Author Topic: disorderstatus and differentia malware. HELP!!!  (Read 2510 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
disorderstatus and differentia malware. HELP!!!
« on: August 18, 2015, 07:13:07 PM »
Avast keeps popping up on my PC which displays these:


Object: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\WINDOWS\SysWOW64\msiexec.exe

and


Object: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\WINDOWS\SysWOW64\msiexec.exe


Can somebody please help me fix this? Thank you so much in advance.
« Last Edit: August 18, 2015, 07:34:51 PM by shanen »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: disorderstatus and differentia malware. HELP!!!
« Reply #1 on: August 18, 2015, 07:53:00 PM »
Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select  additions at the bottom
  • Press Scan button.

  • It will produce a log called FRST.txt in the same directory the tool is run from. 
  • Please attach both logs generated.

REDACTED

  • Guest
Re: disorderstatus and differentia malware. HELP!!!
« Reply #2 on: August 19, 2015, 04:47:39 AM »
Hey. I already did it and attached the FRST.txt and Addition.txt
What do I do next? Thanks for the help by the way.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: disorderstatus and differentia malware. HELP!!!
« Reply #3 on: August 19, 2015, 03:55:11 PM »
Let me know if this stops it

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
2009-07-14 07:31 - 2009-07-14 09:14 - 83350784 ___SH () C:\ProgramData\msmzjrfwa.exe
Task: {C0087446-8B46-48FF-97C4-DC702049DD10} - System32\Tasks\GoforFilesUpdate => C:\Program Files\GoforFiles\GFFUpdater.exe <==== ATTENTION
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

REDACTED

  • Guest
Re: disorderstatus and differentia malware. HELP!!!
« Reply #4 on: August 19, 2015, 04:19:16 PM »
Hey,
I am also infected by this malware. I downloaded and run FRST and generated log files. Now tell me what to do. I am attaching both files.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: disorderstatus and differentia malware. HELP!!!
« Reply #5 on: August 19, 2015, 06:21:43 PM »
aknsms  please start your own thread then there will be no confusion