LordAMV
-
Posts
8 -
Joined
-
Last visited
Content Type
Events
Profiles
Forums
Posts posted by LordAMV
-
-
LDTate - I am having trouble figuring out what you're asking me to do here. All of the steps you asked me to take in your response are assuming I can run ComboFix out of my USB device but I can't start the computer using that USB device because it isn't an operating system. Maybe there is something I am missing here but right now I am not able to take any of those steps you recommended since I can't do any of those things on my infected computer.
-
I am confused here - the link you gave me is an installer file. When I try to run the installer it just runs Combofix and I don't see where or what directory Combofix is installed to...I have no control over that. How can I run it on the infected computer?
Do I just run the installer?
-
Yes I am on a different computer right now, sitting next to the infected computer. I am not sure how I will be able to do what you suggested since I can't run programs even in Safe Mode. Right now the only thing I am doing is running Windows Defender from my USB device. Am I able to run ComboFix the same way?
By the same way I mean - I am running it through going to Boot Setup (F12) during start up. Then I choose to run from the USB device. I assume I would need a different USB device that has ComboFix on it separate from the device with Windows Defender.
-
Are you on a different pc to post here?
Yes I am on a different computer right now, sitting next to the infected computer. I am not sure how I will be able to do what you suggested since I can't run programs even in Safe Mode. Right now the only thing I am doing is running Windows Defender from my USB device. Am I able to run ComboFix the same way?
-

Try this in Safe Mode
Please do the following to see if it resolves the issue: Post back and let us know please
Go to C:\Program Files\Malwarebytes' Anti-Malware\Chameleon
Double Click Chameleon to open the file.
Try clicking Test until one of them works.
MBAM will open and run a quick scan.
As I stated in the original post, unfortunately I am not able to do that. Even Safe Mode does not work because when I start Safe Mode, it gives me the FBI screen. I can't run any programs in safe mode or go to the directory you suggested.
-
Ok so today at some point during my browsing, I encountered FBI MoneyPak. I have encountered it before and usually I just go into Safe Mode and run Malwarebytes. But this version is very nasty - it isn't letting me enter Safe Mode. Any time I enter Safe Mode (with and without networking) it still gives me the FBI screen and won't let me do anything.
I can't even run Malwarebytes or anything else at all right now. My computer is effectively useless. I have tried running Windows Defender as I read somewhere else that it is the only way to deal with a situation like this. I ran it and the scan only went half way through. It detected a version of Sirefef which I deleted. But the scan didn't complete. I tried to restart in safe mode and the problem is still there.
Can anyone help me?
-
Ok so today at some point during my browsing, I encountered FBI MoneyPak. I have encountered it before and usually I just go into Safe Mode and run Malwarebytes. But this version is very nasty - it isn't letting me enter Safe Mode. Any time I enter Safe Mode (with and without networking) it still gives me the FBI screen and won't let me do anything.
I can't even run Malwarebytes or anything else at all right now. My computer is effectively useless. I have tried running Windows Defender as I read somewhere else that it is the only way to deal with a situation like this. I ran it and the scan only went half way through. It detected a version of Sirefef which I deleted. But the scan didn't complete. I tried to restart in safe mode and the problem is still there.
Can anyone help me?
Nasty version of FBI MoneyPak ransomware
in Resolved Malware Removal Logs
Posted
Ok so it looks like I may have done something that worked. I used a System Restore to earlier and even though initially it said it wasn't successful, when I restarted and entered Safe Mode it worked. I immediately ran Malwarebytes quick scan and it detected a single file - Trojan.Ransom which I was able to remove. It seems like my system is back to normal at the moment. Do you think I should do anything else?