MoneyPak Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Commodore, Jan 22, 2013.

  1. Commodore

    Commodore Private E-2

    The MoneyPak virus is inhabiting my computer. I'm running a Windows 7 Home Edition laptop.

    I am not able to boot into safe mode or safe mode with networking. I have downloaded and run the Farbar recovery scan tool. Log is attached.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Commodore

    I'm not seeing much to do using FRST. I do see that you have two anti-virus programs installed and you MUST uninstall one of the below immediately:
    • AVG2012
    • Ad-Aware Antivirus
    After a re-boot, please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and then attach the requested logs to your next reply when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you have problems downloading on the problem PC, download the tools and the manual updates for Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes, you could use a flash drive too, but flash drives are writeable and infections can spread to them.
    2. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run RogueKiller, Malwarebytes, HitmanPro and MGtools on the infected account as requested in the instructions.
    3. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    * Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated - our system works the oldest threads FIRST.
     
  3. Commodore

    Commodore Private E-2

    Logs are attached.

    I can see my desktop again and can also connect to the internet with no trouble.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Commodore

    Please make sure that you boot into "Normal Startup" so all processes and services will be allowed to run.

    Please re-scan with Hitman Pro and have it delete everything under the headings of
    • Potential Unwanted Programs
    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log

    Please uninstall this:
    Java(TM) 6 Update 17 <--- outdated

    NOTE: You're also using this outdated browser --> Mozilla Firefox 14.0.1 (x86 en-US) - the current version is 18.0.1
    http://www.mozilla.org/en-US/firefox/new-b/?utm_expid=65789850-8&utm_referrer=http%3A%2F%2Fmac.majorgeeks.com%2Ffiles%2Fdetails%2Fmozilla_firefox_aurora_18_0a2.html

    Please download and run the 64Bit version of AVG Remover 2013.2706

    Using Windows Explorer - delete this folder:
    C:\ProgramData\blekko toolbars

    Now update to the latest Sun Java

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • updated HitmanPro log

    Any malware problems remain?
     
  5. Commodore

    Commodore Private E-2

    Java has been updated. AVG Remover was run and blekko toolbars was removed.

    Requested logs are attached.

    So far so good. I'm not noticing anything that shouldn't be happening.

    Thanks for the assistance.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Something else is showing... re-scan with Hitman Pro and have it delete everything under the
    • Potential Unwanted Programs
    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\$AVG
    C:\Users\Dana\AppData\Local\Temp\*.*
     
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "AVG_TRAY"=-
    [HKEY_USERS\S-1-5-21-2410629841-2147075556-1986593145-1001\Software\Microsoft\Windows\CurrentVersion\run]
    "Spotify"=-
    "Spotify Web Helper"=-
    
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow barand choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt%21.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Now update Malwarebytes' definitions and re-run it, fixing anything detected.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • updated HitmanPro log
    • C:\_OTM\MovedFiles
    • updated Malwarebytes' log
     
  7. Commodore

    Commodore Private E-2

    Updated logs attached.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    * If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. It provides no "real-time" protection unless you purchase it and does not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 4 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. If running Vista or Win 7, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and/or deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds