Monday, February 25, 2013

FBI virus. How to handle!

This scam presents about itself for the victim as 'The FBI Federal Bureau Investigation' alert and aggressively claims that computer is blocked because of the Copyright and Related Rights Law violation or other reason.However, if you find yourself blocked by a program, which tells that you have been illegally using or distributing copyrighted content, viewing or distributing pornographic content and spreading malware to other computers, you must ignore such alert first of all and remove FBI virus immediately!
There are many options to remove the FBI virus on your own without the help or a professional.






This infection gets inside the system through security vulnerabilities found when user visits infected websites or downloads infected files.
The biggest issue, which is caused by this ransomware, is that similarly to its earlier versions, it completely blocks its victim's computer, 'locks' it and disables all the programs found there. In order to 'unlock' the system, FBI virus shows its warning and requires to pay the fine through MoneyPak. However, you must have already understood that you must never pay this $100 fine if you don't want to help for the scammers who are collecting these fines.

There are several different versions of this virus:

FBI Moneypak
FBI Green Dot Moneypak Virus
FBI Virus Black Screen
FBI Online Agent 
FBI Cybercrime Division virus

Removal process for FBI virus.

  1. Malware Removal Software – Scan, detect, and remove the FBI virus (free or paid recommendations)
  2. Manual Removal – Manually search for and remove FBI virus files and entries
  3. System Restore – Restore PC to a date and time before infection (includes different access options)
  4. Safe Mode With Networking – Manually remove files and/or scan and remove malware (reset proxy settings if needed)
  5. Flash Drive Option – Load Antivirus (AM) software to a flash drive, scan and remove malware
  6. Optical CD-R Option – Scan and remove malware
  7. Slave Hard Disk Drive Option – Scan, detect, and remove malware
I collected this informations from several sites but i strongly recommend  safe mode with networking at first place and then you can easy download malware removal program (ill recommend Malwarebyte cause it's free and very effective). Or when you are in safe mode try search for virus manually, it will give you some experience for future problems as well. Also system restore is very good option for same problem, you can try that first but it's possible that virus already ruined your chekpoints and it will not work properly.
Anyway if you have some basic knowledge you can do it yourself using any of options above and you will solve your problem. Here is free download link for Malwarebyte.





Manual FBI virus removal (special skills needed!):

  1. Reboot you infected PC to 'Safe mode with command prompt' to disable FBI virus (this should be working with all versions of this threat)
  2. Run Regedit
  3. Search for WinLogon Entries and write down all the files that are not explorer.exe or blank. Replace them with explorer.exe.
  4. Search the registry for these files you have written down and delete the registry keys referencing the files.
  5. Reboot and run a full system scan with updated SpyHunter to remove remaining files.