Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works

iastor.sys Blocked by Avest as a virus/Malware

  • Please log in to reply



    New Member

  • Member
  • Pip
  • 1 posts
Hi, I'm new to this forum and came because it seems like there are some really helpful people on board.

I'm having some issues and it seems I am infected. I just recently started using Avest! and a pop=up windows comes up about every second saying "avast File system shield has blocked a threat."
Object: c:\windows\system32\drivers\iastor.sys
Infection: Win32:Alureon-FR
Action: Deleted
Process: PID4"

This is literally happening once second or two for the last hour. It started when I was scanning for viruses.

I don't know what I'm supposed to do at this point. It just keeps popping up.

The second issue is that when I search for something in google and click on a result I get directed to a page completely different then what I was looking for. I would understand if it happened once for some crazy site. But this is for wikipedia and other sites like that. Does this ring any bells??

In advance, thanks or any and all help!
  • 0




  • Malware Removal
  • 9,863 posts
Please download TDSSKiller.zip and unzip it to your Desktop

Run the TDSSKiller and wait until it finishes (should be just a few seconds or below a minute).. Then find the log at your %systemdrive% (drive that contains Windows)

The log shall be named something like this one..

(TDSSKiller.version_date_time_log) for example.. (TDSSKiller.2.1.1_22.12.2009_19.33.44_log)

Please download ComboFix by sUBs from HERE or HERE and save it to your Desktop.

During the download, rename Combofix to Combo-Fix as follows:

Posted Image

Posted Image

It is important you rename Combofix during the download, but not after.

**NOTE: If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

After that, double-click and run Combo-Fix. Let it finish its job and post the log here

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

Note: DON'T do anything with your computer while ComboFix is running.. Let ComboFix finishes its job..
  • 0

Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP