virus. blocking Internet

caught a virus. I can not go to many popular sites. If I go to the site, then redirect the fact that on the screenshot. scan computer - there is nothing found.
file C:\WINDOWS\system32\drivers\etc\hosts is correct
What to do? how to fix?

Try free Mbam. (Update it after install…!)
http://www.malwarebytes.org/mbam.php

This program does not running

you mean there is some malware blocking it from running ?

try running rkill first then start Malwarebytes
rkill http://www.bleepingcomputer.com/download/anti-virus/rkill

you can also try Hitman pro

Hitman Pro 3 - Second Opinion Malware Scanner http://www.surfright.nl/en/hitmanpro
Hitman Pro in Force Breach Mode http://hitmanpro.wordpress.com/2010/03/16/hitman-pro-in-force-breach-mode/

This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish.

Rkill was run on 24.04.2011 at 2:16:56.
Operating System: Microsoft Windows XP

Processes terminated by Rkill or while it was running:

Rkill completed on 24.04.2011 at 2:18:35.

Malwarebytes has not yet started. it is not available in the processes
Hitman Pro 3 - didn’t help. are you need log.xml?

This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish.

Rkill was run on 24.04.2011 at 2:46:19.
Operating System: Microsoft Windows XP

Processes terminated by Rkill or while it was running:

D:\C:\Program Files\Alwil Software\Avast5\defs\11042300\Sf.bin
D:\Program Files\Malwarebytes’ Anti-Malware\mbam.exe

Rkill completed on 24.04.2011 at 2:46:39.

one moore:

This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish.

Rkill was run on 24.04.2011 at 2:53:59.
Operating System: Microsoft Windows XP

Processes terminated by Rkill or while it was running:

C:\Program Files\Alwil Software\Avast5\defs\11042300\Sf.bin

Rkill completed on 24.04.2011 at 2:54:18.

This is a modification of a trojan Winlock.

Click on the link нажмите здесь and take a picture that is written on.

Try to find an unlock code here - http://www.drweb.com/unlocker/index?lng=en

Download and burn to disk or a flash drive.

http://www.freedrweb.com/livecd/?lng=en
http://www.freedrweb.com/livecd/how_it_works/?lng=en

http://www.freedrweb.com/liveusb/?lng=en
http://www.freedrweb.com/liveusb/how_it_works/

Didn’t work

Download and burn to disk or a flash drive.
scanning in live CD: nothing found

Click on the link нажмите здесь and take a picture that is written on.?

To get started, download HijackThis from the official site
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

Do a system scan and save a logfile

in “Attach”

This program does not running

Hi Dim@rik I am watching this one with interest as I have never come across it before. Do you have any links about it ?

Try this code

3323456
    piramida
8563481
30195738
90129159
4403719902

Hi essexboy.

http://virusinfo.info/showthread.php?t=100935

always the same result

Try this: 1351236

did not work

Here is one Ransomware bug http://forums.malwarebytes.org/index.php?showtopic=82506
detected by avast
http://www.virustotal.com/file-scan/report.html?id=5c368108517de7cf09e9614ef205cf49b13b384b49d5456316f3b1a2fe19b9ec-1303456070

and they are working on one case here http://forums.malwarebytes.org/index.php?showtopic=82829

Thanks Dim@rik I only read the English forum there so I missed this

In the Russian segment of trojan Winlock is very common, and if you look very much that you can find.

Should try to help a person (Alookard)

http://support.kaspersky.com/viruses/deblocker
http://www.drweb.com/unlocker/index?lng=en
http://www.esetnod32.ru/.support/winlock/

http://xylibox.blogspot.com/

Malicious program can change the location of the hosts - check the registry key
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ services \ Tcpip \ Parameters \ DataBasePath
MUST be the value% SystemRoot% \ System32 \ drivers \ etc

If the host is clean, but the site does not go - you need to check your static routes:
In the console (with admin rights!)
route print >C:\log.txt
Log.txt file saved in the root of drive C - Show Forum
Delete all static routes - the command in the console route -f
May need to reboot!

Check the settings in IE (Internet Explorer):
Options-> Connections-> Settings and Network Configuration: possible presence of “leftist” proxy servers! Remove.

If you boot into Safe mode (F8) banner left? and if you can out of Safe mode to run HijackThis?, if yes then Do a system scan and save a logfile and log Show Forum.

it helped. you wіn
thanks to all who tried to help