Solved Moneypak virus still on XP after using HitmanPro Kickstart and Kaspersky Rescue

Status
Not open for further replies.

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
PC, appears clean, how is the situation now?


Please go to: VirusTotal
  • Click the Choose File button.
  • Please copy/paste the following text into the 'File name:' box:

    Code:
    C:\WINDOWS\system32\User32.dll
  • Click Open then click the Scan it! button just below.
  • This will scan the file. Please be patient.
  • If you get a message saying File already analyzed: click Reanalyse
  • Once scanned, copy and paste the URL from your browser address bar in your next reply.
 
  • Like
Reactions: Oxygen

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
The videos that play are so slow that one can not understand them.

The computer is still slow after the virus. Either the virus has not been 100% removed or it damaged something intentionally or by consequence that needs fixing.

What can be done to diagnose and fix the problem that is causing the videos to play slowly?

Did the 2 reports above tell you anything?

The defraggler has been running for about 24 hours. I may need to stop it, as it looks like it will run for several days, and I used the quick defragment selection.

Thanks
 

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
Thanks for the follow up. I posted my last message before I saw yours.

Do you want me to stop the defragmment process, before using the Virus Total software?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
PC is clean, no active malware. Can you tell me your PC config, ram memmory, processor etc.


I'd like to state that Microsoft no longer supports Windows XP operating system which makes you vulnerable to malicious software. I'd counsel you to upgrade to Windows Vista or above for full protection.
 

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
Where and How do I find this information (PC config, ram memmory, processor etc.)?
 

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
Attached.

Do you have a utility that will test the effectiveness of the hardware (hard drive, drivers, cpu, memory, ram, etc.)?

Thanks.
 

Attachments

  • System Info.pdf
    179.4 KB · Views: 80

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Ask your questions here

http://malwaretips.com/forums/troubleshooting-hardware-questions-and-help.125/

Here we deal only with malware issues.



The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
checkmark.png
Remove disinfection tools
checkmark.png
Create registry backup
checkmark.png
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
Sounds good.

Before i run this. The system restore window came back and I can get to all of the safe modes.

Do I want to to do a system restore, to a point before the virus occured - as I could play videos then? I need the ability to watch the videos.
 

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
TwinHeadedEagle,

We are getting close. With the system restore to June 4th 2014 (the virus hit on Sat June 7, 2014) I can play music videos.

My test video is “Beat It” by the great Michael Jackson.

However, I have new error messages. The new error messages, don’t seem to stop anything. And always pop up once I click on any applications. Once I click OK, the error message seems to go away, without any consequences.

Maybe these error messages are because this older (2006) computer and older software (Windows XP), can not handle all of the updates.

What can be done to eliminate these error messages? (Samples of the errors attached)

Thanks
 

Attachments

  • New Error Messages.pdf
    190 KB · Views: 60
Last edited:

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Your machine is very slow, and sometimes some errors are very difficult to repait. The best thing is to reinstall your windows or to move on newer system.
 

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
Sounds good.

The computer is back to working good. You have completed the hard work.

The only thing left are the error messages that come up when I click an application. Once I click Ok. The error messages goes away. This does not seem complicated to solve, for someone with your knowledge. they are probably coming from one of the fixes that we were using.

I agree, I will buy a new system soon. Right now this is the only one I got.

I posted the error message in the previous posting. All help in solving this one last issue is appreciated.

Thanks.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
 

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
I downloaded FRST. However, I could not pick the download folder. I moved the downloaded FRST.exe from that folder, to the desktop. The FRST.txt text is attached.

I did not see the Addition.txt on the either the desktop, or in the original folder the applications was downloaded in to.

Thanks
 

Attachments

  • FRST.txt
    42.2 KB · Views: 119

SSS

New Member
Thread author
Verified
Jun 10, 2014
29
This time, I clicked on the check boxes for Addition.txt and Shortcut.txt. Those 2 and the FRST report are attached.

Also, it looks like the error message keeps referencing "this application" or the abbreviations which I think represent the Optimizer Pro software.

As you know, Optimizer Pro is a software to clean up the registry and computer to make the computer run faster.

Thanks
 

Attachments

  • Addition.txt
    38.5 KB · Views: 74
  • Shortcut.txt
    456.3 KB · Views: 2,656
  • FRST.txt
    42.1 KB · Views: 66
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top