I've run all the scans. When I try to go to any anti-virus websites, it redirects me. Here's the scan results.
Thanks for your help.
I've run all the scans. When I try to go to any anti-virus websites, it redirects me. Here's the scan results.
Thanks for your help.
Hello.
Please, execute the script:After restart, upload the quarantine using the link http://virusinfo.info/upload_virus_eng.php?tid=60725 as it's described in the app.3 of the rules. Let us know when you've done that.Код:begin SearchRootkit(true, true); SetAVZGuardStatus(True); QuarantineFile('C:\windows\ld15.exe',''); QuarantineFile('c:\windows\pp12.exe',''); QuarantineFile('C:\WINDOWS\system32\drivers\fio32.sys',''); QuarantineFile('c:\windows\system32\fio32.dll',''); QuarantineFile('c:\windows\mstre24.exe',''); BC_ImportquarantineList; BC_Activate; RebootWindows(true); end.
NB: The script above can't solve your problem yet, because it only gathers the suspicious files in your system, but it's important because it will allow us to define which of them is really harmful.
Did what you suggested. Thanks for all your help.
Looking forward to getting this fixed.
Switch off/Disable:
- Antivirus and and, if you have - Firewall.
- System Restore
- Execute following script
- Make and attach 3 new logs to your new post..Код:begin SearchRootkit(true, true); SetAVZGuardStatus(True); TerminateProcessByName('c:\windows\mstre24.exe'); StopService('fio32'); DeleteFile('C:\windows\ld15.exe'); DeleteFile('c:\windows\pp12.exe'); DeleteFile('C:\WINDOWS\system32\drivers\fio32.sys'); DeleteFile('c:\windows\system32\fio32.dll'); DeleteFile('c:\windows\mstre24.exe'); RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','pp'); RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','SySmstray'); RegKeyParamDel('HKEY_LOCAL_MACHINE','Software\Microsoft\Windows\CurrentVersion\Run','sysldtray'); DeleteService('fio32'); BC_ImportAll; ExecuteSysClean; BC_Activate; BC_DeleteSvc('fio32'); SetAVZPMStatus(True); RebootWindows(true); end.
Thanks