Solved

Your Computer has been blocked - US Department of Justice

Posted on 2013-01-15
11
958 Views
Last Modified: 2013-11-22
I'm an IT guy and am baffled by this one...  I can't even get to the start menu or anything in Safe Mode.  Does anybody have any suggestions as to how I can remove this?
0
Comment
Question by:ITworks
11 Comments
 
LVL 22

Expert Comment

by:Bartender_1
Comment Utility
Have you tried following these steps:
http://malwaretips.com/blogs/department-of-justice-virus/


Hope this helps!

:o)

Bartender_1
0
 
LVL 22

Expert Comment

by:Bartender_1
Comment Utility
If you can't get to safe mode, you could try this software to boot from and edit the affected registry settings:

http://www.raymond.cc/blog/how-to-edit-windows-registry-key-values-without-booting-in-windows/

Hope this helps!

:o)

Bartender_1
0
 
LVL 10

Expert Comment

by:bigbigpig
Comment Utility
You can try booting to a rescue CD like Kaspersky's, or another if you have a preference.
http://support.kaspersky.com/4162
0
 
LVL 3

Accepted Solution

by:
jimminy_ebay earned 500 total points
Comment Utility
Avast has a tutorial on how to remove this infection.  I would also consider wiping an reinstalling or reimaging the OS on this computer if this doesn't work.  And get some AV software installed and updated on it before giving it back to the user.


https://forum.avast.com/index.php?topic=112757.0
0
 
LVL 3

Expert Comment

by:jimminy_ebay
Comment Utility
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 82

Expert Comment

by:Dave Baldwin
Comment Utility
I like the Kapersky Rescue Disk myself.
0
 
LVL 26

Expert Comment

by:Thomas Zucker-Scharff
Comment Utility
I use a SARDU created disk which everything on it.  It is worth making one of these for just such occassions:

http://www.experts-exchange.com/Storage/Misc/A_3038-Boot-Disks-UBCD-UBCD4Win-and-SARDU.html
0
 
LVL 44

Expert Comment

by:Darr247
Comment Utility
It's called "ransomware" malware... whatever steps you take, do NOT give them any money, because that will NOT fix the problem.
0
 
LVL 13

Expert Comment

by:Gabriel Clifton
Comment Utility
I have seen it fixed with sophos antivirus boot disk and/or combofix from bleepingcomputer.com.
0
 
LVL 91

Expert Comment

by:nobus
Comment Utility
0
 
LVL 4

Author Closing Comment

by:ITworks
Comment Utility
I tried EVERYONE's solutions, but ended up having to reformat.
0

Featured Post

Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

Join & Write a Comment

Article by: Lee
Windows 7 Ultimate and Enterprise (and 2008 R2) introduced a new feature you may not be aware of - Boot from VHD.   Boot from VHD (or what Microsoft refers to asNative Boot allows you to install Windows to a VHD (Virtual Hard Disk) file that is t…
Today, still in the boom of Apple, PC's and products, nearly 50% of the computer users use Windows as graphical operating systems. If you are among those users who love windows, but are grappling to keep the system's hard drive optimized, then you s…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now