DotFab Blog » Malware Removal»How to Remove FBI MoneyPak Virus? (Ransomware Removal Guide)

How to Remove FBI MoneyPak Virus? (Ransomware Removal Guide)

 

Your desktop has been taken over by a fake FBI notification that says “Your PC is blocked due to at least one of the reasons specified below”? Your computer operating system is locked and you can’t run any applications on it? Don’t be panic. This is a computer virus, known as ransomware. In this article, you can figure out the real story behind this fraudulent alert and the variants of FBI MoneyPak virus. Apart from that, this post will answer your possible questions about FBI MoneyPak virus like what is FBI MoneyPak virus, how this virus infects my computer, how to remove the variants of FBI MoneyPak virus, and how to avoid being infected by this ransomware etc.

The content table:
What Is FBI MoneyPak Virus?
What Does FBI MoneyPak Virus Do to Your PC?
The Evolvement of FBI MoneyPak Virus
How Does FBI MoneyPak Virus Get on Your Computer?
Symptoms or Harmfulness of FBI MoneyPak Virus
FBI MoneyPak Virus Removal Guide
How to Prevent from Being Infected by FBI MoneyPak Virus?


 

What Is FBI MoneyPak Virus?

 

FBI MoneyPak virus, also referred to as FBI virus, is a series of notorious ransomware that have attacked many computer users in the United States since last year and yet its variants are still in vogue. Some proficient also call the early variants of FBI MoneyPak virus as Trojan Reveton. Recently, its variants are defined as Trojan. Ransomlock. This virus tricks people into thinking that they have violated laws and they are in trouble with the FBI. Now the developer of FBI MoneyPak virus has spread this virus into other countries like France, UK, Australia, Austria, Czech Republic.


 

What Does FBI MoneyPak Virus Do to Your PC?

 

Once installed on your computer, FBI MoneyPak virus will display a full screen fake notification that pretends to be from the FBI. On the head of this notification, there is an official FBI seal and various names of law enforcement authorities related to the FBI accordingly. Your IP address, ISP and physical location are listed in the message of this notification. You shouldn’t be afraid of this, because all these information can be acquired through free service online.

Usually FBI MoneyPak virus states that your computer has been locked, your PC is blocked due to at least one of the reasons specified below and so on. Then in the main part of the fraudulent notification, it lists illegal activities detected on your computer including illegally using and distributing copyrighted content, or viewing and distributing prohibited pornographic materials (Child Porno/Zoophilia and etc) and the laws you have infringed. You may be confused, because you never did such thing. But most of the victims will be panic and feel ashamed to tell anyone when they see such bogus FBI notification. They think that if anyone knows this happened, they may get arrested or even worse – have a criminal record or get listed as a registered sex offender. Be clam down and don’t fall into the scam. If you really violated the law, the penalty wouldn’t be just $100 or so.

FBI MoneyPak virus will also lock up your Windows operating system and you can’t access any application on it. It can also disable the task manager and other system utilities to avoid being removed or terminated. This virus sets itself to start whenever your compute is booting, so whenever you log on into Windows operating system or Safe Mode with Networking it will display the fake notification within seconds. Some new variants of FBI MoneyPak virus will also encrypt your files with .docx, .ppt, .zip, .php, .jpg, .txt, .xlsm … extensions. The encrypted files will not be decrypted automatically when this virus is removed.

You should be aware that the FBI MoneyPak virus notification is a scam. You are not in trouble with the FBI, because no branch of law enforcement will monitor your online activities or collect fine through prepaid electronic payment systems. Never pay the fine! Even if you pay the ransom, the fake FBI warning won’t go away and your PC won’t be unlocked.


 

The Evolvement of FBI MoneyPak Virus

 

The original version of FBI MoneyPak virus:

It claims that to unlock the computer, you must pay the fine $100 through MoneyPak.

FBI MoneyPak virus 2

 

The message displayed in this bogus notification:

The FBI Federal Bureau of Investigation
Attention!
IP:xxxxx
Location:xxxxx
IPS:xxxxx

Your PC is blocked due to at least one of the reasons specified below.

You have been violating Copyright and Related Rights Law (Video, Music, Software) and illegally using or distributing copyrighted content, thus infringing Article I, Section 8, Clause 8, also known as the Copyright of the Criminal Code of United States of America.

Article I, Section 8, Clause 8 of the Criminal Code provides for a fine of two to five hundred minimal wages or a deprivation of liberty for two to eight years.

You have been viewing or distributing prohibited Pornographic content (Child Porno/Zoofilia and etc). Thus violating article 202 of the Criminal Code of United States of America. Article 202 of the Criminal Code provides for a deprivation of liberty for four to twelve years.

Illegal access has been initiated from your PC without your knowledge or consent, your PC may be infected by malware, thus you are violating the law On Neglectful Use of Personal Computer. Article 210 of the Criminal Code provides for a fine of up to $100,000 and/or a deprivation of liberty for four to nine years.

Pursuant to the amendment to the Criminal Code of United States of America of May 28, 2011, this law infringement (if it is not repeated – first time) may be considered as conditional in case you pay the fine to the State.

Fines may only be paid within 72 hours after the infringement. As soon as 72 hours elapse, the possibility to pay the fine expires, and a criminal case is initiated against you automatically within the next 72 hours!

To unblock the computer, you must pay the fine through MoneyPak of 100$.

How do I unlock computer using the MoneyPak?
1. Find a retail location near you.
2. Look for a MoneyPak in the prepaid section. Take it to the cashier and load it with cash. A service fee of up to $4.95 will apply.
3. To pay fine, you should enter the digits MoneyPak resulting code in the payment form and press Pay MoneyPak.

When you pay the fine, your PC will get unlocked in 1 to 48 hours after the money is put into the State’s account.

In case and error occurs, you’ll have to send the code by email fine@fbi.gov (Do not forget to specify IP address).

The upgraded version – this version increases the fine to $200.

FBI MoneyPak virus $200.png

 

United States Cyber Security MoneyPak virus:

This variant of FBI MoneyPak virus is similar to the original version of FBI MoneyPak virus, only the agency name is changed to United States Cyber Security.

United-States-Cyber-Security-virus-MoneyPak-Alert

 

A new variant of FBI MoneyPak virus- claims that your computer has been locked and demands for a non-existing fine of $200 to $400.

New-FBI-Moneypak

FBI-Anti-Piracy-Warning

The message displayed in this fake notification:

FBI Anti-Piracy Warning
All activity of this computer has been recorded.

If you use a webcam, videos and pictures were saved for future identifications.

Your IP Address:xxxxx
Your IP Address and Hostname were recorded for future identification.

Your Computer has been locked!

Illegal downloaded material (MP3′s, Movies or Software) has been located on your computer.

Downloading of copyrighted material from the Internet and music saharing via networks is illegal in accordance with Section 106 of the Copyrght Act of United States of America. This action is subject to imprisonment in a county jail for not more than 3 years or a fine of 400 USD.

Furthermore, possession of illegally downloaded materials is punishable under Section 184 paragraph 3 of the Cryminal Code of United States of America and may result in confiscation of computer equipment.

Unlock your computer:
To unlock your computer and to avoid other legal consequences you are obligated to pay a fine of $400. Payment of the fine is done by GreenDot MoneyPak payment voucher. After payment is made your computer will be unlocked and legal actions will not be taken.
Failure to comply with FBI Anti-Piracy warnings could result in criminal charges and possible imprisonment up to 3 years in country jail.

To perform the payment enter the acquired GreenDot MoneyPak code in the secure payment field and press the “Submit” button.

 

New version of FBI MoneyPak virus – claims that your PC is blocked due to at least one of the reasons specified below and requests a ransom of $200.

FBI MoneyPak virus 3

 

FBI Black Screen virus – titled with red “Your computer has been locked!” and claims you are obliged to pay a fine of $200 to unlock the computer.

FBI MoneyPak virus

The message displayed in this fraudulent notification:

Your computer has been locked!

This operating system is locked due to the violation of the federal laws of the United States of America! (Article I, Section 8, Clause 8; Article 202; Article 210 of the Criminal Code of U.S.A. provides for a deprivation of liberty for four to twelve years.)

Following violations were detected:
Your IP address was used to visit websites containing pornography, child pornography, zoophilia and child abuse. Your computer also contains video files with pornographic content, elements of violence and child pornography! Spam-messages with terrorist motives were also sent from your computer.

This computer lock is almed to stop your illegal activity.

To unlock the computer you are obliged to pay a fine of $200.

You have 72 hours to pay the fine, otherwise you will be arrested.

You must pay the fine through MoneyPak:
To pay the fine, you should enter the digits MoneyPak resulting code, which is located on the back of your MoneyPak, in the payment form and press OK (if you have several codes, enter them one after the other and press OK).

If an error occurs, send the codes to address fine@fbi.gov.

FBI Ultimate Game Card virus:

Like the original FBI MoneyPak virus, FBI Ultimate Game Card virus locks the victim’s computer operating system and incorrectly claims illegal activities. The targeted user is also requested to pay a ransom via Ultimate Game Card.

FBI-Virus-Ultimate-Game-Card

Part of the message displayed in this fake notification:

Access to your computer was denied.

Illegally downloaded music tracks (in other words, “pirated copies”) have been detected at your PC.

While being downloaded the before mentioned tracks were copied – that’s also a criminal offense in conformity with 106 of the Digital Millenium Copyright Act.

For unblocking and commission of any other actions resulted from infringement of the rule of law you should pay a penalty equal to $100. The payment should be delivered through our financial partner – Ultimate Game Card. When the payment procedure is complete your PC will be unblocked automatically.

FBI holds legal rights and permanently contacts with state legislation.

 

FBI MoneyPak virus begins to have drastic change in its new variants. Most apparent change is the agency name that used.

Federal Bureau of Investigation (FBI)-International Police Association virus:

With capitalized “Attention! Your computer has been locked!” on the top, it looks really scaring.

FBI MoneyPak virus 7

Part of the message displayed in this bogus notification:

Federal Bureau of Investigation International Police Association
Attention!

Your computer has been locked!
Your IP Address: xxxxx
Your Houstname: xxxxx
Your PC is blocked due to at least one of the reasons specified below.

Your computer was trying to access a child pornography directory and has been blocked. Everyday we are working on blocking such sites and distribution of this awful materials, and it costs a lot to maintain our operations. You are required to pay administrative fees. Watching, downloading and processing such horrific materials is highly punishable and will leave a long lasting effect on your friends and relatives. If we don’t receive a payment within 48 hours your information will be sent to you local authourities. You will be charged and convicted for up to 5 years in prison time and register as a sex offender for the rest of your life.

To help you make your payment faster and totally anonymous to you, we decided to accept vouchers that are spread nationwide and can be purchased in all major stores.

FBI Online Agent virus:

This virus titles with “FBI Online Agent has blocked your computer for security reason” and demands $200 via green dot MoneyPak.

FBI Online Agent v2.2 virus

This is the message displayed by FBI Online Agent virus:

FBI Online Agent has blocked your computer for security reason

The work of your computer has been suspended on the grounds of unauthorized cyberactivity.

Described below are possible violations, you have made:

Article 274 – Copyright
A fine or imprisonment for the term of up to 4 years. (The use or sharing of copyrighted files – movies, software)

Article 183 – Pornography
A fine or imprisonment for the term of up to 2 years. (The use or distribution of pornographic files).

Article 184 – Pornography involving children (under 18 years)
Imprisonment for the term of up to 15 years. (The use of distribution of pornographic files)
(…)

The United States Department of Justice virus:

This new variant of FBI MoneyPak virus has no FBI logo but the official seal of The United States Department of Justice. It requests a non-existing fine of $300.

The United States Department of Justice virus

The message displayed in this fraudulent notification:

Your computer has been blocked

The work of your computer has been suspended on the grounds of the violation of the law of the United States of America.

Article 274 – Copyright
A fine or imprisonment for the term of up to 4 years. (The use or shanng of copyrighted files-movies, software)

Article 183 – Pornography
A fine or imprisonment for the term of up to 2 years (The use or distribution of pornographic Nes)

Article 184- Pornography involving children (under 18 years)
Imprisonment for the term of up to 15 years (The use or distribution of pornographic files)

Article 104- Promoting Terrorism
Imprisonment for the term of up to 15 years (You have visited websites of terrorist organization)

Article 297 – Neglect computer use, entailing serious consequences
A fine or imprisonment for the term of up to 2 years (Your computer has been infected with a virus, which, in turn, Infected other computers)

In connection with the decision of the Government as of August 12, all of the violations described above could be considered as conditional in case of payment of a fine.

Amount of the fine is $200. Payment must be made within 24 hours after the discovery of the violation. If the fine has not been paid, you will become the subject of criminal prosecution.

FBI Cybercrime Division International Cyber Security Protection Alliance (ICSPA) virus:

Click to view International Cyber Security Protection Alliance virus
This virus claims a fine of $300 for you have been violating Copyright and Related Rights Law.

FBI Cybercrime Division ICSPA virus

Part of the message displayed in this fraudulent notification:

FBI CYBERCRIME DIVISION
International Cyber Security Protection Alliance

ATTENTION!

Your PC is blocked due at least one of the reasons specified below.

You have been violating Copyright and Related Rights Law. (Video, Music, Software) and illegally using or distributing copyrighted content, thus infringing Article 1, Section 2, Clause 8, also known as the Copyright of the Criminal Code of United States of America.

Article 1, Section 2, Clause 8 of the Criminal Code provides for a fine of 200 to 500 minimal wages or a deprivation of liberty for 2 to 8 years.

You have been viewing or distributing prohibited Pornographic content (Child Porn/Zoophilia and etc). Thus violating Article 2, Section 1, Clause 2 of the Criminal Code of United States of America.
(…)

Fines may only be paid within 72 hours after the infringement. As soon as 72 hours elapse, the possibility to pay the fine expires, and a criminal case is initiated against you automatically within the next 72 hours! To unblock the computer you must pay the fine through MoneyPak of $300. When you pay the fine, your PC will get unlocked in 1 to 72 hours after the money is put into the State’s account.

Since your PC is unlocked, you will be given 7 days to correct all violations. In case all violations are not corrected after 7 working days, your PC will be blocked again, and a criminal case will be initiated against you automatically under one or more articles specified above.

 

 

FBI Cybercrime Division International Cyber Security Protection Alliance (ICSPA) virus has some variants in other languages:

These FBI MoneyPak viruses will not only display fake notification and lock your operating system, but also it will encrypt your files. There are variants of this virus prevailing in countries and districts like USA, UK, Australia, Ireland, Finland, France, Greece, Hungary, Austria, Norway, Cyprus, Czech Republic and so on. Some of the variants collect ransom through Paysafecard or Ukash. The fake message displayed in these viruses are began with “Warning! Your computer has been locked and all your data were encrypted!” in local official languages.

 

The screenshot of some versions of FBI Cybercrime Division International Cyber Security Protection Alliance (ICSPA) virus:

USA version – Warning! Your computer has been locked and all your data were encrypted!

 FBI-Cybercrime-Division-ICSPA-virus USA

Austrian version – WARNUNG! Ihr Computer Wurde Gesperrt Und Alle Daten Verschlüsselt Wurden!

Click to view FBI “Ihr Computer wurde gesperrt und alle Daten verschlüsselt wurden!” Virus article.

FBI-Cybercrime-Division-ICSPA-virus Austria

French version –ATTENTION ! Votre ordinateur a été verrouillé et toutes les données sont cryptées !

FBI-Cybercrime-Division-ICSPA-virus France

Norwegian version – ADVARSEL! Datamaskinen har blitt låst og alle dine data ble kryptert

FBI-Cybercrime-Division-ICSPA-virus Norway

United States Courts virus – the newest FBI MoneyPak virus

Click to view United States Courts virus article

united-states-courts-ransomware-virus


 

How Does FBI MoneyPak Virus Get on Your Computer?

 

Commonly, the cybercriminal will place the Trojan horse of this virus on malicious websites and compromised legitimate websites. When you visit such websites, the Trojan will be dropped surreptitiously on your computer through drive-by download. The fraudster may also bundle FBI MoneyPak virus with pirated or illegally acquired software, or disguise it as useful software. Spam email that contains infected attachments or links leading to malicious websites is also a way to propagate this type of ransomware.


 

Symptoms or Harmfulness of FBI MoneyPak Virus

 

Ⅰ. Display a fake notification that purported to be from legitimate law enforcement authorities that related to the FBI whenever you power on your computer.

Ⅱ. In the fake alert, it claims that you have violated copyright law or illegal activities have been detected on your computer, thus you have to pay a fine.

Ⅲ. Lock up your operating system and you can’t access any programs on it.

Ⅳ. It may allow cybercriminal to access your computer to steal your personal information and files for illegal use.

Ⅴ. It may bring in other Trojans or malwares for vicious purpose.


 

FBI MoneyPak Virus Removal Guide

 

Please be patient for the process of removing FBI MoneyPak virus is very complicated and you may need to try more than one method to get rid of this virus.

                                                                                                                         

Deny Flash

 

Some variants of ransomware exploit Java or Flash vulnerabilities to load the malicious code. The symptoms of the infection may be suspended by denying flash. Then you can navigate through the infected system. If the step is not necessary for the removal, then skip to the next step.

To deny/disable flash:
Visit http://www.macromedia.com/support/documentation/en/flashplayer/help/help09.html → select the Deny radio option

                                                                                                                         

Outline of the Removal Guide

 

Option 1 Unplug your Network Cable and Remove Malicious Files

Note: The earlier version of FBI MoneyPak virus downloads the fake warning from the Internet, so you can get rid of this virus by disconnecting to the Internet.

Option 2 Scan and Remove FBI MoneyPak virus in Safe with Networking

Note: Most of the variants of FBI MoneyPak virus will not allow you to boot your computer to Safe Mode with Networking, so this option won’t work if you are not luck enough.

Option 3 Restore the Operating System through safe mode with command prompt

Note: This option works with most of the variants.

Option 4 Disable FBI MoneyPak Virus from Starting Automatically

Note: Some very professional variants may block you from the Safe Mode with Networking and delete all your system restore points, so this option may work. Please note this method requires you to be proficient.

Option 5 Remove FBI MoneyPak Virus by using Anvi Rescue Disk

Note: Some variants of FBI MoneyPak virus will block you from everything, including the running of Safe Mode. This option can be applied to remove most variants of FBI MoneyPak virus.

Restore Encrypted Files to Previous Version with Windows Utility

                                                                                                                         


 

Option 1 Unplug Your Network Cable and Remove Malicious Files

 

The earlier versions of FBI MoneyPak virus works by downloading the fake notification from the Internet, so if you unplug your network cable and manually turn off your then back on, the virus would be gone.

Step 1 Disconnect to the Internet.

Step 2 Turn off your computer manually and then back on.

Step 3 Run a system scan with anti-virus program or antimalware program.

If your anti-virus program and antimalware program won’t work correctly, download Anvi Smart Defender on a clean computer and install it to the infected computer.

1. Download Anvi Smart Defender from the below direct download link.

Anvi Smart Defender direct download link: http://www.dotfab.com/download_asd.html

2. Copy asdsetup.exe file to a USB flash drive and paste it to the infected computer.

3. Double click asdsetup.exe file to install Anvi Smart Defender.

4. Launch Anvi Smart Defender and switch to Scan tab, then click on Full Scan button to start system scan.

Anvi Smart Defender full scan

5. After the scan finished, click on the Repair or Removal button to complete the removal of malicious files.


 

Option 2 Scan and Remove FBI MoneyPak virus in Safe Mode with Networking

 

Some variants of FBI MoneyPak virus will not block your desktop when you start the infected computer in Safe Mode with Networking. Then you can go over the instructions in Option 2 to scan and remove the malicious files.

Step 1 Boot your computer to Safe Mode with Networking

1. Restart your infected computer.

2. Soon after windows starts, tap F8 key repeatedly until you see a menu similar to the picture below.

Advanced Boot Options

3. Use the arrow keys on the keyboard to highlight Safe Mode with Networking and press Enter on your keyboard.

safe-modewithnetworking

Notice: Windows will now boot to Safe Mode with Networking and prompt you to login as a user. Please login as the same user you were previously logged in with in the normal Windows mode.

Step 2 Perform a system scan with Anvi Smart Defender

1. Download Anvi Smart Defender from the below direct download link.

Anvi Smart Defender direct download link: http://www.dotfab.com/download_asd.html

If the download fails, please check the networking settings and the hosts files because many infections may modify them. You can go to How to Check Hosts Files, DNS and Proxy Settings for Normal Internet Access after Malware Infection for tutorial.

2. Double click asdsetup.exe file to install Anvi Smart Defender.

3. Launch Anvi Smart Defender and switch to Scan tab, then click on Full Scan button to start system scan.

Anvi Smart Defender full scan

4. After the scan finished, click on the Repair or Removal button to complete the removal of malicious files.

scan result

5. Restart your computer to Normal mode, run Anvi Smart Defender and perform a Full Scan again to make sure there are no remaining threats.


 

Option 3 Restore the Operating System through safe mode with command prompt

 

System Restore will bring your computer operating system back to a point before you get infected by FBI MoneyPak virus.

Step 1 Boot your computer to Safe Mode with Command Prompt

1. Turn off your computer and then back on.

2. During the start, tap F8 key repeatedly till you are brought to the Windows Advanced Options Menu.

3. Use the arrow keys to highlight Safe Mode with Command Prompt and then press Enter.

Safe Mode with Command Prompt

Step 2 Restore your computer to restore point

1. Once the Command Prompt window comes out, quickly type “explorer” and hit Enter.

If you fail to do so in a few seconds, the ransomware will not allow you to type any more. You should restart the computer to the safe mode and repeat the process.

system restore 1

2. Next, type rstrui and press Enter to launch System Restore

4

Or, close the Command Prompt window, then locate the file rstrui.exe and press Enter to launch System Restore.

The location of the file:

Windows XP: C:\windows\system32\restore\rstrui.exe

Windows 7/Vista: C:\windows\system 32\rstrui.exe

rstrui.exe file

3. Follow all the steps to restore your computer system to an earlier time and date (restore point) before the infection.

Please note that some professionally crafted ransomware variants will delete all you system backup, so you can’t execute system restore, then you can go through Option 4 to remove this virus.

Step 3 Scan and remove malicious files with Anvi Smart Defender

1. Run a computer scan with Anvi Smart Defender and remove the infected files.

Anvi Smart Defender direct download link: http://www.dotfab.com/download_asd.html

Download and install Anvi Smart Defender → run Anvi Smart Defender → switch to Scan tab → run a Full Scan

Anvi Smart Defender

2. Boot your computer into normal mode and run a system scan again to make sure all the infected files were removed.


 

Option 4 Disable FBI MoneyPak Virus from Starting Automatically

 

If your system restore point has been deleted by FBI MoneyPak virus, you can use msconfig to remove its startup entries.

Step 1 Boot your computer to Safe Mode with Command Prompt (same to step 1 of Option 3)

Step 2 Disables FBI MoneyPak virus from starting automatically

1. Quickly type msconfig in the Command Prompt window and press Enter.

msconfig

2. Click on Startup tab in the System Configuration window and uncheck any suspicious and unknown entries, then click Apply button and OK button.

system configuration-startup

By doing so, you can prevent FBI MoneyPak virus from starting along with Windows operating system.

3. Type shutdown/r to restart your computer to normal Windows mode.

msconfig-restart

Step 3 Scan and remove malicious files with Anvi Smart Defender (same to step 3 of Option 3)


 

Option 5 Remove FBI MoneyPak Virus by using Anvi Rescue Disk

 

If your computer is blocked from everything, including the running of Safe Mode with Command Prompt, then you need to go through Option 5.
You can follow the instructions in the following video to get rid of FBI MoneyPak virus by using Anvi Rescue Disk.

Or, you can follow the following step by step instruction.

Step 1 Use a clean computer to download Anvi Rescue Disk files

Download the Anvi Rescue Disk iso image file Rescue.iso and the USB disk production tool BootUsb.exe from Anvisoft official site.

Direct download link: http://www.anvisoft.com/software/rsd/

Please kindly note that Rescue.iso is a large file download; please be patient while it downloads.

Step 2 Record Anvi Rescue Disk iso image to USB drive

You can also record the iso image to a CD/DVD. We will introduce the steps to record iso image to a CD/DVD in following guide.

1. Connect USB to the computer.

You’d better backup your important data and format your USB drive before use it to record the iso image.

2. Locate your download folder and double click on BootUsb.exe to start it. And then click “Choose File” button to browse into your download folder and select Rescue.iso file as your source file.

USB burning

3. Select the path of USB drive, such as Drive H:

4. Click “Start Burning” to start the burn of USB Rescue Disk boot drive.

5. Close BootUsb.exe tool when you get the following message.

congratulations

Now, you have bootable Anvi Rescue Disk to repair your infected computer.

Alternative Option-Record the iso Image to a CD/DVD

Any CD/DVD record software is fine for burn iso image. If you don’t have one, you can download and install Nero Burning ROM and ImgBurn. Here we will use Nero Burning ROM for demonstration purpose.

1. Open and start Nero Burning ROM and select Burn Image from the drop-down menu of the Recorder.

CD/DVD recorder

2. Locate your download folder and select Rescue.iso file as your source file and then click Open button.

3. Click Burn button to start record the iso image.

After a few minutes, you will have a bootable Anvi Rescue Disk to repair your computer.

Step 3 Configure your computer to boot from USB drive/CD/DVD

Restart your infected computer and configure your computer to boot from USB drive/CD/DVD that recorded Anvi Rescue Disk. Basically, you can use F8 to load USB boot menu.

For different motherboard, you may need to use the Delete or F2, F11 keys, to load the BIOS menu. Normally, the information how to enter the BIOS menu is displayed on the screen at the start of the OS boot.

boot menu instruction

The keys F1, F8, F10, F12 might be used for some motherboards, as well as the following key combinations:

• Ctrl+Esc
• Ctrl+Ins
• Ctrl+Alt
• Ctrl+Alt+Esc
• Ctrl+Alt+Enter
• Ctrl+Alt+Del
• Ctrl+Alt+Ins
• Ctrl+Alt+S

Step 4 Boot your computer from Anvi Rescue Disk

1. Restart your computer and press any key to load Anvi Rescue Disk.

2. After you enter Anvisoft Rescue Disk menu, please selected your preferred language and press Enter to continue.

Anvi Rescue disk language setting

Step 5 Scan and remove malicious files and repair registry errors

1. Now you are in the mini Operating system, please double click Rescue tool to start Anvi Rescue disk.

Anvi Rescue Disk

2. Make sure that your computer is connected to network connection before you run a scan on your computer. You can go to Network Troubleshooting Tips for Ransomware Removal using Anvi Rescue Disk for tutorial.

Internet connection

3. Run a full scan by clicking the “Scan Computer” button in the middle of the program to detect and kill the PC lockup virus.

Anvi Rescue disk scan

4. Clicking “Fix Now” to Remove the detected threat by Anvi Rescue Disk.

Anvi Rescue disk fix now

5. Switch to Repair tab. Scan and fix the registry error with the “Repair” module of Anvi Rescue Disk.

Anvi Rescue disk repair

Important Notice: You must repair the registry error after kill the virus. You are probably disabled to boot your Windows without fixing registry damaged by the virus.

Step 6 Scan and remove persistent residual files with Anvi Smart Defender

Some ransomware variants are incredibly persistent, so you are highly recommended to download the antimalware promgram Anvi Smart Defender to remove all the detected threats as prompted.

Download-ASD-in-Rescue-Disk

After download, please restart your computer to normal Windows mode and then go to the folder: C:\Users\[username]\Downloads.

Double click asdsetup.exe file to install Anvi Smart Defender, then perform a Full Scan.

Or you can download it from this direct download link: http://www.dotfab.com/download_asd.html when you boot your computer to normal Windows mode.


 

Restore Encrypted Files to Previous Version with Windows Utility

 

Unfortunately, a decrypt tool for the files that have been encrypted by this virus is not available at this time. You need to restore them from a backup or attempt to restore the important files from a previous version using Windows.

To restore from a previous version using Windows: backup the existing encrypted file → rename the file to its original name → right click on it and select Property → click on Previous Versions tab → select one available previous and click on Restore button


 

How to Prevent from Being Infected by FBI MoneyPak Virus?

 

In order to prevent from being infected by FBI MoneyPak Virus, you should develop a sound online surfing habit. This could keep you always from many other computer viruses.

In the first place, you should avoid visiting any malicious websites or websites that asking for your personal and financial information. Such websites may contain drive-by download that can cause the infection of FBI MoneyPak virus. If you are not sure whether the website is legitimate or not, you can use Anvi Ad Blocker to protect your computer against the malicious websites, compromised websites and vicious pop-up ads.

Anvi Ad Blocker download link: http://www.dotfab.com/download_adb.html

Second, be cautious whenever you want to download something on the Internet, because FBI MoneyPak virus may be bundled in other useful software or free software. You should always download files or applications from trustworthy websites. And it is crucial to have a professional anti-virus program on your computer to detect and prevent virus from getting on your computer. Further guarding your computer with a trustworthy antimalware program, such as Anvi Smart Defender, would be even better.

Third, when sharing files with your friends and colleagues through social engineering, scan all the files with anti-virus program before sending or acknowledging receipt to check for any malicious viruses.

Last but not least, the malwares often explores the vulnerabilities of the target computer, so you should upgrade and patch your operating system timely.