Run Hijackthis and select "Do a system scan only", place a check by the following entries.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [Microsoft Incroporate] mfs.exe
O4 - HKLM\..\Run: [Winsock2 driver] SYSADWARE.EXE
O4 - HKLM\..\Run: [Microsoft Machine Script] iexplorersis.exe
O4 - HKLM\..\RunServices: [NeroFil] NeroFil.EXE
O4 - HKLM\..\RunServices: [Microsoft Incroporate] mfs.exe
O4 - HKLM\..\RunServices: [Microsoft Machine Script] iexplorersis.exe
O4 - HKCU\..\RunServices: [NeroFil] NeroFil.EXE
O4 - HKCU\..\RunOnce: [Winsock2 driver] SYSADWARE.EXE
Close all open windows and browsers, and hit "Fix Checked".
Delete these files.
C:\WINDOWS\System32\mfs.exe
C:\WINDOWS\System32\SYSADWARE.EXE
C:\WINDOWS\System32\iexplorersis.exe
Find and delete this file.
NeroFil.EXE
Reboot and post a new Hijackthis log, and say how things are now.
__________________
Son of Glyndwr
Mae hen wlad fy nhadau yn annwyl i mi
|