Some help with FBI moneypak please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by jshapp03, Oct 18, 2012.

  1. jshapp03

    jshapp03 Private E-2

    So my friend is a bit computer illiterate and actually called 911 when got the FBI threat on his screen. He called Best Buy after that and they wanted to charge him $200 to fix it. I thought I'd give him a hand before forking out the money but I'm struggling with it too.

    Its a laptop, I never bothered starting it in normal mode, I went straight to safe mode. I ran an updated spybot s&d from a flash drive. It got rid of a lot of things but I don't believe it got all or maybe even any of the FBI.

    He had mcafee, malware bytes, and avg all installed on his computer already. All of them are acting up giving errors and shutting down when you try updating.

    I'm currently at work, but what suggestions should I try next? Should I post a hijack this log? I'd really rather avoid manually messing with any registry stuff since I'm not a pro, but if you can instruct me I will.

    Thanks for any help!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. jshapp03

    jshapp03 Private E-2

    I'm on step 95 or so. Downloading the programs I didn't have.. Will update when finished. I apologize for not reading this before hand
     
  4. jshapp03

    jshapp03 Private E-2

    Okay making progress.... Can anyone tell me how these logs are looking?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks better. Run CCLeaner and clean out your temp folders. Then re-run Hitman and have it remove everything it finds.

    Uninstall either the Mcafee Security Center or AVG. You also have leftovers from Microsoft Security Essentials.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Find and delete this file:
    c:\\Program Files\\Microsoft Security Essentials

    Tell me what issues you may still have, if any.
     
  6. jshapp03

    jshapp03 Private E-2



    Ok, did all of the above. Sorry, I had forgotten to run CC cleaner. And I felt bad deleting Mcafee because I thought he had an active subscription for it but he didn't so I removed it. The registry file was successful.

    Issues I ran into...
    Hitman asked me to restart the computer after the scan.. Presumably to rescan on startup? Well, when I clicked restart, I walked away for about 15 minutes... When I came back the computer was off. I don't know if it did what it was suppose to.

    Also, you said to delete everything hitman found... I assumed that just meant to do hitmans suggested tasks with everything it found... some of them said quarantine, some said remove, some said do nothing.... so I just let it do what it suggested, hope thats okay? I'll attach the final log that it gave me before I clicked restart.

    Thirdly, the Microsoft security essential file was already gone before I deleted it.. I assume thats okay.

    Finally, for my own learning and future reference... In the tutorial you showed me on how to use these programs, it said not to take action on anything hitman shows you until someone tells you to... It seems like a harmless scan, why should people not follow what it recommends?
     
  7. jshapp03

    jshapp03 Private E-2

    Sorry for double post... Firefox didn't let me upload the new log.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run Hitman and be sure to remove all that Askbar crap. Then be sure to tell me how things are running.
     
  9. jshapp03

    jshapp03 Private E-2

    All virus issues seem to be cured. Thank you so much....

    I don't believe this is a virus issue, but his battery icon always shows at "1% available, plugged in, not charging".. Even when its plugged in. Any ideas?

    And before I give it back to him, do you have any suggestions what simple firewall / antivirus programs to keep installed for him? I currently have the spybot resident, avg free antivirus, and windows firewall. Is windows firewall effective?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You'll have to pursue that in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds