FacebookTwitterLinkedIn

Ured Za Posebne Poslove Sigurnosti Virus

Also Known As: Ured Za Posebne Poslove Sigurnosti Ransomware
Damage level: Severe

What is Ured Za Posebne Poslove Sigurnosti?

The Ured Za Posobne Poslove Sigurnosti (Croatian Police) message, "Vaš kompjuter je blokiran zbog barem jednoga od razioga navedenog u nastavku", blocks the computer user's screen and demands payment of a 100 Euro (or 500 HRK) fine. This is a scam.

If you observe this message on your computer screen, your PC is infiltrated with a ransomware virus, which makes false accusations of law violations such as watching child pornography, being in possession of pirated copies of music and video files, etc. This is in order to trick you into paying a bogus fine.

Note that paying this fine, using Ukash or paysafecard when requested by this message, is equivalent to sending your money to cyber criminals. This ransomware virus originates from a family called "Urausy" and targets PC users predominantly from Croatia.

Internet users should be aware that no legitimate authorities, including Ured Za Posobne Poslove Sigurnosti, use screen-blocking messages to collect fines for any law violations.

Ured Za Posebne poslove Sigurnosti Virus

Rogue messages, which appear at system start-up and disable the Task Manager and other Windows features, are known as 'ransomware' and are widely used by cyber criminals to extort money from unsuspecting PC users.

To make the deceptive messages appear authentic, cyber criminals develop the ransomware with an IP-detection feature to allow it to determine the location of the computer targeted for infection. This allows the software to present each victim with a localized variant of the screen-blocking message.

The Ured Za Posobne Poslove Sigurnosti message is a scam - do not trust this message or you will lose your money to cyber criminals.

Ured Za Posobne Poslove Sigurnosti is just one of many authority names, which are exploited by cyber criminals responsible for creating ransomware viruses from the Urausy family.

Other known localized variants of this scam exploit the names of the FBI Cybercrime Division (targeting PC users from USA), AFP (targeting PC users from Australia), RCMP (targeting PC users from Canada), amongst many others. Commonly, ransomware viruses are proliferated using 'exploit kits' (BlackHole), which infiltrate users' operating systems through infected email messages, malicious websites, and drive-by downloads.

The method exploits any detected security vulnerabilities within the system, and therefore, the best way to protect your PC is by keeping the operating system and installed software up-to-date. If your computer is already infected with the Ured Za Posobne Poslove Sigurnosti ransomware virus, use the removal guide provided to eliminate this scam.

A fake message displayed by the Ured Za Posobne Poslove Sigurnosti ransomware virus:

URED ZA POSEBNE POSLOVE SIGURNOSTI.
PAŽNJA! Vaš kompjuter je blokiran zbog barem jednoga od razioga navedenog u nastavku. Tu su kršenja "autorskom pravu i srodnim pravima u području prava,, (video, glazba, softver) i protuzakonito korištenje ili distribuiranje sadrzaja zaštićenih autorskim pravima, čime se krši članak 128. Krivičnog Zakona Republike Hrvatske. Članak 128. Krivičnog Zakona predvida novčane kazne od 200 do 500 minimainih mjesečnih plaća ili oduzimanjem slobode od 2 do 8 godina. Gledanje ili distribuiranje pornografskog sadrzaja je zabranjeno (Dječja pornografija/Zoofilija i tako slično). Tako se krši članak 202 Krivičnog Zakona Republike Hrvatske. Članak 202. Krivičnog Zakona predvida oduzimanje slobode od 4 do 12 godina. Ilegalni pristup kompjuterskih podataka je pokrenut sa kompjutera ili ste pokrenuli... Članak 208. Krivičnog Zakona predvida novčanu kaznu do HRK 100.000 ili oduzimanjem slobode od 4 do 9 godina. Ilegalni pristup je pokrenut sa kompjutera bez vaseg znanja ili pristanka, vas kompjuter može biti zaražen zionamjeran softverom, tako da se krši Zakon o nemarnom korištenju osobnog kompjutera.
Članak 210. Krivičnog zakona predvida novčane kazne od HRK 2.000 do HRK 8.000. Spam ili drugo širenje ilegalne reklame bilo je učinjeno sa vašeg kompjutera sa ciljem dobitka ili bez vašeg znanja, vaš kompjuter može biti zaražen štetnim programima. Članak 212. Krivičnog Zakona predvida novčanu kaznu do HRK 250.000 i oduzimanje slobode do 6 godina. U slučaju da je ova aktivnost izvrsena bez vaseg znanja, što potpada pod spomenutom člankom 210. Krivičnog Zakona Republike Hrvatske. Vaša osobnost i adresa trenutno identificirani, kažnjeni postupak de se pokrenuti protiv vas od jedan ili više navedenih gore članaka u narednih 72 sati. Temeljem izmjena i dopuna Krivičnog Zakona Republike Hrvatske od 04. veljače 201 3 je kršenje zakona (ako se ne ponovi- prvi put) može se smatrati uvjetno u slučaju ako se plati novčana kazna državi. Kazne mogu biti plaćeni u roku od 72 sati nakon povrede. Čim 72 sati protekne, mogućnost platiti kaznu istekne, a kazneni postupak protiv vas automatski se pokreće u narednih 72 sati. Iznos novčane kazne je HRK 500 ili €100. Mozete platiti kaznu preko PaySafeCard ili Ukash. Kada ćete platiti kaznu vaš kompjuter de biti otključan od 1 do 72 sati nakon primitka sredstava nametnutih na državni račun.

Instant automatic malware removal: Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
▼ DOWNLOAD Combo Cleaner By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.

Quick menu:

Ured Za Posobne Poslove Sigurnosti virus removal:

Step 1

Windows XP and Windows 7 users: Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK. During your computer starting process press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, then select Safe Mode with Networking from the list.

Safe Mode with Networking

Video showing how to start Windows 7 in "Safe Mode with Networking":

Windows 8 users: Go to the Windows 8 Start Screen, type Advanced, in the search results select Settings. Click on Advanced Startup options, in the opened "General PC Settings" window select Advanced Startup. Click on the "Restart now" button. Your computer will now restart into "Advanced Startup options menu".

Click on the "Troubleshoot" button, then click on "Advanced options" button. In the advanced option screen click on "Startup settings". Click on the "Restart" button. Your PC will restart into the Startup Settings screen. Press "5" to boot in Safe Mode with Networking.

Windows 8 Safe Mode with networking

Video showing how to start Windows 8 in "Safe Mode with Networking":

Step 2

Log in to the account infected with the Ured Za Posobne Poslove Sigurnosti virus. Start your Internet browser and download a legitimate anti-spyware program. Update the anti-spyware software and start a full system scan. Remove all entries detected.


If you cannot start your computer in Safe Mode with Networking, try performing a System Restore.

Video showing how to remove ransomware virus using "Safe Mode with Command Prompt" and "System Restore":

1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.

Boot your computer in Safe Mode with Command Prompt

2. When Command Prompt Mode loads, enter the following line: cd restore and press ENTER.

system restore using command prompt type cd restore

3. Next, type this line: rstrui.exe and press ENTER.

system restore using command prompt rstrui.exe

4. In the opened window click "Next".

restore system files and settings

5. Select one of the available Restore Points and click "Next" (this will restore your computer system to an earlier time and date, prior to the Ured Za Posobne Poslove Sigurnosti ransomware virus infiltrating your PC).

select a restore point

6. In the opened window click "Yes".

run system restore

7. After restoring your computer to a previous date, download and scan your PC with recommended malware removal software to eliminate any remnants of the Ured Za Posobne Poslove Sigurnosti virus.

If you cannot start your computer in Safe Mode with Networking (or with Command Prompt), boot your computer using a rescue disk. Some variants of ransomware disable Safe Mode making its removal complicated. For this step, you require access to another computer.

After removing the Ured Za Posobne Poslove Sigurnosti virus from your PC, restart your computer and scan it with legitimate antispyware software to remove any possible remnants of this security infection.

Other tools known to remove the Ured Za Posobne Poslove Sigurnosti virus:

▼ Show Discussion

About the author:

Tomas Meskauskas

Tomas Meskauskas - expert security researcher, professional malware analyst.

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats. Contact Tomas Meskauskas.

PCrisk security portal is brought by a company RCS LT. Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

QR Code
Ured Za Posebne Poslove Sigurnosti Ransomware QR code
Scan this QR code to have an easy access removal guide of Ured Za Posebne Poslove Sigurnosti Ransomware on your mobile device.
We Recommend:

Get rid of Windows malware infections today:

▼ REMOVE IT NOW
Download Combo Cleaner

Platform: Windows

Editors' Rating for Combo Cleaner:
Editors ratingOutstanding!

[Back to Top]

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.