Please help remove Moneypak/FBI ransomware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by craaber, Jul 4, 2012.

  1. craaber

    craaber Private E-2

    My PC is infected wit the Moneypak/FBI ransomware - it puts up a fake FBI screen with m y IP address and takes control of my camera. It says I can pay $100 at several different stores to "unlock" my machine.

    I have a Sony VGN-FW laptop running Win7 (64-Bit).
    I had a malware issue about 8 years ago - and got help here.

    I followed the Malware Removal Guide steps for Win7 and have attached my logs. I ran these steps in safe mode with netoworking. When Ilog back on to Win7 normally (with an internet connection) I get the same "FBI" ransom screen.

    Hope eveyone is enjoying their Independence Day. When someone has a chance - help would be much apprecciated.

    Thanks.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, craaber :)

    [​IMG] Open RogueKiller.
    • Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    • When it opens, press the Scan button.
    • Once the scan has completed, press the Delete button.
    • When it is finished, there will be a log on your desktop called: RKreport[2].txt
    • Attach RKreport[2].txt to your next message. (How to attach)

    Now delete this file: C:\Users\craab\AppData\Local\Temp\0_0u_l.exe

    Reviewing the rest of your logs now.
     
  3. thisisu

    thisisu Malware Consultant

    Once you have finished with the above you can proceed with these steps:

    [​IMG] Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    O4 - Startup: ctfmon.lnk = C:\Windows\System32\rundll32.exe

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4

    __

    [​IMG] From Programs and Features (via Control Panel), please uninstall the below:
    • Java(TM) 6 Update 31

    __

    The rest of your logs look fine.
    Let me know what malware related problems you are experiencing after you have completed these steps.
     
  4. craaber

    craaber Private E-2

    Ok - I ran Rogue Killer again - deleted what came up and have attached the log. I 'm working on completing your instruction from your second post now...
     

    Attached Files:

  5. craaber

    craaber Private E-2

    Ok - I followed your instructions per below, but I did not get the O4 line you mention in the scan results. I checked carefully.
    I did remove the Java updater you told me to.

    What should I do now?
    Thanks!
     
    Last edited by a moderator: Jul 5, 2012
  6. thisisu

    thisisu Malware Consultant

    It looks like RogueKiller deleted the O4 entry we see in HJT too, so that's good. I just wanted to make sure it was gone.
    Did you delete this file? C:\Users\craab\AppData\Local\Temp\0_0u_l.exe

    __

    [​IMG] Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)

    __

    Let me know what problems persist after you have completed this step.
     
    Last edited: Jul 5, 2012
  7. craaber

    craaber Private E-2

    I did find and delete this: C:\Users\craab\AppData\Local\Temp\0_0u_l.exe

    Following the second half of your instructions now - will post logs shortly.
     
  8. craaber

    craaber Private E-2

    I did find and delete this: C:\Users\craab\AppData\Local\Temp\0_0u_l.exe

    Following the second half of your instructions now - will post logs shortly.
     
  9. craaber

    craaber Private E-2

    Ok - new MGlogs.zip attached...
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    [​IMG] Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4

    __

    Other than the above, your latest logs look fine. Experiment with the PC a bit. I can see you were in Normal Mode last time you ran MGtools (GetLogs.bat) so that's good.
     
  11. craaber

    craaber Private E-2

    Ok - I'll do that this afternoon.

    Yes I was in normal mode and the PC seems to be ok - no ransom screen.
    Do you need me to post any more logs after scanning and "fixing" that line?

    I apprecciate the help!
     
  12. thisisu

    thisisu Malware Consultant

    Yes if you could run GetLogs.bat once again after you fix that line so I can make sure that entry is gone that would be fine ;)
     
  13. craaber

    craaber Private E-2

    Ok - here's the latest log:
     

    Attached Files:

  14. thisisu

    thisisu Malware Consultant

    Looks like it was removed successfully :)

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds