Author Topic: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php  (Read 5234 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« on: November 12, 2015, 05:03:37 PM »
Hello! I've been getting these popups today on avast every 30 seconds or so ever since i had to use a friends usb. I already tried checking to see if it could be uninstalled in the 'programs and features' or if maybe it was installed w/o my knowledge as an extension on chrome. PLS HELP! Im worried that the longer this is left unresolved the more likely the situation for my laptop could get worse.

1st Popup:

URL: disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe


2nd Popup:

URL: differentia.ru/diff.php
Infection: URL:Mal
Process: C:\Windows\SysWOW64\msiexec.exe

thank youuuuu!

(will follow up with attachments soon)
« Last Edit: November 12, 2015, 05:49:12 PM by oppai hoodie »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: popups! disorderstatus.ru/order.php and http://differentia.ru/diff.php
« Reply #1 on: November 12, 2015, 05:24:04 PM »
Follow Instructions here https://forum.avast.com/index.php?topic=53253.0
Attach Malwarebytes and Farbar Recovery Scan Tool logs ....  3 logs total


See below the box you write in ... Attachments and other options



Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: popups! disorderstatus.ru/order.php and http://differentia.ru/diff.php
« Reply #2 on: November 12, 2015, 05:26:03 PM »
Quote
ever since i had to use a friends usb.
so most likely Your friends computer also have a infection and should get in checked here also
we can also clean the USB stick used ...


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: popups! disorderstatus.ru/order.php and http://differentia.ru/diff.php
« Reply #3 on: November 12, 2015, 05:43:58 PM »
oppai hoodie

make the links not clickable.
We do not want people to visit malicious websites.

REDACTED

  • Guest
Re: popups! disorderstatus.ru/order.php and http://differentia.ru/diff.php
« Reply #4 on: November 12, 2015, 05:47:10 PM »
The thing is my friend doesn't have a computer so I have no idea where she got the infection.  :-\
btw after i had a threat scan the popups have stopped. does this mean the infection is completely gone or is there a chance that its still hiding somewhere?

also a big thank you again for looking into this
« Last Edit: November 14, 2015, 10:44:45 PM by oppai hoodie »

REDACTED

  • Guest
Re: popups! disorderstatus.ru/order.php and http://differentia.ru/diff.php
« Reply #5 on: November 12, 2015, 05:48:17 PM »
oppai hoodie

make the links not clickable.
We do not want people to visit malicious websites.

oh damn. sorry about that
thanks for pointing that out

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #6 on: November 12, 2015, 07:02:01 PM »
Did you install windivert ?

Quote
WinDivert is a user-mode capture/sniffing/modification/blocking/re-injection package for Windows Vista, Windows Server 2008, Windows 7, and Windows 8. WinDivert can be used to implement user-mode packet filters, packet sniffers, firewalls, NAT, VPNs, tunneling applications, etc., without the need to write kernel-mode code.

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
BHO-x32: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
S5 WinDivert1.1;  <===== ATTENTION: Locked Service
cmd: sc stop WinDivert1.1
cmd: sc delete WinDivert1.1
2013-08-22 11:56 - 2013-08-22 11:56 - 104827520 ___SH () C:\ProgramData\msjzsvc.exe
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #7 on: November 12, 2015, 10:30:02 PM »
Did you install windivert ?

Nope. Do I still have to?
I mean the popups have stopped right after I dl malwarebytes and had a threat scan.
« Last Edit: November 12, 2015, 10:39:09 PM by oppai hoodie »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #8 on: November 12, 2015, 10:44:11 PM »
Run FRST as MBAM did not kill the file

REDACTED

  • Guest
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #9 on: November 12, 2015, 11:36:07 PM »
Here it is:
« Last Edit: November 13, 2015, 05:49:38 PM by oppai hoodie »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #10 on: November 13, 2015, 01:43:53 PM »
That service did not want to go .. Is your windows genuine ?

REDACTED

  • Guest
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #11 on: November 13, 2015, 02:17:09 PM »
im actually not sure. i think i just had a friend install it for me  :-\

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #12 on: November 13, 2015, 03:12:05 PM »
It appears to be illegal

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
« Last Edit: November 13, 2015, 03:54:33 PM by essexboy »

REDACTED

  • Guest
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #13 on: November 13, 2015, 04:01:53 PM »
It appears to be illegal

oh geez. i had a feeling it was
sorry if this makes things more of a hassle


Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

will get right to it now

REDACTED

  • Guest
Re: popups! disorderstatus.ru/order.php and/differentia.ru/diff.php
« Reply #14 on: November 13, 2015, 04:10:01 PM »
done
« Last Edit: November 14, 2015, 10:43:56 PM by oppai hoodie »