HELP: windows\SysWOW64\msiexec.exe PROBLEM

Hi, although I use AVAST some years ago, Im a newbie, sorry for the duplication post, but just read that I have to open a new thread.
I have problems since yesterday with C:\windows\SysWOW64\msiexec.exe that is detected every 10 seconds by AVAST web shield, but cant delete that virus or infected file

AVAST shows these two messages:


Blocked infection

URL: http://disorderstatus.ru/order.php
Infección: URL:Mal
Proceso: C:\windows\SysWOW64\msiexec.exe

and…

URL: http://disorderstatus.ru/order.php
Infección: URL:Mal
Proceso: C:\windows\SysWOW64\msiexec.exe

I need your HELP, since my laptop is no more useful this malware, virus??

I followed your instructions, used MBAM and Farbar Recovery Scan Tool, obtaining these 3 files, but I really dont understand what to do next, so before worsing this situation I would appreciate your advice

Can this infection be adquired by an USB used in another computer, and how to test and clean this usb? (its in quarantine now: isolated)

Thanks in advance

Hang on; will be back with scripts shortly.

FIRST >>>>

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[b] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/b]
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

- Right-click on 

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
- Press the Fix button just once and wait.
- If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
- When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

SECOND >>>>

AdwCleaner by Xplode

Download AdwCleaner from here or from here. Save the file to the desktop.

NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

- [b]Vista/7/8 users:[/b] Right click the [b]AdwCleaner[/b] icon on the desktop, click [b]Run as administrator[/b] and accept the UAC prompt to run AdwCleaner.

You will see the following console:

http://i1351.photobucket.com/albums/p785/dbreeze2/Scanners%20screens/AdwCleaner_v4111_zpsn56hzjza.png

- Click the [b]Scan[/b] button and wait for the scan to finish.
- After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: [b]Waiting for action. Please uncheck elements you don't want to remove.[/b]
- Click the [b]Clean[/b] button.
- [b]Everything checked[/b] will be deleted.
- When the program has finished cleaning a report appears.
- Once done it will ask to reboot, allow this

http://1.bp.blogspot.com/-vitKqfMQS4o/UEDylIQ7HJI/AAAAAAAABLc/Hx-IwqKoaxg/s1600/adwcleaner_delete_restart.jpg

- On reboot a log will be produced; please attach that in your next reply. This report is also saved to [b]C:\AdwCleaner\AdwCleaner[C0].txt[/b]

Optional:

NOTE: If you see AVG Secure Search being targeted for deletion, Here’s Why and Here. You can always Reinstall it.


[b]LASTLY >>>>[/b]

To clean and protect USB drives (extra protection above Avast):

Download MCShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives

https://dl.dropbox.com/u/73555776/mcshield%20unhide.JPG

Plug in the drive and McShield will start a scan
Select logs and then copy/paste it to your next post

Sorry for this newbie question,
is the attached log I posted named “FRST.txt” the one I have to rename to "fixlist.txt " for execute the Fix option of FRST …I dont find other way to function this option?

When I rename the file and try to execute Fix option, a warning pops up: “looks you dont know what to do. To prevent damage to the sistem the tool will exit”

Or there is another fixlist.txt ??

What should I do

There is a file attached to dbrise’s post you need to download. (Fixlist.txt).

Put that in the same location as FRST then follow directions as given.

Just in case you did not see it in the other post, the Fixlist.txt file is attached here
|
|
|
|
/

dbrisendine

Thanks for the help.

I follow all instructions and so I attach the reports.

The pops up warnings of avast blocked “windows\SysWOW64\msiexec.exe” stoped, but is now my computer clean for safely use??

One thing I have noticed is that when I now open firefox or chrome browsers, many pages, such as google.com or youtube are blocked as untrusted… What can I do?

Here are some screenshots

Using firefox

This Connection is Untrusted

You have asked Firefox to connect securely to www.google.com.pe, but we can’t confirm that your connection is secure.

Normally, when you try to connect securely, sites will present trusted identification to prove that you are going to the right place. However, this site’s identity can’t be verified.
What Should I Do?

If you usually connect to this site without problems, this error could mean that someone is trying to impersonate the site, and you shouldn’t continue.

or using chrome:

Your connection is not private

Attackers might be trying to steal your information from www.google.com.pe (for example, passwords, messages, or credit cards). NET::ERR_CERT_AUTHORITY_INVALID

Thanks
Pd. what program protection do you advise for making donations (or making web pays secure)?? … I got scared by this infection

Hi,

The MCShield Scan is corrupt. Refer to this link/Picture:
http://i.imgur.com/IJKehlb.png

Save is as MCShield.txt though, not OTL (Previous scan tool). Reupload it so we can read it :slight_smile:

Your logs look great and your system should be good to use now. ;D

The error with the https connections is due to the Avast Web Shield scanning; Avast is aware of this and is working on a solution.

As to a online payment solutions, you can give Avast Safe Zone a try. Avast > Tools > SafeZone.


Clean up of Malware Removal Tools
Now that we are through using these tools, let’s clean them off your system so that should you ever need to have malware removed again (we hope not) fresh, updated copies will be downloaded.

[]Download Delfix from here to your desktop and double click it to start the program
[*]Ensure Remove disinfection tools is ticked
Also tick:
[
]Activate UAC
[]Create registry backup
[
]Purge system restore
[*]Reset system settings

http://i1351.photobucket.com/albums/p785/dbreeze2/just%20stuff/DelFixSelectall_zps0f04cec4.png

[*]Click Run
[*]The program will run for a few moments and then notepad will open with a log. Please attach the log in your next reply.

You can delete any log files left on your desktop as these are no longer needed.