Sunday, 9 February 2014

Remove Ad.yieldmanager.com Infection, How To Remove Ad.yieldmanager.com

How to remove Ad.yieldmanager.com infection [SOLVED] – Ad.yieldmanager.com Removal Guide

 

Ad.yieldmanager.com is an advertising platform, which is designed to promote advertisements and generate traffic. It collects information such as the type of browser or IP address being used, the number of times certain websites are accessed, the length of time spent on each site and any other internet related information. The most interesting thing is that even after the intruder has managed to get inside the targeted system, the deceitful application does not reveal its presence. On the contrary, it stays hidden and tries to accomplish its fraudulent plan from inside the infected computer. One needs to remove Ad.yieldmanager.com as early as possible.

Ad.yieldmanager.com is responsible for collecting the privacy data such as IP address, email address, name, telephone and even financial data (online bank account and password), and then sending the information to cyber criminals. As harmful as some cookies may be, Ad.yieldmanager.com does not fall under the category of spyware or malware. However, Ad.yieldmanager.com can still be used for malicious activities. In other words, the malicious cookie Ad.yieldmanager.com is trying to steal your personal information, and then use it in a dishonest way. Remove this browser hijacker as soon as possible from your Windows PC.

What is Luxembourg Police Ukash Virus and how to remove it?

What is Luxembourg Police Ukash Virus?

Luxembourg Police Ukash Virus is classified as a pesky Ransomware that mainly attacks PC users in Luxembourg. You turn on your computer only to find that your computer is locked and you are accused of violating the laws. And you are required to pay 100 Euros to unlock your computer. Obviously, it is a fraud because no legitimate government institution. Similar to the most notorious FBI Moneypak Virus, Luxembourg Police Ukash Virus is designed by cyber-criminals to scare PC users and rip off their money. It gets into your computer unexpectedly when you visit an unsafe website or when you download a program containing the virus.

Impacts of Luxembourg Police Ukash Virus

It can consume a large percent of your CPU and dramatically drag down the performance of your PC.
It can introduce other spywares which enable cyber criminals to track your privacy and steal moneys from your online account.
It can change important files and registry settings and make your computer end up with a mess and lead to computer crash.

Luxembourg Police Ukash Virus Removal Guide

When receiving such a ridiculous warning message, what you should do is ignore it and remove this virus as quickly as you can before it damages your system. Here is the guide to help you remove the virus.
Step 1. Restart your PC and press “F8” constantly before windows launches. Choose “Safe Mode with Networking” option, and then press Enter key.


Step 2. Show hidden files and folders, by taking the following steps:
Click the Start button>Control Panel>Appearance and Personalization>Folder Options> View.
Under Advanced settings, click Show hidden files and folders, uncheck Hide protected operating system files and then click OK.

Step 3. Click Start> click Run >type regedit > click OK
Step 4. Search for all related registry entries infected by Luxembourg Police Ukash Virus and wipe them out:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\InternetSettings“CertificateRevocation” = ‘0′
HKEY_CURRENT_USER\Software\Microsoft\ Internet Explorer\Dowload “CheckExeSignatures” = ‘ 0′
Step 5.Reboot the computer to normal mode when the above steps are done.

Pictures to Show How to Safely Delete Windows Registry Values:

The registry serves as the central database of the operating system and stores all the information that the computer needs to run, including the hardware information of the computer and the user information. It also contains all reference data about programs installed on the system and even the slightest deviation from the removal tutorial may cause irreparable system instability. Therefore, you need to be very careful when you use registry. Here are the pictures to help you use the Windows Registry Editor:
Step1. Click on Start menu > Run.

Step 2. Type regedit, press OK to open your registry.

Step 3. Find out the target value.

Step 4. Right-click on the target value and choose Delete.

Australian Federal Police Ukash Virus Scams PC Users with Its Fake Police Alert

Australian Federal Police Ukash Virus Scams PC Users with Its Fake Police Alert

October 03, 2012   Technology News
(PRLEAP.COM) Australian Federal Police Ukash Virus is another ransomware reported by EnigmaSofware.com and essentially a fabricated message that is designed to extort money from computer users after their PC has been locked up and told that they have supposedly performed illegal activity or conducted copyright infringement actions.

The fact remains is that Australian Federal Police Ukash Virus is a fake message that tends to have installed Trojans that lock up a PC and may prevent access to some sites or applications.

Australian Federal Police Ukash Virus is much like other ransomware threats such as the FBI Moneypak or Ukash Virus ransomware messages. Each of these messages serves a purpose of relaying a false message that some PC users may fall for in an effort to collect a couple hundred dollars. The Australian Federal Police Ukash Virus will take the money of gullible PC users.

PC users will naturally seek a solution to Australian Federal Police Ukash Virus by removing any related malware files. In doing this, the security researchers at EnigmaSoftware.com have made it easy. They have done this through a removal report addressing the needs for PC users to automatically remove the Australian Federal Police Ukash Virus.

In removing Australian Federal Police Ukash Virus, PC users will no longer get this message plastered on their computer screen, nor will their system be locked. Paying the so-called penalty or ransom through Australian Federal Police Ukash Virus will usually not unlock a computer; it will only aggravate the situation by having an even more frustrated PC user.

The newly released removal report, including resources to eliminate Australian Federal Police Ukash Virus, is now available at http://www.enigmasoftware.com/australianfederalpoliceukashvirus-removal/.

PC users of virtually any type of Windows-based system, may utilize this removal report to obtain resources that are custom tailored to remove malware and other threats such as the Australian Federal Police Ukash Virus.

How to Remove Cheshire Police Ukash Scam? (PC Blocked by Cheshire Police)


How to Remove Cheshire Police Ukash Scam? (PC Blocked by Cheshire Police)

Computer blocked by Cheshire Police Authority and you are prevented from booting into your operating system? Need help to unlock your computer operating system? This article is going to offer step-to-step guide on remvoing Cheshire Police Ukash Scam. Please read more.

When you see the PC lock-up screen of Cheshire Police Authority, you are supposed to get infected with the ransomware virus, which is a type of malware used for data kidnapping, an exploit in which the attacker encrypts the victim’s data and demands payments for the decryption key. Technically, malware used for such purpose is sometimes called acryptovirus, cryptitrojan or cryotoworm as well.

As stated above, the Cheshire Police Authority lock screen is a scam, which will display a bogus notification, which pretends to be from official Law enforcement agency such as, the United Kingdom Police (Metropolitan Police) and states that your computer has been blocked due to it being involved with the distribution of pornographic material, SPAM and copyrighted content.

In the bogus notification, you are required to pay 100 Euro in order to unlock your computer via Ukash or Paysafecard. The PC lock screen is so real that many victims have fallen in the scam and pay money as required to cyber criminal. Once again, Cheshire Police Authority lock screen is a scam and please never compromise to cyber criminals, paying money to them will never help you unlock your PC.

Below is a screenshot of Cheshire Police Ukash Scam:


Cheshire Police Ukash Scam.jpg





Similar ransomware infections:

FBI moneypak virus, Citadel Reventon Malware, United States Cyber Security virus, FBI Ultimate Game Card virus, All Activity on This Computer Has Been Recorded-Fake FBI Warning infection, FBI Online Agent virus, Internet Crime Compliant Center Virus PCeU virus (aka Metropolitan Police Ukash virus), Malex ransomware, Your computer is locked for violating the Law of Great Britain virus, DOJ virus, File Encryption Virus, SGAE virus, An Garda Síochána. Ireland’s National Police Service virus, ISCA 2012 virus, Automated Information Control System virus, ACCDFISA Protection Program ransomware, Celas ransomware, Votre ordinateur est bloque! Gendarmerie Ukash virus, Canadian Police Association Virus, Urausy virus/ransomware, Office Central de Lutte contre la Criminalité Virus, Bundesamt fur Polizei Virus, Canadian Police Cybercrime Investigation Department Virus, GEMA: Your computer has been locked virus, Den Syenska Polisen IT-Sakerhet Ransomware, Bundes Polizei Ukash virus, Australian Federal Police Ukash Virus, FBI. Cybercrime Division virus, UK Police virus, Royal Canadian Mounted Police virus, ICE virus, LPD BM.I Virus etc.



Damage or Symptoms of Cheshire Police Ukash scam:


• Damage or Symptoms of Cheshire Police Ukash scam:

• You are not allowed to access the computer’s desktop for the screen was locked up by the ransomware virus.

• You are unable to access the Internet.

• Safe mode may also be disalbed by Cheshire Police Ukash Virus.

• System Restore may be deleted by the virus that you are unable to recover your computer via System Restore point.



How to Remove Cheshire Police Authority Ukash Scam (Ransomware Remvoal Guide)

We are going to provide two ways to remove the ukash scam, please follow one of below method that is easier for you to unlock your computer.


Removal Option 1 Using Rescue Disk to recover your computer


Anvi Rescue Disk is a brand-new blockbuster developed by Anvisoft to help users remove ransomware infection. If your computer is locked up due to ransomware infection and even unable to boot into safe mode, then you may need this powerful ransomware killer–Anvi Rescue Disk to save your computer OS. For detail information, please check below.


Step 1> Download the Anvi Rescue Disk isoimage file Rescue.iso and the USB disk production tool BootUsb.exe from Anvisoft official site.


Direct download link: http://download.anvisoft.com/software/rescuedisk.zip


Please kindly note that Rescue.iso is a large file download; please be patient while it downloads.


Step 2> Record Anvi Rescue Disk iso image to USB drive. You can also record the iso image to a CD/DVD. We will introduce the steps to record iso image to a CD/DVD in following guide.


Connect USB to computer. You’d better backup your important data and format your USB drive before use it to record the iso image.


Locate your download folder and double-clicking on BootUsb.exe to start it. And then click “Choose File” button to browser into your download folder and select Rescue.iso file as your source file.

Image


Select the path of USB drive, such as Drive H:

Click “Start Burning” to start the burn of USB Rescue Disk boot drive.

Please close BootUsb.exe tool after you successfully burn the file to USB drive when you get following message.


Image

Now, you have bootable Anvi Rescue Disk to repair your computer.


Alternative Option

You can also record Anvi Rescue Disk iso image to a DV/DVD. Any CD/DVD record software is fine for burn iso image. If you don’t have any, you can download and install Nero Burning ROM and ImgBurn. Here we will use Nero Burning ROM for demonstration purpose.

Please open and start Nero Burning ROM and select Burn Image from the drop-down menu of the Recorder.


Image

Locate your download folder and select Rescue.iso file as your source file and then click Open button.


Image


Click Burn button to start record the iso image. After a few minutes, you will have a bootable Anvi Rescue Disk to repair your computer.


Image


Step 3>Restart your computer and configure your computer to boot from USB drive/DV/DVD that recorded Anvi Rescue Disk. Basically , you can use F8 to load USB boot menu.

For different motherboard, you may need to use the Delete or F2, F11 keys, to load the BIOS menu. Normally, the information how to enter the BIOS menu is displayed on the screen at the start of the OS boot.


Image

The keys F1, F8, F10, F12 might be used for some motherboards, as well as the following key
combinations:

• Ctrl+Esc
• Ctrl+Ins
• Ctrl+Alt
• Ctrl+Alt+Esc
• Ctrl+Alt+Enter
• Ctrl+Alt+Del
• Ctrl+Alt+Ins
• Ctrl+Alt+S


If you can enter Boot Menu directly then simply select your CD/DVD-ROM as your 1st boot device.

If you can't enter Boot Menu directly then simply use Delete key to enter BIOS menu. Select Boot from the main BIOS menu and then select Boot Device Priority. After that, set USB drive or CD/DVD-ROM as your 1st Boot Device. Save changes and exist BIOS menu.


Step> 4 After that let's boot your computer from Anvi Rescue Disk.

Restart your computer. After restart, a message will appear on the screen: press any key to enter the menu. So, press Enter or any other key to load the Anvi Rescue Disk

please selected your preferred language and press Enter to continue.



Image

Step> 5Now you are in the mini Operating system, please double click Rescue tool to start Anvi Rescue disk.


Image

Step> 6 Make sure that your computer is connected to network connection before you run a scan on your computer. If you fail to connect your computer to Internet, please check the tutorial on network configuration in this article: Remove Ransomware using Anvi Rescue Disk-Network Troubleshooting Tips

Image


Step> 7 Please run a full scan by clicking the “Scan Computer” button in the middle of the program to detect and kill the PC lockup virus.


Image

Step>8 Clicking “Fix Now” to Remove the detected threat by Anvi Rescue Disk.

Image

Step> 9 Switch to Repair tab. Scan and fix the registry error with the “Repair” module of Anvi Rescue Disk.

Image


Important Notice: You must repair the registry error after kill the virus. You are probably disabled to boot your Windows without fixing registry damaged by the virus. After you remove the virus and repair the registry errors, you should follow the tips and download Anvi Smart Defender to full scan your PC to completely clean leftover of the virus infection.


Anvi Smart Defender direct download link: http://download.anvisoft.com/software/asdsetup.exe

You may need to upgrade to Pro version of Anvi Smart Defender to fix the registry error.

Image

If you are not sure how to remove the ukash scam virus, please refer to the video of ransomware removal using Anvi Rescue Disk for reference below.





Option 2 Safe Mode with Command Prompt Restore

In some case,when your computer is not severely infected, you can easily recover your computer with Windows restore point. For detail information , please read more on following steps.

Step 1> Reboot your computer to Safe Mode with Command Prompt.

Unplug your Internet Cable and boot your computer into safe mode or normal mode. Please note that you should log in as administrator. By disconnecting your operating system from Internet, Korps Landelijke Politiediensten (klpd) Ransomware Virus will be disabled to run on your computer.

Image


Step 2> Once the Command Prompt appears you only have few seconds to type “explorer” and hit Enter. If you fail to do so within 2-3 seconds, the ransomware virus will not allow you to type anymore.

Image


Step 3> Once Windows Explorer shows up browse to:

Win XP: C:\windows\system32\restore\rstrui.exe and press Enter
Win Vista/Seven: C:\windows\system32\rstrui.exe and press Enter

Image

Step4 > Follow all steps to restore or recover your computer system to an earlier time and date (restore point), before infection.

Image

Step5 > Download and install Anvi Smart Defender to remove all threats detected and reboot your PC. A good antivirus program can prevent your computer from getting those similar infection in future.

We highly recommend you to install your computer with a legitimate antivirus/antimalware program. Anvi Smart Defender can provide computers with real-time, smart and powerful protection against viruses, Trojans, adware, spyware, ransomware, rogueware, bots and other online threats.


Image
Anvisoft--A leading Internet security solutions provider

3 Easy ways to remove any Police Ransom Trojan Ukash or MoneyPak Virus Removal Guide instructions

If your computer is locked, and you are seeing a “Your computer has been blocked” notification from a law enforcement agency (FBI, Australian Federal Police, Metropolitan Police, U.S. Department of Justice) asking you to pay a fine via GreenDot MoneyPak, Ukash or Paysafecard code, then your computer is infected with a piece of malware known as Trojan Reveton.
[Image: FBI Moneypak virus]
The Police Ukash or Moneypak virus is distributed through several means. Malicious websites, or legitimate websites that have been hacked, can infect your machine through exploit kits that use vulnerabilities on your computer to install this trojan without your permission of knowledge.
Another method used to propagate this type of malware is spam email containing infected attachments or links to malicious websites. Cybercriminals spam out an email, with forged header information, tricking you into believing that it is from a shipping company like DHL or FedEx. The email tells you that they tried to deliver a package to you, but failed for some reason. Sometimes the emails claim to be notifications of a shipment you have made. Either way, you can’t resist being curious as to what the email is referring to – and open the attached file (or click on a link embedded inside the email). And with that, your computer is infected with the Police Ukash or Moneypak virus.
The threat may also be downloaded manually by tricking the user into thinking they are installing a useful piece of software, for instance a bogus update for Adobe Flash Player or another piece of software.
The Police Ukash or Moneypak virus is also prevalent on peer-to-peer file sharing websites and is often packaged with pirated or illegally acquired software.
Once installed on your computer, the Police Ukash or Moneypak virus will display a bogus notification that pretends to be from an official law enforcement agency (examples: Irish An Garda Síochána, Royal Canadian Mounted Police, Police Central e-crime Unit) and states that your computer has been blocked due to it being involved with the distribution of pornographic material, SPAM and copyrighted content.
The Police Ukash or Moneypak virus will lock you out of your computer and applications, so whenever you’ll try to log on into your Windows operating system or Safe Mode with Networking, it will display instead a lock screen asking you to pay a non-existing fine of  in the form of a Moneypak, Ukash or Paysafecard voucher.
Furthermore, to make this alert seem more authentic, this virus also has the ability to access your installed webcam, so that the bogus Police Ukash or Moneypak notification shows what is happening in the room.
The Police Ukash or Moneypak virus locks the computer and depending on the user’s current location, displays a localized webpage that covers the entire desktop of the infected computer and demands payment for the supposed possession of illicit material.


Cyber criminals often updated the design of this lock screen, however you should always keep in mind that Police Ukash or Moneypak will never lock down your computer or monitor your online activities. The message displayed by the threat can be localized depending on the user’s location, with text written in the appropriate language.
The Police Ukash or Moneypak lock screen is a scam, and you should ignore any alerts that this malicious software might generate.
Under no circumstance should you send any Greendot Moneypak, Paysafecard or Ukash code to these cyber criminals, and if you have, you can  should request a refund, stating that you are the victim of a computer virus and scam.

Remove any Police Ukash,MoneyPak or PaySafecard virus

This page is a comprehensive guide, which will remove the Police Ukash or Moneypak infection from your your computer. Please perform all the steps in the correct order. If you have any questions or doubt at any point STOP and ask for our assistance.
The Police Ukash or Moneypak will start automatically when you login to your computer and display its screenlocker so that you are unable to access your computer, therefore we will need to remove this infection by using any of the below methods:
OPTION 1: Remove Police Ukash or Moneypak lock screen virus with System Restore
OPTION 2: Remove Police Ukash or Moneypak virus with with HitmanPro Kickstart
OPTION 3: Remove Police Ukash or Moneypak virus with Kaspersky Rescue Disk

OPTION 1: Remove Police Ukash or Moneypak lock screen virus with System Restore

System Restore helps you restore your computer’s system files to an earlier point in time. It’s a way to undo system changes to your computer without affecting your personal files, such as e‑mail, documents, or photos.
Because the Police Ukash or Moneypak virus will not allow you to start the computer in Windows regular mode, we will need to start System Restore from the Safe Mode with Command Prompt mode.

STEP 1: Restore Windows to a previous state using System Restore

  1. Reboot your computer into Safe Mode with Command Prompt. To do this, turn your computer off and then back on and immediately when you see anything on the screen, start tapping the F8 key on your keyboard.
    [Image: F8 key]
    If you are using Windows 8, the trick is to hold the Shift button and gently tap the F8 key repeatedly, this will sometimes boot you into the new advanced “recovery mode”, where you can choose to see advanced repair options. On the next screen, you will need to click on the Troubleshoot option, then select Advanced Options and select Windows Startup Settings. Click on the Restart button, and you should now be able to see the Advanced Boot Options screen.
  2. Using the arrow keys on your keyboard, select Safe Mode with Command Prompt and press Enter on your keyboard.
    [Image: Starting computer in Safe Mode with Command Prompt]
  3. At the command prompt, type rstrui.exe, and then press ENTER.
    [Image: Start System Restore to remove lock screen virus]
    Alternatively, if you are using Windows Vista, 7 and 8, you can type: C:\windows\system32\rstrui.exe , and press Enter. And if you are a Windows XP user, type C:\windows\system32\restore\rstrui.exe, then press Enter.
  4. System Restore should start, and you will display also a list of restore points. Try using a restore point created just before the date and time the Police Ukash or Moneypak lock screen virus has infected your computer.
    [Image: Restore settings to remove ransomware]
  5. When System Restore has completed its task, start your computer in Windows regular mode, and perform a scan with Malwarebytes Anti-Malware and HitmanPro, as seen in the next step.

STEP 2: Remove Police Ukash or Moneypak malicious files with Malwarebytes Anti-Malware Free

Even after using System Restore,
  1. You can download Malwarebytes Anti-Malware Free from the below link, then double-click on the icon named mbam-setup.exe to install this program.
    MALWAREBYTES ANTI-MALWARE DOWNLOAD LINK(This link will open a download page in a new window from where you can download Malwarebytes Anti-Malware Free)
  2. When the installation begins, keep following the prompts in order to continue with the setup process, then at the last screen click on the Finish button.
    [Image: Malwarebytes Anti-Malware final installation screen]
  3. On the Scanner tab, select Perform quick scan, and then click on the Scan button to start searching for the Police Ukash or Moneypak malicious files.
    [Image: Malwarebytes Anti-Malware Quick Scan]
  4. Malwarebytes’ Anti-Malware will now start scanning your computer for Police Ukash or Moneypak virus as shown below.
    [Image: Malwarebytes Anti-Malware scanning for Police Ukash or Moneypak
  5. When the Malwarebytes Anti-Malware scan has finished, click on the Show Results button.
    [Image: Malwarebytes Anti-Malware scan results]
  6. You will now be presented with a screen showing you the computer infections that Malwarebytes Anti-Malware has detected. Make sure that everything is Checked (ticked), then click on the Remove Selected button.
    [Image: Malwarebytes Anti-Malwar removing Police Ukash or Moneypak virus]

STEP 3: Double-check for the Police Ukash or Moneypak virus with HitmanPro

  1. You can download HitmanPro from the below link:
    HITMANPRO DOWNLOAD LINK (This link will open a web page from where you can download HitmanPro)
  2. Double-click on the file named HitmanPro.exe (for 32-bit versions of Windows) or HitmanPro_x64.exe (for 64-bit versions of Windows). When the program starts you will be presented with the start screen as shown below.
    HitmanPro scanner
    Click on the Next button, to install HitmanPro on your computer.
    HitmanPro installation
  3. HitmanPro will now begin to scan your computer for Police Ukash or Moneypak malicious files.
    HitmanPro detecting for Police Ukash or Moneypak virus
  4. When it has finished it will display a list of all the malware that the program found as shown in the image below. Click on the Next button, to remove Police Ukash or Moneypak virus.
    HitmanPro scan results
  5. Click on the Activate free license button to begin the free 30 days trial, and remove all the malicious files from your computer.
    [Image: HitmanPro 30 days activation button]

OPTION 2: Remove Police Ukash or Moneypak virus with with HitmanPro Kickstart

If you cannot start your computer into Safe Mode with Command Prompt mode, we can use the HitmanPro Kickstart program to bypass Police Ukash or Moneypak lock screen.
As the Police Ukash or Moneypak ransomware infection locks you out of your computer, you will need to create a bootable USB drive that contains the HitmanPro Kickstart program.
We will then boot your computer using this bootable USB drive and use it to clean the infection so that you are able to access Windows normally again.
You will also need a USB drive, which will have all of its data erased and will then be formatted. Therefore, only use a USB drive that does not contain any important data.
  1. Using a “clean” (non-infected) computer, please download HitmanPro Kickstart from the below link.
    HITMANPRO DOWNLOAD LINK (This link will open a download page in a new web page from where you can download HitmanPro Kickstart)
  2. Once HitmanPro has been downloaded, please insert the USB flash drive that you would like to erase and use for the installation of HitmanPro Kickstart. Then double-click on the file named HitmanPro.exe (for 32-bit versions of Windows) or HitmanPro_x64.exe (for 64-bit versions of Windows).
    To create a bootable HitmanPro USB drive, please follow the instructions from this video:
  3. Now, remove the HitmanPro Kickstart USB drive and insert it into the Police Ukash or Moneypak infected computer.
  4. Once you have inserted the HitmanPro Kickstart USB drive, turn off the infected computer and then turn it on. As soon as you power it on, look for text on the screen that tells you how to access the boot menu.
    [Image: Windows Boot Menu screens]
    The keys that are commonly associated with enabling the boot menu are F10, F11 or F12.
  5. Once you determine the proper key (usually the F11 key) that you need to press to access the Boot Menu, restart your computer again and start immediately tapping that key. Next, please perform a scan with HitmanPro Kickstart as shown in the video below.
  6. HitmanPro will now reboot your computer and Windows should start normally. Then please Malwarebytes Anti-Malware and HitmanPro, and scan your computer for any left over infections.

OPTION 3: Remove Police Ukash or Moneypak virus with Kaspersky Rescue Disk

If any of the above methods did not clean your infected computer, we can use a Kaspersky Rescue Disk Bootable to clean the Windows registry and to perform a system scan to remove the Police Ukash or Moneypak virus.
To create a bootable Kaspersky Rescue Disk, we will need the following items:
  • A clean (non-infected) computer with Internet access
  • A blank DVD or CD
  • A computer with a DVD or CD burner

STEP 1: Download and create a bootable Kaspersky Rescue Disk CD

  1. You can download Kaspersky Rescue Disk utility from link below:
    KASPERSKY RESCUE DISK DOWNLOAD LINK (This link will automatically download Kaspersky Rescue Disk (kav_rescue_10.iso) on your computer.)
  2. To create the bootable rescue disk, we will need to use the ImgBurn program. You can download ImgBurn from the below link, then install this program.
    IMGBURN DOWNLOAD LINK (This link will open a new page from where you can download the ImgBurn program)
  3. Insert your blank DVD or CD in your burner, then start ImgBurn and click on the Write image file to disc button.
  4. Under Source click on the Browse for file button, then navigate to the location where you previously saved the Kaspersky Rescue Disk utility (kav_rescue_10.iso), then click on the Write button.
    [Image: Bootable Kaspersky Rescue CD]
    That’s it, ImgBurn will now begin writing your bootable Kaspersky Rescue Disk.

STEP 2: Start your computer using the Kaspersky Rescue Disk

  1. Once you’ve got the Kasperky Rescue Disk in hand, insert it into the infected computer, and turn off and then turn it on again.
  2. As soon as you power it on, you will see a screen that tells you to press any key to enter the menu, so please tap any key to boot your machine from the Kaspersky Rescue Disk.
    [Image: Starting infected computer from Kaspersky Rescue Disk]
  3. In the next screen, you will need to chose a language, then you click on Kaspersky Rescue Disk. Graphic Mode and press ENTER, to start the Kaspersky Rescue Disk.[Image: Kaspersky Rescue Disk Graphic Mode screen]

STEP 3: Scan your system with Kaspersky Rescue Disk

  1. Within a few short seconds you should see the full working environment, with the Kaspersky Rescue Disk screen front and center as shown below.
    [Image: Kaspersky Rescue Disk scanner]
  2. Switch tabs over to the My Update Center, and then click the Start update button to load the latest anti-virus definitions. Please be patience while this process its completed.
    [Image: Updating Kaspersky Rescue Disk antivirus definitions]
  3. Switch back over to the Objects Scan tab, select the drives you want to scan, and then click the Start Objects Scan button.
    [Image: Kaspersky Rescue Disk scan]
  4. When Kaspersky Antivirus will detect the Police Ukash or Moneypak virus, you’ll be prompted to select an action. When this happens, please select Quarantine or Delete to remove this infection from your computer.
    [Image: Kaspersky Rescue Disk prompt]
  5. When the antivirus scan has completed, you can restart back into Windows regular mode, by clicking on the Kaspersky Start button [Image: Kaspersky Rescue Disk Restart button] (lower left corner), and selecting Restart.
    Once your computer will start in Windows regular more, download Malwarebytes Anti-Malware and HitmanPro, and scan your computer for any left over infections.

Your computer should now be free of the Police Ukash or Moneypak infection. If your current anti-virus solution let this infection through, you may want to consider purchasing the PRO version of Malwarebytes Anti-Malware to protect against these types of threats in the future, and perform regular computer scans with HitmanPro.
If you are still experiencing problems while trying to remove Police Ukash or Moneypak virus from your machine, please start a new thread in our Malware Removal Assistance forum.