I think it’s from my flashdrive because I insert it on another PC and then I insert it to my PC then this Malware always detected by my AV. I attached FRST logs. Thanks in advance!
I think it's from my flashdrivesee instructions here https://forum.avast.com/index.php?topic=53253.0 scroll down to [b]SPECIFIC INFECTIONS LOGS[/b] (picture 5) Follow instructions for [b]MCShield[/b]
this log you Copy and Paste here … not attach
MCShield AllScans.txt <<<
MCShield ::Anti-Malware Tool:: http://www.mcshield.net/
v 3.0.5.28 / DB: 2015.7.25.1 / Windows 8.1 <<<
8/14/2015 2:14:16 PM > Drive C: - scan started (no label ~195 GB, NTFS HDD )…
=> The drive is clean.
8/14/2015 2:14:16 PM > Drive D: - scan started (no label ~20 GB, NTFS HDD )…
=> The drive is clean.
8/14/2015 2:14:16 PM > Drive F: - scan started (Local Disk ~251 GB, NTFS HDD )…
=> The drive is clean.
8/14/2015 2:14:17 PM > Drive I: - scan started (EJAY ~15047 MB, FAT32 flash drive )…
I:\EJAY (16GB).lnk - Malware > Deleted. (15.08.14. 14.14 EJAY (16GB).lnk.720074; MD5: 35aa9a7cd3ab432a6367bbf2eba6db68)
Resetting attributes: I:\ < Successful.
=> Malicious files : 1/1 deleted.
=> Hidden folders : 1/1 unhidden.
::::: Scan duration: 6sec ::::::::::::::::::
MCShield ::Anti-Malware Tool:: http://www.mcshield.net/
v 3.0.5.28 / DB: 2015.7.25.1 / Windows 8.1 <<<
8/14/2015 2:17:54 PM > Drive I: - scan started (EJAY ~15047 MB, FAT32 flash drive )…
=> The drive is clean.
Is this okay? At first my flashdrive was detected but after I unplug then plug it again, there’s nothing detected but it still create shortcut of my flashdrive. And pop ups of the Avast about disorderstatus.ru/order.php and http://differentia.ru/diff.php is still there.
now you have to wait for one of the malware experts to assist you. It may take some hours before they are online
Okay. Thanks for the help. I’ll wait for them 'cause I really need to fix this. It slows down my PC and the pop up annoys me.
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[b] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/b]
Download attached fixlist.txt file and save it to the Desktop:
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!
- Right-click on
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
- Press the Fix button just once and wait.
- If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
- When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
Also, tell me how your system is running now. Thanks.
I don’t know what fixes my PC. With all of the tools I have used, I don’t know which one. @dbrisendine, can I use that even if the pop ups about Malware is gone? BTW, Thanks Guys!
Not sure I understand your last question …
MCShield will just clean USB transfered malware; the Fixlist / FRST run was to fix / remove what else was on your system. The Fixlist.txt / FRST should be run even with the popups gone. (Final insurance, so to speak.)
Oh. Sorry. I didn’t know. ;D So I used the Fixlist in my FRST and here is my Fixlog. I didn’t notice any changes. Maybe I’m just not aware. But I’m sure my PC is now clean as before. Thank you very much!
Cool! Thanks for the follow up. Let’s get you clean from the tools and on your way …
Clean up of Malware Removal Tools
Now that we are through using these tools, let’s clean them off your system so that should you ever need to have malware removed again (we hope not) fresh, updated copies will be downloaded.
[]Download Delfix from here to your desktop and double click it to start the program
[*]Ensure Remove disinfection tools is ticked
Also tick:
[]Activate UAC
[]Create registry backup
[]Purge system restore
[*]Reset system settings
http://i1351.photobucket.com/albums/p785/dbreeze2/just%20stuff/DelFixSelectall_zps0f04cec4.png
[*]Click Run
[*]The program will run for a few moments and then notepad will open with a log. Please attach the log in your next reply.
You can delete any log files left on your desktop as these are no longer needed.
Here is the DelFix log file. Thank you!