moneypak kapersky failure

Discussion in 'Malware Help (A Specialist Will Reply)' started by entreri00, Nov 25, 2012.

  1. entreri00

    entreri00 Private E-2

    This is the second time this pc has had the moneypak. I managed to get rid of it once for the person but this time it's not turning out to be...easy?

    At any rate, I believe I followed the the steps for using the rescue disk corectly by mounting it on a usb and running the object scan, etc. The pc prior to that would not boot into windows except when the ethernet was pulled or I used Last Known Good Configuration.

    Before the rescue disk I had tried using Combofix/MalwareBytes/TDSSkiller/Roguekiller. Still I'd get the splash screen with a regular boot.

    As with others, Safe Mode would just boot cycle which led me to try the Rescue Disk.

    Every few boots now it's been running a checkdisk as well. That worries me.

    Hopefully I'm just missing a remnant. Now, the first time I was trying this I'd not really followed the steps and just did the object scan without running the unlocker. The second time I ran it all but it didn't find much. So I did skip steps once if that helps. There were things it found in the first scan that looked bad but recommended not quarantining or deleting. Nothing the second time. I wonder that it doesn't recommend I scan C: although I'm sure I did my first run through.

    Guess I should've come here first but this is the first time I've gotten stuck completely.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. entreri00

    entreri00 Private E-2

    I'll try all that. I'm almost done getting the files together but keep in mind I'm not able to maintain the ethernet connection or I get the splash screen for moneypak. Normal boot and Last Known have the moneypak with ethernet in. Safe Modes don't boot. So I'm doing this offline.

    So no updating of malwarebytes definitions, of which he has the paid version from my last foray. I don't know if any of the others like to update off the top of my head or if they're all current and don't need internet connections to run.
     
  4. entreri00

    entreri00 Private E-2

    I don't know what to do on the malwarebytes part. The one that was there said it was corrupt. That was a Pro version. Then I installed the new one thinking it was just the database update as that was the link I used. It was a new install and it functions but its 57 days out of date. I don't see where to get an update file. Anyway, the out of date version finds nothing.
     
    Last edited: Nov 26, 2012
  5. entreri00

    entreri00 Private E-2

    1. Roguekiller is eaten by AVG if it's enabled. Deleted as a virus. FYI
    2. MGtools doesn't function off flash drive. Copied and pasted from flash. Running it extracts files but runs no batches. I see an command box flash by but just get a folder on C with lots of files.
     
  6. entreri00

    entreri00 Private E-2

  7. entreri00

    entreri00 Private E-2

    Correction, it will now boot normally to the desktop without a moneypak screen. It will not boot into safe mode of any kind however.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was explained in the instructions. It is updated as part of the install. And if you do not have a network connection, it showed you where to download a manual update from.

    You need to attach the log from Malwarebytes and also the log from MGtools which is C:\MGlogs.zip as stated. You must run MGtools from the Windows boot drive not from the flash drive.
     
  9. entreri00

    entreri00 Private E-2

    I get it but when you run the database updater both his pro version and my free one still say it's out of date. I just tried it on mine and after running it when I start Malwarebytes it says I'm 8 days out of date. Doesn't matter for me, I have an internet connection. Doesn't matter for him now, I got to the desktop with internet and updated it and ran it.

    I said I copied and ran MGtools from the the drive. I just was saying I tried it off the flash first so you'd know what I had done possibly wrong. It creates a folder but doesn't seem to run any of the .exe in it on it's own. I'll look at the instructions again.
     

    Attached Files:

  10. entreri00

    entreri00 Private E-2

    Redownloaded and ran MGtools on c: again. No batch files run. Just creates folder with files in it.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was AVG disabled before running?


    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    nwktst<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    getnetinf<-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     
  12. entreri00

    entreri00 Private E-2

    Yes, disabled until restart was the option i'd been using. It's either that or 10 minutes max as an option.

    I can't get a command prompt. It opens for just a split second and closes again. I tried it through the accessories as well as trying a slash ipconfig to see if it would do anything. I don't think it's executing any commands. All I see is the path it's on when i do it a few times. c:\documents and settings\administrator.
     
  13. entreri00

    entreri00 Private E-2

    Can't get a command prompt. It just flashes by.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Reset Registry Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.

    Please download OTL by OldTimer.
     
  15. entreri00

    entreri00 Private E-2

    The first part was no problems. The OTL kept asking if I want to make two files that don't exist when the scan completes and then I couldn't find them after I said yes. As I'm typing this message now I see it's giving me a notepad file for OTL.ext that I'm including. Took three or four tries for some reason.

    Btw, it was tempting to check the "repair safe mode" or something similar but you didn't say to do that so I restrained myself.
     

    Attached Files:

    • OTL.Txt
      File size:
      139.4 KB
      Views:
      6
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think you are having problems due to AVG being installed. Probably what also cause issues with MGtools running.

    I'm not seeing any malware. Are you still having problems?
     
  17. entreri00

    entreri00 Private E-2

    Yes, and no. I went ahead and uninstalled AVG. It still doesn't want to boot into safe mode which has been an issue from the start. It will do a normal boot. This is the only apparent issue I can see.

    1. Anything to do to fix Safe Mode?
    2. Reinstall AVG? What other AV to use? It seems about as good as the others to me.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay leave AVG uninstall for now. If you happened to have reinstall it, then uninstall it again and leave it this way.

    Now let's try another fix with Windows Repair.

    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    And now that AVG is uninstalled, let's try the below.


    Now run the C:\MGtools\FixSBM.bat file by double clicking on it . This will run quickly.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  19. entreri00

    entreri00 Private E-2

    I think we touched on it before but cmd doesn't really work. Which is probably why MGtools isn't working either.

    When i follow all your latest steps they appear to work fine but you don't get a log file. I searched for it. I assume it's probably going to show up in C: or the MGtools folder or desktop. It's not anywhere on C:

    The windows fix program runs for awhile and I see no reason to think it didn't complete all the assigned tasks.

    Start-Run-Cmd, just makes the dos box flash open and you can't do anything. similarly commands like ipconfig don't appear to execute either.

    I found a post indicating combofix might work but I've refrained from trying it.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does safe boot mode work now?

    Is AVG still uninstalled? If yes leave it uninstall for now to avoid having it get in our way.

    Can you do the below?


    Also download and save the below to your PC in the C:\MGtools folder. Then locate the ReZip.txt file with Windows Explorer and Right Click on it and select Rename. .

    ReZip.txt

    Change the name to Rezip.bat

    Then Right Click on it and select Run As Administrator.

    It should take a couple seconds to run. You will see a black command prompt window while it is running and it should tell you that the C:\MGtools\MGlogsR.zip file as been created. Attach this ZIP file.
     
  21. entreri00

    entreri00 Private E-2

    No, still no safe mode. Yes, AVG still not installed. Got file.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing to useful in that log as nothing from MGtools really ran properly. Also OTL did not show any malware either. It seems you may just have a lot of damage to Windows. Does System Restore work? If yes, you may want to see if you have an old restore point to go back to that predates these problems.
     
  23. entreri00

    entreri00 Private E-2

    ok. He was going to check and see what OS he had for it. It's got XP on it but it's a Vista shipped machine. Cast off from his spouses travel agency. Figured we've probably run our course on it. Thanks for the help though.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need a disk to try running system restore. A disk would be need to perform a repair install or a total reinstall unless there is still a factory image partition available which could be used to reimage the drive. I cannot tell if you have one since MGtools could not be run.
     
  25. entreri00

    entreri00 Private E-2

    I'm aware of that. I was thinking we've exhausted the possibilites other than system restore. Turns out system restore doesn't work. I can't see if there are any points as it won't run. I can't get to it just like I can't get to a dos prompt.

    I just turned to it now after it was on all night and the message was that skype was out of system memory. It won't even let me click on My Computer. It's locked. Assuming it's not a hardware issue in there I just think we are wasting our time at this point. Reinstall. Don't you think? If he's got a vista disk the dell sticker with the key is on it. I could've done that 3 times over by now but I figured I'd save him from whatever he hasn't thought of backing up. He's got his email, pics and docs off it.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes if he has everything he needs backed up and has the required OS disk and drivers disk to reinstall, I would just reinstall.

    Note: Also what I can say is that there had to be more wrong than just moneypak as these problems are not indicative of a just a moneypak infection.
     
  27. entreri00

    entreri00 Private E-2

    I guess I would only wonder if it's heading for a hardware issue. I have older stuff at work than his but this one is pretty old. The old Dells at work are the survivors. Plenty of the other pentium 4s didn't make it so long.

    Well, he'll bring me a vista disk and I'll use the key it came with. He wants to double check it tomorrow for files and then I'll do a reinstall.

    thanks a bunch.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Good luck with the reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds