POLITIE Belgique Police Fédérale Virus - How To Remove?

Type: Ransomware

POLITIE Belgique Police Fédérale virus is a ransomware that belongs to a wide Urausy family. As many other Trojans it blocks a computer‘s screen a few minutes after attacking a system. Once the locking message is displayed a PC does not respond to almost any commands. In order to remove the locking one is supposed to pay a fine of 100 EUR. The scam targets computers located in Belgium.

If you see a warning informing that laws related to illegal distribution and usage of copyrighted content, for example, music, videos or films have been breached, that files related to child pornography were detected in this computer or it was used for Spam, it is very likely you are facing POLITIE Belgique Police Fédérale virus. Do not fall for this scam no matter how legitimate it might look from the first sight. The text may vary time to time but it should be similar to the one below:

ATTENTION! Votre ordinateur est bloqué à cause d’un ou de plusieurs
liberté pour de 4 à 9 ans. L’accès illégal a été effectué à votre insu, votre ordinateur est probablement infecté par le logiciel nuisible, de ce fait vous violez la loi «Sur l’utilisation négligente de l’ordinateur. L’article 210 du Code pénal prévoit l’amende d’un montant de 2000€ jusqu’à 8000E.

La somme de l’amende fait 100E. Utilisez PaySafeCard ou Ukash. Au paiement de l’amende et après ce que ragréent est reçu sur le compte de l’État votre ordinateur sera débloqué pendant 1 à 72 heures.

Please note, that none of official institutions use such methods as blocking computer’s screen remotely. If POLITIE Belgique Police Fédérale virus turns your webcam on and films the surroundings, you should not get scared as well. This is one more trick it uses and the information is never sent to any police. Moreover, if a payment method is given as prepaid payment, for example Ukash, Moneypak or Paysafecard, you can be 100% sure cyber criminals are behind it. This is the only way for them to collect money without being caught because tracing the money according to the PIN’s is almost impossible as these are quickly sold at underground forums.

Depending on the version of the POLITIE Belgique Police Fédérale virus there is more than one its removal method:

When Safe mode is available:

  1. For a Safe mode with networking to be selected restart your computer and press F8 while it is restarting;
  2. Launch MSConfig;
  3. Disable startup items rundll32 turning on any application from Application Data;
  4. Restart your computer again;
  5. Scan your computer using Spyhunter. It will find and remove the POLITIE Belgique Police Fédérale virus. Below is a video showing how to complete the steps:

When Safe Mode and Safe Mode with Networking is blocked

  1. For a Safe Mode with command prompt to be selected restart your computer and press F8 while it is restarting.
  2. Run regedit. Search for Winlogon.
  3. There will be a key labeled Shell under Winlogon. It should refer to Explorer.exe or be blank. If there is something else referring an executable in one of user’s folders, replace it with explorer.exe.
  4. Save changes, restart to safe mode with networking.
  5. Run msconfig and disable all unnecessary startup entries. You should be able to restart normally.
  6. Download Spyhunter and scan your computer using it. The tool will find and remove the POLITIE Belgique Police Fédérale virus. Watch the video illustrating these steps:

When none of Safe Modes can be selected

Some of the POLITIE Belgique Police Fédérale virus versions might block all of safe modes. In such a case you will need another (uninfected) computer. Download and save Spyhunter to Bootable antivirus CD/USB disk. Insert it to an infected computer. Antivirus should start working automatically and remove the blocking.

Automatic POLITIE Belgique Police Fédérale virus removal tools

Note: Reimage trial provides detection of parasites and assists in their removal for free. You can remove detected files, processes and registry entries yourself or purchase a full version.  We might be affiliated with some of these programs. Full information is available in disclosure

Manual removal


Important Note: Although it is possible to manually remove POLITIE Belgique Police Fédérale virus, such activity can permanently damage your system if any mistakes are made in the process, as advanced spyware parasites are able to automatically repair themselves if not completely removed. Thus, manual spyware removal is recommended for experienced users only, such as IT specialists or highly qualified system administrators. For other users, we recommend using Reimage or other tools found on


POLITIE Belgique Police Fédérale virus screenshots


About the author

 - Main Editor

I have started in 2007 after wanting to be more or less independent from single security program maker. Since then, we kept working on this site to make internet better and safer place to use.

March 19, 2013 09:41, June 3, 2013 13:32

Leave a Reply

Your email address will not be published. Required fields are marked *