Author Topic: http://disorderstatus.ru/order.php alert persists  (Read 2958 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
http://disorderstatus.ru/order.php alert persists
« on: August 03, 2015, 10:41:58 AM »
Hoping to get help with this new detection repeatedly popping up on Avast:

Recently, every 3-5 minutes, Avast Web Shield would pop up with the following alert:

Avast Web Shield has blocked a harmful webpage or file
URL: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe

I have run numerous virus/malware applications, yet the problem still persists.
I downloaded Zoek and attached the generated report.

Can anyone please assist with the removal of this virus?

Thanks in advance!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: http://disorderstatus.ru/order.php alert persists
« Reply #1 on: August 03, 2015, 01:03:01 PM »
follow instructions and attach requested logs   https://forum.avast.com/index.php?topic=53253.0



Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5625
  • Spartan Warrior
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

REDACTED

  • Guest
Re: http://disorderstatus.ru/order.php alert persists
« Reply #3 on: August 04, 2015, 08:24:13 AM »
Hi Pondus

Thanks for responding.
Please see attached requested logs

Thanks =)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: http://disorderstatus.ru/order.php alert persists
« Reply #4 on: August 04, 2015, 08:25:10 AM »
malware experts will be online later today ....


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: http://disorderstatus.ru/order.php alert persists
« Reply #5 on: August 04, 2015, 04:21:19 PM »
This was a present with the cracked Adobe you installed

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
HKU\S-1-5-21-2369146234-665257770-333335392-1000\...\Run: [AdobeBridge] => [X]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
2015-08-04 06:53 - 2015-08-04 06:53 - 00000000 ____D C:\Program Files (x86)\Easy Auto Refresh
2015-08-04 06:52 - 2015-08-04 06:54 - 00000000 ____D C:\Program Files (x86)\bestadblocker
2015-08-04 06:50 - 2015-08-04 06:50 - 00000000 ____D C:\Program Files (x86)\CutThePirIcE
2015-08-04 06:48 - 2015-08-04 07:10 - 00000390 _____ C:\Windows\Tasks\TransmitAll.job
2015-08-04 06:48 - 2015-08-04 06:48 - 00003304 _____ C:\Windows\System32\Tasks\TransmitAll
2015-08-04 06:48 - 2015-08-04 06:48 - 00000000 ____D C:\Users\Armand\Downloads\Adobe_Sounbooth_CS5_3_keygen_by_orion (2)
2015-08-04 06:48 - 2015-08-04 06:48 - 00000000 ____D C:\ProgramData\{c7e36294-d8bc-3619-c7e3-36294d8b8a53}
2015-08-04 06:45 - 2015-08-04 06:46 - 00204920 _____ C:\Users\Armand\Downloads\Adobe_Sounbooth_CS5_3_keygen_by_orion (2).zip
2015-08-04 06:44 - 2015-08-04 06:44 - 01678049 _____ C:\Users\Armand\Downloads\Adobe_Sounbooth_CS5_3_keygen (2).zip
2009-07-14 01:31 - 2009-07-14 03:14 - 90646400 ___SH () C:\ProgramData\msihrbtj.exe
Task: {0C232C2B-617C-4217-8202-0AB3BA71A6C6} - System32\Tasks\TransmitAll => c:\programdata\{c7e36294-d8bc-3619-c7e3-36294d8b8a53}\adobe_sounbooth_cs5_3_keygen_by_orion.exe [2015-08-04] () <==== ATTENTION
Task: C:\Windows\Tasks\TransmitAll.job => c:\programdata\{c7e36294-d8bc-3619-c7e3-36294d8b8a53}\adobe_sounbooth_cs5_3_keygen_by_orion.exe <==== ATTENTION
c:\programdata\{c7e36294-d8bc-3619-c7e3-36294d8b8a53}
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

REDACTED

  • Guest
Re: http://disorderstatus.ru/order.php alert persists
« Reply #6 on: August 05, 2015, 05:13:01 PM »
Hi essexboy

Thank you for your response
Please find attached logfiles requested.

Thanks =)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: http://disorderstatus.ru/order.php alert persists
« Reply #7 on: August 05, 2015, 07:09:09 PM »
Have the alerts now ceased ?