Remove FBI MoneyPak (Gamecard) virus as a winlock of Russian origin that pretends to act in the name of USA

FBI MoneyPak \ Gamecard (Federal Bureau of Investigation malware) virus

is a winlocker (Reveton Trojan) that restricts access to your OS showing officially locking popup saying your computer has been locked in the name of the Federal Bureau of Investigation.
There are two options, according to the scary alert. Either you buy unlock code worth $200 through MopneyPack and enter it into relevant fields generated by the ransomware or you go to prison in 72 hours.
That is bluff, of course, for the program speaking to you is a hacking tool used by black hats worldwide. The scareware developers do not seem to use the applet themselves selling it instead to anyone willing on affiliate terms. It is very popular bid on Russian IT black-market.
Removal of FBI MoneyPak implies extermination of the malware components. Please do not waste your time trying various cracks as any codes entered into MoneyPak field do not trigger self-elimination procedure for the trojan. Click here to get rid of FBI MoneyPak and other malicious programs as detected by free scanner.



Automatic removal of FBI MoneyPak virus:

Malware is likely to be accomponied by a group of numerous relatives and assisting programs. That is why we recomend to scan computer for malware and viruses if FBI MoneyPak virus is your computer resident. The scan is 100% free. After the scan, you can remove FBI MoneyPak virus in a safe mode as fast as your PC perfomance permits. Click here to scan your computer for free and get rid of this dangerous malware.

FBI\MoneyPak virus fake message:

The FBI
Federal Bureau of Investigation

ATTENTION!
IP: xxx.xxx.xxx
Location: Your Country Here
IPS: Your ISP Here

Your PC is blocked due to at least one of the reasons specified below.

You have been violation Copyright and Related Rights Law (Video, Music, Software) and illegally using or distributing copyrighted content, thus infringing Article I, Section 8, Clause 8, also known as the Copyright of the Criminal Code of United States of America.

Article I, Section 8, Clause 8 of the Criminal Code provides for a fine of two to five hundred minimal wages or a deprivation of liberty for two to eight years.

You have been viewing or distributing prohibited Pornographic content (Child Porno, Zoofilia and etc). Thus violating article 202 of the Criminal Code of United States of America. Article 202 of the Criminal Code provides for a deprivation of liberty for four to twelve years.

Illegal access has been initiated from your PC without your knowledge or consent, your PC may be infected by malware, thus you are violating the law of Neglectful Use of Personal Computer. Article 210 of the Criminal Code provides for a fine of up to $100,000 and/or a deprivation of liberty for four to nine years.

Pursuant to the amendment to the Criminal Code of United States of America of May 28, 2011, this law infringement (if it is not repeated – first time) may be considered as conditional in case you pay the fine to the State.

Fines may be paid within 72 hours after the infringement. As soon as 72 hours elapse, the possibility to pay the fine expires, and a criminal case is initiated against you automatically within the next 72 hours!

To unblock the computer, you must pay the fine through MoneyPak of 100$.

Download SpyHunter (Alternative anti-spyware) to uninstall FBI MoneyPak virus and protect your PC from malware threats

Manual removal of FBI MoneyPak virus:

Manual removal means that you have relevant skills for managing .dll files and PC registry. After you remove FBI MoneyPak virus manually, we still highly recommend you due to the reasons explained above to perform free scan for malware. Follow the relevant link above to start free scan (click on “Download StopZilla! to remove FBI MoneyPak virus malware”).
To Remove FBI virus manually press Start>Run> type “regedit”, locate the following “HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\” registry entry, then locate RANDOM TEXT KEY in rundll32.exe registry key and delete it (as shown on the screenshot). After you need to detect and delete all Fbi ransomware files.

Delete FBI MoneyPak virus related files and folders:

%Temp%\<random>.exe
%StartupFolder%\ctfmon.lnk
File Location Notes:

%Temp% refers to the Windows Temp folder. By default, this is C:\Windows\Temp for Windows 95/98/ME, C:\DOCUMENTS AND SETTINGS\<Current User>\LOCAL SETTINGS\Temp for Windows 2000/XP, and C:\Users\<Current User>\AppData\Local\Temp for Windows Vista and Windows 7.

%StartupFolder% refers to the Startup folder in the Start Menu. For Windows 95/98/ME it refers to C:\windows\start menu\programs\Startup, for Windows XP, Vista, NT, 2000 and 2003 it refers to C:\Documents and Settings\<Current User>\Start Menu\Programs
\Startup, and for Windows Vista/7 it is C:\Users\<Current User>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup.

Bleepingcomputer.com
information

Delete FBI MoneyPak virus registry entries:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\RANDOM KEY

Incoming search terms:

Share it:


Did you enjoy this post? Why not leave a comment below and continue the conversation, or subscribe to my feed and get articles like this delivered automatically to your feed reader.

Comments

No comments yet.

Leave a comment

(required)

(required)