![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Infected with FBI Moneypak virus a couple of days back.
Specs: Dell Laptop. Win XP home, Serivce Pack 3, 32 bit Symptoms: - After normal boot-up, plain white screen would appear covering entire desktop. - Task Manager was disabled, only option was to power off the laptop. - Could not log-in in Safe Mode. Received blue screen of death During boot-up prior to this white screen appearing, I was able to quickly launch Malwarebytes for a full scan which ID'd two threats. Also ran full McAfee Scan which found two trojans. Researched on another computer and downloaded/ran HitManPro. This enabled a normal boot and somewhat restored the desktop, but it only showed wallpaper and task bar across bottom with start button. All desktop icons were missing. System Restore and RegEdit were disabled by the virus. Everytime these were launched I would receive error messages. "System Restore not able to protect your computer. Please restart your computer, then run System Restore again." The same would appear for RegEdit. When I checked "My Computer" and "System Restore" tab, the checkbox to disable was and remains empty. Once I found MajorGeeks, I followed all steps in your guide to removing Malware. Scripts are attached. After running RogueKiller, all desktop icons reappeared and the laptop seems to be running fine, but System Restore is still not working. Am also unable to toggle System Restore. I receive the same error message above. During WIN OS Cleaning, the scans for Malwarebytes, TDSSKiller and HitmanPro were all clean (no threats). Was unable to copy/paste outcome of MGlogs. Please review and let me know what needs to be done to re-enable System Restore as well as anything else which still needs to be corrected. Thanks! |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
You have attached some logs that we did not request and did not attach others that we did request
![]() Quote:
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#3
|
|||
|
|||
|
Requested logs attached.
|
|
#4
|
|||
|
|||
|
MGTools zipfile attached.
|
|
#5
|
||||
|
||||
|
You did not attach anything and the file is named C:\MGlogs.zip and nothing else. Notice it is not in the C:\MGtools folder.
![]()
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
MGLogs.zip file attached.
|
|
#7
|
||||
|
||||
|
Uninstall the below:
Fix items using RogueKiller.Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator) When it opens, press the Scan button Now click the Registry tab and locate these 5 detections:
Now press the Delete button. When it is finished, there will be a log on your desktop called: RKreport[2].txt Attach RKreport[2].txt to your next message. (How to attach) Do not reboot your computer yet. Delete these folders if they show:
Run CCleaner to clean out temp files. Re run RogueKiller and attach the log. Open up your services (start > run > type services.msc and hit ENTER. Look for the Background Intelligent Transfer Service if it shows, let me know its status and start up type.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#8
|
|||
|
|||
|
Followed your instructions. Could not identify the final two bullets in your list, bullets 4 "[PROXY IE...] and 5 [APPINIT] in the registry tab of the RogueKiller scan. The PC forced a shutdown every time I tried and would close in less than 1 minute.
I booted back up, deleted RogueKiller, and downloaded a fresh copy. Scanned and ran again. Attached are the 3 scan reports obtained during that process. Of the folders you suggested I delete, I only found and deleted the first one ("kdnyokjla"). All others were not present. Ran CCleaner. When I re-ran RogueKiller I received the following error message: "The instruction at "0x02b14fao" referenced memory at "0x02b14fao". The memory could not be "written" Click on OK to terminate. Click on CANCEL to debug the program. I clicked cancel and ran RogueKiller anyway. The attached scan titled "RKreport[9].txt" is from that final scan. "Background Intelligent Transfer Service" was not present in the list of services. |
|
#9
|
||||
|
||||
|
Uninstall this please:
Browser Manager Now before we tackle the BITS service you should do this: Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#10
|
|||
|
|||
|
OK. Removed "Browser Manager". Ran MGTools. MGLogs attached.
|
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Download the below two files to your desktop.
BITS.reg Netman.reg
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#12
|
||||
|
||||
|
Also: Delete these leftover folders:
C:\Documents and Settings\All Users\Application Data\Browser Manager C:\Documents and Settings\Steve\Start Menu\Programs\Browser Manager
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#13
|
|||
|
|||
|
MGLogs attached.
|
|
#14
|
||||
|
||||
|
Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
After reboot, check to see if your firewall is working. Now repeat the steps in post 11 to do the BITS.reg again. Once done.... Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#15
|
|||
|
|||
|
Completed all steps as instructed. Was not able to initiate a system restore using using Windows Repair by tweaking.com. Received the same error message as before, stating "System Restore not able to protect your computer. Please restart your computer, then run System Restore again."
Added BITS and NetMan to registry. Rebooted. Re-ran MGTools. Log attached. |
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
How is everything currently running?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#17
|
||||
|
||||
|
Quote:
Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
Kestrel13! (10-06-12) | ||
![]() |
| Tags |
| fbi moneypak, system restore |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| FBI Green Dot Moneypak Virus and GWRMDX.EXE - System Error | MWarren | Malware Removal | 6 | 09-15-12 16:30 |
| System Restore stuck at "Preparing to restore... | forrest mc | Software | 5 | 08-28-12 10:15 |
| No Restore points created with system restore turned on | boneyeye | Software | 29 | 02-03-12 21:17 |
| XP System restore is not working (unable to create Restore Points) | hobiefreak | Malware Removal | 1 | 10-02-09 23:42 |
| .EXE executions blocked; can't get to system restore | revmomles88 | Malware Removal | 2 | 02-16-05 02:19 |