Question:
Metropolitan police virus help!?
Annabel M
2012-09-24 07:39:15 UTC
I have a virus on my computer that says if you dont pay the met police £100 then ur computer will stay blocked. Anyway I no its a scam but I can't get it off my comp. I've tried to do the system restore but for some reason it won't work it won't let me go back. So any help on how to get rid of this would help. Oh and I have norton security which has says that it has removed and virus's etc but it hasn't!?
Eleven answers:
sewrobb
2012-09-24 08:28:25 UTC
If Norton said that it had been removed have you checked the Quarantine Folder?



If it is in there, then just delete it.



Actually if you had clicked on it like most people do in a panic, your computer would

have been actually locked or just allowed sufficient control to pay the "Fine"

to release it. After all a flea or leech will not totally disable or kill it's host!



Which then comes back to the Restore Points. Is your Restore actually turned on?



Also you have a misconception about Restore. It is meant to restore the Registry entries.



It will not remove viruses.
?
2016-08-24 02:00:16 UTC
2
2016-08-02 02:19:44 UTC
Congrats, you simply received one of the hazardous viruses ever recognized in history. This virus is a ransomware where a false message pops up wherein it tells you, you did these crimes. They will ask you to pay 100 euro so your monitor will also be "unlocked." although the message could be rather long, i'll promise you, when you read this, you will thoroughly do away with the virus and be virus free. :) What you first must do, is to restart your pc. Once that is ready, you have to wait on the proper second. You could discover by way of urgent F8 repeatedly correct earlier than it suggests the windows/apple logo on the screen. What you wish to have to do next is: they are going to show you a menu displaying which mode you need to head on, or if you wish to do procedure repair. Do not DO procedure restore!!! In an effort to DELETE all of your files AND it is horrible!!! I inspire YOU to not PRESS THAT BUTTON!!! Choose dependable mode on your laptop. When you get there, it should exhibit a computing device with an unfamiliar wallpaper display. Press and hold windows key+R. Here, form in the box, MSCONFIG. On the record on the left, they are going to exhibit you a suite of important databases. First, you need to move to your listing force. Then whenever you get there, there will be a file that says records and Settings. Click on on the file. There might be a few more files if you open it, click on on the file that indicates your user identify. Click on that file. Then, go to application data. If you get there, click on gizza, but something variant your making use of, it can be one of a kind. Nonetheless it can be the first file, and they are able to both be the identical. However, if it is not, preserve on browsing to peer if it's there. That you could check that by way of watching throughout the file, and checking to see if it has ip.Txt and percentbmp. Let's get to the point. Once you get there, go away the file, and delete the "gizza" file or whatever it is named. Go back over again. If you left, go to regional Settings. Then you'll go to the Temp file. Once you get there, you can records which have random numbers and textual content then.Tmp as the title. You'll be able to must delete every single one of those files. Once you have finished that, you may want to go to the records and Settings file again. You could take a shortcut by means of looking on the list to your left, and clicking documents and Settings. If you have long past there, click on the All customers file. Then, go to local Settings, then Temp, and you'll see a file that says msdubm.Exe. Once more, the file name can exchange considering of the variation you might be making use of. However, while you get there, delete that file. That's the virus that is causing all the commotion. Go to autoruns.. When you get there, there may also be some matters in which it may be quite complicated. Some of these can also be very most important documents. Look on the description of the file. I are not able to tell you the file in view that there are various ransomware that is just like the one you are dealing with. As soon as you know that it's the virus, delete it. Be careful! In case you DELETE THE mistaken FILE, YOU could end YOUR pc'S existence AS WE realize it! Now, there can even be a file. It's going to say 21867. Delete that file. You have got efficiently deleted the area records. I will provide an explanation for extra. As soon as you could have deleted these records, exit the window. Then, restart. It might crash normally but that is a good signal. As soon as you have finished that, it may well both free up you back to your long-established windows person, or it might crash and inform you that the computer didn't restart effectually. Go to home windows frequently and press that. You could've deleted the area records for the virus, but you didn't dispose of all of it but. ***I recommend MALWAREBYTES AND HITMANPRO FOR THIS STEP once you have got downloaded the encouraged anti-malware application. Go to each of those and do a full scan. Once they've detected the other secret records, your laptop is nontoxic now. You'll ought to do a different reboot. As soon as you will have finished that, the virus is effectively gone!! HURRAY!! The quality answer shown on here is not particularly precise and unique so I confirmed a more certain message right here. Hope this helped you :)
♁ღĐⱤɄ₲₲łɆ ₴Ʉ₵Ɏღ♁
2012-09-24 07:45:21 UTC
Removal Instructions:

http://deletemalware.blogspot.com/2011/06/remove-metropolitan-police-ransomware.html
2012-09-24 10:45:52 UTC
This video may prove useful. It uses Kaspersky rescue Disk 10:



http://www.youtube.com/watch?v=5Ws2IcM4CMA



If the video didn't help, the following procedure also uses Kaspersky Rescue Disk 10, then employs the WindowsUnlocker feature.



There are simpler fixes for SOME of the ransomware infections, but this should work with all forms of ransomware...even those that disable all Safe Mode options, plus Regedit and Task Manager, etc....



Use a working computer to download and burn the Kaspersky Rescue Disk 10 .ISO file. Burn the file to a CD or DVD or flash drive, then use it to boot your infected computer. Once at the desktop, use the WindowsUnlocker feature.



This link is for the download of Kaspersky Rescue Disk 10. It's primarily designed to boot and disinfect computers that have been rendered unbootable due to an infection, but it's fine to use it on an uninfected machine. The .ISO file is 262MB in size, and it's easier to burn it to a CD or DVD than a flash drive, but the link does includes instructions on how to burn the file to a flash drive (USB device):



http://support.kaspersky.com/viruses/rescuedisk



If you don't have burning software installed on the working computer, download and install Ashampoo Burning Studio 6. It's free, and I recommend it...I use it myself:



https://www.ashampoo.com/uk/gbp/pin/0710/0-Offline/Ashampoo-Burning-Studio-6



Start up Ashampoo and select Create/Burn Disc Images...then select Burn a CD/DVD/Blu-ray Disc from a Disc Image.



Burn the CD or DVD, and use it to boot your faulty computer. You may need to enter your BIOS (Setup), and change the boot sequence to boot from CD first, but this isn't always necessary.



As already stated...once the CD or DVD or flash drive has got you to a desktop, select the WindowsUnlocker feature. Once your computer is unlocked, scan it with your currently installed security product, or download a free one.



It should be noted that although certain ransomware pretends to encrypt some files, at least one example (West Yorkshire Police) actually does encrypt some files. In this case, you should use a decryptor utility supplied by Kaspersky Lab.



This video shows how to remove the West Yorkshire Police ransomware:



http://www.youtube.com/watch?v=1gwMhaJHwro



This link leads to the RannohDecryptor utility, from Kaspersky Lab:



http://support.kaspersky.com/faq/?qid=208286527



This WindowsUnlocker explanation and video link should also prove useful:



http://support.kaspersky.com/faq/?qid=208285998



http://www.youtube.com/watch?v=C5hvSlrOUlE



Hope this helps.
Skylinez
2012-09-24 07:42:56 UTC
The only way of removing it is by doing a factory reset. This kind of virus is too strong for most AV products. Take it to a computer repair shop so they can back up your data and perform the reset.
2014-07-15 17:38:39 UTC
I found a free download of Ashampoo Burning Studio here http://bit.ly/1rnRN5D.



Ashampoo Burning Studio 2013 is a great piece of burning and ripping software for anyone using physical discs.
2014-07-19 19:50:52 UTC
Adblock is an amazing sofware that will block all the boring pop-up and advertisement



I downloaded the last versione here http://j.mp/1pkhHFc
Kittysue
2012-09-24 07:53:27 UTC
If system restore won't work and Malwarebytes doesn't work then you have to take your computer to be professionally repaired
2012-09-24 07:46:09 UTC
malwarebytes.org has a really good free one which get rid of stuff and does not ask you to pay or download stupid crap. It gets rid of things that have attached themselves to the registry it is great. give it a go







http://www.malwarebytes.org/
Make Love not War
2012-09-24 07:39:53 UTC
Youtube

have lots of ways too show you gk :)


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...