Remove Decrypt Protect Virus MBL Block Off (Decrypt Protect MoneyPak Virus Removal Guide)

This article contains step by step removal instructions for the Decrypt Protect Virus, MBL BLOCK OFF PC lock-up virus. If you are locked out by this ransomware virus, please read on this post about detail removal guide of the virus infection.

What is Decrypt Protect Virus MBL Block Off?

Decrypt Protect Virus MBL Block Off is the new variant of ransomware infection from the Reveton malware family that pretends to be from official Law enforcement agency and states to display a bogus notification that your system and all your files has been blocked and encrypted because you were spreading the Malware (virus, Trojans, worms). You are fined because you are breaking numerous International and USA laws.
Below is a screenshot of Decrypt Protect Virus:

In the bogus notification, you are required to pay $300 in order to unlock your computer via MoneyPak, Paysafecard or Ukash within 48 hours. The PC lock screen is so real that many victims have fallen in the scam and pay money as required to cyber criminal. Once again, the Decrypt Protect Virus MBL Block Off screen is a scam and please never compromise to cyber criminals, paying money to them will never help you unlock your PC.


Fake message presented in Decrypt Protect Virus MBL Block Off virus:

MBL Advisory
You have 48 hours left to enter your payment.
You have lost control over your computer. Your system and all your files has been blocked and encrypted because you were spreading the Malware (viruses, trojans, worms). You are breaking numerous International and USA laws.
Actions made by your computer backed up under United States law USA Patriot ACT What exactly is THE Patriot Act? The Patriot Act is short for the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and obstruct Terrorism Act of 2001. We have the right backed by law: Sec.201. Authority to intercept wire, oral, and electronic communications relating to terrorism. Sec.202. Authority to intercept wire, oral, and electronic communications relating to computer fraud and abuse offences. Sec.209. Seizure of voice-mail messages pursuant to warrants. Sec.2017. Interception of computer trespasser communications. With the support of the federal Bureau investigation department on cybercrime and the Supreme court of the United States of America. We have the legal right to scan and intercept any information going in and out of your computers. Your IP address was identified and isolated by our organisation in connection with a complaint to the involvement of distributed denial of service (DDoS) attack such organisations: NASDAQ and BATSS stock exchange markets and WIKILEAKS.ORG website. Such attacks caused $15 billion in damage. In order to isolate the infected files we have blocked your access to the outside world and your IP address was listed in our MBL (Malware Block List). You can not use the Internet or any of your programs. You have a chance to settle this issue right now before we contact the proper authorities. Within 48 hours you can pay a fine of $300. All your files will be decrypted, and access to the computer will be granted, a claim for compensation from affected companies will be removed and your IP address will be restored to good standings with MBL (Malware Block List). If your don’t pay a penalty within next 48 hours, local authorities and service will be contacted, and most likely it will result in your arrest. You can and will be prosecuted to the fullest extent of the law in order to recover our losses. Do not take any chance to be convicted as a felon. Our Decrypt Protect agent has conducted a full check of your system and found following violations: Your are a distributor of pornographic and porno materials, regular watch porno sites with child pornography and zoophillia. You possess unlicensed software and private audio and video records…


Remove Decrypt Protect Virus MBL Block Off (Decrypt Protect MoneyPak Virus Removal Guide)

Removal Option 1 Using Rescue Disk to recover your computer

Anvi Rescue Disk is a brand-new blockbuster developed by Anvisoft to help users remove ransomware infection. If your computer is locked up due to ransomware infection and even unable to boot into safe mode, then you may need this powerful ransomware killer–Anvi Rescue Disk to save your computer OS.


Anvi Rescue Disk Download:


(Note:rescueDisk.iso is a large file download; please be patient while downloading.)

step 1

Download the Anvi Rescue Disk iso image file Rescue.iso and the USB disk production tool BootUsb.exe from Anvisoft official site. (Direct download link)

Please note that Rescue.iso is a large file download; please be patient while it downloads.

step 2

Record Anvi Rescue Disk iso image to USB drive. You can also record the iso image to a CD/DVD, and the tutorial is included in the download file.

Connect USB to computer. You’d better backup your important data and format your USB drive before use it to record the iso image.

Locate your download folder and double-clicking on BootUsb.exe to start it. And then click “Choose File” button to browser into your download folder and select Rescue.iso file as your source file.

Select the path of USB drive, such as drive H:

Click “Start Burning” to start the burn of USB Rescue Disk boot drive.

Please close BootUsb.exe tool after you successfully burn the file to USB drive when you get following message.

Now, you have bootable Anvi Rescue Disk to repair your computer.

step 3

Start your infected computer and configure your computer to boot from USB drive/DV/DVD that recorded Anvi Rescue Disk. Basically, you can use F8 to load USB boot menu.

For different motherboard, you may need to use the Delete or F2, F11 keys, to load the BIOS menu. Normally, the information how to enter the BIOS menu is displayed on the screen at the start of the OS boot.

step 4

After you enter Anvisoft Rescue Disk menu, please selected your preferred language and press Enter to continue.

step 5

Now you are in the mini Operating system, please double click Rescue tool to start Anvi Rescue disk.

step 6

Please run a full scan by clicking the “Scan Computer” button in the middle of the program to detect and kill the PC lockup virus.

step 7

Clicking “Fix Now” to remove the detected threat by Anvi Rescue Disk.

step 8

Switch to Repair tab. Scan and fix the registry error with the “Repair” module of Anvi Rescue Disk.

Important Notice: You must repair the registry error after kill the virus. You are probably disabled to boot your Windows without fixing registry damaged by the virus. After you remove the virus and repair the registry errors, you should follow the tips and download Anvi Smart Defenderto full scan your PC to completely clean leftover of the virus infection.
Anvi Smart Defender direct download link:
You may need to upgrade to Pro version of Anvi Smart Defender to fix the registry error.

You may need to check the article about Tutorial on Network Configuration if you fail to connect to Internet cloud when you are using Anvi Rescue Disk to recover your computer.
For any question, please feel free to let us know. You can simply leave a reply or send us an email (

Ransomware Removal Guide video


Option 2 Safe Mode with Command Prompt Restore


In some case,when your computer is not severely infected, you can easily recover your computer with Windows restore point. For detail information , please read more on following steps.

step 1

Reboot your computer to Safe Mode with Command Prompt.

Unplug your Internet Cable and boot your computer into safe mode or normal mode. Please note that you should log in as administrator. By disconnecting your operating system from Internet, Korps Landelijke Politiediensten (klpd) Ransomware Virus will be disabled to run on your computer.

step 2

Once the Command Prompt appears you only have few seconds to type “explorer” and hit Enter. If you fail to do so within 2-3 seconds, the ransomware virus will not allow you to type anymore.

step 3

Once Windows Explorer shows up browse to:

Win XP: C:\windows\system32\restore\rstrui.exe and press Enter
Win Vista/Seven: C:\windows\system32\rstrui.exe and press Enter

step 4

Follow all steps to restore or recover your computer system to an earlier time and date (restore point), before infection.

step 5

Download and install Anvi Smart Defender to remove all threats detected and reboot your PC. A good antivirus program can prevent your computer from getting those similar infection in future.
We highly recommend you to install your computer with a legitimate antivirus/antimalware program. Anvi Smart Defender can provide computers with real-time, smart and powerful protection against viruses, Trojans, adware, spyware, ransomware, rogueware, bots and other online threats.

Anvi Smart Defender Download



We Anvisoft are devoted to develop most practical software and many other useful free tools to protect PC security as well as optimize computer for fast performance. Should you have any problem, please post your issue here. We will answer your question as soon as possible. Thank you for your support to Anvisoft.

Social Share Toolbar