{"id":3222,"date":"2012-05-07T03:49:18","date_gmt":"2012-05-07T03:49:18","guid":{"rendered":"http:\/\/malwaretips.com\/blogs\/?p=3222"},"modified":"2012-12-01T09:40:12","modified_gmt":"2012-12-01T09:40:12","slug":"remove-your-computer-has-been-locked-ransomware","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/remove-your-computer-has-been-locked-ransomware\/","title":{"rendered":"Remove Your computer has been locked Ransomware"},"content":{"rendered":"<p>The <strong>Your computer has been locked.<\/strong> lockdown \u00a0is a ransomware alert that is locking your computer, and posing as an official notice from the Royal Canadian Mounted Police , claims that the your PC has been determined to have visited illegal websites.In reality, none of what the Royal Canadian Mounted Police screen is reporting is real, and the alert is only used to scare you into paying for a non-existing fine and stealing your personal financial information.<br \/>\nIf you&#8217;ve got a <strong>Your computer has been locked.<\/strong> ransomware infection , you&#8217;ll be seeing this screens :<\/p><div id=\"mwtad1928432370\" class=\"gas_fallback-ad_309684--placement_360520\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<figure id=\"attachment_3223\" aria-describedby=\"caption-attachment-3223\" style=\"width: 790px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/05\/Royal-Canadian-Mounted-Police-ransomware.jpg\"><img decoding=\"async\" class=\"size-full wp-image-3223\" title=\"Royal Canadian Mounted Police ransomware\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/05\/Royal-Canadian-Mounted-Police-ransomware.jpg\" alt=\"Royal Canadian Mounted Police Alert\" width=\"800\" height=\"598\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/05\/Royal-Canadian-Mounted-Police-ransomware.jpg 800w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/05\/Royal-Canadian-Mounted-Police-ransomware-300x224.jpg 300w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/a><figcaption id=\"caption-attachment-3223\" class=\"wp-caption-text\">Royal Canadian Mounted Police fake alert<\/figcaption><\/figure>\n<p>Here is what the <strong>Your computer has been locked<\/strong> fake screen says:<br \/>\n<code>Your computer has been locked!<br \/>\nWarning!<br \/>\nYour computer has been locked due to violation of the law in Canada.<br \/>\nThe following violations have been revealed:<br \/>\n- The act of the film shooting. Registration or transfer of documents with pornographic content involving minors, child pornography, sodomy and violence against children. The punishment provided by Article 163.1\/164 of the Criminal Code of Canada entails imprisonment for a term of 5 to 7 years.<br \/>\n- Software copyright violation. The punishment provided by Article 432 of the Criminal code of Canada entails imprisonment for a term of 3 to 5 years.<br \/>\n- Sending multimedia files with copyright violation. The punishment provided by Article 432.2 of the Criminal Code of Canada entails imprisonment for a term of 1 to 3 years.<br \/>\nTo unlock your computer, you have to pay a fine in accordance with Canadian law in the amount of 100 euros. A penalty in the form of fine is possible only if it is your first violation. Repeated violation entails criminal liability. If you do not pay the fine, your computer will be confiscated and your case will be referred to the Court.<br \/>\nYou can pay the fine through our partner or by using Ukash voucher. You can get Ukash voucher for the amount of $250, then fill in the form, specifying a voucher code and then click on the \u201cPay the fine\u201d button.<br \/>\n1. Your computer will be unlocked right after authenticity control of Ukash voucher. Usually it takes about 1-4 hours. Find your nearest store terminal<br \/>\n2. As for a Ukash voucher for $250<br \/>\n3. Give the retailer your cash including your fee<br \/>\n4. The shopkeeper will print your voucher with a 19-digit Ukash PIN<br \/>\n5. Take the voucher and pay the fine<br \/>\nWhere can I buy Ukash?<br \/>\nYou can get Ukash from hundreds of thousands of global locations, online, from wallets, from kiosks and ATMs. Visit ukash.ca for more information. Instore \u2013 get your Ukash from any of the 15,000+ locations with a Now Prepayment terminal.<\/code><\/p>\n<p>We strongly advise you to follow our Royal Canadian Mounted Police ransomware removal guide and ignore any alerts that this malicious software might generate.Under no circumstance should you send any any money to this cyber criminals as this could lead to identity theft.<\/p><div id=\"mwtad3891086766\" class=\"gas_fallback-ad_381396-ad_309691-placement_360566\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<div id=\"mwtad587955682\" class=\"gas_fallback-ad_309746-ad_309691-placement_360521\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Removal Instructions for <strong>Royal Canadian Mounted Police <\/strong> ransomware<\/h2>\n<p>We will be using the <strong>Kaspersky Rescue Disk <em>Bootable CD<\/em><\/strong> to clean the Windows registry and to perform a system scan to remove the malicious files.<br \/>\nWhat you&#8217;ll need to perform this removal guide :<\/p>\n<ol>\n<li>A computer with Internet access.<\/li>\n<li>1 blank DVD or CD<\/li>\n<li>1 DVD\/CD Burner<\/li>\n<li>Software which can create a bootable CD &#8211; \u00a0http:\/\/www.imgburn.com\/index.php?act=download<\/li>\n<li>A copy of the latest Kaspersky Rescue Disc from here &#8211; \u00a0http:\/\/rescuedisk.kaspersky-labs.com\/rescuedisk\/updatable\/<\/li>\n<li>About 1 -2 \u00a0hours depending on how much data you have on C:<\/li>\n<\/ol>\n<h3>STEP 1: Download and create a bootable Kaspersky Rescue Disk CD<\/h3>\n<ol>\n<li><strong>Download the Kaspersky Rescue Disk ISO<\/strong>image from below.<br \/>\n<a href=\"http:\/\/support.kaspersky.com\/faq\/?qid=208282173\" rel=\"nofollow noopener\" target=\"_blank\"><strong>KASPERSKY RESCUE DISK DOWNLOAD LINK<\/strong><\/a> <em>(This link will open a new page from where you can download Kaspersky Rescue Disk ISO)<\/em><\/li>\n<li><strong>Download ImgBurn<\/strong>, a software that will help us create this bootable disk.<br \/>\n<a href=\"http:\/\/www.imgburn.com\/index.php?act=download\" rel=\"nofollow noopener\" target=\"_blank\"><strong>IMGBURN DOWNLOAD LINK<\/strong><\/a> <em>(This link will open a new page from where you can download ImgBurn)<\/em><\/li>\n<li>You can now <strong>insert your blank DVD\/CD in your burner<\/strong>.<\/li>\n<li><strong>Install ImgBurn by following the prompts<\/strong> and then start this program.<\/li>\n<li>Click on the <strong>Write image file to disc<\/strong> button.<br \/>\n<img decoding=\"async\" title=\"Create a bootable CD\" src=\"\/\/malwaretips.com\/images\/removalguide\/img1.png\" alt=\"Create bootable CD step1\" width=\"510\" height=\"537\" \/><\/li>\n<li>Under <strong>&#8216;Source&#8217;<\/strong> click on the <strong>Browse for file<\/strong> button, then browse to the location where you previously saved the Kaspersky Rescue Disk ISO file.(kav_rescue_10.iso)<br \/>\n<img decoding=\"async\" title=\"Browse to the Kaspersky Rescue Disk Image\" src=\"\/\/malwaretips.com\/images\/removalguide\/img3.png\" alt=\"Create bootable CD step2\" width=\"512\" height=\"171\" \/><\/li>\n<li>Click on the big <strong>Write<\/strong> button.<br \/>\n<img decoding=\"async\" title=\"Click 'Write' to create the bootable disk\" src=\"\/\/malwaretips.com\/images\/removalguide\/img4.png\" alt=\"Create bootable CD step3\" width=\"480\" height=\"91\" \/><\/li>\n<li>The disc creation process will now start and it will take around 5-10 minutes to complete.<\/li>\n<\/ol>\n<h3>STEP 2:Configure the computer to boot from CD-ROM<\/h3>\n<ol>\n<li><strong>Use the Delete or F2 keys, to load the BIOS menu<\/strong>.Information how to enter the BIOS menu is displayed on the screen at the start of the OS boot:<br \/>\n<img decoding=\"async\" title=\"Boot into BIOS\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp1.png\" alt=\"Boot into Bios\" width=\"285\" height=\"137\" \/><\/li>\n<li>In your PC <strong>BIOS<\/strong> settings select the <strong>Boot menu<\/strong> and set CD\/DVD-ROM as a primary boot device.<br \/>\n<img decoding=\"async\" title=\"Select to boot from CD\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp2.png\" alt=\"Boot into BIOS Step2\" width=\"250\" height=\"146\" \/><\/li>\n<li><strong>Insert your Kaspersky Rescue Disk and restart your computer.<\/strong><\/li>\n<\/ol>\n<h3>STEP 3:Boot your computer from Kaspersky Rescue Disk<\/h3>\n<ol>\n<li>Your computer will now boot from the Kaspersky Rescue Disk,and you&#8217;ll be asked to <strong>press any key<\/strong> to proceed with this process<br \/>\n<img decoding=\"async\" title=\"Press any key\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp3.png\" alt=\"Kaspersky Rescue Disk 1\" width=\"450\" height=\"337\" \/><\/li>\n<li>In the start up wizard window that will open, <strong>select your language<\/strong> using the cursor moving keys. <strong>Press the ENTER<\/strong> key on the keyboard.<br \/>\n<img decoding=\"async\" title=\"Select your language\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp4.png\" alt=\"Kaspersky Rescue Disk 2\" width=\"450\" height=\"337\" \/><\/li>\n<li>On the next screen, select <strong>Kaspersky Rescue Disk. Graphic Mode<\/strong> then press <strong>ENTER<\/strong>.<br \/>\n<img decoding=\"async\" title=\"Select Graphic Mode for Kaspersky Rescue Disk\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp5.png\" alt=\"Kaspersky Rescue Disk 3\" width=\"450\" height=\"337\" \/><\/li>\n<li>The End User License Agreement of Kaspersky Rescue Disk will be displayed on the screen. Read carefully the agreement then <strong>press the C <\/strong> button on your keyboard.<br \/>\n<img decoding=\"async\" title=\"Accept the End User License Agreement \" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp6.png\" alt=\"Kaspersky Rescue Disk 4\" width=\"487\" height=\"273\" \/><\/li>\n<li>Once the actions described above have been performed, the Kasprsky operating system will start.<\/li>\n<\/ol>\n<h3>STEP 4: Launch Kaspersky WindowsUnlocker to remove the <em>Your computer has been locked<\/em> malicious registry changes<\/h3>\n<p>This virus has modified your Windows system registry so that when you&#8217;re trying to boot your computer it will instead launch his lock screen.To remove this malicious registry changes we need to use the Kasersky WindowsUnlocker from Kaspersky Rescue Disk.<\/p>\n<ol>\n<li><strong>Click on the Start button<\/strong> located in the left bottom corner of the screen and <strong>select the Kaspersky WindowsUnlocker<\/strong>.<br \/>\n<img decoding=\"async\" title=\"Start the Kaspersky WindowsUnlocker utility\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp13.png\" alt=\"Kaspersky Rescue Disk WindowsUnlocker 1\" width=\"338\" height=\"224\" \/><br \/>\nAlternatively you can select <strong>Terminal<\/strong> and in the command prompt type <strong>windowsunlocker<\/strong> and then press <strong> Enter<\/strong>on the keyboard.<\/li>\n<li>A white colored console window will appear and will automatically start loading the registry files for scanning and disinfection. The whole process will take only a couple of seconds and after this process you should be able to boot your computer in normal mode.<br \/>\n<img decoding=\"async\" title=\"Kaspersky WindowsUnlocker Log\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp14.png\" alt=\"Kaspersky Rescue Disk WindowsUnlocker 2\" width=\"558\" height=\"315\" \/><\/li>\n<\/ol>\n<h3>STEP 5:Scan your system with Kaspersky Rescue Disk<\/h3>\n<ol>\n<li>Click on the Start button located in the left bottom corner of the screen and <strong>select the Kaspersky Rescue Disk<\/strong> then click on <strong>My Update Center<\/strong> and press <strong>Start update<\/strong>.<br \/>\n<img decoding=\"async\" title=\"Update Kaspersky Rescue Disk AV Definitions\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp8.png\" alt=\"Kaspersky Bootable Cd scan 1\" width=\"385\" height=\"404\" \/><\/li>\n<li>When the update process has completed, the light at the top of the window will turn green, and the databases release date will be updated.<br \/>\n<img decoding=\"async\" title=\"Kaspersky Updated Definitions\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp9.png\" alt=\"Kaspersky Bootable Cd scan 2\" width=\"385\" height=\"404\" \/><\/li>\n<li>Click on the <strong>Objects Scan<\/strong> tab, then click <strong>Start Objects Scan<\/strong>to begin the scan.<br \/>\n<img decoding=\"async\" title=\"Start a Kaspersky Rescue Disk scan\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp10.png\" alt=\"Kaspersky Bootable Cd scan 3\" width=\"385\" height=\"404\" \/><\/li>\n<li>If any malicious items are found, the default settings are to prompt you for action with a red popup window on the bottom right. <strong>Delete<\/strong> is the recommended action in most cases but we <strong>strongly recommend\u00a0<\/strong>that you try first to disinfect , and if it doesn&#8217;t work chose to quarantine the infected files just to be on the safe side.<br \/>\n<img decoding=\"async\" title=\"Kaspersky Rescue Disk detecting malicious objects\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp11.png\" alt=\"Kaspersky Bootable Cd scan 5\" width=\"262\" height=\"345\" \/><\/li>\n<li>When all detected items have been processed and removed, the light in the window will turn green and the scan will show as completed.<br \/>\n<img decoding=\"async\" title=\"Kaspersky Rescue Disk After malware removal\" src=\"\/\/malwaretips.com\/images\/removalguide\/kasp12.png\" alt=\"Kaspersky Bootable Cd scan 7\" width=\"385\" height=\"404\" \/><\/li>\n<li>When done you can close the Kaspersky Rescue Disk window and use the Start Menu to <strong>Restart the computer<\/strong>.<\/li>\n<\/ol>\n<h3>STEP 6:\u00a0Download and scan with Malwarebytes Anti-Malware FREE to remove any left over malicious files from your computer.<\/h3>\n<ol>\n<li>Download and run Malwarebytes Anti-Malware FREE<br \/>\n<a href=\"http:\/\/malwaretips.com\/download-malwarebytes\" rel=\"nofollow\" target=\"_blank\"><strong>MALWAREBYTES ANTI-MALWARE DOWNLOAD LINK<\/strong><\/a><\/li>\n<li><strong>Install Mawlarebytes Anti-Malware by following the prompts<\/strong>. Do not make any changes to the default installation settings and do not restart your computer if asked so.<br \/>\n<img decoding=\"async\" title=\"Install Malwarebytes Anti-Malware\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam2.png\" alt=\"[Image: install-malwarebytes.png]\" width=\"516\" height=\"398\" border=\"0\" \/><\/li>\n<li>On the\u00a0<strong>Scanner<\/strong>\u00a0tab,please select\u00a0<strong>Perform full scan<\/strong>\u00a0and then click on the\u00a0<strong>Scan<\/strong>\u00a0button to start scanning your computer for any possible infections.<br \/>\n<img decoding=\"async\" title=\"Perform a Full System Scan\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam4.png\" alt=\"[Image: malwarebytes-full-system-scan.png]\" width=\"538\" height=\"387\" border=\"0\" \/><\/li>\n<li>When the scan is finished click the &#8216;<strong>OK<\/strong>&#8216; button and then you will be presented with a screen showing you the malware infections that Malwarebytes&#8217; Anti-Malware has detected.<br \/>\nMake sure that <strong>everything is\u00a0Checked\u00a0(ticked)<\/strong> and click on\u00a0<strong>Remove Selected<\/strong>\u00a0button.<br \/>\n<img decoding=\"async\" title=\"Scan results\" src=\"\/\/malwaretips.com\/images\/removalguide\/mbam6.png\" alt=\"[Image: malwarebytes-scan-results.png]\" width=\"541\" height=\"387\" border=\"0\" \/><\/li>\n<li>Malwarebytes&#8217; Anti-Malware will now start removing the malicious files.If during the removal process Malwarebytes will display a message stating that it needs to<strong> reboot, please allow<\/strong> this request.<\/li>\n<\/ol>\n<h4>If you are still experiencing problems while trying to remove Polisen Enheten for databrott alert from your machine, please start a new thread in our <a href=\"http:\/\/malwaretips.com\/Forum-Malware-Removal-Assistance-and-Help\" rel=\"nofollow\" target=\"_blank\">Malware Removal Assistance<\/a> forum.<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>The Your computer has been locked. lockdown \u00a0is a ransomware alert that is locking your computer, and posing as an official notice from the Royal Canadian Mounted Police , claims that the your PC has &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Remove Your computer has been locked Ransomware\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/remove-your-computer-has-been-locked-ransomware\/#more-3222\" aria-label=\"Read more about Remove Your computer has been locked Ransomware\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":3223,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2727,49],"tags":[],"class_list":["post-3222","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/3222","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=3222"}],"version-history":[{"count":0,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/3222\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/3223"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=3222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=3222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=3222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}