Moneypak and possible ZeroAccess issues.

Discussion in 'Malware Help (A Specialist Will Reply)' started by NeoNot, Nov 18, 2012.

  1. NeoNot

    NeoNot Private E-2

    I have recently contracted the Moneypak virus.
    I have not ,knowingly, installed any new software to the system and nothing was noticed in system performance prior to the moneypak screen showing up.

    I am able to boot to safe mode and ran Malware bytes allowing it to correct all errors it found but the moneypak screen is still present in the Windows7 desktop screen.

    At times I have been able to get the moneypak screen to minimize and get to my desktop but this has been hit and miss. When I did get to the desktop I ran Malware bytes and the Malware bytes rootkit. Both programs show no infections found.

    As directed in the malware removal thread I have attached the following logs for assistance.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I see you have run a bunch of other tools like ComboFix, FRST, and Kaspersky Rescue Disk 10.0. Are you working at another forum??

    Do you have a log from FRST?


    Uninstall the below software:
    BitTorrentBar Toolbar
    Java(TM) 6 Update 24
    Java(TM) 6 Update 30
    Java(TM) 7 Update 5

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Users\NeoNot\AppData\Roaming\setui.dll
    C\Program Files (x86)\facemoods.com
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "UpdReg"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run\Disabled (Auslogics Startup Manager)]
    "facemoods"="\"C:\\Program Files (x86)\\facemoods.com\\facemoods\\1.4.17.11\\facemoodssrv.exe\" /md I"
    "QuickTime Task"=-
    "TkBellExe"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BitTorrent]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\setui]
    "command"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TkBellExe]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escort.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\esrv.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\escort.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\esrv.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. NeoNot

    NeoNot Private E-2

    I am not able to uninstall any of the items you requested, through the safe mode control panel.
    When I goto the control panel and try to uninstall I get the following error.

    The windows installer service could not be accessed.
    This can occur if the windows installer is not correctly installed. Contact your support personnel for assistance.

    After running OTM I have gained access to normal windows but I am still not able to uninstall the toolbar as requested.
     
    Last edited: Nov 20, 2012
  4. NeoNot

    NeoNot Private E-2

    Sorry forgot to attach the OTM log.

    I will run MGtools this evening.
    Time for work.

    Appreciate your assistance with this problem.
     

    Attached Files:

  5. NeoNot

    NeoNot Private E-2

    All Java's uninstalled and latest version installed.
    BitTorrent toolbar still refuses to uninstall.

    At the present system seems to be running normal but does boot slower than previously.


    MG Logs attached.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the OTM fix on the correct account? The fix log shows it did not find some items and they still show in your current MGtools log. You have malware trapped in MSconfig registry keys and you SHOULD NOT be using MSConfig as a log term startup manager. The below entry needs to be deleted before putting MSconfig back to normal startup
    Do you know how to manually delete registry entries? If yes, see if you can delete the below key

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\setui]
     
  7. NeoNot

    NeoNot Private E-2

    I ran the OTM fix in safe mode. It was the only way I could access the computer. The computer only has one account on it or at least that is all it should have.

    I have manually deleted the registry key and ran a new MG log for you.
    It is attached below.

    Thank you for the assistance.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Also please run another scan with Hitman Pro and attach this new log too.
     
  9. NeoNot

    NeoNot Private E-2

    Logs as requested.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. NeoNot

    NeoNot Private E-2

    I thought I was clean but I have noticed a few things not working over the last couple of days.

    CMD prompt will not run unless ran as an Admin.
    The TaskManager will open then instantly close.

    Using a secondary TaskManager I can see that something in the system uses about 100K of the network when nothing should be.

    It also seems like the network connection resets itself about every 30-60 seconds causing major lag in games, lost download, etc....

    Please let me know what logs you need me to provide you with for further assistance.

    Thank you for taking the time to help.
     
  12. NeoNot

    NeoNot Private E-2

    I think I resolved the issue with the network connection.
    It appears that AVG got corrupted. I uninstalled and reinstalled it and now the network issue seems to be gone.

    I however still can not access Task Manager or the Command prompt without them opening and instantly closing.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall AVG again and leave it uninstalled at lease until we finish trying to fix your problems. After uninstalling, continue with the below . Redownload MGtools if you already removed it.



    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. NeoNot

    NeoNot Private E-2

    Windows repair has been ran.
    I however can not run the GetLogs.bat due it coming up in a command prompt.

    Prior to running Windows repair I was able to access the command prompt via the run window and select to run as Admin. This no longer works and anything that tries to run through the command prompt closes within a second of opening.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are to you able to run in safe boot mode?

    Which user account are you currently trying to run there on?


    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  16. NeoNot

    NeoNot Private E-2

    Log attached.
     

    Attached Files:

  17. NeoNot

    NeoNot Private E-2


    Sorry I forgot to answer some of your questions when I posted the log.

    Yes I can boot to safe mode.

    NeoNot should be the only account on the computer any additional accounts, if not a part of the standard windows7 pro install, should not be on the computer.


    I also notice I kinda mis-typed how I could access the command prompt.
    I would goto the start menu, type cmd and then select it from the start menu by right clicking and selecting to run as admin.

    The above no longer works.

    Both the command prompt and the task manager open for about 1 second then instantly exit. There are no errors given when they close and nothing seems to be running poorly but neither program is accessible at this time due to the stated reason.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so do things work properly there.


    So you are saying that you do not know what the below user account is?

    Mcx1-GAMER

    Is it the below?

    http://windows7themes.net/what-is-the-mcx1-user-folder-should-i-delete-it.html


    Is AVG uninstalled?
     
  19. NeoNot

    NeoNot Private E-2

    Yes, everything seems to be working correctly in Safe Mode.
    The Mcx1-Gamer is a legit account. Sorry forgot about the Media Center install.
    Avg was uninstalled via the control panel.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then see if the below runs in safe mode.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    I'm not seeing any malware in your logs. But FRST thinks two system files are not the correct versions

    C:\Windows\SysWOW64\User32.dll
    [2009-07-13 15:24] - [2009-07-13 17:11] - 0861696 ____A (Microsoft Corporation) 9FE88137B18D3EE88D4FCDD2951AD3D8
    C:\Windows\System32\Drivers\volsnap.sys
    [2011-12-30 07:29] - [2011-02-24 22:36] - 0295296 ____A (Microsoft Corporation) C9D0EAF58D6BA71E128E715EA43AD87


    You may want to try using an old restore point to see if that helps correct issues with the command prompt. Per FRST, you have the below
    Obviously this does not go back in time before you first posted but maybe it would help with the command prompt issue since that only started after 12/05 when you ran Windows Repair. Only other thing to do may be to do a Windows Repair but I'm not sure that would help.
     
    Last edited: Dec 10, 2012

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds