Wednesday, April 17, 2013

The Effective Guide to Remove Metropolitan Police Ransomware Virus - Manual Removal Tips

Are you frustrated by getting Metropolitan Police Ransomware virus? Do you want to know more about Metropolitan Police Ransomware virus? Can’t remove it by security software? In the following post we'll help you get rid of it completely and safely.

screen shot:



Metropolitan Police Ransomware description:

Metropolitan Police Virus is a ransomware which always lock your computer with a warning like: “Your computer has been locked by a illegal activity!” This ransomware virus is created by Cyber criminals for tricking money from PC user who actually believed. With time pass by, Metropolitan Police became more and more popular among Cyber criminals to use it as an effected way in Internet fraud. Usually, the locked computer released by using name of FBI and Interpol which can scares people at first.
Besides money trick, Metropolitan Police can also access your infected PC and delete your computer’s IP address and information or encrypt the document from your PC. Then, only if you pay the money to cyber criminals behind the ramsomware, can he open it even not. For example, if your PC be infected by this ramsomware , you have to pay a fine like 100 pounds for meaningless in order to open your computer again.  In this case, what you need to do is ignoring the scam and just install the ransomware without hesitation. Anyway, if you still send your money to Cyber criminals, your computer will still be infected and damaged.

Harmful properties of Metropolitan Police Ransomware Virus:

 1.  It can compromise your system and may introduce additional infections like rogue software.
2.  It enters your computer without your consent and disguises itself in root of the system.
3. This virus often takes up high resources and strikingly slow down your computer speed.
4. It can help the cyber criminals to track your computer and steal your personal information.

Help you uninstall Metropolitan Police Ransomware Virus manual remove:

1) Boot your computer into safe mode with networking by restarting your computer and keeping pressing F8 key until Windows Advanced Options menu shows up, then using arrow key to select “Safe Mode with Networking” from the list and press ENTER to get into that mode.

Protector-[rnd].exe

2) Open your Task Manger by pressing Ctrl+Alt+Delete keys and end the processes of XY:
C:\Windows\system32\nvvsvc.exe
 C:\Windows\system32\WLANExt.exe
 C:\Windows\system32\conhost.exe
 C:\Windows\System32\spoolsv.exe

3) The associated files to be removed in folders on Local Disk (note: new files are still created each month so far):

4) Open your Registry Editor and then find out the registry entries of XY virus to remove them (note: new registry entries are still made every month so far):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ERROR_PAGE_BYPASS_ZONE_CHECK_FOR_HTTPS_KB954312
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnOnHTTPSToHTTPRedirect" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegedit" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Inspector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "ID" = 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "net" = "2012-2-17_2"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Settings "UID" = "rudbxijemb"


How to Remove Metropolitan Police Ransomware Virus With Spyhunter? 

1. download Spyhunter into your computer;
2. Once it been installed in your computer, you should run a full scan with it to find out any threat in your computer. 

3. Click select all, then remove those threats from your computer completely.


The video direction below can give you a hand:



Note: This tricky virus just uses random file names in same system directories or even its mutating versions will use different directories to escape various security tools' detection and add more difficulty to manual removal.