FBI Moneypak Virus removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by adordollz, Jan 31, 2013.

  1. adordollz

    adordollz Private E-2

    Hi,
    I have my nieces laptop because it became locked by the FBI Moneypak virus. I had to download all the Major Geeks tools using my laptop and then moved them to the infected laptop using a USB. The infected computer had to be operated in safe mode because I couldn't get past the "locked" FBI screen. Once I ran CCleaner I was able to run in regular mode. I followed all the "Run First" directions and I thought when I was done that I was good to go. The laptop seemed fine - then, I connected it to the internet and the FBI screen popped up again. So, I re-ran all the tools and have attached the logs here. I hope you can work your magic and help me get rid of this thing.
    Thank You. Diana
     

    Attached Files:

  2. adordollz

    adordollz Private E-2

    I just realized that I ran all the tools in safe mode. Because it was my second time going through the step by step process, I didn't have to turn off the user controls and reboot. They were already off from the first run.
    Sorry about that.
    Diana
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : (c:\Users\toshiba2011\gdwooknijayyysxotbzot.exe) -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-3912137570-3849313530-3598963392-1000[...]\Run : (c:\Users\toshiba2011\gdwooknijayyysxotbzot.exe) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now re-run Hitman and have it fix this item if it is still there:
    c:\users\toshiba2011\gdwooknijayyysxotbzot.exe

    Reboot and re-run both Roguekiller and Hitman and attach those logs as well.

    Tell me how things are running now.
     
  4. adordollz

    adordollz Private E-2

    Yesterday I shut down the infected laptop after I ran everything and posted my logs online. When I started it today the FBI locked screen popped up. I restarted in safe mode and ran the programs you mentioned. Roguekiller found the threats you listed and I deleted them. The log is posted. When I ran HitMan the first time, it said no threats were found. I then rebooted and ran the programs again. This second time Hitman found 2 threats -
    C:\Users\ToshibaA2011\wdfrricfoxvqorjepgekt.exe
    c:\users\toshiba2011\gdwooknijayyysxotbzot.exe

    I did not go past that screen where it says to click next to remove malicious software because you didn't say to do that. So I don't have the log from hitman. Tell me what I should do with the 2 worm threats mentioned above and I will finish the Hitman scan and submit the log.

    There was no sign of the fBI screen this time around. I have not rebooted - I still have hitman open.

    Thanks,
    Diana
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes!! Have Hitman remove those infections> then attach the new log from Hitman.
     
  6. adordollz

    adordollz Private E-2

    ok here is the hitman log.
    Thanks again,
    Diana
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rescan with both RogueKiller and Hitman and attach the new logs. Tell me how things are running now!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds