BullGuard
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Advanced version of moneypak virus, need some high-level help please
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Advanced version of moneypak virus, need some high-level help please  
Forum Quick Jump
 
New Topic Post reply to : Advanced version of moneypak virus, need some high-level help please Printable version of : Advanced version of moneypak virus, need some high-level help please
[ << Previous Thread | Next Thread >> ]

joe3321
New Member


Date Joined Jan 2013
Total Posts : 1
 
   Posted 1/28/2013 7:09 AM (GMT +3)    Quote: Advanced version of moneypak virus, need some high-level help pleaseAlert an admin about: Advanced version of moneypak virus, need some high-level help please
Hi, i contracted the moneypak virus while surfing the web. I've seen this virus before and was able to remove it from a friends laptop with some avira anti-virus software, but this one i just got on my desktop is much more difficult.
 
Ok so to launch in -- I'm using a custom built desktop with windows XP operating system. Originally this virus attached itself to explorer.exe and if not terminated via task manager it would sieze my system (in both normal and safe mode), this took approximately 5 seconds and was difficult to thwart. I looked online on how to get rid of the virus unfortunately all the remedies have been comprimised: cant get online help (blocked), cant install antivirus software (its got something hogging memory that wont allow various anti-virus software to be launched each with thier own unique error), i cant do a system restore (says it cant be performed safely, restart system), and cant launch the antivirus software from flashdrive.
 
I've tried closing down all my task manager process trees but i think the virus stuck itself in something that cant be closed like system_idle.exe. anyways im really stumped as to what to try next, i've got very limited functionality in both normal and safe mode (can use like windows explorer and search functions, but its as if theres some kind of intentional logic loop tieing up tons of system resources).
 
Would love an experienced helping hand. Thanks.
Back to Top
 

Andreea-Luciana Ostache
Forum Moderator




Date Joined Aug 2010
Total Posts : 550
 
   Posted 2/1/2013 4:32 AM (GMT +3)    Quote: Advanced version of moneypak virus, need some high-level help pleaseAlert an admin about: Advanced version of moneypak virus, need some high-level help please
As long as you can still access windows explorer, then you need to search for and remove:

<random>.exe
Look in
C:\Windows\Temp
and
C:\DOCUMENTS AND SETTINGS\<This folder should have your Windows Account name>\LOCAL SETTINGS\Temp for this random letters and/or numbers executable.

ctfmon.lnk
Look in C:\Documents and Settings\<This folder should have your Windows Account name>\Start Menu\Programs\Startup

If you find them and remove them, you should be able to get the computer in a state in which you can continue with a scan to remove the rest of the infection.

Cheers!


Andreea-Luciana Ostache
Senior Support Technician EN
support@bullguard.com
www.bullguard.com

Download the Free Trial version of BullGuard Internet Security 12

You have a BullGuard related problem? Post your question on these forums, contact Support or contact me on Twitter!

Back to Top
 
New Topic Post reply to : Advanced version of moneypak virus, need some high-level help please Printable version of : Advanced version of moneypak virus, need some high-level help please
 
Forum Information
Currently it is Tuesday, July 29, 2014 7:56 PM (GMT +3)
There are a total of 60,529 posts in 13,304 threads.
In the last 3 days there were 0 new threads and 1 reply posts. View Active Threads
Who's Online
This forum has 36187 registered members. Please welcome our newest member, DorothyBell.
3 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads