![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
||||
|
||||
|
Hey there! Earlier this weekend my computer became infected with the FBI/Moneypak ransomware. After rebooting my system in Safe Mode, I went through all the Read/Run First instructions. Upon completion, I rebooted in Normal mode and it looked like the problem had been fixed with two exceptions. As soon as my login finished, I was presented with this:
![]() I clicked "OK" and still everything seemed fine. Hitman Pro ran its start up scan and once again, I was presented with an alert stating that my system was infected. Malwarebytes says my system is clean so I'm just a little concerned about the Hitman Pro results. The initial RunDLL popup is more of an annoyance than anything, but I want to be certain that my computer is clean. Thanks! I've attached all of the original clean up results. The hitmanpro2 file is the current scan results I'm getting. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Here's the MGlogs.
|
|
#3
|
||||
|
||||
For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive. Plug the flashdrive into the infected PC. Enter System Recovery Options. To enter System Recovery Options from the Advanced Boot Options:
To enter System Recovery Options by using Windows installation disc:
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#4
|
||||
|
||||
|
So now there's a new problem...
I tried opening up BIOS and for the first time since I purchased the computer, it asked for the admin password. It's not accepting the admin password and I'm at a loss on how to change it and access BIOS. I thought that maybe I put in the wrong password, but nothing is working. Suggestions...? |
|
#5
|
||||
|
||||
|
Agh. This is something that you will have to ask about in the software forum and then return here to complete malware removal.
Do not keep trying to guess at the password because it could get locked up completely! I believe there is software out there that can resolve the problem, but again, ask the guys and gals in the other forum and then return here. ![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Alright! Sorry that took so long.
That was far easier than I expected. Turns out, I didn't need to enter BIOS at all. Just F8 prior to startup opened my advance boot options. Go figure. Regardless, now I have the admin password ![]() |
|
#7
|
||||
|
||||
|
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Attached is fixlist.txt
Now re-enter System Recovery Options. Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (How to attach) Now attempt to boot normally. Delete this folder: C:\ProgramData\blekko toolbars Delete this file: C:\Windows\assembly\GAC_32\desktop.ini Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now! Run FRST again like you did the very first time and attach the log.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#8
|
||||
|
||||
|
All ran well. My boot up was a little slow this time though. Not sure if that means anything.
C:\ProgramData\blekko toolbars has been deleted. I could not find C:\Windows\assembly\GAC_32\desktop.ini anywhere, however. It seems the only time I see that full file name anywhere is when it pops up in HitmanPro. HitmanPro's initial scan when I booted popped up with that same trojan warning and it also came up with a "suspicious file" warning as well. I've attached the xml file just in case you wish to take a look. Not sure if I'm supposed to but I've tried deleteing that desktop.ini file through HitmanPro but it pops up with it again when I boot up. Also, I'm still getting the RunDLL pop up: ![]() And one more new addition: I'm getting "An add-on for this website failed to run" error whenever a new page loads. I've tried multiple websites. Not sure if that's my ActiveX settings that are messed up somehow or what. I just find it annoying haha. |
|
#9
|
||||
|
||||
|
Please run FRST again like you did the very first time and let me see that log too please.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#10
|
||||
|
||||
|
Here you go!
|
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Download this >> fixlist.txt
Save fixlist.txt to your flash drive.
Run FRST64 and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt). Please attach this to your next message. (See how to attach) Now boot into normal Windows can continue with the below. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following 2 Users Say Thank You to chaslang For This Useful Post: | ||
Kestrel13! (07-13-12), RaineShadow (07-13-12) | ||
|
#12
|
||||
|
||||
|
Thank you so much! Everything looks good! It booted up fine and everything is loading normally again with no delay. HitmanPro's Quick Scan was clean this time, and no RunDLL popup.
Still getting that add-on error though. I'm thinking that's probably not related to this problem though haha. |
|
#13
|
||||
|
||||
|
Oh, I just noticed this, too. I don't know if something got messed up during the cleaning process or if the ransomeware disabled it, but my biometric quick launch is not working. The scanner is working so I can log into Windows, but for websites that it's supposed to run passwords for, it will not run. I've checked my device settings and everything is still set to default (I've even changed it and re set it to default) and nadda. Where would I go to find help on this? I have a lot of trust in that device (I had a problem with keyloggers on an old machine) and it's a new machine so I really don't want to have to just forget about it.
|
|
#14
|
||||
|
||||
|
You can ask about that ain the software forum. Just run Ccleaner (not the registry scanner, the cleaner itself)
If you are not having any other malware problems, it is time to do our final steps:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#15
|
||||
|
||||
|
Ok, on the second to last step. Just so I make sure I don't mess this up, I have 2 drives showing up in my system protection tab:
Local Disk (C (System) OnRECOVERY (D OffI want the Local Disk, right? I'm just asking because the screenshot for both Win7 & Vista don't touch the "system" drive. |
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
Are you referring to system restore?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#17
|
||||
|
||||
|
Yes, the system restore.
I want to turn off system protection to the local disk, correct? My options are Recovery and Local Disk. |
|
#18
|
||||
|
||||
|
Ok, I'm officially annoyed with this. I just tried to change some of my theme settings and now I'm getting the error:
Windows cannot find 'C:\WINDOWS\\system32\\rundll32.exe'. Make sure you typed the name correctly, and then try again. I looked in the other threads and I don't have my Windows 7 CD and I can't find another file. I don't understand when this happened because everything was working just fine until now. I tried going into my settings to view hidden folders and I get the same error. I haven't been on any websites other than my e-mail, here, facebook, and google. I just want my computer back to normal... |
|
#19
|
||||
|
||||
|
I want you to run TDSSKiller so refer to the below for how to do so.
TDSSkiller - How to run Please also download MBRCheck to your desktop
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#20
|
||||
|
||||
|
Ok! I did as you said. Both came up clean :P Anyway, here's the logs!
It's weird. Other than that rundll32.exe file, everything is running fine. |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Please help remove Moneypak/FBI ransomware | craaber | Malware Removal | 13 | 07-05-12 16:10 |
| PLEASE HELP! About to lose it - Aurora remnant? VCMnet11.exe | rschryver1 | Malware Removal | 6 | 05-25-05 12:59 |
| Possible remnant spyware | oquela | Malware Removal | 8 | 02-10-05 13:10 |