup.exe (Data: c:\ or c:\windows\ plus msup.exe)
Remove the Extra bit
9) It also adds a link to a currently in progress Islamic website in your Internet Explorer Tools menu.
To delete it:
a) Start, run, type regedit press ok.
b) Edit>>Find. "saoura".
c) When it finds it, you will see something like {F75E0D20-3328-4795-B229-59AB09F85A7A} on the left.
d) Click on that code, and delete it.
http://www.hn-ams.org/forum/images/attach/jpg.gif remislam.jpg (
http://www.hn-ams.org/forum/attachment.php?attachmentid=2741&stc=1)
Downloaded Program Files Applet
10) Start, run. Type "c:\windows\downloaded program files" and press OK.
11) You will see something like
http://www.hn-ams.org/forum/images/attach/jpg.gif remapp.jpg (
http://www.hn-ams.org/forum/attachment.php?attachmentid=2738&stc=1) Delete it.
10) Restart your PC. You should be clean.
Never Click links you don't know again ;-)
Note
These instructions are compiled by myself. I infected a test windows installation and found out the above for myself.
The file names and sizes can vary, as well as locations. I cannot guarnatee the infection will totally be killed.
Always make sure your anti virus scanner is upto date, and run it."