Solved Moneypak Virus, Dept of Justice version, 5 days fighting

Status
Not open for further replies.

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
Sorry with these questions, but every time I try to download combofix from that link I get a webpage that says "Unfortunately the page that you requested does not exist"
 

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
Also, these instructions seem to require internet since I'd have to download things while running the program?
 

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
Thanks. I started combofix and got as far as extracting, then it was making output folder when I got "runtime error 216 at 0004B18B" and hangs
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Very good, I think I found the source of infection :)


Now is important to follow it very carefully:

Download this file:

http://www73.zippyshare.com/v/88841583/file.html

Copy it on you C partition. So location of file should be C:\user32.dll



***** NEXT *****



Download attached fixlist.txt on the same location as FRST (otherwise the fix won't work)
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Open FRST, and click Fix. Attach me that report after it is finished.
 

Attachments

  • fixlist.txt
    2.1 KB · Views: 131

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
Sorry, I should have been mentioning that frst64 gets to "loading modules" and then seems to stop, but since it generates reports I didn't realize it was significant. Now that I know that shouldn't happen, I can say that it happened again and the malware was recreated according to the log. Sorry!
 

Attachments

  • FRST.txt
    47.3 KB · Views: 108
  • Addition.txt
    21 KB · Views: 227

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Download attached fixlist.txt on the same location as FRST (otherwise the fix won't work)
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Open FRST, and click Fix. Attach me that report after it is finished.



***** NEXT *****



Try to run ComboFix straight after FRST has finished.
 

Attachments

  • fixlist.txt
    939 bytes · Views: 70

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
I ran frst64 after combofix crash and without restarting just in case, here are logs
 

Attachments

  • FRST.txt
    46.8 KB · Views: 133
  • Addition.txt
    20.9 KB · Views: 95

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
  • Please download RogueKiller and save to the desktop.
  • Close all windows and browsers
  • Right-click the program and select 'Run as Administrator'
  • Press the Scan button.
  • A report opens on the desktop named - RKreport.txt
  • Please post it in your next reply.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top