Author Topic: Help for http://differentia.ru/diff.php and http://disorderstatus.ru/  (Read 2792 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Got infected by a friend's thumb drive.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Help for http://differentia.ru/diff.php and http://disorderstatus.ru/
« Reply #1 on: August 31, 2015, 10:07:21 AM »
Got infected by a friend's thumb drive.
Then i guess you dont have the tumb drive?


anyway, install (and so should your friend)  MCShield  http://www.mcshield.net/    it will protect against malware that use removable drives to spread
it is a install and forget tool




REDACTED

  • Guest
Re: Help for http://differentia.ru/diff.php and http://disorderstatus.ru/
« Reply #2 on: August 31, 2015, 11:59:56 AM »
What about the malware? It is gone for good?

I had him reformat the thumb drive.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Help for http://differentia.ru/diff.php and http://disorderstatus.ru/
« Reply #3 on: August 31, 2015, 12:02:27 PM »
removal team will be online later and work your case ... 4-5 hours i guess


REDACTED

  • Guest
Re: Help for http://differentia.ru/diff.php and http://disorderstatus.ru/
« Reply #4 on: August 31, 2015, 12:07:07 PM »
Okay, thanks!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help for http://differentia.ru/diff.php and http://disorderstatus.ru/
« Reply #5 on: August 31, 2015, 04:02:44 PM »
Did Malwarebytes remove it ?

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe64.dll [2010-09-17] (Trend Micro Inc.)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll [2010-09-17] (Trend Micro Inc.)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll [2010-09-17] (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg32.dll [2010-09-17] (Trend Micro Inc.)
FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension [2011-04-13]
S4 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [X]
R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90704 2010-09-17] (Trend Micro Inc.)
R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144464 2010-09-17] (Trend Micro Inc.)
R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [67664 2010-09-17] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2010-09-17] (Trend Micro Inc.)
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Help for http://differentia.ru/diff.php and http://disorderstatus.ru/
« Reply #6 on: August 31, 2015, 06:05:36 PM »
Here you go.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help for http://differentia.ru/diff.php and http://disorderstatus.ru/
« Reply #7 on: August 31, 2015, 07:06:13 PM »
Are you still getting the alerts ?