Solved Department of Justice Moneypak Virus

Matt232222

New Member
Thread author
Jun 26, 2014
9
Apologies for the 3 identical postings...when I submitted "Create Post", the webpage never confirmed the posting...it just kept "idled" and I had assumed the posting did not go through. Thank you!
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Please download Farbar Recovery Scan Tool and save it to a flash drive.
  • Plug the flashdrive into the infected PC.
  • Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer
  • Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.
In the next menu, use the arrow keys on the keyboard to highlight Command Prompt and press Enter.
  • In the command window type in notepad and press Enter.
  • When notepad opens, click File and select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe and press Enter.
Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run. When the tool opens click Yes to disclaimer.
  • Press Scan button.

It will make a log (FRST.txt) on the flash drive. Please attach it to your reply.
 

Matt232222

New Member
Thread author
Jun 26, 2014
9
Thanks...super good instructions! Here is the txt file that was produced.
 

Attachments

  • FRST.txt
    2.9 KB · Views: 75

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST report wasn't created properly.

When you boot to Command Prompt in Recovery Environment, type this command

Chkdsk C: /r

Then when it is over, reboot, and then repeat FRST scan again and attach fresh report.
 

Matt232222

New Member
Thread author
Jun 26, 2014
9
Thanks. When I enter that command, I get the below italicized message. I still attached the FRST report it created, although it appears basically identical.

The type of the file system is NTFS.
Unable to determine volume version and state. CHKDSK aborted.
Failed to transfer logged messages to the event log with status 50.
 

Attachments

  • FRST.txt
    3.2 KB · Views: 87

Matt232222

New Member
Thread author
Jun 26, 2014
9
I also ran Listparts.exe and have attached the report if that is helpful.
 

Attachments

  • Result.txt
    2.8 KB · Views: 62

Matt232222

New Member
Thread author
Jun 26, 2014
9
Yes, I can boot Windows normally. However, the Department of Justice Moneypak screen loads up immediately when I sign on.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST won't show proper report in recovery, because you have strange file system, called RAW. Do you know something about this?
 

Matt232222

New Member
Thread author
Jun 26, 2014
9
From what I can find, RAW refer to a disk partition that has not been formatted with an NT file system, neither FAT nor NTFS. Before now I did not know my system used RAW...I'm a bit surprised. FYI, my computer is a Dell Latitude laptop that uses Windows 7 Enterprise.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
The only way out will be to re-format the partition, but all data will be lost. There is no way to convert a RAW volume to a NTFS file system without loosing the data as the volume will need to be reformatted.
 

Matt232222

New Member
Thread author
Jun 26, 2014
9
I see, understood. Not the answer I was hoping for, but that's life I suppose! Thanks so much for your help...it is much appreciated!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top