{"id":8436,"date":"2013-05-07T17:21:24","date_gmt":"2013-05-07T17:21:24","guid":{"rendered":"http:\/\/malwaretips.com\/blogs\/?p=8436"},"modified":"2013-05-07T17:21:24","modified_gmt":"2013-05-07T17:21:24","slug":"el-ordenador-se-ha-bloqueado-y-todos-sus-datos-se-cifran-virus","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/el-ordenador-se-ha-bloqueado-y-todos-sus-datos-se-cifran-virus\/","title":{"rendered":"Remove &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus"},"content":{"rendered":"<p>If your computer is locked, and you are seeing a <em>&#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221;<\/em> notification from <strong>FBI Cybercrime Division<\/strong>\u00a0, then your computer is infected with a piece of malware known as <em>Trojan Reveton<\/em>.<\/p><div id=\"mwtad3878894545\" class=\"gas_fallback-ad_309684--placement_360520\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus is distributed through several means. Malicious websites, or legitimate websites that have been compromised, may drop this trojan onto a compromised computer. This drive-by-download often happens surreptitiously. Another method used to propagate this type of malware is spam email containing infected attachments or links to malicious websites. The threat may also be downloaded manually by tricking the user into thinking they are installing a useful piece of software.<br \/>\nThe &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus is also prevalent on peer-to-peer file sharing websites and is often packaged with pirated or illegally acquired software.<\/p>\n<p>Once installed on your computer, the &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; MoneyPak virus will display a <strong>bogus notification<\/strong>\u00a0that pretends to be from the FBI Cybercrime Division, and states that your computer has been blocked due to it being involved with the distribution of pornographic material, SPAM and copyrighted content.<br \/>\nThe <strong>&#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus will lock you out of your computer and applications<\/strong>, so whenever you&#8217;ll try to log on into your Windows operating system or Safe Mode with Networking, it will display instead a lock screen asking you to pay <strong>a non-existing fine of 200 Euro<\/strong>\u00a0in the form of a MoneyPak code.<br \/>\nFurthermore, to make this alert seem more authentic, <strong>this virus also has the ability to access your installed webcam<\/strong>, so that the bogus &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221;\u00a0notification shows what is happening in the room.<\/p><div id=\"mwtad3288657707\" class=\"gas_fallback-ad_381396-ad_309691-placement_360566\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus locks the computer and, depending on the user\u2019s current location, displays a localized webpage that covers the entire desktop of the infected computer and demands payment for the supposed possession of illicit material.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-8437\" title=\"El ordenador se ha bloqueado y todos sus datos se cifran virus\" alt=\"El ordenador se ha bloqueado y todos sus datos se cifran virus\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/05\/el-ordenador-se-ha-bloqueado-y-todos-sus-datos-se-cifran-virus.jpg\" width=\"806\" height=\"599\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/05\/el-ordenador-se-ha-bloqueado-y-todos-sus-datos-se-cifran-virus.jpg 806w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/05\/el-ordenador-se-ha-bloqueado-y-todos-sus-datos-se-cifran-virus-300x222.jpg 300w\" sizes=\"(max-width: 806px) 100vw, 806px\" \/><br \/>\nCyber criminals often updated the design of this lock screen, however you should always keep in mind that <strong>FBI Cybercrime Division<\/strong> will never lock down your computer or monitor your online activities.<br \/>\nThe message displayed by the threat can be localized depending on the user\u2019s location, with text written in the appropriate language.<\/p>\n<blockquote><p><strong>FBI Cybercrime Division <\/strong><br \/>\n<strong>ADVERTENCIA! El ordenador se ha bloqueado y todos sus datos se cifran!<\/strong><br \/>\nSu computadora ha sido bloqueado y todos sus archivos estaban cifrados. Motivo: violaci\u00f3n de la ley. Las posibles violaciones se describen a continuaci\u00f3n: Titulo 17 &amp;; DERECHOS DE AUTOR, Capitulo 10, Subcapitulo B ,CONTROLES DE COPIA<br \/>\n(a) Prohibici\u00f3n de Importaci\u00f3n. Fabricaci\u00f3n y Distribuci\u00f3n &#8211; Ninguna persona podr\u00e1 importar, fabricar o distribuir cualquier dispositivo de grabaci\u00f3n digital de audio o interfaz de audio digital. dispositivo que no se ajusta a-(1) Sistema de gesti\u00f3n de copia en serie, (2) un sistema que tiene las mismas caracter\u00edsticas funcionales que el sistema de gesti\u00f3n de copia en serie y exige que los derechos de autor y la informaci\u00f3n de estado de generaci\u00f3n de forma precisa enviada, recibida, y actuar en consecuencia entre los dispositivos que utilizan el m\u00e9todo del sistema de regulaci\u00f3n de copia en serie y los dispositivos que utilizan el Sistema de gesti\u00f3n de copia en serie, o (3) cualquier otro sistema certificado por el Secretario de Comercio que prohibe la copia no autorizada de serie. Titulo 18 DELITOS Y PROCEDIMIENTO PENAL &#8216;Mulo 18 Parte Ir Capitulo 117 r\u00a72427 La inclusi\u00f3n de los delitos relacionados con la pornograf\u00eda infantil en la definici\u00f3n de la actividad sexual por la que puede ser cualquier persona acusada de un delito penal Titulo &gt; 18 i Parte Ir Cap\u00edtulo 110 &gt; \u00a72258C La inclusi\u00f3n de los delitos relacionados con la pornograf\u00eda infantil en la definici\u00f3n de la actividad sexual por la que puede ser cualquier persona acusada de un delito penal (a) Elementos\u2014. (1) En general \u2014 El Centro Nacional para Ni\u00f1os Desaparecidos y Explotados puede proporcionar elementos relacionados con cualquier imagen de pornograf\u00eda infantil aparente de un ni\u00f1o identificado a un proveedor de servicios de comunicaci\u00f3n electr\u00f3nica o de un proveedor de servicios de computaci\u00f3n remota para el \u00fanico y el prop\u00f3sito exclusivo de permitir que el proveedor de servicios de comunicaci\u00f3n electr\u00f3nica o el proveedor de servicios inform\u00e1ticos a distancia para detenerlo transmisi\u00f3n de otro tipo de im\u00e1genes. (2)\u2014 Inclusiones. Los elementos autorizados en el p\u00e1rrafo (1) puede incluir valores de has u otros identificadores \u00fanicos asociados con una imagen espec\u00edfica, ubicaci\u00f3n de Internet de im\u00e1genes, y otros elementos tecnol\u00f3gicos queso pueden utilizar para identificar y detenerlo transmisi\u00f3n de pornograf\u00eda infantil. (3) Exclusi\u00f3n \u2014. Los elementos autorizados en virtud del p\u00e1rrafo (1) no puede incluir las im\u00e1genes reales. (b) El uso por las proveedores de servicios de comunicaciones electr\u00f3nicas y los proveedores de servicios remotos Inform\u00e1tica \u2014. Cualquier proveedor de servicios de comunicaci\u00f3n electr\u00f3nica o el proveedor de servicio de computaci\u00f3n remoto que recibe los elementos relativas a cualquier imagen de pornograf\u00eda infantil aparente de un ni\u00f1o identificado por el Centro Nacional para Ni\u00f1os Desaparecidos y Explotados en esta secci\u00f3n puede utilizar dicha informaci\u00f3n \u00fanicamente para los fines descritas en esta secci\u00f3n, siempre que dicho uso no liberar\u00e1 a ese proveedor de servicios de comunicaci\u00f3n electr\u00f3nica o el proveedor de servicios inform\u00e1ticos a distancia de sus obligaciones de presentar informes bajo la secci\u00f3n 2258A.<br \/>\n(c) Limitaciones \u2014 Nada en las subvenciones. [1] (a) o (b) requiere que los proveedores de servicios de comunicaciones electr\u00f3nicas o remotas proveedores de servicios inform\u00e1ticos que reciben los elementos relativos a cualquier imagen de pornograf\u00eda infantil aparente de un ni\u00f1o identificado por el Centro Nacional para Menores Desaparecidos y Explotados Los ni\u00f1os a utilizar los elementos para detener la transmisi\u00f3n ulterior de las im\u00e1genes. (d) Provisi\u00f3n de elementos a la polic\u00eda \u2014 El Centro Nacional para Ni\u00f1os Desaparecidos y Explotados pondr\u00e1 a disposici\u00f3n Federal. Estatal y las autoridades locales involucradas en la investigaci\u00f3n de delitos de pornograf\u00eda infantil elementos, incluidos los valores hash, en relaci\u00f3n con cualquier ni\u00f1o aparente imagen de pornograf\u00eda a un ni\u00f1o identificado inform\u00f3 el Centro Nacional para Menores Desaparecidos y Explotado&amp; (e) El uso por aplicaci\u00f3n de la ley \u2014 Cualquier federal, estatal o agencia de polic\u00eda local que recibe los elementos relativos a cualquier imagen de pornograf\u00eda infantil aparente de un ni\u00f1o identificado por el Centro Nacional para Menores Desaparecidos y Explotados en virtud del articulo [1] (d) Puede utilizar estos elementos s\u00f3lo en el ejercicio de las funciones oficiales de esa agencia para investigar los delitos de pornograf\u00eda infantil. Titulo 18 r Parte Ir Capitulo 110 r \u00a7 2252A \u00a7 2252A &#8211; Ciertas actividades relacionadas con el material que constituya o contenga pornograf\u00eda infantil Titulo 26 r Subt\u00edtulo F \u00bb Cap\u00edtulo 78, Subcapitulo A, \u00a77612 Procedimientos especiales para las citaciones para el software de la computadora Para desbloquear el ordenador, debe pagar una multa dentro de 24 horas y el c\u00f3digo de cup\u00f3n para una entrada siguiente formulario. Tendr\u00e1 un m\u00e1ximo de 24 horas para comprobar el c\u00f3digo de cup\u00f3n y descifrar los datos.<\/p><\/blockquote>\n<p>The <strong>&#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; lock screen is a scam<\/strong>, and you should ignore any alerts that this malicious software might generate.<br \/>\n<strong>Under no circumstance should you send any Ukash code to these cyber criminals<\/strong>, and if you have, you can \u00a0should request a refund, stating that you are the victim of a computer virus and scam.<\/p>\n<div id=\"mwtad2527763054\" class=\"gas_fallback-ad_309746-ad_309691-placement_360521\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>&#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221;\u00a0lock screen &#8211; Virus Removal Guide<\/h2>\n<div id=\"mwtad4167507222\" class=\"gas_fallback-ad_309747-ad_309691-placement_360587\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>STEP 1: Remove &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; lock screen from your computer<\/h2>\n<p>&#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus has modified your Windows registry and added its malicious files to run at start-up, so whenever you&#8217;re trying to boot your computer it will launch instead its bogus notification.To remove these malicious changes,\u00a0<strong>we can use any of the below methods<\/strong> :<\/p><div id=\"mwtad430755256\" class=\"gas_fallback-ad_309686-ad_309691-placement_360569\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>Method 1: Start your computer in Safe Mode with Networking and scan for malware<\/h3>\n<p>Some variants of &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus will allow the users to start the infected computer in <em>Safe Mode with Networking<\/em> without displaying the bogus lock screen. In this first method, we will try to start the computer in Safe Mode with Networking and then scan for malware to remove the malicious files.<\/p>\n<ol>\n<li>Remove all floppy disks, CDs, and DVDs from your computer, and then <strong>restart your computer<\/strong>.<\/li>\n<li><strong>Press and hold the F8 key as your computer restarts<\/strong>.Please keep in mind that you need to press the F8 key <strong>before the Windows start-up logo appears<\/strong>.<br \/>\n<em>Note<\/em>: With some computers, if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the &#8220;F8 key&#8221;, <strong>tap the &#8220;F8 key&#8221; continuously<\/strong> until you get the Advanced Boot Options screen.<\/li>\n<li>On the Advanced Boot Options screen, use the arrow keys to <strong>highlight Safe Mode with Networking<\/strong> , and then <strong>press ENTER<\/strong>.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-6072\" title=\"\" alt=\"[Image: Safe Mode with Networking]\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/safemode.jpg\" width=\"539\" height=\"292\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/safemode.jpg 539w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/safemode-300x162.jpg 300w\" sizes=\"(max-width: 539px) 100vw, 539px\" \/><\/li>\n<li>If your computer has started in Safe Mode with Networking, you&#8217;ll need to perform a system scan (<em>as seen on STEP 2<\/em>) with <a href=\"http:\/\/malwaretips.com\/download-malwarebytes\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Malwarebytes Anti-Malware<\/strong><\/a> and <a href=\"http:\/\/malwaretips.com\/download-hitmanpro\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>HitmanPro<\/strong><\/a> to remove the malicious files from your machine.<\/li>\n<\/ol>\n<p><strong>IF<\/strong> the &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus didn&#8217;t allow you to start the computer in <em>Safe Mode with Networking<\/em>,you&#8217;ll need to follow <em>Method 2<\/em>\u00a0to get rid of its lock screen.<\/p>\n<hr \/>\n<h3>Method 2: Restore Windows to a previous state using System Restore<\/h3>\n<p>System Restore can return your computer system files and programs to a time when everything was working fine, so we will try to use this Windows feature to get rid of &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; \u00a0lock screen.<\/p><div id=\"mwtad1596407034\" class=\"gas_fallback-ad_381401-ad_309691-placement_360573\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<ol>\n<li>Restart your computer, and then <strong>press and hold F8 during the initial startup<\/strong> to start your computer in safe mode with a Command prompt.<br \/>\n<em>Note<\/em>: With some computers, if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the &#8220;F8 key&#8221;, <strong>tap the &#8220;F8 key&#8221; continuously<\/strong> until you get the Advanced Boot Options screen.<\/li>\n<li>Use the arrow keys to select the\u00a0<strong>Safe mode with a Command prompt<\/strong>\u00a0option.<br \/>\n<img decoding=\"async\" title=\"Safe Mode with Command Prompt Screen\" alt=\"Enter Safe Mode with Command Prompt\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/06\/safemode12.jpg\" width=\"539\" height=\"292\" \/><\/li>\n<li>At the command prompt, type\u00a0<em><strong>cd restore<\/strong><\/em>, and then press ENTER.<br \/>\nNext,we will type <em><strong>rstrui.exe\u00a0<\/strong><\/em>, and then press <strong>ENTER<\/strong>.Alternatively, if you are using Windows Vista, 7 and 8, you can just type : <em><strong>C:\\windows\\system32\\rstrui.exe<\/strong><\/em> , and press <strong>ENTER<\/strong>.<br \/>\nIf you are using Windows XP, you will need to type <em><strong>C:\\windows\\system32\\restore\\rstrui.exe<\/strong><\/em>, and then press <strong>ENTER<\/strong>.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-4564\" title=\"Start System Restore from Safe Mode with Command Prompt\" alt=\"System Restore commands\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/cmd-restore.png\" width=\"677\" height=\"118\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/cmd-restore.png 677w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/cmd-restore-300x52.png 300w\" sizes=\"(max-width: 677px) 100vw, 677px\" \/><\/li>\n<li>The System Restore utility will start, and you&#8217;ll need to select a restore point previous to this infection.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-4573\" title=\"Select a previous restore point\" alt=\"Restore points in Windows 7\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/06\/system-restore.png\" width=\"580\" height=\"465\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/06\/system-restore.png 580w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/06\/system-restore-300x240.png 300w\" sizes=\"(max-width: 580px) 100vw, 580px\" \/><\/li>\n<li>After System Restore has completed its task, you should be able to boot in Windows normal mode, and perform a system scan (<em>as seen on STEP 2<\/em>) with <a href=\"http:\/\/malwaretips.com\/download-malwarebytes\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Malwarebytes Anti-Malware<\/strong><\/a> and <a href=\"http:\/\/malwaretips.com\/download-hitmanpro\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>HitmanPro<\/strong><\/a> to remove the malicious files from your machine.<\/li>\n<\/ol>\n<p><strong>IF<\/strong> the &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; \u00a0virus didn&#8217;t allow you to restore your computer to a previous point, you&#8217;ll need to follow <em>Method 3<\/em> to get rid of its screen lock.<\/p>\n<hr \/>\n<h3>Method 3: Remove &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus with HitmanPro Kickstart<\/h3>\n<p><strong>IF<\/strong> you couldn&#8217;t boot into <em>Safe Mode with Command Prompt<\/em> or didn&#8217;t have a System Restore point on your machine, we can use <strong>HitmanPro Kickstart<\/strong> to bypass this infection, and access your computer to scan it for malware.<\/p>\n<ol>\n<li>We will need to create a HitmanPro Kickstart USB flash drive,so while you are using a &#8220;clean&#8221; (non-infected) computer, <strong>download HitmanPro<\/strong> from the below link.<br \/>\n<a href=\"http:\/\/malwaretips.com\/download-hitmanpro\" target=\"_blank\" rel=\"noopener noreferrer\"> <strong>HITMANPRO DOWNLOAD LINK<\/strong><\/a> <em>(This link will open a download page in a new window from where you can download HitmanPro)<\/em><\/li>\n<li>Insert your USB flash drive into your computer and follow the instructions from the below video:<br \/>\n<iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/aBS902Qr0oc?rel=0\" height=\"360\" width=\"640\" frameborder=\"0\"><\/iframe><\/li>\n<li>After you have create the HitmanPro Kickstart USB flash drive, you can <strong>insert this USB drive into the infected machine<\/strong> and start your computer.<\/li>\n<li>Once the computer starts, <strong>repeatedly tap the F11 key <\/strong>(on some machines its <em>F10<\/em> or <em>F2<\/em>),which should bring up the Boot Menu, from there you can select to boot from your USB.<br \/>\nNext,you&#8217;ll need to <strong>perform a system scan with HitmanPro<\/strong> as see in the below video:<br \/>\n<iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/lUNHidkYsDQ?rel=0\" height=\"360\" width=\"640\" frameborder=\"0\"><\/iframe><\/li>\n<li>After HitmanPro Kickstart has completed its task,you should be able to boot in Windows normal mode,from there you&#8217;ll need to <strong>perform a system scan<\/strong> (<em>as seen on STEP 2<\/em>) with <a href=\"http:\/\/malwaretips.com\/download-malwarebytes\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Malwarebytes Anti-Malware<\/strong><\/a> and <a href=\"http:\/\/malwaretips.com\/download-hitmanpro\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>HitmanPro<\/strong><\/a> to remove the malicious files from your machine.<\/li>\n<\/ol>\n<hr \/>\n<div id=\"mwtad915049033\" class=\"gas_fallback-ad_309748-ad_309691-placement_360588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>STEP 2: Remove &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; malicious files from your computer<\/h2>\n<h4>Run a computer scan with Malwarebytes Anti-Malware Free<\/h4>\n<ol>\n<li>You can <strong>download Malwarebytes Anti-Malware Free<\/strong> from the below link,then double click on it to install this program.<br \/>\n<a href=\"http:\/\/malwaretips.com\/download-malwarebytes\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>MALWAREBYTES ANTI-MALWARE DOWNLOAD LINK<\/strong><\/a><em>(This link will open a download page in a new window from where you can download Malwarebytes Anti-Malware Free)<\/em><\/li>\n<li>When the installation begins, <strong>keep following the prompts<\/strong> in order to continue with the setup process.<br \/>\n<strong>DO NOT make any changes to default settings<\/strong> and when the program has finished installing, make sure you leave both the <strong>Update Malwarebytes&#8217; Anti-Malware<\/strong> and <strong>Launch Malwarebytes&#8217; Anti-Malware<\/strong> checked,then click on the <strong>Finish <\/strong>button.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-6075\" title=\"Malwarebytes Anti-Malware final installation screen\" alt=\"[Image: Malwarebytes Anti-Malware final installation screen]\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-installation.jpg\" width=\"402\" height=\"310\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-installation.jpg 402w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-installation-300x231.jpg 300w\" sizes=\"(max-width: 402px) 100vw, 402px\" \/><\/li>\n<li>On the <strong>Scanner<\/strong> tab,select <strong>Perform quick scan<\/strong> and then click on the <strong>Scan\u00a0<\/strong>button to start scanning your computer.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-6076\" title=\"Run a Quick Scan with Malwarebytes Anti-Malware\" alt=\"[Image: Malwarebytes Anti-Malware Quick Scan]\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-quick-scan.jpg\" width=\"521\" height=\"397\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-quick-scan.jpg 521w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-quick-scan-300x228.jpg 300w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><\/li>\n<li>Malwarebytes&#8217; Anti-Malware will now start scanning your computer for &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus as shown below.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-6077\" title=\"Malwarebytes Anti-Malware scanning for \" alt=\"[Image: Malwarebytes Anti-Malware scanning for \" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-scan.jpg\" width=\"521\" height=\"397\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-scan.jpg 521w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-scan-300x228.jpg 300w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><\/li>\n<li>When the Malwarebytes scan will be completed,click on\u00a0<strong>Show Result<\/strong>.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-6078\" title=\"Malwarebytes when the system scan has completed\" alt=\"[Image: Malwarebytes Anti-Malware scan results]\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-scan-results.jpg\" width=\"521\" height=\"397\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-scan-results.jpg 521w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-scan-results-300x228.jpg 300w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><\/li>\n<li>You will now be presented with a screen showing you the malware infections that Malwarebytes&#8217; Anti-Malware has detected.Please note that the infections found may be different than what is shown in the image.Make sure that everything is <strong>Checked (ticked)<\/strong> and click on the <strong>Remove Selected <\/strong>button.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-6079\" title=\"Click on Remove Selected to get rid of \" alt=\"[Image:Malwarebytes removing virus]\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-virus-removal.jpg\" width=\"521\" height=\"397\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-virus-removal.jpg 521w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2013\/01\/malwarebytes-virus-removal-300x228.jpg 300w\" sizes=\"(max-width: 521px) 100vw, 521px\" \/><\/li>\n<li>After your computer will restart in <strong>Normal mode<\/strong>, open\u00a0<strong>Malwarebytes Anti-Malware<\/strong>\u00a0and <strong>perform a Full System scan<\/strong> to verify that there are no remaining threats<\/li>\n<\/ol>\n<h4>Run a computer scan with HitmanPro<\/h4>\n<ol>\n<li><strong>Download HitmanPro<\/strong> from the below link,then double click on it to start this program.<br \/>\n<a href=\"http:\/\/malwaretips.com\/download-hitmanpro\" target=\"_blank\" rel=\"noopener noreferrer\"> <strong>HITMANPRO DOWNLOAD LINK<\/strong><\/a> <em>(This link will open a new web page from where you can download HitmanPro)<\/em><br \/>\n<strong>IF<\/strong> you are experiencing problems while trying to start HitmanPro, you can use the <em>Force Breach<\/em> mode.To start HitmanPro in Force Breach mode,<strong> hold down the left CTRL-key when you start HitmanPro<\/strong> and all non-essential processes are terminated, including the malware process. (<a href=\"http:\/\/www.youtube.com\/watch?feature=player_embedded&amp;v=m6eRWTv2STk\" target=\"_blank\" rel=\"noopener\">How to start HitmanPro in Force Breach mode &#8211; Video<\/a>)<\/li>\n<li>HitmanPro will start and you&#8217;ll need to follow the prompts (by clicking on the <strong>Next<\/strong> button) to start a system scan with this program.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-5176\" title=\"HitmanPro startup screen (Click Next)\" alt=\"HitmanPro scanner\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-install.jpg\" width=\"497\" height=\"393\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-install.jpg 497w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-install-300x237.jpg 300w\" sizes=\"(max-width: 497px) 100vw, 497px\" \/><br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-5179\" title=\"HitmanPro installation options (Click Next)\" alt=\"HitmanPro installation\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmapro-start-scan.jpg\" width=\"497\" height=\"393\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmapro-start-scan.jpg 497w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmapro-start-scan-300x237.jpg 300w\" sizes=\"(max-width: 497px) 100vw, 497px\" \/><\/li>\n<li>HitmanPro will start scanning your computer for &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; \u00a0malicious files\u00a0as seen in the image below.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-5177\" title=\"HitmanPro while scanning for \" alt=\"HitmanPro scans after \" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-scan.jpg\" width=\"497\" height=\"393\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-scan.jpg 497w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-scan-300x237.jpg 300w\" sizes=\"(max-width: 497px) 100vw, 497px\" \/><\/li>\n<li>Once the scan is complete,you&#8217;ll see a screen which will display all the infected files that this utility has detected, and you&#8217;ll need to click on <strong>Next<\/strong> to remove these malicious files.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-5178\" title=\"HitmanPro reporting scan results\" alt=\"HitmanPro scan results\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-scan-results.jpg\" width=\"497\" height=\"393\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-scan-results.jpg 497w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-scan-results-300x237.jpg 300w\" sizes=\"(max-width: 497px) 100vw, 497px\" \/><\/li>\n<li>Click <strong>Activate free license <\/strong>to start the free 30 days trial and remove all the malicious files from your computer.<br \/>\n<img decoding=\"async\" class=\"alignnone size-full wp-image-5175\" title=\"Activate HitmanPro free 30 days trial license\" alt=\"HitmanPro 30 days activation button\" src=\"\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-activation.jpg\" width=\"497\" height=\"393\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-activation.jpg 497w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2012\/11\/hitmanpro-activation-300x237.jpg 300w\" sizes=\"(max-width: 497px) 100vw, 497px\" \/><\/li>\n<\/ol>\n<h4>If you are still experiencing problems while trying to remove &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; \u00a0virus from your machine, please start a new thread in our <a href=\"http:\/\/malwaretips.com\/Forum-Malware-Removal-Assistance\">Malware Removal Assistance<\/a> forum.<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>If your computer is locked, and you are seeing a &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; notification from FBI Cybercrime Division\u00a0, then your computer is infected with a piece of &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Remove &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/el-ordenador-se-ha-bloqueado-y-todos-sus-datos-se-cifran-virus\/#more-8436\" aria-label=\"Read more about Remove &#8220;El ordenador se ha bloqueado y todos sus datos se cifran&#8221; virus\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":8437,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ai_generated_summary":"","footnotes":""},"categories":[2727],"tags":[],"class_list":["post-8436","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/8436","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=8436"}],"version-history":[{"count":0,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/8436\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/8437"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=8436"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=8436"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=8436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}