FBI MoneyPak Virus

On this page is detailed description of FBI MoneyPak. Ways to remove the threat and methods to protect the computer against similar attack is also presented.

FBI MoneyPak virus will lock the computer allegedly due to involvement in illicit activities. It reports that you are downloading or distributing copyrighted material and other adult contents. To be able to unlock the PC, FBI MoneyPak demands you to pay a penalty ranging from $100 to as high as $200 within 72 hours. This ransom program only accepts MoneyPak payment method that you can purchase from selected convenience and retail stores. MoneyPak is very similar to credit card, however, it has a pre-loaded amount of money that you can use to buy things and purchase online.

If FBI MoneyPak virus infiltrates your computer, it denies your access instantly. Suffering from a locked PC denotes that the virus has already altered some of your system settings particularly the registry. Apart from that, expect that harmful files be already dropped on various spot of your hard drive. With some components hidden on the system, there is no easy way to remove FBI MoneyPak virus.

The best approach to uninstall FBI MoneyPak virus is by using a removal tool in the presence of anti-malware software. If you will only follow the guide below, you can get rid of this ransom Trojan without paying for the fee. Regain control of your computer once more after completing the removal process.

TypeRansomware
Sub-TypeWindows Lock, PC Lock
OS AffectedWindows

What are the Symptoms of FBI MoneyPak Virus Infection?

FBI MoneyPak Virus will not allow you to use the computer until you pay for the fine, which cost $100 to $200. Once payment has made, you will receive the unlock code that you can use to regain access.

FBI MoneyPak Virus

The fake FBI (Federal Bureau of Investigation) fake warning page as shown above will contain accusation of illegal acts observed on your computer. Here are some excerpts.

All activity of this computer has been recorded.
Of you use a webcam, videos and pictures were saved for identification.
You can be clearly identified by resolving your IP address and associated hostname.
Your Computer has been locked!
Illegally downloaded material (MP3’s, Movies or Software) has been located on your computer…

Update: August 22, 2012
A new version of FBI MoneyPak is in the wild. This time, it added a new payment scheme called Ultimate Game Card by PaybyCash.com. Here is the screenshot image.

FBI - Ultimate Gane Card

Updated: October 13, 2012
The new version of FBI MoneyPak virus exhibits a new layout. Everything remains the same. See image below for reference.

FBI MoneyPak Virus Image 3

Follow these Procedures to Remove FBI MoneyPak

Procedure 1 : Create bootable USB drive via Kaspersky Rescue Disk

Procedure 2 : Start the computer with Kaspersky Rescue Disk

Procedure 3 : Remove FBI MoneyPak with WindowsUnlocker

Procedure 4 : Run a virus scan using the same tool to ensure that no more leftover items from FBI MoneyPak

Ransom Trojans and viruses will lock the screen and makes the computer unusable. Common ways to deal with this type of infection is to boot the PC using another device. For this tutorial we will do a bootable disk that contains FBI MoneyPak remover.

Create a USB Bootable Device

1. Download Kaspersky Rescue Disk from their official server. Click the button below. The file will be in .ISO format.

2. Download this utility called rescue2usb to record your .ISO file into the USB drive. Obviously you need a USB thumb drive at least 512MB in capacity. Plug it to the computer.

3. Once you have the two programs, double-click on the rescue2usb.exe to start creating a bootable USB drive.
4. You will see on the screen in the program called Kasperksy USB Rescue Disk Maker. Click on Browse and locate the .ISO file.
5. Under USB Medium, select the proper drive of your USB device.
6. Click on START. It will now begin to create a bootable USB drive with Kaspersky Rescue Disk in it.

Start the Computer with Kaspersky Rescue Disk.

1. You must set the computer to use other bootable device aside from hard drive. For this procedure, enable your BIOS to boot to USB device. If you are not familiar with this, please refer to your computer's instruction manual.

2. Another option is to access the Boot Menu right after you turn one the PC. It will present a Menu so that you can select a preferred boot drive. Select Removable Devices.

Boot Menu

3. Your computer will now start and load Kaspersky Rescue Disk.
4. If you see a message on the screen, please Press any key to enter the menu. You only have 10 seconds to do this, otherwise it will boot with the hard drive.

5. Next screen will be the interface language. Please select desired language to use.
6. You must run the program in Graphic Mode. This gives you easy access to all commands and menus.
7. End User License Agreement will appear. Please accept to continue using the program. Press 1 to proceed.

Using WindowsUnlocker to Remove FBI MoneyPak

1.Click on the K button at the lower left corner of the screen.

2. Select Terminal on the list. It will open a command prompt.
3. Type windowsunlocker and press Enter on your keyboard.

4. On WindowsUnlocker menu, please type 1 to Unlock Windows. This utility will clean the registry for malicious entries.

5. After the cleanup process, it will display the menu once more.
6. Press 0 on your keyboard to exit WindowsUnlocker.

Run a Virus Scan

1. After removing FBI MoneyPak, you need to delete all remaining components.
2. Click on the K to display the menu.

3. Select Kaspersky Rescue Disk. This will open the virus scanning tool.
4. You need to update the program first. Select My Update Center tab and click on Start update. This requires an Internet connection.

5. After updating the program, select Object Scan tab and click on Start Object Scan. You must scan the following:

  • Disk boot sectors
  • Hidden startup objects
  • All drives

6. Scanning the entire hard drive may take some time. Please let the scan to finish.
7. Once the scan process is complete, the tool will prompt you for preferred actions on detected threats. Deleting all threats is recommended.
8. You can now turn off the computer, unplug the USB drive, and start Windows in normal mode.

Protect your PC from FBI MoneyPak or Similar Attack

Turn On Security Features of your Internet Browser

Internet Explorer - Activate SmartScreen Filter

Internet Explorer versions 8 and 9 has this feature called SmartScreen Filter. It helps detect phishing web sites and protect you from downloading malicious files online. You may have avoided FBI MoneyPak virus if this has been active on your PC. To turn on SmartScreen Filter, follow these steps:

1. Please open Internet Explorer.
2. On top menu, select Tools (IE 9). For IE 8, please look for Safety menu.
3. Select SmartScreen Filter from the drop-down list and click on Turn on SmartScreen Filter.

IE SmartScreen Filter

4. Please restart Internet Explorer.

Google Chrome's Enable Phishing and Malware Protection

With Google Chrome's Phishing and Malware Detection feature, you will have lesser risks browsing the web. It will display a warning when the site you are trying to visit is suspicious. To enable Phishing and Malware Protection, please do these steps:

1. Open Google Chrome.
2. Click on the Customize and control Google Chrome (3-Bars Icon) located on top right corner of the browser.
3. Select Settings from the drop-down list.
4. Once on the settings page, click on Show advanced settings... at the bottom of the page to see the rest of the Chrome setup.
5. Locate Privacy section and mark 'Enable phishing and malware protection'.

Chrome Security Settings

6. Please restart Google Chrome. New settings keep your browser safe while surfing the web.

Mozilla Firefox - Block Attack Sites and Web Forgeries

Phishing and Malware Protection is a built-in feature on Firefox version 3 or later. It warns you when a page you are trying to visit contains phishing content or an attack site designed to drop threats on the computer. To help you keep safe while browsing the Internet using Firefox, please follow this guide:

1. Open Mozilla Firefox browser.
2. On top menu, click on Tools. Then select Options from the list.
3. Select Security and put a check mark on the following items:

  • Warn me when sites try to install add-ons
  • Block reported attack sites
  • Block reported web forgeries

Firefox Security Settings

Remove FBI MoneyPak & Protect Your Computer Now!

Get Protection
30 Day Trial

5 Responses to“FBI MoneyPak Virus”

  1. Unkown
    August 11, 2012 at 8:16 am #

    Yeah.. im a Victum to this little damn virus.. and Ummm.. I just unlocked it with a very easy way.. See what i did was i had open programs that was.. Well already opened and so i went to turn off my computer and then simply canceled it. Now the mailwear is still in the computer but at least it unlocks your screen free of charge.

  2. addoodi
    December 22, 2012 at 11:18 am #

    I did exactly as explained here.. But after selecting that the computer boot from the usb the screen stops at a blank black screen.. I think that the usb is not booting.. is there a way to fix this

  3. prodigal_john
    December 24, 2012 at 8:17 pm #

    ya, mine did the same black screen thing after saying it was booting the program.

  4. LookwhoIsIn
    January 15, 2013 at 2:45 am #

    All the steps followed from this website, last step taking tons of time… hopefully it will remove this damn virus. Thanks to the author!!

  5. Tom
    February 15, 2013 at 5:49 pm #

    Blank screen after selecting GUI option from main menu took a long time to load up. Wait for it. Once loaded, run the terminal executable to scan and clean the registry then the rescue program, update defs., and scan all as described. Ransom virus found numerous times in local profile path on “C” drive. Hopefully this fixes it. You used to be able to bring up PC in safe mode and kill the process and manually obliterate it. Seems this virus has evolved and these sneaky little b**rds disabled the CTRL-ALT-Delete option for task manager and now you can’t get into it. The only way to blow this virus away is using some outside force other than the Windows OS that’s installed. Crazy! Never seen anything like it :-)

Leave a Reply

Your email address will not be published. Required fields are marked *

(Required)

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>