Royal Canadian Mounted Police scam

andy | February 15, 2013

The picture that you see depicted below supposedly from Royal Canadian Mounted Police isn’t associated with RCMP at all. Instead, what you see is a serious virus that strikes many computers located in Canada today. This virus is classified as ransomware, i.e. the application that locks the desktop of your system and asks for money to be paid by user in order to unlock it. Hopefully, after you’ve read this post you will never agree for such a fraudulent proposal of the crooks. To be certain about this, please remain with us as we share more facts about Royal Canadian Mounted Police virus and ways it can be removed from your system.

Royal Canadian Mounted Police virus

Royal Canadian Mounted Police ransomware appears on your screen out of the blue. This takes place unexpectedly, when you don’t even realize anything bad to occur. By the way, this particular type of locker belongs to the Urausy malware clan. Immediately the entire workstation become inoperable. Users cannot do anything on their computers. Even after repeated reboot of the computer using hard reset the same locked status remains. The virus says that users were noticed of performing a lot of illegal activities while surfing the web. In particular, the accusation sentence includes activities of illegal software, audio and video downloads, sending massive unsolicited spam, visiting the sites of terrorist organizations for the purpose of supporting them and, in particular, performing a lot of other illegal adult activities online. Surely, to receive such a message and condemnation might be very scary, even it you have never done such things in your life.

Royal Canadian Mounted Police virus locker prompts users to pay the ransom fine through indication of Ukash of Paysafecard voucher (PIN) codes. Of course, when one obeys the instructions of the crooks the money is wasted and not returned back. And, by the way, there’s no guarantee that the system will be unlocked by the crooks.

Royal Canadian Mounted Police uses the logo of CPA (ACP), as well as that of ICSPA (International Cyber Security Protection Alliance). This is in order to make the text of the faulty accusation even more scary. Please do not worry! The message you see supposedly from RCMP is the one from the cyber frauds and crooks, in fact. Ignore its scary alert and follow the simple malware removal guide below that we’ve developed specifically for ransomware removal.

Ransomware unlocking procedure

Note! This tutorial is effective for all GreenDot MoneyPak, Ukash and Paysafecard ransomwares.

  1. Restart your computer and press F8 while it is restarting.
  2. Choose safe mode with networking.
  3. safe mode with networking

  4. Press Start menu and select Run, or press [Win]+R on keyboard.
  5. Run command

  6. Type msconfig
  7. msconfig

  8. Disable startup items rundll32 turning on any application from Application Data.
  9. Restart your system once again.
  10. Scan your system with GridinSoft Trojan Killer to identify file and delete it.

Some versions of these viruses disable all safe modes, but give a short gap that you can use to run anti-malware programs. Then do following:

  1. Reboot normally.
  2. Click Start and choose Run.
  3. Enter the text specified in the quotation below. If malware is loaded, just press Alt+Tab once and keep entering the string blindly then press Enter.
  4. http://trojan-killer.net/download.php

  5. Press Alt+tab and then R (letter) a couple of times. The process of ransomware virus should be killed after you succeed to download, install our recommended software and scan your PC with it.

Download GridinSoft Trojan Killer for thorough system checkup

3 Comments

  1. Lisa says:

    I keep trying this procedure and unfortunately my pc just keeps going back to the fake screen. Is it possible that I’m doing something wrong??

  2. Connie says:

    i can get to step two.. however, my computer reboots itself once i see safemode in the corners :(

  3. Roland says:

    My computer also keeps rebooting once safe mode is initiated. What to do?

1 Trackbacks

Leave a comment

*