Author Topic: Disorder/Differentia.ru Malware  (Read 2502 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Disorder/Differentia.ru Malware
« on: November 11, 2015, 12:18:54 PM »
Recently I plugged my pendrive to my friends PC and when i plugged it back to my laptop avast is telling me this error every 15 seconds. Is there is any way to fix it?


Those arent actually my screens but I have identical virus pop up.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Disorder/Differentia.ru Malware
« Reply #1 on: November 11, 2015, 12:30:22 PM »
Please follow the instructions in the sticky at the top of this forum and attach the requested logs to your next post.

REDACTED

  • Guest
Re: Disorder/Differentia.ru Malware
« Reply #2 on: November 11, 2015, 02:16:13 PM »
Im extremly sorry for that , was in a bit of a hurry.
« Last Edit: November 11, 2015, 04:36:57 PM by Emos »

REDACTED

  • Guest
Re: Disorder/Differentia.ru Malware
« Reply #3 on: November 11, 2015, 04:38:30 PM »
Can't send more then 4 attachments in one message, here is the rest of the files.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Disorder/Differentia.ru Malware
« Reply #4 on: November 11, 2015, 04:58:22 PM »
Looks like MBAM got the run key so I will get the file

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
URLSearchHook: HKLM-x32 -> Domyslne = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D}
Toolbar: HKLM - Brak nazwy - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  Brak pliku
FF Extension: Brak nazwy - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08] [Brak podpisu cyfrowego]
2015-10-13 06:42 - 2015-10-07 18:58 - 00000102 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-07-14 20:25 - 2015-06-15 22:16 - 99058944 ___SH () C:\ProgramData\msqujksi.exe
2015-10-07 18:58 - 2015-10-13 06:42 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Disorder/Differentia.ru Malware
« Reply #5 on: November 11, 2015, 05:25:31 PM »
Thank you! So far no pop ups

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Disorder/Differentia.ru Malware
« Reply #6 on: November 11, 2015, 07:05:53 PM »
Could you put the following folder into dropbox public c:\FRST
Send me the sharing link so that I can grab it for onward transmission to Avast
Once I have it you can delete it :)

Any further problems ?

 

REDACTED

  • Guest

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Disorder/Differentia.ru Malware
« Reply #8 on: November 12, 2015, 03:34:38 PM »
Oops you appears to have given me some pictures

Did you zip c:\FRST ?