How to get rid of MoneyPak ransomware infection


  1. lko
    Posts : 2
    Windows 7 Home Premium 64 bit
       #1

    How to get rid of MoneyPak ransomware infection


    My husband's user account has been taken over by the FBI-MoneyPak virus and is currently unusable. The other two accounts on the computer are password-protected (his isn't) and seem OK for now. I ran Windows Security Essentials and Malwarebytes scans from my account and they detected nothing. How can I get rid of this thing?
      My Computer


  2. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #2

    Hi Iko,

    Please follow the instructions in this tutorial:

    Windows Defender Offline

    Regards,
    Golden
      My Computer


  3. lko
    Posts : 2
    Windows 7 Home Premium 64 bit
    Thread Starter
       #3

    Thanks, Golden. I also received a suggestion from my IT staff at work to try HitMan Pro. It seems like one of these should do the trick.
      My Computer


  4. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #4

    No worries - let us know if you need more help.

    Regards,
    Golden
      My Computer


  5. Posts : 2
    Windows 7 Home Premiumx64
       #5

    Hi.

    Newbie here, I was infected with the Money Pak ransomware and using Hitman Pro, Malware Bytes, and other stuff I can't remember, I got rid of it EXCEPT when I logon I get a .dll error that it can't find C:\users\Mark\AppData\Local\Temp\0_0u_I.exe I have run Emsisoft, Malware Bytes, CCleaner and SUPERAntivirus but can't get rid of it. Any ideas?

    I appreciate any ideas....I did Google "manual removal" and it references HKEY registry files but I cannot locate them in my registry? Thanks so much!

    Mark
      My Computer


  6. Posts : 2
    Windows 7 x64
       #6

    FBI moneypak ransom


    Hi,

    I'm new here as well and currently struggling with the remnants of this virus.

    Usedtobegood, the key is located in:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

    See this image:



    Credits: Remove FBI MoneyPak Ransomware (Uninstall Guide)

    Mine as gr5_qor_78.exe or something like that. The virus is gone now but my PC is slow as hell. Web browser crashes like five minutes or so. Could you guys tell me how to fix those errors and make my precious PC run faster again?

    Any advice is much appreciated.

    Simon
      My Computer


  7. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #7

    @Usedtobegood - Follow Goldens excellent advice in post #2

    @Black7 - have a look at this link & try running SFC, the virus may have damaged some of your files.

    SFC /SCANNOW Command - System File Checker

    Be sure to run it 3X as SFC doesn't always get everything the first/second time around

    You may have to do a repair install.....

    Repair Install

    And...there's always a chance you still have something on your system. Viruses are known for introducing other viruses.
    Last edited by Borg 386; 07 Jul 2012 at 08:06.
      My Computer


  8. Posts : 2
    Windows 7 Home Premiumx64
       #8

    @Black 7 I do not have a file similar to the one you show above.

    I will try Goldens recommendations and report back.


    Thanks!
    Attached Thumbnails Attached Thumbnails How to get rid of MoneyPak ransomware infection-registry.png  
      My Computer


  9. Posts : 296
    Microsoft Windows 7 Home Premium 32-bit
       #9

    i got this virus myself what i did to stop the pop up of the fake fbi warning was deleted
    C:\Users\bigdog2626\AppData\Local\Temp\glom0_og.exe
    then removed a file from the startup folder called ctfmon.lnk
    now im doing some scanning
    i couldn't locate anything in my reg
    Last edited by bigdog2626; 10 Jul 2012 at 01:22.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 05:13.
Find Us