FacebookTwitterLinkedIn

Interpol Virus - Your computer has been blocked

Also Known As: Interpol Ransomware
Damage level: Severe

What is Interpol Virus - Your computer has been blocked?

Interpol "Your computer has been blocked" is ransomware created by Cybercriminals. This is a scam, which asks unsuspecting PC users to pay a bogus fine of 100 Euros to unblock their computers.

The text within this misleading screen locker reports that you have been violating the law by distributing illegal content. In fact, no authorities use computer screen lockers to collect fines for any law violations - this message is displayed with the sole purpose of scaring computer users for financial gain.

To make this message appear authentic, Cyber criminals incorporate a video recording window within their ransomware. Furthermore, this message displays your IP address, ISP, and a current date.

This message is fake; do not pay any fines to unblock your PC. If you closely study the message issued by this ransomware, you will notice poorly-translated text and sentences that make little or no sense.

Recently, ransomware infections have become popular among Cyber criminals, and they tend to exploit the names of trusted authorities (such as the FBI, Interpol, etc.) within their fake screen lockers. You can read more about this misleading ransomware business model at the Krebs on Security website.

Do not pay this bogus fine to unblock your computer - you will send your money to Cyber criminals.

Interpol Interpol virus alt fake Interpol ranosmware screen locker

Like other ransomware, Interpol "Your computer has been blocked" is proliferated using Trojans and Java exploits. To prevent your computer becoming infected with ransomware and other malware, always update your operating system and installed software regularly.

Also use legitimate antivirus and anti-spyware programs. Cyber criminals use Ukash and paysafecard for money transactions, making it difficult to track them.

If you see this fake Interpol message on your computer, use this removal guide to help you unblock your PC.

A fake message displayed in Interpol "Your computer has been blocked" ransomware:

Interpol Department of Cybercrime.
Attention!
Your computer is blocked due at least one of the reasons specified below:
You have been violating Copyright and Related Rights Law (Video, Music, Software) and illegally using or distributing copyrighted content, thus infringing Article 128 of the Criminal Code of Great Britain. Article 128 of the Criminal Code provides for a fine of two to five hundred minimal wages or a deprivation of liberty for two to eight years. You have been viewing or distributing prohibited Pornographic content (Child Porno/Zoofilia and etc). Thus violating article 202 of the Criminal Code of Great Britain. Article 202 of the Criminal Code provides for a deprivation of liberty for four to twelve years.. Illegal access to computer data has been initiated from your PC, or you have been.... Article 208 other Criminal Code provides for a fine of up to 100,000 and/or a deprivation of liberty for four to nine years. Illegal access has been initiated from your PC without your knowledge or consent, your PC may be infected by malware, thus you are violating the law of On Neglectful Use of Personal Computer. Article 210 of the Criminal Code provides for a fine of 2000 to 8000 euro...

Instant automatic malware removal: Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
▼ DOWNLOAD Combo Cleaner By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.

Quick menu:

Interpol Virus "Your computer has been blocked" removal:

Step 1

Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK.

During your computer starting process press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, then select Safe Mode with Networking from the list.

alt

Video showing how to start Windows 7 in "Safe Mode with Networking":

Step 2

Log in to the account infected with Interpol Virus "Your computer has been blocked". Start your Internet browser and download a legitimate anti-spyware program.

Update the anti-spyware software and start a full system scan. Remove all the entries detected.

Cannot boot in Safe Mode with Networking? (Interpol Virus "Your computer has been blocked" blocks Safe Mode with Networking)

If you have more than one user account in your operating system - please log-in to the clean account and download the recommended malware removal software, install it and run a full system scan, remove all the security infections detected. If, however, you have only one user account, please follow this guide (this guide demonstrates how to create a new user account using Safe Mode with Command Prompt - using this newly created user account, you will be able to remove "Interpol "Your computer has been blocked" virus).

If "Interpol "Your computer has been blocked" virus also blocks your operating system's Safe Mode with Networking, follow these removal instructions:

1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.

Boot your computer in Safe Mode with Command Prompt

2. When Command Prompt mode loads, enter the following line: net user removevirus /add and press ENTER.

alt

3. Next, enter this line: net localgroup administrators removevirus /add and press ENTER.

creating new user using command prompt

4. Finally, enter this line: shutdown -r and press ENTER.

adding a new user in command prompt

5. Wait for your computer to restart, boot your PC in Normal Mode, and then login to the newly created user account ("removevirus"). This account will not be affected by the ransomware infection and you will be able to download and install recommended malware removal software to eliminate this virus from your computer.

new user account created

6. Download and install recommended malware removal software to eliminate this ransomware infection from your computer:

If the newly-created user account is also affected by the ransomware infection, try performing a System Restore:

Video showing how to remove ransomware virus using "Safe Mode with Command Prompt" and "System Restore":

1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.

Boot your computer in Safe Mode with Command Prompt

2. When Command Prompt mode loads, enter the following line: cd restore and press ENTER.

system restore using command prompt type cd restore

3. Next, type this line: rstrui.exe and press ENTER.

system restore using command prompt rstrui.exe

4. In the opened window, click "Next".

restore system files and settings

5. Select one of the available restore points and click "Next" (this will restore your computer's system to an earlier time and date, prior to the ransomware infiltrating your PC).

select a restore point

6. In the opened window, click "Yes".

run system restore

7. After restoring your computer to a previous date, download and scan your PC with recommended malware removal software to eliminate any remnants of Interpol "Your computer has been blocked" ransomware.

Some ransomware infections are capable of encrypting all files stored on an infected PC. If you are dealing with such an infection, you can use some of the tools listed below to decrypt your files.

To regain control of your files (decrypt) try using these tools:

RannohDecryptor (Kaspersky)

XoristDecryptor (Kaspersky)

RectorDecryptor (Kaspersky)

Trojan.Winlock decoding utility (Dr.Web)

Alternative Interpol Virus "Your computer has been blocked" removal guide:

If this ransomware blocks your screen when you start your computer, in Safe Mode with networking, try starting your PC in Safe Mode with Command Prompt.

1. During your computer starting process, press the F8 key on your keyboard multiple times until the Windows Advanced Options menu appears, and then select Safe Mode with Command Prompt from the list and press ENTER.

win 7 safe mode with command prompt

2. In the opened Command Prompt, type explorer and press Enter. This command will open the explorer window.

Do not close it, and continue to the next step.

3. In the Command Prompt, type regedit and press Enter. This will open the Registry Editor window.

4. In the Registry Editor window, navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

registy editor winlogon

5. In the right side of the window, locate "Shell" and right click on it. Click on Modify.

The default value in the Data column is Explorer.exe - if you see something else displayed in this window, remove it and type Explorer.exe (take a note of whatever else was displayed in the Data column - this is the path of the rogue execution file). Use this information to navigate to the rogue executable and remove it.

6. Restart your computer, download and install legitimate anti-spyware software and perform a full system scan to eliminate any remnants of Windows Anytime Upgrade scam.

If you cannot start your computer in Safe Mode with Networking (or with Command Prompt), boot your computer using a rescue disk. Some variants of ransomware disable Safe Mode, making its removal more complicated.

For this step, you need access to another computer. After removing Interpol "Your computer has been blocked" scam from your PC, restart your computer and scan it with legitimate antispyware software to remove any possible remnants of this security infection.

▼ Show Discussion

About the author:

Tomas Meskauskas

Tomas Meskauskas - expert security researcher, professional malware analyst.

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats. Contact Tomas Meskauskas.

PCrisk security portal is brought by a company RCS LT. Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Removal Instructions in other languages
Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

QR Code
Interpol Ransomware QR code
Scan this QR code to have an easy access removal guide of Interpol Ransomware on your mobile device.
We Recommend:

Get rid of Windows malware infections today:

▼ REMOVE IT NOW
Download Combo Cleaner

Platform: Windows

Editors' Rating for Combo Cleaner:
Editors ratingOutstanding!

[Back to Top]

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by Rcs Lt, the parent company of PCRisk.com read more.