Author Topic: help remove disorderstatus.ru and differentia  (Read 1676 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
help remove disorderstatus.ru and differentia
« on: August 21, 2015, 02:08:42 PM »
Hello,

Avast was continuously popping up on my PC because of
-http://disorderstatus.ru/order.php
- http://differentia.ru/diff.php



After using the softwares listed on the information topic, Avast popUp ceased  but I understood that  the malware is still on my laptop.

Can someone help me to remove it completely ? Thank you very much.

-> here are the log files from MbAM, FRST and aswMBR.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help remove disorderstatus.ru and differentia
« Reply #1 on: August 21, 2015, 02:26:49 PM »
Could you let me know if this stops it

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
ProxyEnable: [.DEFAULT] => Internet Explorer proxy est activé.
ProxyServer: [.DEFAULT] => http=127.0.0.1:58103;https=127.0.0.1:58103
2015-07-15 15:27 - 2015-06-16 04:42 - 87209984 ___SH () C:\ProgramData\msiishx.exe
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

REDACTED

  • Guest
Re: help remove disorderstatus.ru and differentia
« Reply #2 on: August 22, 2015, 10:31:19 AM »
Done.

and here are the two logs.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help remove disorderstatus.ru and differentia
« Reply #3 on: August 22, 2015, 12:03:52 PM »
Have the alerts now ceased