Off-topic MT4/mql4 questions. - page 5

 
Rita:
Can't find the Win key.


))

Between Ctrl and Alt, the windows...

 
Rita:

In the meantime, let's make you an expert user - keyboard shortcuts rule ))))
 

That is, I press. Win+R and then I have to insert in the window that appears:

HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters/PersistentRoutes - OK?

 
Rita:

That is, I press. W+R and then I have to insert in the window that appears:

HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters/PersistentRoutes - OK?


Not

Win+R

type Regedit

(registry editor)

Press Enter.

In the editor, look for this

HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters/PersistentRoutes

 
Abzasc:

Win +R Regedit

Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\PersistentRoutes

It must be empty.


No, it's not empty at all. On the contrary. There's a lot here :

 

Apparently - these are the banned addresses!

Do they all need to be deleted ?

 

It's a Trojan

5 sec.

 

Delete all

type Win +R

over there cmd

route -f

Enter

Reboot may be required but first try to access some sort of antivirus...

Also, take a screenshot of the task manager to see what processes are running

Then try this.

"Open a command line. We press Start and choose Run and write there cmd and press Enter. In the window that will appear, type in

ping ftp.drweb.com

You will most likely get an error message saying that the host cannot be found.

Now let's try to find out the IP address of Dr.Web hosting.

Click Start and select Run and type cmd there and hit Enter. In the window that will appear, type

nslookup ftp.drweb.com

This will bring up a table
Unofficial response:
Name: rr.drweb.com
Addresses: this will be a bunch of IP addresses written in commas: 81.176.67.171, 81.176.67.173, etc.

We will paste one of these addresses into your web browser: web browser, internet explorer, opera, windows, etc..

This will display the FTP files. At the top it says Index of/
and also says
../
pub/.

Select pub/, then drweb/, then cureit/.

There will be a lot of text there.

2009905014759/ 04-Sep-2009 21:48 -
200990905031449/ 04-Sep-2009 23:14 PM -
200990905033351/ 04-Sep-2009 23:33 -
200990905070446/ 05-Sep-2009 03:04 PM -
200990905075820/ 05-Sep-2009 03:58 PM -
2009905103708/ 05-Sep-2009 06:37 PM -
2009905113339/ 05-Sep-2009 07:33 PM -
2009905121904/ 05-Sep-2009 08:19 -
20099055130918/ 05-Sep-2009 09:09 PM -
2009905140400/ 05-Sep-2009 10:04 AM -
200990905145432/ 05-Sep-2009 10:54 AM -
2009905154905/ 05-Sep-2009 11:49 PM -
2009905164001/ 05-Sep-2009 12:40 PM -
2009905173400/ 05-Sep-2009 13:34 -
2009905182503/ 05-Sep-2009 14:25 am -
2009905191533/ 05-Sep-2009 15:15 - 22:00 - 23:30 - 23:00
2009905201014/ 05-Sep-2009 16:10 - 22:00 PM
2009905210050/ 05-Sep-2009 17:00 PM -
2009905215507/ 05-Sep-2009 17:55 PM -
2009905224558/ 05-Sep-2009 18:45 -
2009906012506/ 05-Sep-2009 21:25 PM -
2009906032816/ 05-Sep-2009 23:28 PM -
2009906033257/ 05-Sep-2009 23:33 PM -
200990906040421/ 06-Sep-2009 00:04 -
200990906045849/ 06-Sep-2009 00:58 -
200990906055647/ 06-Sep-2009 01:56 -
200990906064926/ 06-Sep-2009 02:49 -
200990906074653/ 06-Sep-2009 03:46 -
200990906084026/ 06-Sep-2009 04:40 PM -
200990906093641/ 06-Sep-2009 05:36 PM -
2009906103406/ 06-Sep-2009 06:34 -
2009906112057/ 06-Sep-2009 07:20 PM -
2009906121647/ 06-Sep-2009 08:16 -

Select the most recent date from the above captions. Example: 06-Sep-2009 08:16 and click on the link to the left. In this case 20090906121647/

Download cureit.exe and install.

CureIT is a free disposable anti-virus from DrWeb. It serves for a single run to check the system for viruses. It is not updatable, you can only download it again.

Run CureIt. It will most likely find Win32.HLLW.Shadow.based.

CureIT will tell you that it has cleaned this virus and prompt you to reboot your computer. After computer restart - antivirus sites will open and antivirus installed on the computer will be updated.
"

Then write down the result...

 

Thank you, Abzasc .

I'm going to go to lunch now. And then I'll follow your instructions.

In the meantime, in five minutes, check your personal pages. I'll send you something for your efforts - a sort of grail for trading.

 

Well done!