Green Dot Moneypak Virus - How to remove?
Green Dot Moneypak Virus is an aggressive ransomware that blocks an infected computer completely. It uses the same psychological techniques as FBI Moneypak Virus to convince people into paying the fine. If you see your PC screen locked and a message from the Federal Bureau of Investigation informing that you breached federal laws, do not believe this scam. This blocking has nothing to do with the actual organization. Internet Crime Complaint Center (IC3) – FBI cyber crime division – informs that they get dozens of complains regarding Green Dot Moneypak Virus and its other versions. If your computer is infected with it, IC3 strongly recommends not paying any money or providing any personal information to the virus developers.
To determine if your computer is blocked by Green Dot Moneypak Virus or similar type of ransomware, it should have these signs:
- Your computer has been blocked out of a sudden, e.g. after navigating the Internet and clicking on a compromised website, which can be an ordinary webpage that was not malicious before.
- The message displayed is supposedly from FBI or any other governmental institution, local police, etc. It has this institutions logo. It displays extracts from laws and regulations related to cyber crimes, such as illegal usage of copyrighted content, usage and distribution of child pornography, using computer for spam campaigns, etc.
- In order to unblock a computer, one must pay a fine. This varies from several hundred dollars. A fine should be paid using prepaid payment systems such as Ukash or Moneypak. Note, none of governmental authorities collect payments and fines using prepaid payment systems. If you meet such a payment method, this is a clear sign of a scam.
It is very important to remove infection as soon as you notice it. Even if you are able to unfreeze your computer on your own, it is essential to perform a thorough system scan because the ransomware may still operate in the background. Certain types of malware are programmed to monitor and record personal information such as user names, passwords, and credit card numbers through embedded keystroke logging programs.
Here are detailed instructions for removing Green Dot Moneypak Virus:
- Restart your computer, press F8 while it is restarting
- Choose safe mode with networking
- Launch MSConfig
- Disable startup items rundll32 turning on any application from Application Data;
- Restart your computer again.
- Scan with http://www.2-viruses.com/downloads/spyhunter-i.exeto identify the file and remove it. Here is a video guide, showing how to perform all the steps:
Some versions of Green Dot Moneypak Virus disable all of safe modes therefore you might not be able to choose it. In such a case follow these steps:
- Reboot normally.
- Enter http://2-viruses.com/downloads/spyhunter-i.exe . If malware is loaded, just press alt+tab once and keep entering the string blindly. Press Enter.
- Press Alt+tab and then R couple of times. The process of Green Dot Moneypak Virus should be killed. Here is a video, showing how to follow the above instructions:
If none of the above worked for you, try these Green Dot Moneypak Virus removal instructions:
- Reboot into safe mode with command prompt. Green Dot Moneypak Virus should not be launched this time.
- Run regedit. Search for Winlogon.
- There will be a key labeled Shell under Winlogon. It should reference Explorer.exe or be blank. If there is something else referring an executable in one of users folders, replace it with explorer.exe.
- Save changes, reboot to safe mode with networking.
- Run msconfig and disable all unnecessary startup entries. You should be able to reboot normally.
- Install and run http://www.2-viruses.com/downloads/spyhunter-i.exe. Scan with it the PC and delete Green Dot Moneypak Virus executables it finds. Here is a video guide illustrating this virus removal method:
We also recommend filing a complaint on IC3 website regarding the infection. If you have any questions regarding Green Dot Moneypak Virus removal or face any difficulties, leave a comment below. Our stuff will answer it as soon as possible.