Solved Moneypak Virus, Dept of Justice version, 5 days fighting

Status
Not open for further replies.

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
I ran it and here's the report, but i haven't taken action yet on its suggestions, not sure?
 

Attachments

  • RKreport_SCN_06272014_121333.log
    2.5 KB · Views: 82

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Click on Start --> Run, and then copy this text:

Code:
"C:\Users\Petty home\Desktop\ComboFix(2).exe" /KillAll /StepDel /NoMBR

Press OK, and tell me is ComboFix working now>
 

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
No, here's what happened: first I got this message " error opening file for writing: c:\32788R22FWJFW\ERUNT.3XE" I pressed retry, same, pressed ignore. It went forward but then at that same point where I get the 216 (which I now see is connected to output folder c:\32788R22FWJFW) now I get: "Contents of folder c:\Windows\erdnt\Hiv-backup could not be deleted" and it stops like before.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Is your Antivirus enabled when running ComboFix?


Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
 

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
OK, back from the dentist for something more painful. I turned the antivirus off before running combofix but it might have come back on. Here's the log
 

Attachments

  • FSS.txt
    5.5 KB · Views: 176

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
OK, here's what we're going to do:


Go to recovery mode and from there make fresh FRST report.


Also when in recovery:



Type the following in the edit box after "Search:"

Code:
user32.dll

Click Search File(s) button and post the log (Search.txt) it makes to your reply.
 

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
Search is taking quite a long time, 20 minutes now, is that normal? If so I'll ignore it, just trying not to waste time.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
I think it is normal. Wait 10 minutes more, if it doesn't finish comeback to me with at least one report.
 

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
40 minutes and it didn't stop. Here's the first log.
 

Attachments

  • FRST.txt
    32.6 KB · Views: 89

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
Well frst64 in normal mode finally finished the scan, got through the loaded modules.
 

Attachments

  • FRST.txt
    47.9 KB · Views: 177
  • Addition.txt
    39.8 KB · Views: 417

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Yeah, I think we finally got him :)


Download attached fixlist.txt on the same location as FRST (otherwise the fix won't work)
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Open FRST, and click Fix. Attach me that report after it is finished.



Next try to run ComboFix.
 

Attachments

  • fixlist.txt
    1,023 bytes · Views: 51

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
Attached fixlog. Combofix has made it through installation without any of the previous problems and it is now running, will see how this works out.
 

Attachments

  • Fixlog.txt
    2.3 KB · Views: 88

typicaldani

New Member
Thread author
Verified
Jun 25, 2014
53
I've been just leaving it but this stage has been like 90 minutes so far, the others did go faster
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top