Lebanese Internal Security Forces Virus - How to remove

Lebanese Internal Security Forces Virus

Lebanese Internal Security Forces Virus is another ransomware that belongs to Urausy family of Trojans. It targets computers located in Lebanon. The virus is capable of identifying PC‘s IP address and according to this information display a message adapted to a particular country. Lebanese Internal Security Forces Virus pretends to be sent from local police authorities – Lebanese Internal Security Forces. Even though it might look like a real warning, one should not believe it and definitely should not pay any fine.

As many other ransomware from Urausy family, this virus blocks an infected computer with a message informing about a breach of laws. A victim is presented with charges related to illegal usage and distribution of music, videos, films or software, sending spam e-mails or even having child pornography files on computer. For the blocking to be removed an infected computer user is asked to pay a fine of 100$ (100 Euro or 200,000 Lebanese pounds). A prepaid payment system called chashU is listed as an option for the money to be sent.

Please note that Lebanese Internal Security Forces Virus is a scam. Paying the fine will not unblock your computer. The only solution to the problem is removing ransomware from an infected computer using reputable antivirus software and special removal instructions:

Method I

If your computer has at least one user’s account that is not infected with Lebanese Internal Security Forces Virus, login to it. Scan your computer with antivirus, for example, Spyhunter. It will remove the infection.

Method II- when Safe Mode with Networking is not blocked

  1. If Lebanese Internal Security Forces Virus does not block it, select Safe Mode with Networking. You will need to restart your computer and press F8 while it is restarting;
  2. Launch MSConfig
  3. Disable startup items rundll32 turning on any application from Application Data;
  4. Restart your computer one more time.
  5. Scan system with https://www.2-viruses.com/downloads/spyhunter-i.exe. It will detect Lebanese Internal Security Forces Virus and remove it. A video of another Urausy family virus illustrates these steps:

Method III – when Safe Mode with Networking is blocked

  1. If Lebanese Internal Security Forces Virus does not block it, restart computer choosing Safe Mode with Command Prompt.
  2. Run regedit. Look for Winlogon.
  3. There will be a key labeled Shell under Winlogon. It should refer to Explorer.exe or be blank. If there is something else referring an executable in one of user’s folders, replace it with explorer.exe.
  4. Save change and restart again but this time to safe mode with networking.
  5. Run msconfig and disable all unnecessary startup entries. You should be able to restart normally.
  6. Install and run https://www.2-viruses.com/downloads/spyhunter-i.exe. Scan the system and Lebanese Internal Security Forces Virus executables. It is recommended to watch this video guide before using the method:

Method IV – when all of Safe Modes are blocked

Some of Lebanese Internal Security Forces Virus versions might block all of safe modes. If your computer is infected with such a virus version, you will need an uninfected computer. Download and save Anti-Malware program to Bootable antivirus CD/USB disk. Insert it to an infected computer. Antivirus should start working automatically and remove the blocking.

Automatic Malware removal tools

Download Spyhunter for Malware detection
(Win)

Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions,

Download Combo Cleaner for Malware detection
(Mac)

Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy ,

Manual removal

Leave a Reply

Your email address will not be published. Required fields are marked *