FacebookTwitterLinkedIn

Removal instructions for the "Metropolitan Police" screen-locking virus

Also Known As: Metropolitan Police Ransomware
Damage level: Severe

What is the "Metropolitan Police" virus?

"Metropolitan Police - your computer was locked to stop your illegal activity!" is a ransomware computer infection. This fake message was created by Cyber criminals and blocks computer users from accessing their desktops.

This screen locker targets computer users from the United Kingdom. Recently, ransomware became popular amongst Cyber criminals who continue to create and distribute new versions of their misleading screen lockers.

To make their messages appear more authentic, Cyber criminals exploit the names of authorities, and in this case, use the Metropolitan Police. Other previously-released screen lockers use the names of the FBI and Interpol.

Furthermore, the creators of these rogue screen lockers are able to detect your computer's IP address and use this information to ensure the fake messages appear in your language. The message that blocks your desktop states that you have to pay a fine of £100 in order to unlock your PC. Do not pay this fine - it is a scam.

No authorities use screen lockers to collect fines for any violations. If you pay the fine, you will send your money to cyber criminals and your PC will remain infected.

Metropolitan Police Scam Metropolitan Police virus Metropolitan Police rogue program

"Metropolitan Police - your computer was locked to stop your illegal activity!" is merely another scam that attempts to trick unsuspecting PC users into paying a bogus fine.

Cyber criminals use Ukash and Paysafecard for money transactions, making it difficult to track them. If you see this type of message on your computer screen, use the removal guide provided to remove it and unlock your PC.

A fake message shown within the Metropolitan Police virus:

Metropolitan Police Working together for a safer London Location: United Kingdom.
This computer was locked to stop your illegal activity!
To unlock the computer you must pay a fine of 100 pounds.
You could pay the fine in two ways:
1) Paying by Ukash:
To do this, you should enter the 19 digits code in the payment form and press OK. (if you have several codes, enter them one after the other and press OK). If errors occur, send your IP address and payment code to email: info@online-cyber-police.com
2) Paying by Paysafecard:
To do this, you should enter the 19 digits code in the payment form and press OK. (if you have several codes, enter them one after the other and press OK). You could buy Ukash in many places: shops, stand-alone-terminals, online or via E-Wallet (electronic cash). Below you can find the list of points of sale of Ukash in United Kingdom...

Instant automatic malware removal: Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
▼ DOWNLOAD Combo Cleaner By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.

Quick menu:

Metropolitan Police virus removal:

Step 1

Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK.

During your computer starting process press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, then select Safe Mode with Networking from the list.

alt

Video showing how to start Windows 7 in "Safe Mode with Networking":

Step 2

Log in to the account infected with Metropolitan Police virus. Start your Internet browser and download a legitimate anti-spyware program.

Update the anti-spyware software and start a full system scan. Remove all the entries detected.

Cannot boot in Safe Mode with Networking? (Metropolitan Police virus blocks Safe Mode with Networking)

If you have more than one user account in your operating system - please log-in to the clean account and download the recommended malware removal software, install it and run a full system scan, and remove all the security infections detected.

If, however, you have only one user account, please follow this guide (it will demonstrate how to create a new user account using Safe Mode with Command Prompt - using this newly created user account, you will be able to remove Metropolitan Police ransomware).

If Metropolitan Police virus also blocks your operating system's Safe Mode with Networking, follow these removal instructions:

1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.

Boot your computer in Safe Mode with Command Prompt

2. When Command Prompt mode loads, enter the following line: net user removevirus /add and press ENTER.

alt

3. Next, enter this line: net localgroup administrators removevirus /add and press ENTER.

creating new user using command prompt

4. Finally, enter this line: shutdown -r and press ENTER.

adding a new user in command prompt

5. Wait for your computer to restart, boot your PC in Normal Mode, and then login to the newly created user account ("removevirus"). This account will not be affected by the ransomware infection and you will be able to download and install recommended malware removal software to eliminate this virus from your computer.

new user account created

6. Download and install recommended malware removal software to eliminate this ransomware infection from your computer:

If the newly created user account is also affected by the ransomware infection, try performing a System Restore:

Video showing how to remove ransomware virus using "Safe Mode with Command Prompt" and "System Restore":

1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.

Boot your computer in Safe Mode with Command Prompt

2. When Command Prompt mode loads, enter the following line: cd restore and press ENTER.

system restore using command prompt type cd restore

3. Next, type this line: rstrui.exe and press ENTER.

system restore using command prompt rstrui.exe

4. In the opened window, click "Next".

restore system files and settings

5. Select one of the available restore points and click "Next" (this will restore your computer's system to an earlier time and date, prior to the ransomware infiltrating your PC).

select a restore point

6. In the opened window, click "Yes".

run system restore

7. After restoring your computer to a previous date, download and scan your PC with recommended malware removal software to eliminate any remnants of Metropolitan Police ransomware.

Alternative Metropolitan Police virus removal guide:

If this ransomware blocks your screen when you start your computer in Safe Mode with Networking, try starting your PC in Safe Mode with Command Prompt.

1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.

win 7 safe mode with command prompt

2. In the opened command prompt type explorer and press Enter. This command will open explorer window.

Do not close it and continue to the next step.

3. In the Command Prompt type regedit and press Enter. This will open the Registry Editor window.

4. In the Registry Editor window, navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

registy editor winlogon

5. In the right side of the window, locate "Shell" and right click on it. Click on Modify.

The default value in the Data column is Explorer.exe - if you see something else displayed in this window, remove it and type Explorer.exe (take a note of whatever else was displayed in the Data column - this is the path of the rogue execution file). Use this information to navigate to the rogue executable and remove it.

6. Restart your computer, download and install legitimate anti-spyware software, and perform a full system scan to eliminate any remnants of Metropolitan Police scam.

If you cannot start your computer in Safe Mode with Networking (or with Command Prompt), boot your computer using a rescue disk. Some variants of ransomware disable Safe Mode, making its removal more complicated.

For this step, you need access to another computer. After removing Metropolitan Police scam from your PC, restart your computer and scan it with legitimate antispyware software to remove any possible remnants of this security infection.

Other tools known to remove Metropolitan Police virus:

If you continue having problems removing Metropolitan Police virus, or you cannot start your computer in Safe Mode, try booting your computer using a rescue disk. For this step you will need access to another computer.

Frequently Asked Questions (FAQ)

My computer is infected with Metropolitan Police malware, should I format my storage device to get rid of it?

No, Metropolitan Police malware removal does not require formatting.

What is the purpose of Metropolitan Police malware?

Metropolitan Police malware is designed to lock victims' devices and deceive them into paying the cyber criminals, who pretend to be the authorities.

Should I pay the ransom?

No, paying cyber criminals is ill-advised. Access to devices can be restored by removing the screen-locking malware. Furthermore, paying criminals supports their illegal activities.

How did Metropolitan Police malware infiltrate my computer?

Malware is primarily spread via drive-by (stealthy/deceptive) downloads, online scams, spam emails/messages, malvertising, untrustworthy download channels (e.g., freeware and third-party sites, Peer-to-Peer sharing networks, etc.), illegal program activation tools ("cracks"), and fake updates. Furthermore, some malicious programs can self-proliferate through local networks and removable storage devices (e.g., external hard drives, USB flash drives, etc.).

Will Combo Cleaner protect me from malware?

Yes, Combo Cleaner is capable of detecting and eliminating most of the known malware infections. Note that sophisticated malicious software typically hides deep within systems – therefore, performing a full system scan is paramount.

▼ Show Discussion

About the author:

Tomas Meskauskas

Tomas Meskauskas - expert security researcher, professional malware analyst.

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats. Contact Tomas Meskauskas.

PCrisk security portal is brought by a company RCS LT. Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

QR Code
Metropolitan Police Ransomware QR code
Scan this QR code to have an easy access removal guide of Metropolitan Police Ransomware on your mobile device.
We Recommend:

Get rid of Windows malware infections today:

▼ REMOVE IT NOW
Download Combo Cleaner

Platform: Windows

Editors' Rating for Combo Cleaner:
Editors ratingOutstanding!

[Back to Top]

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.