Overclock.net › Forums › Software, Programming and Coding › Networking & Security › FBI Money Pak Virus - How to remove?
New Posts  All Forums:Forum Nav:

FBI Money Pak Virus - How to remove?

post #1 of 21
Thread Starter 
My friend kindly asked me to remove a virus, and I told him no problem... but I had no luck!

I opened his computer, booted into safe mode with networking (which might be my problem, I should've done it in regular safe mode) and tried to use malwarebytes and then restarted in the same mode to use spybot search&destroy. No luck, and I was hoping there was a fix to this where I wouldn't need to System Restore or Reformat.

Thanks in advance!
ProRev
(14 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7-3770K [Ivy Bridge] MSI Z77 M Power NVidia Gigabyte GTX 660 [BIOS flashed] Corsair Dominator 2x4GB DDR3 
Hard DriveHard DriveHard DriveOS
Intel X25-V 40GB Intel X25-V 40GB Samsung EVO 840 500GB Microsoft Windows 7 Ultimate [64-bit] 
MonitorKeyboardPowerCase
Asus VG248QE [24" 144Hz @ 1920x1080] KBT Race [Cherry MX-Blue] SeaSonic X-750  Cooler Master HAF 932 [No Side-panels] 
MouseMouse Pad
Logitech MX518 BestBuy Rocketfish  
  hide details  
Reply
ProRev
(14 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7-3770K [Ivy Bridge] MSI Z77 M Power NVidia Gigabyte GTX 660 [BIOS flashed] Corsair Dominator 2x4GB DDR3 
Hard DriveHard DriveHard DriveOS
Intel X25-V 40GB Intel X25-V 40GB Samsung EVO 840 500GB Microsoft Windows 7 Ultimate [64-bit] 
MonitorKeyboardPowerCase
Asus VG248QE [24" 144Hz @ 1920x1080] KBT Race [Cherry MX-Blue] SeaSonic X-750  Cooler Master HAF 932 [No Side-panels] 
MouseMouse Pad
Logitech MX518 BestBuy Rocketfish  
  hide details  
Reply
post #2 of 21
Read this....http://guides.yoosecurity.com/how-remove-fbi-moneypak-virus-malware-that-blocked-pc-asks-for-payment-100-dollars/

You began right by safe mode with networking.Then Alt,ctrl,del to bring up the task manager.The virus is listed as acrord32.exe,at least it is in the link.

My guess is to look for all of the suspicious entries and remove them.I have used avg free anti virus until it let one through,now I use avast.

I also, have read the virus does disable antimalware and anti virus programs.

I think it will be easier to do a system restore.Good luck.
Edited by Fishinfan - 8/22/12 at 7:58pm
Back in Black
(18 items)
 
  
CPUMotherboardGraphicsRAM
AMD FX-4350 Vishera 4.8 ghz. ASUS M5A99FX PRO R2.0  MSI R7950 Twin Frozr 3GD5/OC Radeon HD 7950 CORSAIR Vengeance 8GB DDR3 2133  
Hard DriveHard DriveHard DriveHard Drive
Samsung 840 pro 128gb[boot] Seagate 250 gb [games] Hitachi 500 gb [media] Seagate 160 gb [steam] 
Hard DriveOptical DriveCoolingOS
Crucial M4 64gb [apps/win xp] Lg Corsair Hydro H110 W7 64bit/Win Xp 32bit 
MonitorKeyboardPowerCase
Dell s2440L compaq Corsair Hx750 Corsair Vengence C70 
Mouse
logitech 
  hide details  
Reply
Back in Black
(18 items)
 
  
CPUMotherboardGraphicsRAM
AMD FX-4350 Vishera 4.8 ghz. ASUS M5A99FX PRO R2.0  MSI R7950 Twin Frozr 3GD5/OC Radeon HD 7950 CORSAIR Vengeance 8GB DDR3 2133  
Hard DriveHard DriveHard DriveHard Drive
Samsung 840 pro 128gb[boot] Seagate 250 gb [games] Hitachi 500 gb [media] Seagate 160 gb [steam] 
Hard DriveOptical DriveCoolingOS
Crucial M4 64gb [apps/win xp] Lg Corsair Hydro H110 W7 64bit/Win Xp 32bit 
MonitorKeyboardPowerCase
Dell s2440L compaq Corsair Hx750 Corsair Vengence C70 
Mouse
logitech 
  hide details  
Reply
post #3 of 21
Usually need to go outside Windows with a bootable AV environment to tag this particular infection, it can be a bit rough.

ESET, Kaspersky or MSSS should be able to remove it from outside Windows without much issue. This infection does, however, have a decent chance of damaging system files and thus requiring a repair or, at worst, a reinstall.
    
CPUMotherboardGraphicsRAM
Core i7 970 @ 4.0 GHz 1.22 Vcore Asus Rampage II Gene GTX 260 216SP G.SKILL PI 3x2gb DDR3 1600 @ 7-8-7-24 
Hard DriveOSMonitorPower
2x 500gb Seagates RAID 0, 1x 500gb non-RAID Windows 7 Professional x64 ASUS 24'' VH242H / Spectre 24'' WS Corsair 750TX 
Case
Corsair 300R 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
Core i7 970 @ 4.0 GHz 1.22 Vcore Asus Rampage II Gene GTX 260 216SP G.SKILL PI 3x2gb DDR3 1600 @ 7-8-7-24 
Hard DriveOSMonitorPower
2x 500gb Seagates RAID 0, 1x 500gb non-RAID Windows 7 Professional x64 ASUS 24'' VH242H / Spectre 24'' WS Corsair 750TX 
Case
Corsair 300R 
  hide details  
Reply
post #4 of 21
http://botcrawl.com/how-to-remove-the-fbi-moneypak-ransomware-virus-fake-fbi-malware-removal/

Scroll to bullet #2 "manual removal".

Cannot confirm if this works as I have not seen that virus. Hope it helps.
Lilith VIII
(13 items)
 
  
CPUMotherboardGraphicsGraphics
Intel Core i5 2500K Maximus IV GENE-Z WindForce 7950 @ 1.2GHz EVGA GTX 470 *Hybrid PhysX* 
RAMHard DriveCoolingOS
16GB, 1600MHz Ripjaws X (4x4GB) 1TB + 1TB + 250GB + 160GB + 160GB CM Hyper 212 Plus Windows 8 Professional 
MonitorKeyboardPowerCase
23' + 21.5' Logitech Classic Keyboard 200 OCZ 700w ModXStream Pro CM Storm Trooper 
Mouse
Microsoft Wireless Mouse 3000 
  hide details  
Reply
Lilith VIII
(13 items)
 
  
CPUMotherboardGraphicsGraphics
Intel Core i5 2500K Maximus IV GENE-Z WindForce 7950 @ 1.2GHz EVGA GTX 470 *Hybrid PhysX* 
RAMHard DriveCoolingOS
16GB, 1600MHz Ripjaws X (4x4GB) 1TB + 1TB + 250GB + 160GB + 160GB CM Hyper 212 Plus Windows 8 Professional 
MonitorKeyboardPowerCase
23' + 21.5' Logitech Classic Keyboard 200 OCZ 700w ModXStream Pro CM Storm Trooper 
Mouse
Microsoft Wireless Mouse 3000 
  hide details  
Reply
post #5 of 21
Thread Starter 
I'll give it a shot and report back with +reputation.
ProRev
(14 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7-3770K [Ivy Bridge] MSI Z77 M Power NVidia Gigabyte GTX 660 [BIOS flashed] Corsair Dominator 2x4GB DDR3 
Hard DriveHard DriveHard DriveOS
Intel X25-V 40GB Intel X25-V 40GB Samsung EVO 840 500GB Microsoft Windows 7 Ultimate [64-bit] 
MonitorKeyboardPowerCase
Asus VG248QE [24" 144Hz @ 1920x1080] KBT Race [Cherry MX-Blue] SeaSonic X-750  Cooler Master HAF 932 [No Side-panels] 
MouseMouse Pad
Logitech MX518 BestBuy Rocketfish  
  hide details  
Reply
ProRev
(14 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7-3770K [Ivy Bridge] MSI Z77 M Power NVidia Gigabyte GTX 660 [BIOS flashed] Corsair Dominator 2x4GB DDR3 
Hard DriveHard DriveHard DriveOS
Intel X25-V 40GB Intel X25-V 40GB Samsung EVO 840 500GB Microsoft Windows 7 Ultimate [64-bit] 
MonitorKeyboardPowerCase
Asus VG248QE [24" 144Hz @ 1920x1080] KBT Race [Cherry MX-Blue] SeaSonic X-750  Cooler Master HAF 932 [No Side-panels] 
MouseMouse Pad
Logitech MX518 BestBuy Rocketfish  
  hide details  
Reply
post #6 of 21
If it's that amount of trouble I would suggest i total reinstall.I hope your friend doesn't have a lot of valuable saved stuff on his computer.
Back in Black
(18 items)
 
  
CPUMotherboardGraphicsRAM
AMD FX-4350 Vishera 4.8 ghz. ASUS M5A99FX PRO R2.0  MSI R7950 Twin Frozr 3GD5/OC Radeon HD 7950 CORSAIR Vengeance 8GB DDR3 2133  
Hard DriveHard DriveHard DriveHard Drive
Samsung 840 pro 128gb[boot] Seagate 250 gb [games] Hitachi 500 gb [media] Seagate 160 gb [steam] 
Hard DriveOptical DriveCoolingOS
Crucial M4 64gb [apps/win xp] Lg Corsair Hydro H110 W7 64bit/Win Xp 32bit 
MonitorKeyboardPowerCase
Dell s2440L compaq Corsair Hx750 Corsair Vengence C70 
Mouse
logitech 
  hide details  
Reply
Back in Black
(18 items)
 
  
CPUMotherboardGraphicsRAM
AMD FX-4350 Vishera 4.8 ghz. ASUS M5A99FX PRO R2.0  MSI R7950 Twin Frozr 3GD5/OC Radeon HD 7950 CORSAIR Vengeance 8GB DDR3 2133  
Hard DriveHard DriveHard DriveHard Drive
Samsung 840 pro 128gb[boot] Seagate 250 gb [games] Hitachi 500 gb [media] Seagate 160 gb [steam] 
Hard DriveOptical DriveCoolingOS
Crucial M4 64gb [apps/win xp] Lg Corsair Hydro H110 W7 64bit/Win Xp 32bit 
MonitorKeyboardPowerCase
Dell s2440L compaq Corsair Hx750 Corsair Vengence C70 
Mouse
logitech 
  hide details  
Reply
post #7 of 21
Thread Starter 
I appreciate everyone's post, thank you for your help
ProRev
(14 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7-3770K [Ivy Bridge] MSI Z77 M Power NVidia Gigabyte GTX 660 [BIOS flashed] Corsair Dominator 2x4GB DDR3 
Hard DriveHard DriveHard DriveOS
Intel X25-V 40GB Intel X25-V 40GB Samsung EVO 840 500GB Microsoft Windows 7 Ultimate [64-bit] 
MonitorKeyboardPowerCase
Asus VG248QE [24" 144Hz @ 1920x1080] KBT Race [Cherry MX-Blue] SeaSonic X-750  Cooler Master HAF 932 [No Side-panels] 
MouseMouse Pad
Logitech MX518 BestBuy Rocketfish  
  hide details  
Reply
ProRev
(14 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7-3770K [Ivy Bridge] MSI Z77 M Power NVidia Gigabyte GTX 660 [BIOS flashed] Corsair Dominator 2x4GB DDR3 
Hard DriveHard DriveHard DriveOS
Intel X25-V 40GB Intel X25-V 40GB Samsung EVO 840 500GB Microsoft Windows 7 Ultimate [64-bit] 
MonitorKeyboardPowerCase
Asus VG248QE [24" 144Hz @ 1920x1080] KBT Race [Cherry MX-Blue] SeaSonic X-750  Cooler Master HAF 932 [No Side-panels] 
MouseMouse Pad
Logitech MX518 BestBuy Rocketfish  
  hide details  
Reply
post #8 of 21
Avast has a boot time scan, Kaspersky can make a bootable scan disk, as others I'm sure have similar. I generally recommend to people with tough situations to download the Kaspsky free trial and do their boot disc thingy. seems like youre on the path to a solution, though. keep us posted. curious how it works out.
    
CPUMotherboardGraphicsRAM
3570k@4.5ghz 1.21v Gigabyte Sniper M3 Sapphire 6950 Samsung 8g1866 
Hard DriveHard DriveHard DriveCooling
Samsung 830 Samsung F1 500 Crucial M4 64 (SRC) cpu:Noc NF-F12 / case:4x TY-141/gpu: 2x NB-Multi 
CoolingOSMonitorKeyboard
Venomous X, Accelero TT Win 7 64 Acer X213H Saitek Eclipse 
PowerCaseMouse
Superflower 650 plat Fractal Arc Midi G500 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
3570k@4.5ghz 1.21v Gigabyte Sniper M3 Sapphire 6950 Samsung 8g1866 
Hard DriveHard DriveHard DriveCooling
Samsung 830 Samsung F1 500 Crucial M4 64 (SRC) cpu:Noc NF-F12 / case:4x TY-141/gpu: 2x NB-Multi 
CoolingOSMonitorKeyboard
Venomous X, Accelero TT Win 7 64 Acer X213H Saitek Eclipse 
PowerCaseMouse
Superflower 650 plat Fractal Arc Midi G500 
  hide details  
Reply
post #9 of 21
Quote:
Originally Posted by Fishinfan View Post

If it's that amount of trouble I would suggest i total reinstall.I hope your friend doesn't have a lot of valuable saved stuff on his computer.

Yes, I never trust a Windows PC after infection, back up and re-image.
post #10 of 21
Thread Starter 
Gentleman, while I was trying to watch some sexy time videos... I too got a similar virus, the Platinum security.

So I used Rkill, ccleaner, and Spybot S&D to remove it... Took a LOT of attempts, and I'm not sure how I finally got it to work, but it did.

I am going to just rinse and repeat what I kept trying with my friend, and see if it works....

Sorry, I know I've had the option of making these boot disks... I'm just not experienced, and need to do the research (I'm sure it's not that hard).
ProRev
(14 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7-3770K [Ivy Bridge] MSI Z77 M Power NVidia Gigabyte GTX 660 [BIOS flashed] Corsair Dominator 2x4GB DDR3 
Hard DriveHard DriveHard DriveOS
Intel X25-V 40GB Intel X25-V 40GB Samsung EVO 840 500GB Microsoft Windows 7 Ultimate [64-bit] 
MonitorKeyboardPowerCase
Asus VG248QE [24" 144Hz @ 1920x1080] KBT Race [Cherry MX-Blue] SeaSonic X-750  Cooler Master HAF 932 [No Side-panels] 
MouseMouse Pad
Logitech MX518 BestBuy Rocketfish  
  hide details  
Reply
ProRev
(14 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7-3770K [Ivy Bridge] MSI Z77 M Power NVidia Gigabyte GTX 660 [BIOS flashed] Corsair Dominator 2x4GB DDR3 
Hard DriveHard DriveHard DriveOS
Intel X25-V 40GB Intel X25-V 40GB Samsung EVO 840 500GB Microsoft Windows 7 Ultimate [64-bit] 
MonitorKeyboardPowerCase
Asus VG248QE [24" 144Hz @ 1920x1080] KBT Race [Cherry MX-Blue] SeaSonic X-750  Cooler Master HAF 932 [No Side-panels] 
MouseMouse Pad
Logitech MX518 BestBuy Rocketfish  
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Networking & Security
Overclock.net › Forums › Software, Programming and Coding › Networking & Security › FBI Money Pak Virus - How to remove?