Severity scale:  
  (97/100)

FBI Moneypak. How to remove? (Uninstall guide)

removal by Lucia Danes - -   Also known as FBI Green Dot Moneypak virus, FBI virus | Type: Ransomware

FBI Moneypak (can also be found as FBI virus) is a ransomware infection that clearly shows how the bad guys are skillfully improving their techniques while trying to earn more money. This virus not only displays misleading alert looking like a legitimate notification sent by Federal Bureu of Investigation but also locks the system down so that you can't do anything about it. The main reason why scammers have released such virus is really simple – they expect you to believe that you have been 'illegally watching copyrighted content and now you have to pay a 'fine' through Moneypak service'. Victim is usually asked to go to Wallmart or Wallgreens stores to make a payment (see the image below). Before you go and pay, read the details below to make sure that you have a deal with serious cyber infection. We highly recommend not to fall for FBI Moneypak virus because you will only support the online criminals in this way.

How people get infected with FBI Moneypak?

This sophisticated intruder gets inside the system via trojan horses that come inside unnoticed by a user and download all the files needed for FBI Moneypak. In addition, FBI Moneypak locks the system down and displays its pop-up message based on misleading information about copyright and related rights law violation. In fact, it looks almost like a legitimate message displayed by FBI! However, you must keep in mind that this alert is completely deceitful and wants only to mislead you into spending your $100 to unlock the PC. Instead of that, you should don't waste your time and remove FBI Moneypak from your computer before it starts additional activity on your computer.

How can I remove FBI Moneypak?

First of all, read how you can avoid getting infected with FBI Moneypak virus: security experts recommend to ignore all the spam letters and never open attachments that can be found inside them. In addition, stop wasting your time with freeware because such programs may also come together with viruses. Finally, always make sure you have reputable anti-virus and anti-spyware programs installed so that they could help you to prevent such viruses like FBI Moneypak.

Questions about FBI Moneypak

In order to remove this dangerous threat and unlock your computer, you are highly recommended using reputable anti-malware programs, such as Reimage, Malwarebytes Malwarebytes or Plumbytes Anti-MalwareNorton Internet Security. In addition, if you find yourself completely disabled, follow these steps before you run a full system scan wiith anti-malware:

  1. Take another machine and use it to download Malwarebytes Malwarebytes, Reimage, Plumbytes Anti-MalwareNorton Internet Security or other reputable anti-malware program.
  2. Update the program and put into the USB drive or simple CD.
  3. In the meanwhile, reboot your infected machine to Safe Mode with command prompt and stick USB drive in it.
  4. Reboot computer infected with FBI ransomware once more and run a full system scan.

Update: There are new versions of FBI Moneypak or FBI virus, that use other alerts and demand $200, not $100, for the fine. They are called FBI Green Dot Moneypak virus and FBI Virus Black Screen. They have no video recording, but use an audio warning that asks to pay the chash and get the Moneypak code to unlock your computer. We highly recommend to ignore this forged alert and remove the virus from your computer. If flash drive methos hasn't been effective, you cal also follow additional information for FBI Moneypak removal:

* Users infected with FBI Moneypak/FBI virus/FBI Green Dot Moneypak virus/FBI Virus Black Screen are allowed to access other accounts on their Windows systems. If one of such accounts has administrator rights, you should be capable to launch anti-malware program.

* Try to deny the Flash to make your ransomware stop function as intended. In order to disable the Flash, go to Macromedia support and select 'Deny': http://www.macromedia.com/support/documentation/en/flashplayer/help/help09.html. After doing that, run a full system scan with anti-malware program.

* Manual FBI Moneypak removal (special skills needed!):

  1. Reboot you infected PC to 'Safe mode with command prompt' to disable FBI Moneypak (this should be working with all versions of this threat)
  2. Run Regedit
  3. Search for WinLogon Entries and write down all the files that are not explorer.exe or blank. Replace them with explorer.exe.
  4. Search the registry for these files you have written down and delete the registry keys referencing the files.
  5. Reboot and run a full system scan with updated Reimage to remove remaining FBI Moneypak virus files.
We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove FBI Moneypak you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall FBI Moneypak. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.
Press mentions on Reimage
Alternate Software
Plumbytes Anti-Malware
We have tested Plumbytes Anti-Malware's efficiency in removing FBI Moneypak (2014-10-16)
Malwarebytes
We have tested Malwarebytes's efficiency in removing FBI Moneypak (2014-10-16)
Hitman Pro
We have tested Hitman Pro's efficiency in removing FBI Moneypak (2014-10-16)
Malwarebytes
We have tested Malwarebytes's efficiency in removing FBI Moneypak (2014-10-16)
FBI Moneypak snapshot
FBI Moneypak snapshot

FBI Moneypak manual removal:

Kill processes:
tpl_0_c.exe

ch810.exe

0_0u_l.exe

[random].exe

jork_0_typ_col.exe

vsdsrv32.exe

Protector-[rnd].exe

Inspector-[rnd].exe

Delete registry values:
HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun[random].exe

HKEY_LOCAL_MACHINESOFTWAREFBI Moneypak Virus

HKEY_CURRENT_USER SoftwareMicrosoftWindowsCurrentVersionPoliciesSystem ‘DisableRegistryTools’ = 0

HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem ‘EnableLUA’ = 0

HKEY_CURRENT_USER SoftwareMicrosoftWindowsCurrentVersionInternet Settings ‘WarnOnHTTPSToHTTPRedirect’ = 0

HKEY_CURRENT_USER SoftwareMicrosoftWindowsCurrentVersionPoliciesSystem ‘DisableRegedit’= 0

HKEY_CURRENT_USERSoftwareFBI Moneypak Virus

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun ‘Inspector’

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallFBI Moneypak Virus

HKEY_CURRENT_USER SoftwareMicrosoftWindowsCurrentVersionPoliciesSystem ‘DisableTaskMgr’ = 0

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Optionsprotector.exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunInspector %AppData%Protector-[rnd].exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet SettingsWarnOnHTTPSToHTTPRedirect 0

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettingsID 4

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettingsUID [rnd]

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionSettingsnet [date of installation]

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystemConsentPromptBehaviorAdmin 0

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystemConsentPromptBehaviorUser 0

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystemEnableLUA 0

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAAWTray.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAAWTray.exeDebugger svchost.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAVCare.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAVCare.exeDebugger svchost.exe

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAVENGINE.EXE

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution OptionsAVENGINE.EXEDebugger svchost.exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem “DisableRegistryTools” = 0

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem “DisableTaskMgr” = 0

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem “ConsentPromptBehaviorAdmin” = 0

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem “ConsentPromptBehaviorUser” = 0

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciessystem “EnableLUA” = 0

Unregister DLLs:
wpbt0.dll

Delete files:
%Program Files%FBI Moneypak Virus

%AppData%Protector-[rnd].exe

%AppData%Inspector-[rnd].exe

%AppData%vsdsrv32.exe

%AppData%result.db

%AppData%jork_0_typ_col.exe

%appdata%[random].exe

%Windows%system32[random].exe

%Documents and Settings%[UserName]Application Data[random].exe

%Documents and Settings%[UserName]Desktop[random].lnk

%Documents and Settings%All UsersApplication DataFBI Moneypak Virus

%CommonStartMenu%ProgramsFBI Moneypak Virus.lnk

%Temp%_0u_l.exe

%Temp%[random].exe

%StartupFolder%wpbt0.dll

%StartupFolder%ctfmon.lnk

%StartupFolder%ch810.exe

%UserProfile%DesktopFBI Moneypak Virus.lnk

WARNING.txt

V.class

cconf.txt.enc

tpl_0_c.exe

About the author

Lucia Danes
Lucia Danes - Virus researcher

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Lucia Danes
About the company Esolutions

Removal guides in other languages