Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
FBI Moneypack - Missing files in System32 folder!
Message
<blockquote data-quote="raccarva" data-source="post: 120611" data-attributes="member: 8234"><p>Hi,</p><p></p><p>I've got the nasty FBI Virus and the situation is:</p><p></p><p>- Can't access the internet;</p><p>- Can't boot Windows in Safe mode. It goes immediately to shutdown after booting;</p><p>- I could go to command prompt under "System Recovery Options" and can run 64 bit programs. Could not run OTL.exe.</p><p>- It looks like many files in the system32 folder are gone.</p><p></p><p>Can you give me any advice? I've run FRST64 and the log generated is below:</p><p></p><p>Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-05-2013</p><p>Ran by SYSTEM on 14-05-2013 11:05:57</p><p>Running from F:\</p><p>WIN_7 (X64) OS Language: English(US)</p><p>Boot Mode: RecoveryAttention: Could not load system hive.</p><p>Attention: System hive is missing.</p><p></p><p>==================== Registry (Whitelisted) ==================</p><p></p><p>Attention: Software hive is missing.</p><p></p><p>ATTENTION: Software hive is not loaded.</p><p></p><p>BootExecute: </p><p></p><p>==================== Services (Whitelisted) =================</p><p></p><p></p><p>==================== Drivers (Whitelisted) ====================</p><p></p><p></p><p>==================== NetSvcs (Whitelisted) ===================</p><p></p><p></p><p>==================== One Month Created Files and Folders ========</p><p></p><p></p><p>==================== One Month Modified Files and Folders =======</p><p></p><p></p><p>==================== Known DLLs (Whitelisted) ================</p><p></p><p></p><p>==================== Bamital & volsnap Check =================</p><p></p><p>C:\Windows\System32\winlogon.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\explorer.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\SysWOW64\explorer.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\svchost.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\SysWOW64\svchost.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\services.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\User32.dll IS MISSING <==== ATTENTION!.</p><p>C:\Windows\SysWOW64\User32.dll IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\userinit.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\SysWOW64\userinit.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\Drivers\volsnap.sys IS MISSING <==== ATTENTION!.</p><p>C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\winsrv.dll IS MISSING <==== ATTENTION!.</p><p></p><p>==================== EXE ASSOCIATION =====================</p><p></p><p>HKLM\...\.exe: <===== ATTENTION!</p><p>HKLM\...\exefile\DefaultIcon: <===== ATTENTION!</p><p>HKLM\...\exefile\open\command: <===== ATTENTION!</p><p></p><p>==================== Restore Points =========================</p><p></p><p></p><p>==================== Memory info =========================== </p><p></p><p>Percentage of memory in use: 8%</p><p>Total physical RAM: 8142.33 MB</p><p>Available physical RAM: 7444.71 MB</p><p>Total Pagefile: 8140.48 MB</p><p>Available Pagefile: 7426.62 MB</p><p>Total Virtual: 8192 MB</p><p>Available Virtual: 8191.89 MB</p><p></p><p>==================== Drives ================================</p><p></p><p>Drive f: (HITMANPRO) (Removable) (Total:7.48 GB) (Free:7.44 GB) FAT32 (Disk=1 Partition=1)</p><p>Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS</p><p>Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)]</p><p></p><p>==================== MBR & Partition Table ==================</p><p></p><p>========================================================</p><p>Disk: 0 (Size: 466 GB) (Disk ID: A0753CB5)</p><p>Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)</p><p>Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)</p><p></p><p>========================================================</p><p>Disk: 1 (Size: 7 GB) (Disk ID: 0BEDF1BC)</p><p>Partition 1: (Active) - (Size=7 GB) - (Type=0B)</p><p></p><p>==================== End Of Log ============================</p><p></p><p>Regards.</p></blockquote><p></p>
[QUOTE="raccarva, post: 120611, member: 8234"] Hi, I've got the nasty FBI Virus and the situation is: - Can't access the internet; - Can't boot Windows in Safe mode. It goes immediately to shutdown after booting; - I could go to command prompt under "System Recovery Options" and can run 64 bit programs. Could not run OTL.exe. - It looks like many files in the system32 folder are gone. Can you give me any advice? I've run FRST64 and the log generated is below: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-05-2013 Ran by SYSTEM on 14-05-2013 11:05:57 Running from F:\ WIN_7 (X64) OS Language: English(US) Boot Mode: RecoveryAttention: Could not load system hive. Attention: System hive is missing. ==================== Registry (Whitelisted) ================== Attention: Software hive is missing. ATTENTION: Software hive is not loaded. BootExecute: ==================== Services (Whitelisted) ================= ==================== Drivers (Whitelisted) ==================== ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== ==================== One Month Modified Files and Folders ======= ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\wininit.exe IS MISSING <==== ATTENTION!. C:\Windows\SysWOW64\wininit.exe IS MISSING <==== ATTENTION!. C:\Windows\explorer.exe IS MISSING <==== ATTENTION!. C:\Windows\SysWOW64\explorer.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\svchost.exe IS MISSING <==== ATTENTION!. C:\Windows\SysWOW64\svchost.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\services.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\User32.dll IS MISSING <==== ATTENTION!. C:\Windows\SysWOW64\User32.dll IS MISSING <==== ATTENTION!. C:\Windows\System32\userinit.exe IS MISSING <==== ATTENTION!. C:\Windows\SysWOW64\userinit.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\Drivers\volsnap.sys IS MISSING <==== ATTENTION!. C:\Windows\system32\codeintegrity\Bootcat.cache IS MISSING <==== ATTENTION!. C:\Windows\System32\winsrv.dll IS MISSING <==== ATTENTION!. ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: <===== ATTENTION! HKLM\...\exefile\DefaultIcon: <===== ATTENTION! HKLM\...\exefile\open\command: <===== ATTENTION! ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 8% Total physical RAM: 8142.33 MB Available physical RAM: 7444.71 MB Total Pagefile: 8140.48 MB Available Pagefile: 7426.62 MB Total Virtual: 8192 MB Available Virtual: 8191.89 MB ==================== Drives ================================ Drive f: (HITMANPRO) (Removable) (Total:7.48 GB) (Free:7.44 GB) FAT32 (Disk=1 Partition=1) Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: A0753CB5) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 7 GB) (Disk ID: 0BEDF1BC) Partition 1: (Active) - (Size=7 GB) - (Type=0B) ==================== End Of Log ============================ Regards. [/QUOTE]
Insert quotes…
Verification
Post reply
Top