Interpol Virus - Your computer has been blocked
Written by Tomas Meskauskas on (updated)
What is Interpol Virus - Your computer has been blocked?
Interpol "Your computer has been blocked" is ransomware created by Cybercriminals. This is a scam, which asks unsuspecting PC users to pay a bogus fine of 100 Euros to unblock their computers.
The text within this misleading screen locker reports that you have been violating the law by distributing illegal content. In fact, no authorities use computer screen lockers to collect fines for any law violations - this message is displayed with the sole purpose of scaring computer users for financial gain.
To make this message appear authentic, Cyber criminals incorporate a video recording window within their ransomware. Furthermore, this message displays your IP address, ISP, and a current date.
This message is fake; do not pay any fines to unblock your PC. If you closely study the message issued by this ransomware, you will notice poorly-translated text and sentences that make little or no sense.
Recently, ransomware infections have become popular among Cyber criminals, and they tend to exploit the names of trusted authorities (such as the FBI, Interpol, etc.) within their fake screen lockers. You can read more about this misleading ransomware business model at the Krebs on Security website.
Do not pay this bogus fine to unblock your computer - you will send your money to Cyber criminals.
Like other ransomware, Interpol "Your computer has been blocked" is proliferated using Trojans and Java exploits. To prevent your computer becoming infected with ransomware and other malware, always update your operating system and installed software regularly.
Also use legitimate antivirus and anti-spyware programs. Cyber criminals use Ukash and paysafecard for money transactions, making it difficult to track them.
If you see this fake Interpol message on your computer, use this removal guide to help you unblock your PC.
A fake message displayed in Interpol "Your computer has been blocked" ransomware:
Interpol Department of Cybercrime.
Attention!
Your computer is blocked due at least one of the reasons specified below:
You have been violating Copyright and Related Rights Law (Video, Music, Software) and illegally using or distributing copyrighted content, thus infringing Article 128 of the Criminal Code of Great Britain. Article 128 of the Criminal Code provides for a fine of two to five hundred minimal wages or a deprivation of liberty for two to eight years. You have been viewing or distributing prohibited Pornographic content (Child Porno/Zoofilia and etc). Thus violating article 202 of the Criminal Code of Great Britain. Article 202 of the Criminal Code provides for a deprivation of liberty for four to twelve years.. Illegal access to computer data has been initiated from your PC, or you have been.... Article 208 other Criminal Code provides for a fine of up to 100,000 and/or a deprivation of liberty for four to nine years. Illegal access has been initiated from your PC without your knowledge or consent, your PC may be infected by malware, thus you are violating the law of On Neglectful Use of Personal Computer. Article 210 of the Criminal Code provides for a fine of 2000 to 8000 euro...
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
▼ DOWNLOAD Combo Cleaner
By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.
Quick menu:
- What is Interpol Virus - Your computer has been blocked?
- STEP 1. "Interpol Virus - Your computer has been blocked" removal using safe mode with networking.
- STEP 2. "Interpol Virus - Your computer has been blocked" removal using safe mode with command prompt.
- STEP 3. "Interpol Virus - Your computer has been blocked" ransomware removal using System Restore.
- STEP 4. Remove "Interpol Virus - Your computer has been blocked" manually editing registry entries.
Interpol Virus "Your computer has been blocked" removal:
Step 1
Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK.
During your computer starting process press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, then select Safe Mode with Networking from the list.
Video showing how to start Windows 7 in "Safe Mode with Networking":
Step 2
Log in to the account infected with Interpol Virus "Your computer has been blocked". Start your Internet browser and download a legitimate anti-spyware program.
Update the anti-spyware software and start a full system scan. Remove all the entries detected.
Cannot boot in Safe Mode with Networking? (Interpol Virus "Your computer has been blocked" blocks Safe Mode with Networking)
If you have more than one user account in your operating system - please log-in to the clean account and download the recommended malware removal software, install it and run a full system scan, remove all the security infections detected. If, however, you have only one user account, please follow this guide (this guide demonstrates how to create a new user account using Safe Mode with Command Prompt - using this newly created user account, you will be able to remove "Interpol "Your computer has been blocked" virus).
If "Interpol "Your computer has been blocked" virus also blocks your operating system's Safe Mode with Networking, follow these removal instructions:
1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.
2. When Command Prompt mode loads, enter the following line: net user removevirus /add and press ENTER.
3. Next, enter this line: net localgroup administrators removevirus /add and press ENTER.
4. Finally, enter this line: shutdown -r and press ENTER.
5. Wait for your computer to restart, boot your PC in Normal Mode, and then login to the newly created user account ("removevirus"). This account will not be affected by the ransomware infection and you will be able to download and install recommended malware removal software to eliminate this virus from your computer.
6. Download and install recommended malware removal software to eliminate this ransomware infection from your computer:
If the newly-created user account is also affected by the ransomware infection, try performing a System Restore:
Video showing how to remove ransomware virus using "Safe Mode with Command Prompt" and "System Restore":
1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.
2. When Command Prompt mode loads, enter the following line: cd restore and press ENTER.
3. Next, type this line: rstrui.exe and press ENTER.
4. In the opened window, click "Next".
5. Select one of the available restore points and click "Next" (this will restore your computer's system to an earlier time and date, prior to the ransomware infiltrating your PC).
6. In the opened window, click "Yes".
7. After restoring your computer to a previous date, download and scan your PC with recommended malware removal software to eliminate any remnants of Interpol "Your computer has been blocked" ransomware.
Some ransomware infections are capable of encrypting all files stored on an infected PC. If you are dealing with such an infection, you can use some of the tools listed below to decrypt your files.
To regain control of your files (decrypt) try using these tools:
Trojan.Winlock decoding utility (Dr.Web)
Alternative Interpol Virus "Your computer has been blocked" removal guide:
If this ransomware blocks your screen when you start your computer, in Safe Mode with networking, try starting your PC in Safe Mode with Command Prompt.
1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.
2. In the opened Command Prompt, type explorer and press Enter. This command will open the explorer window.
Do not close it, and continue to the next step.
3. In the Command Prompt, type regedit and press Enter. This will open the Registry Editor window.
4. In the Registry Editor window, navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
5. In the right side of the window, locate "Shell" and right click on it. Click on Modify.
The default value in the Data column is Explorer.exe - if you see something else displayed in this window, remove it and type Explorer.exe (take a note of whatever else was displayed in the Data column - this is the path of the rogue execution file). Use this information to navigate to the rogue executable and remove it.
6. Restart your computer, download and install legitimate anti-spyware software and perform a full system scan to eliminate any remnants of Windows Anytime Upgrade scam.
If you cannot start your computer in Safe Mode with Networking (or with Command Prompt), boot your computer using a rescue disk. Some variants of ransomware disable Safe Mode, making its removal more complicated.
For this step, you need access to another computer. After removing Interpol "Your computer has been blocked" scam from your PC, restart your computer and scan it with legitimate antispyware software to remove any possible remnants of this security infection.
▼ Show Discussion