Print

Interpol "Your computer has been blocked" scam

How to unblock your computer after Interpol "Your computer has been blocked" scam?

Interpol "Your computer has been blocked" is another ransomware created by Cybercriminals. This is a scam which asks to pay unsuspecting PC users a non existent fine of 100 euros to unblock their computers. The text in this misleading screen locker says that you have been violating the law by distributing illegal content. In reality none of the authorities are using such computer screen lockers to collect fines for any law violations, this message is displayed with a sole purpose of scaring computer users.

To make this message appear more legitimate Cyber criminals have incorporated a video recording window in their ransomware. Furthermore this message displays your IP address, your ISP and a current date. You should understand that this message is fake, you shouldn't pay any fines to unblock your PC. If you would closely look at the message in this ransomware you could clearly see that it has a poorly translated text and most of the used sentences doesn't make any sense. Lately such infections (ransomware) have become very popular among Cyber criminals, they tend to exploit the names of trusted authorities (FBI, Interpol, etc)  in their fake screen lockers. You can read more about this misleading ransomware business model in Krebs on Security website. You shouldn't pay this fake fine to unblock your computer - you will send your money to Cyber criminals.

Interpol virus

fake Interpol ranosmware screen locker

Interpol "Your computer has been blocked" as other ransomware is spread using Trojans and Java exploits. To prevent your computer from being infected with such ransomware and other malware you should always update your operating system and all of your installed software, you should also use a legitimate antivirus and anti-spyware programs. Note that Cyber criminals are using Ukash and paysafecard for money transactions, this makes it very complicated to track them. If you see such fake Interpol message on your computer you should use this removal guide to help you unblock your PC.

Fake message shown in Interpol "Your computer has been blocked" ransomware:

Interpol Department of Cybercrime
Attention!
Your computer is blocked due at least one of the reasons specified below
You have been violating Copyright and Related Rights Law (Video, Music, Software) and illegally using or distributing copyrighted content, thus infringing Article 128 of the Criminal Code of Great Britain. Article 128 of the Criminal Code provides for a fine of two to five hundred minimal wages or a deprivation of liberty for two to eight years. You have been viewing or distributing prohibited Pornographic content (Child Porno/Zoofilia and etc). Thus violating article 202 of the Criminal Code of Great Britain. Article 202 of the Criminal Code provides for a deprivation of liberty for four to twelve years.. Illegal access to computer data has been initiated from your PC, or you have been.... Article 208 other Criminal Code provides for a fine of up to 100,000 and/or a deprivation of liberty for four to nine years. Illegal access has been initiated from your PC without your knowledge or consent, your PC may be infected by malware, thus you are violating the law of On Neglectful Use of Personal Computer. Article 210 of the Criminal Code provides for a fine of 2000 to 8000 euro...

Interpol "Your computer has been blocked" ransomware removal:

Step 1

Start your computer in safe mode. Click Start, then click Shut down. Select Restart and click OK. During your computer starting process press F8 key on your keyboard multiple times until Windows Advanced Options menu shows up, then select Safe mode with networking from the list and press ENTER.

Step 2

Log in to the account that is infected with Interpol "Your computer has been blocked" scam. Start your Internet browser and download a legitimate anti-spyware program. Update the anti-spyware software and start a full system scan. Remove all the entries that it detects.

remover for Interpol "Your computer has been blocked" ransomware

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. We are affiliated with anti-virus and anti-spyware software listed on this site. All the products we recommend were carefully tested and approved by our technicians as being one of the most effective solutions for removing this threat.

Can't boot in Safe Mode with Networking? (Interpol "Your computer has been blocked" virus blocks Safe Mode with Networking)

If you have more than one user account in your operating system - please log-in to the clean account and download the recommended anti-spyware software, install it and run a full system scan, remove all the security infections it will detect, however if you have only one user account please follow this guide (this guide will show you how to create a new user account using safe mode with command prompt - using this newly created user account you will be able to remove Interpol "Your computer has been blocked" ransomware).

If "Interpol "Your computer has been blocked" virus also blocks your operating system's Safe Mode with Networking follow these removal instructions:

1. Start your computer in Safe Mode with Command Prompt - During your computer starting process press F8 key on your keyboard multiple times until Windows Advanced Options menu shows up, then select Safe mode with command prompt from the list and press ENTER.

Boot your computer in Safe Mode with Command Prompt

2. When command prompt mode loads enter the following line: net user removevirus /add and press ENTER.

3. Next enter this line: net localgroup administrators removevirus /add and press ENTER.

creating new user using command prompt

4. Finnaly enter this line: shutdown -r and press ENTER.

adding a new user in command prompt

5. Wait for your computer to restart,  then boot your PC in Normal Mode and login to the newly created user account ("removevirus"). This account won't be affected by the ransomware infection and you will be able to download and install recommended anti-spyware software to eliminate this virus from your computer.

new user account created

6. Download and install recommended anti-spyware software to eliminate this ransomware infection from your computer:

remover for Interpol "Your computer has been blocked" virus

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. We are affiliated with anti-virus and anti-spyware software listed on this site. All the products we recommend were carefully tested and approved by our technicians as being one of the most effective solutions for removing this threat.

If the newly created user account is also affected by the ransomware infection try doing a System Restore:

1. Start your computer in Safe Mode with Command Prompt - During your computer starting process press F8 key on your keyboard multiple times until Windows Advanced Options menu shows up, then select Safe mode with command prompt from the list and press ENTER.

Boot your computer in Safe Mode with Command Prompt

2. When command prompt mode loads enter the following line: cd restore and press ENTER.

system restore using command prompt type cd restore

3. Next type this line: rstrui.exe and press ENTER.

system restore using command prompt rstrui.exe

4. In the opened window click "Next".

restore system files and settings

5. Select one of the available restore point and click "Next" (this will restore your computer's system to an earlier time and date, before the ransomware infiltrated your PC).

select a restore point

6. In the opened window click "Yes".

run system restore

7. After restoring your computer to a previous date download and scan your PC with a recommended anti-spyware software to eliminate any left remnants of Interpol "Your computer has been blocked" ransomware.

Notice that some ransomware infections are capable of encrypting all the files that were stored on an infected PC. If you are dealing with such infection you can use some of the tools listed below to decrypt your files.

To regain control of your files (decrypt) try using these tools:

RannohDecryptor (Kaspersky)

XoristDecryptor (Kaspersky)

RectorDecryptor (Kaspersky)

Trojan.Winlock decoding utility (Dr.Web)

Alternative Interpol "Your computer has been blocked" scam removal guide:

If this ransomware blocks your screen when you start your computer in safe mode with networking, try starting your PC in safe mode with command prompt.

1. During your computer starting process press F8 key on your keyboard multiple times until Windows Advanced Options menu shows up, then select Safe mode with command prompt from the list and press ENTER.

win 7 safe mode with command prompt

2. In the opened command prompt type explorer and press Enter. This command will open explorer window, don't close it and continue to the next step.

3. In the command prompt type regedit and press Enter. This will open the registry editor window.

4. In the registry editor window you should navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

registy editor winlogon

5. In the right side of the window locate "Shell" and right click on it. Click on Modify. The default value data is Explorer.exe if you see something else written in this window remove it and type in Explorer.exe (you can write down whatever else was written in the value data section - this is a path of the rogue execution file) - use this information to navigate to the rogue executable and remove it.

6. Restart your computer, download and install a legitmate anti-spyware software and perform a full system scan to eliminate any left remnants of Interpol "Your computer has been blocked" scam.

remover for Interpol "Your computer has been blocked" scam

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. We are affiliated with anti-virus and anti-spyware software listed on this site. All the products we recommend were carefully tested and approved by our technicians as being one of the most effective solutions for removing this threat.

If you can't start your computer in safe mode with networking (or with command prompt) you should boot your computer using a rescue disk. Some variants of ransomware disables safe mode making it's removal more complicated. For this step you will need access to another computer. After removing Interpol "Your computer has been blocked" scam from your PC restart your computer and scan it with a legitimate antispyware software to remove any possibly left remnants of this security infection.

Other tools known to remove Interpol "Your computer has been blocked" ransomware:

Some malicious software modifies browser settings and disables downloads of spyware and virus removing software. If you have problems downloading anti-spyware software with Internet Explorer, try downloading with Chrome, FireFox, Opera, etc.

If you can't access Internet:

Load your computer in safe mode. Click Start, click Shut down, click Restart, click OK. During your computer starting process press F8 key on your keyboard multiple times until you see Windows Advanced Option menu, then select Safe mode with networking from the list.

Start Task manager. Press ctrl+alt+del (or ctrl+shift+esc) and end task the processes of rogue program. ( if after this procedure you can't access any programs press ctrl+alt+del, click File, select New Task, and type explorer.exe then press OK.

Open Internet explorer, click Tools and select Internet Options. Select Connections, then click LAN settings, if a Use a proxy server for your LAN is checked, un-check it and press OK.

After this procedure you should be able to access Internet. Now you can download anti-spyware software from our "Top spyware removers" section and run a full scan. Download, install and don't forget to update your selected anti-spyware program.

Manual Interpol "Your computer has been blocked" ransomware removal:

If you were unable to remove Interpol "Your computer has been blocked" scam using the steps above, you can use this manual removal instruction. Use it at your own risk. If you don't have strong computer knowledge you could harm your operating system. Be careful and use it only if you are an experienced computer user. (Instructions on how to end processes, remove registry entries...)

End these processes:

random.exe

Delete these files:

%Temp%\<random>.exe
%StartupFolder%\ctfmon.lnk

If you can't start your computer in safe mode you can try booting your computer using a rescue disk. In some cases this is the only way how you can eliminate ransomware from your computer. When testing this screen locker it didn't encrypt any files, thought if in your case your files are encrypted you should use Kaspersky's Rannoh Decryptor to decrypt your files.

Comments 

 
#9 admin 2013-04-19 08:11
Hi Kara-Lee, messages which locks computer user's screen are called ransomware viruses. They are created by Cyber criminals. To remove the one that infected your computer use this removal guide http://www.pcrisk.com/removal-guides/6813-remove-australian-federal-police-scam
Quote
 
 
#8 Kara-Lee 2013-04-19 04:30
Hi
I just got this last night it said that i was violating a law and locked my computer and to pay $100 through epay or ukash in 72 hours. It had the australian federal logo on it and the interpol logo on it. I was not sure if it was a scam so i did ths and now the screen of my computer is white.
Was it real or fake and what should i do????
Quote
 
 
#7 Stephen Innes 2013-01-19 19:57
I just went in to watch a football match and this ransomware came apon me! Kodos to the Bastards it does look good but thank god I looked up on Google and came across this info!!! I just can't get into my pc at all but now and windows came up with its own rescue file,I clicked on what it said,along the lines of "Windows knows there is a block on the start up menu and click on a recovery file (recommended) but as we speak it didn't work so I've now got my work cut out !! I knew I should have made a back up disk!!!
Quote
 
 
#6 admin 2012-12-07 13:52
Hi Parivash, sometimes the only possible solution to remove ransomware infection is using a rescue disk. Try using these instructions: http://www.pcrisk.com/computer-technician-blog/general-information/6775-how-to-boot-your-computer-using-a-rescue-disk
Quote
 
 
#5 Parivash 2012-12-07 12:35
my regedit window will not open in command prompt what can i do?plz help
Quote
 
 
#4 admin 2012-11-17 21:52
Hi Martin, such situation may occur if your system is infected with some Trojan downloader or a rootkit infection. After getting rid of this scam be sure to run a full system scan of your computer hard disk drives.
Quote
 
 
#3 Martin 2012-11-17 14:10
Tried several ways now, and got rid of it several ways, but as soon as I connect back to the internet on my laptop in normal mode, it pops back up. Any idea whats actually causing this?
Quote
 
 
#2 rascal 2012-10-31 06:55
Thank you so much for this info. Had a nanosecond of panic until I realised they were asking for money. Duh! I booted in safe mode and ran my BT NetProtect McAfee scan but it detected nothing...didnt stop the damn scam in the first instance either...so much for protection! I downloaded the free version of Malwarebyes and it caught it within moments. Back to normal and no more problems. Many thanks again
Quote
 
 
#1 Mike Magnatta 2012-10-08 03:42
Thanks for the information on this SCAM, it had me going for a few minutes, until I realized they were trying to con people out of money. Here is what I did to get my machine to boot - booted to Safe mode with command prompt(could not get to main screen in safe mode. Once i had prompt > msconfig - takes you to system configuration menu - select Tools tab the highlight "System Restore" and hit Launch button. Set the restore back to a point before the infection. This should give the computer back to you. Then download the Stopzilla or your choice of malware protection to clean the computer.
Quote
 

Add comment

PCrisk.com is not responsible for the content of the comments.


Security code
Refresh