URL: http://differentia.ru/diff.php
Infekcja: URL:Mal
Proces: C:\Windows\SysWOW64\msiexec.exe
It shows over and over again. I used malwerebytes anti malwere, anti rootkit and adwcleaner. It found nothing.
I attached logs. Please help
URL: http://differentia.ru/diff.php
Infekcja: URL:Mal
Proces: C:\Windows\SysWOW64\msiexec.exe
It shows over and over again. I used malwerebytes anti malwere, anti rootkit and adwcleaner. It found nothing.
I attached logs. Please help
Also attach the MBam log.
If you haven’t done so already, install McShield and have it scan your usb stick(s).
I do so.
Below my MB log.
Ok, now have some patience.
One of the malware removers will soon guide you.
This will stop it
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint: 2015-07-15 14:34 - 2015-06-15 22:16 - 67341440 ___SH () C:\ProgramData\msdojjboq.exe Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.