malware/virus: http://disorderstatus.ru/order.php

Hi, I’m not sure how I got this virus but I think after I use my external hard disk on my friend’s computer. I’ve tried Adwcleaner, Malwarebytes, HitmanPro, and SuperAntiSpyware (all free versions) but it keeps popping out every 5 minutes or so. Sometimes when I plugged in the usb or when I’m trying to run an app.

URL: http://disorderstatus.ru/order.php
Infection: URL:Mal
Process: C:\WINDOWS\SysWOW64\msiexec.exe

I tried running MCShield but it said my hard disk is clean… there’s a shortcut of the hard disk in the hard disk. All of my files are in the shortcut. I also can’t run Google Chrome but I’ve already uninstalled it.

I really don’t know what else to do except re-install windows and it’s my last resort. Can somebody help me please??

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

[*]Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
[*]Select additions at the bottom
[*]Press Scan button.

https://dl.dropboxusercontent.com/u/73555776/frst.JPG

[*]It will produce a log called FRST.txt in the same directory the tool is run from.
[*]Please attach both logs generated.

attached the logs. is it the right one?

Let me know how the computer is after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: HKLM\...\Policies\Explorer\Run: [1448931458] => C:\ProgramData\msufcox.exe [83808128 2013-08-22] () HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [] => [X] GroupPolicyUsers\S-1-5-21-1080907322-2641521147-851447987-1002\User: Group Policy Restriction detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-1080907322-2641521147-851447987-1001\User: Group Policy Restriction detected <======= ATTENTION Toolbar: HKU\S-1-5-21-1080907322-2641521147-851447987-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKU\S-1-5-21-1080907322-2641521147-851447987-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Toolbar: HKU\S-1-5-21-1080907322-2641521147-851447987-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKU\S-1-5-21-1080907322-2641521147-851447987-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Toolbar: HKU\S-1-5-21-1080907322-2641521147-851447987-1002 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Toolbar: HKU\S-1-5-21-1080907322-2641521147-851447987-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File CHR Extension: (No Name) - C:\Users\User1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2015-04-25] CHR Extension: (No Name) - C:\Users\User1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-07] CHR Extension: (No Name) - C:\Users\User1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-07] 2013-08-22 11:56 - 2013-08-22 11:56 - 83808128 ___SH () C:\ProgramData\msufcox.exe RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.

Done. Attached the log.

I think it’s ok now. No more pop-ups :slight_smile:

One more thing, theres a $RECYCLE.BIN folder in the hard disk, can I delete it? It’s not actually a hidden folder. I’m afraid it’s gonna mess up something. and so sorry for the stupid question

thank you very much for your help :smiley:

Have the alerts now ceased