How to remove FBI Cybercrime Division Ransomware Virus? (ICSPA Scam Removal Guide)

This article contains step by step removal instructions for the FBI Cybercrime Division Ransomware Virus, International Cyber Security Protection Alliance pc lock-up virus (ICSPA scam). If you are locked out by this ransomware virus, please read on this post about detail removal guide of the virus infection.
 

What is FBI Cybercrime Division, International Cyber Security Protection Alliance (ICSPA scam)?

FBI Cybercrime Division, International Cyber Security Protection Alliance pc lock screen (ICSPA scam) is a ransomware infection from the Reveton malware family that pretends to be from official Law enforcement agency and states to display a bogus notification that your computer has been locked due to it being involved with the distribution of pornographic material, spam and copyrighted contents.
 
The purpose of the FBI Cybercrime Division ransomware virus is to infect your computer and lock down your operating system, and then ask for money to unlock them. All attempts of users to do something on the locked computer turn out to be vain. The fake “FBI Cybercrime Division, International Cyber Security Protection Alliance” warning message says that in order to unblock your computer you must pay the fine through Moneypak, paysafecard, or ukash payment systems.
Still, this is a serious mistake to obey the instructions of this scary desktop locker. You’d better find the proper anti-malware solution and malware uninstall guidelines that will help you unlock your system.

 

Below are screenshots of FBI Cybercrime Division, ICSPA Scam ransomware virus:

 

 

There are two basic forms of FBI Cybercrime Division ransomware. The older version has the ability to access your installed webcam so that the bogus “Your computer has been blocked!” notification shows what is happening in the room. While both FBI Cybercrime Division ransomware have the ability to detect your IP address so that to show the local language alert according the detected location.
 
Important Notice: The messages from the claimed official organization FBI Cybercrime Division, International Cyber Security Protection Alliance are bogus. When you get such kind of message on your computer, it indicates that your computer is getting infected with ransomware virus. Please do not pay any money with the hope to unlock your computer. The only method to recover your operating system is to remove the ransomware virus.
 

How to remove FBI Cybercrime Division Ransomware Virus?

Below we will offer two method to remove FBI Cybercrime Division, International Cyber Security Protection Alliance ransomware virus. Please follow one of the method to unlock your computer. If any problem, please leave a reply below, or contact us by sending email to support@anvisoft.com.

Removal Option 1 Using Rescue Disk to recover your computer

Anvi Rescue Disk is a brand-new blockbuster developed by Anvisoft to help users remove ransomware infection. If your computer is locked up due to ransomware infection and even unable to boot into safe mode, then you may need this powerful ransomware killer–Anvi Rescue Disk to save your computer OS.
 

Anvi Rescue Disk Download:

 


 
(Note:rescueDisk.iso is a large file download; please be patient while downloading.)
 

step 1

Download the Anvi Rescue Disk iso image file Rescue.iso and the USB disk production tool BootUsb.exe from Anvisoft official site. (Direct download link)

Please note that Rescue.iso is a large file download; please be patient while it downloads.

step 2

Record Anvi Rescue Disk iso image to USB drive. You can also record the iso image to a CD/DVD, and the tutorial is included in the download file.

Connect USB to computer. You’d better backup your important data and format your USB drive before use it to record the iso image.

Locate your download folder and double-clicking on BootUsb.exe to start it. And then click “Choose File” button to browser into your download folder and select Rescue.iso file as your source file.

Select the path of USB drive, such as drive H:

Click “Start Burning” to start the burn of USB Rescue Disk boot drive.

Please close BootUsb.exe tool after you successfully burn the file to USB drive when you get following message.

Now, you have bootable Anvi Rescue Disk to repair your computer.

step 3

Start your infected computer and configure your computer to boot from USB drive/DV/DVD that recorded Anvi Rescue Disk. Basically, you can use F8 to load USB boot menu.

For different motherboard, you may need to use the Delete or F2, F11 keys, to load theBIOS menu. Normally, the information how to enter the BIOS menu is displayed on the screen at the start of the OS boot.

step 4

After you enter Anvisoft Rescue Disk menu, please selected your preferred language and press Enter to continue.

step 5

Now you are in the mini Operating system, please double click Rescue tool to start Anvi Rescue disk.

step 6

Please run a full scan by clicking the “Scan Computer” button in the middle of the program to detect and kill the PC lockup virus.

step 7

Clicking “Fix Now” to remove the detected threat by Anvi Rescue Disk.

step 8

Switch to Repair tab. Scan and fix the registry error with the “Repair” module of Anvi Rescue Disk.

Important Notice: You must repair the registry error after kill the virus. You are probably disabled to boot your Windows without fixing registry damaged by the virus. After you remove the virus and repair the registry errors, you should follow the tips and download Anvi Smart Defenderto full scan your PC to completely clean leftover of the virus infection.
 
Anvi Smart Defender direct download link: http://download.anvisoft.com/software/asdsetup.exe
 

You may need to upgrade to Pro version of Anvi Smart Defender to fix the registry error.
 

 

You may need to check the article about Tutorial on Network Configuration if you fail to connect to Internet cloud when you are using Anvi Rescue Disk to recover your computer.
 
For any question, please feel free to let us know. You can simply leave a reply or send us an email (support@anvisoft.com).

Ransomware Removal Guide video

Option 2 Safe Mode with Command Prompt Restore

In some case,when your computer is not severely infected, you can easily recover your computer with Windows restore point. For detail information , please read more on following steps.
 

step 1

Reboot your computer to Safe Mode with Command Prompt.

Unplug your Internet Cable and boot your computer into safe mode or normal mode. Please note that you should log in as administrator. By disconnecting your operating system from Internet, Korps Landelijke Politiediensten (klpd) Ransomware Virus will be disabled to run on your computer.
 

step 2

Once the Command Prompt appears you only have few seconds to type “explorer” and hit Enter. If you fail to do so within 2-3 seconds, the ransomware virus will not allow you to type anymore.

 

step 3

Once Windows Explorer shows up browse to:

Win XP: C:\windows\system32\restore\rstrui.exe and press Enter
Win Vista/Seven: C:\windows\system32\rstrui.exe and press Enter

step 4

Follow all steps to restore or recover your computer system to an earlier time and date (restore point), before infection.
 

step 5

Download and install Anvi Smart Defender to remove all threats detected and reboot your PC. A good antivirus program can prevent your computer from getting those similar infection in future.
 
We highly recommend you to install your computer with a legitimate antivirus/antimalware program. Anvi Smart Defender can provide computers with real-time, smart and powerful protection against viruses, Trojans, adware, spyware, ransomware, rogueware, bots and other online threats.
 

Anvi Smart Defender Download

 

 
We Anvisoft are devoted to develop most practical software and many other useful free tools to protect PC security as well as optimize computer for fast performance. Should you have any problem, please post your issue here. We will answer your question as soon as possible. Thank you for your support to Anvisoft.
 

Social Share Toolbar
Leave a comment

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>