Author Topic: Help with http://disorderstatus.ru/order.php  (Read 23167 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Help with http://disorderstatus.ru/order.php
« on: May 15, 2015, 08:33:42 AM »
Hi,

Hoping to get help with this new detection repeatedly popping up on Avast:

Avast Web Shield has blocked a harmful webpage or file

URL: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe

I suspect I was infected through a thumb drive, although Avast didn't detect anything when I initially scanned the drive, which seems strange to me.

MBAM, FRST and aswMBR logs attached.

Thanks in advance!

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Help with http://disorderstatus.ru/order.php
« Reply #1 on: May 15, 2015, 08:35:40 AM »
Hello,


Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
autoclean;
emptyalltemp;
bitsadmin /reset /allusers;b
ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Help with http://disorderstatus.ru/order.php
« Reply #2 on: May 15, 2015, 08:56:57 AM »
Hi TwinHeadedEagle,

As requested, Zoek-results attached here. Thanks for the help!

REDACTED

  • Guest
Re: Help with http://disorderstatus.ru/order.php
« Reply #3 on: May 15, 2015, 08:59:10 AM »
The detection seems to have stopped so far after the ZOEK reboot

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Help with http://disorderstatus.ru/order.php
« Reply #4 on: May 15, 2015, 11:25:59 AM »
Very good. Anything else I can help?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Help with http://disorderstatus.ru/order.php
« Reply #5 on: May 15, 2015, 11:27:31 AM »
Thank you very much TwinHeadedEagle!

REDACTED

  • Guest
Re: Help with http://disorderstatus.ru/order.php
« Reply #6 on: May 18, 2015, 05:42:26 PM »
Hi TwinHeadedEagle i have the same problem of : gcbaluyut
Avast is always detecting a virus
URL: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe
I'm following the instructions that you gave in the topic.
What should i do after using Zoek???

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Help with http://disorderstatus.ru/order.php
« Reply #7 on: May 18, 2015, 08:10:11 PM »
Please open your own topic.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Help with http://disorderstatus.ru/order.php
« Reply #8 on: August 03, 2015, 01:52:50 PM »
Hi TwinHeadedEagle i have the same problem with
URL: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe
I'm following the instructions that you gave in the topic.

REDACTED

  • Guest
Re: Help with http://disorderstatus.ru/order.php
« Reply #9 on: August 03, 2015, 03:36:07 PM »
Hi TwinHeadedEagle, 

I have the same problem with
URL: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe

I followed the instustions u have mentioned above, and i have attached my Zoek-results here. But my problem is not solved :-[

REDACTED

  • Guest
Re: Help with http://disorderstatus.ru/order.php
« Reply #10 on: October 09, 2015, 11:55:08 AM »
Hi TwinHeadedEagle,
I just do what you told and the ZOEK is work for me...
 Thanks a lot!

sorry for my bad english

REDACTED

  • Guest
Re: Help with http://disorderstatus.ru/order.php
« Reply #11 on: November 10, 2015, 07:57:24 PM »
Greatings !

I had the same problem and followed the instructions .
The problem was solved but my laptop has no sound after the procedure ..
What can I do about it ? I've checked all of the drivers and the speakers... And the system didn't detect any problems ..