Author Topic: Disorderstatus and differentia.ru  (Read 2185 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Disorderstatus and differentia.ru
« on: August 21, 2015, 04:20:18 AM »
Hello!

I've started to getting popus from Avast telling me that I do have these malwares.

Would someone help me, please?

1st Popup:

URL: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe


2nd Popup:

URL: http://differentia.ru/diff.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe
« Last Edit: August 21, 2015, 06:47:59 AM by Yasmim2 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Disorderstatus and differentia.ru
« Reply #1 on: August 21, 2015, 06:25:15 AM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Disorderstatus and differentia.ru
« Reply #2 on: August 21, 2015, 06:49:12 AM »
About the mbam log, I've made two. The first one I did using the program in portugeuse and it accused a Trojan, the second one is in English and didn't accuse an error.
Both attached

Thank you for your attention :)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Disorderstatus and differentia.ru
« Reply #3 on: August 21, 2015, 06:53:55 AM »
OK, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Disorderstatus and differentia.ru
« Reply #4 on: August 21, 2015, 06:57:22 AM »
That's fine, thank you so much. It's 02am in Brazil, so I'm going to sleep atm haha but I'm back as soon as I can.

Thank you again for your help anyway :)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Disorderstatus and differentia.ru
« Reply #5 on: August 21, 2015, 07:05:17 AM »
You're welcome, good night.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Disorderstatus and differentia.ru
« Reply #6 on: August 21, 2015, 02:21:11 PM »
Could you let me know if this stops it

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]
2015-07-17 09:46 - 2015-06-15 18:16 - 74387072 ___SH () C:\ProgramData\msbnuznf.exe
C:\ProgramData\FileSplitUpLoad.dll
C:\ProgramData\msbnuznf.exe
C:\Users\Todos os Usuários\FileSplitUpLoad.dll
C:\Users\Todos os Usuários\msbnuznf.exe
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that