Question about FBI MoneyPak

Norby

New member
Local time
3:29 AM
Messages
3
Hi,
I've been reading so much about the FBI MoneyPak virus contaminating computers. You would think that with all the techs out there someone could find a way to block it. Can anyone explain why this malware is so hard to block from entering a computer.
 

My Computer My Computer

At a glance

windows 7
OS
windows 7
Hello Norby and welcome to Seven Forums.

The FBI MonkeyPak Ransomware is a computer infection that locks you out of your computer and your applications until you pay a ransom of $100 in the form of a MoneyPak. This infection is typically installed onto a computer when the user visits a hacked web site that contains malicious scripts that exploit vulnerabilities on the computer to install the FBI Ransomware without their knowledge or permission. It is for these reasons that it is imperative that all computer users make sure their installed programs, including Windows, are up-to-date with the latest patches.

Remove the FBI MoneyPak Ransomware or the Reveton Trojan

So the biggest problem is when people fail to install the latest patches, hotfixes, etc on all their installed programs, not just Windows. No anti-malware program is going to be 100% effective 100% of the time (if there was such a thing we'd all be using it.) If someone is running an outdated Java, Adobe Flash, Adobe or Foxit Reader, etc they are contributing to their own infection. By the time an anti-malware program might detect that the user has accessed a hacked web site containing the malicious scripts, the damage has already been done.
 

My Computer My Computer

At a glance

Win 7 Pro 64-bitIntel i5 2.4 Ghz8GB DDR3Intel HD 3000
Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Here is another little possibility. Using Torrents. When downloading using such programs the things you download come in little pieces for different computers all over the world. The infection comes in little pieces (without a complete signature) and sneaks by the security. Once in the system it is put back together and presto your infected.
The infection looks like this to a security program
xoxoxox and when a security programs sees that it stops it. When it is sent xo and from another computer is sent xo ect. the security program lets the xo in your system where the get put back together as xoxoxol and presto you are infected. Also many users of Torrents set their computer for smooth downloading and bypass their firewall and security programs and many don't even know they have done so. Many people don't do the basics and expect their security programs to do everything.
They open what ever email they receive. They don't scan programs when downloaded, they just install them. The list goes on and on. Here is a Microsoft site to get started on learning about being more secure.
Their are many this is just one.
Resources | Microsoft Safety & Security Center
 

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
A "Drive-by" through a website where malware is planted is a way of getting infected. The download happens without a person's knowledge...
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
There is another issue.
Although all FBI Moneypak shares about the same text and design, it is completely different parasites in many cases.
There are like 10 families of it, where several are more dominant. So, there is lots of work to detect such parasites in time.
 

My Computer My Computer

At a glance

Windows 7 64 / Windows 8 64
OS
Windows 7 64 / Windows 8 64
P'O'd I just got this virus last night.
FWIW they are now asking for $300.00 and it disables the safe mode option.
I am uncertain if I will be able to even get a command prompt, and don't really have the "voodoo" to use commands. I may just replace the OS completely by putting a New Drive in and reinstalling the OS from a restore drive.
If I'm not command prompt savy what are my other options?
 

My Computer My Computer

At a glance

Wondows 7
Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Wondows 7
Might be a good idea to use Firefox with NoScript add on in future.

A bootable antimalware of some kind may be the answer.

There are several available for free download:
 

My Computers My Computers

  • At a glance

    7 X64i5 84002x8gb 3200mhz
    Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • At a glance

    7x64g54008gb ddr4 2400
    Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w

My Computers My Computers

  • At a glance

    7 X64i5 84002x8gb 3200mhz
    Computer type
    PC/Desktop
    OS
    7 X64
    CPU
    i5 8400
    Motherboard
    gigabyte b365m ds3h
    Memory
    2x8gb 3200mhz
    Hard Drives
    various
    PSU
    pure power 11 400w cm
    Case
    Coolermaster
    Cooling
    cryorig m9i
  • At a glance

    7x64g54008gb ddr4 2400
    Computer type
    PC/Desktop
    OS
    7x64
    CPU
    g5400
    Motherboard
    ga b365m ds3h
    Memory
    8gb ddr4 2400
    PSU
    xfx pro 450w
I found this
"Processes
%WINDIR%\system32\0_0u_l.exe
%APPDATA%\jork_0_typ_col.exe
%TEMP%\0_0u_l.exe
%Temp%\[RANDOM].exe
tpl_0_c.exe
%StartupFolder%\ch810.exe
DLLs
%StartupFolder%\wpbt0.dll
Other Files
%StartupFolder%\ctfmon.lnk
WARNING.txt
V.class
Registry Keys
%AppData%\vsdsrv32.exe
cconf.txt.enc"

but am uncertain if I know how to get to the directories in command prompt
 

My Computer My Computer

At a glance

Wondows 7
Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Wondows 7
Don't attempt manual removal - use the links SiW provided
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I fixed this on my computer by booting from the Windows CD and choosing Repair and restoring to an earlier time. Choosing any safe mode would just cause the computer to reboot. I had an error the restore didn't work but upon reboot it infact did work. I then used other programs to delete any leftover files. There were alot in the Temp file.

I was on google looking at pictures of Toyota Tacoma's and I got this (I think it had to do with Java so I no longer have it installed).
 

My Computer My Computer

At a glance

Windows 7 Professional 64bitIntel i7-5960X64GB Corsair Dominator 2400MHz3 EVGA GTX980's
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Professional 64bit
CPU
Intel i7-5960X
Motherboard
EVGA X99 Classified
Memory
64GB Corsair Dominator 2400MHz
Graphics Card(s)
3 EVGA GTX980's
Sound Card
on board
Monitor(s) Displays
3 Dell E2715H 27"
Screen Resolution
1920x1080 (5760x1080)
Hard Drives
Samsung 950 Pro 1TB M.2 SSD,
Western Digital Black 2TB HDD's x5
Western Digital Black 1TB HDD's x3
PSU
Corsair AX1200i
Case
Corsair 750D
Cooling
Corsair H110i GT
Keyboard
Corsair K70
Mouse
Corsair M45
Internet Speed
250 down/10 up
Antivirus
Microsoft Security Essentials
Browser
IE 11, Google Chrome
After great wailing and gnashing of teeth I managed to get my guest profile changed to an admin profile. then went to another pc and downloaded malware of different types. not sure which one got it but I'm now on my pc and it is seeming to be ok. I will take it to a friend who has more voodoo than I do and have him ops check everything
Malware Bytes
Hitman and
Spybot
between the three I seem to have cleaned up the problem
 

My Computer My Computer

At a glance

Wondows 7
Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Wondows 7

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Back
Top