Title: Department of Justice Virus
Type: Ransomware
Also known as: Ukash virus

Remove Department of Justice Virus
Removal instructions

 
Severity scale:Department of Justice Virus severity is 90  (90 / 100)
 

Department of Justice Virus is one of the latest threats from Ukash virus group that try to attack people living in the United States of America. This threat belongs to the category of ransomware, so it is designed to get inside the system secretly and then try to rip users off. Just like FBI virus, FBI Moneypak or FBI Green Dot Moneypak virus, it creates lots of troubles for its victims by locking the system down. This results is complete system's take over - user becomes incapable to get on the Internet, launch legitimate anti-malware programs or do other things on his PC. He only sees a forged Department of Justice Virus alert, which states that user is caught doing illegal activities on his computer. Before you fall for this alert, you must note that such organizations as Department of Justice do NOT collect their fines in such way. You must remove Department of Justice Virus immediately!

HOW CAN I GET INFECTED WITH Department of Justice Virus?

This scam is designed to use the same ways intrussion as all previous Ukash viruses: it uses spam emails, freeware, shareware and other sources to come inside undetected. Once there, it locks the system down and shows its only message, claiming that Windows system has been blocked because you have been using copyrighted content, visiting pornographic websites or even spreading malware. For that, now you have to make a payment of $200 using the Moneypak prepayment system. Here's how this message looks like:

Your computer has been locked!
This operating system is locked due to the violation of the federal laws of the United States of America (Article: 1, Section 8, Clause 8; Article 202; Article 2012 of the criminal code of the U.S.A. Provides for the deprivation of liberty for four to twelve years.)
Following violations detected:
Your IP address was used to visit websites containing pornopraphy, child pornography, zoophillia and child abuse. Your computer also contains video files with pornographic content, elements of violence and child pornography!
(…)
You have 72 hours to pay the fine, otherwise you will be arrested.
(...)

No matter how trustworthy it seems, you must ignore this alert because it has nothing to do with Department of Justice. If you pay this $100 or $300 fine, you won't have your computer unlocked and you will lose your money as well. In order to avid that, you should remove Department of Justice Virus as soon as possible.

HOW CAN I REMOVE Department of Justice Virus?

In order to remove Department of Justice virus, you should try following this information. It includes different methids that MAY work in this virus removal. Remember that manual removal methid can be used only if you have enough nowledge about computer's system and its architecture:

* Users infected with Department of Justice virus are allowed to access other accounts on their Windows systems. If one of such accounts has administrator rights, you should be capable to launch anti-malware program.

* Try to deny the Flash to make your ransomware stop function as intended. In order to disable the Flash, go to Macromedia support and select 'Deny': http://www.macromedia.com/support/documentation/en/flashplayer/help/help09.html. After doing that, run a full system scan with anti-malware program.

* Flash drive method: 

  1. Take another machine and use it to download Defender Pro Ultimate Security Suite, SpyHunter or other reputable anti-malware program.
  2. Update the program and put into the USB drive or simple CD.
  3. In the meanwhile, reboot your infected machine to Safe Mode with command prompt and stick USB drive in it.
  4. Reboot computer infected with Department of Justice virus once more and run a full system scan with updated anti-malware program.

* Manual Department of Justice removal (special skills needed!):

  1. Open Windows Start Menu, enter %appdata% into the search field, click Enter.
  2. Go to: Microsoft\Windows\Start Menu\Programs\Startup.
  3. Remove ctfmon (don't mix it with ctfmon.exe!).
  4. Open Windows Start Menu, enter %userprofile% into the search field, click Enter.
  5. Go to Appdata\Local\Temp and remove rool0_pk.exeDelete [random characters].mof file
  6. Delete V.class
  7. Run a full system scan with updated SpyHunter to remove remaining Department of Justice virus files.

UPDATE: There is a new Ukash virus, which uses the logo of the Department of Justice. This threat now says 'Your computer has been blocked! The work of your computer has been suspended on the grounds of the violation of the law of the United States of America". Similarly to the previous version of the Department of Justice virus, this ransomware shows a list of laws, that have been violated, and asks to pay the fine of $300 using MoneyPak prepayment system. Besides, it speaks to the victim!



Automatic Department of Justice Virus removal:

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
By Downloading any provided Anti-spyware software to remove Department of Justice Virus you agree to our privacy policy and agreement of use.
SpyHunter is recommended remover to uninstall Department of Justice Virus. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

If you failed to remove Department of Justice Virus using SpyHunter, submit question to our support team and provide as much details as possible.
dot
Malwarebytes Anti Malware
download
manual required
We are testing Malwarebytes Anti Malware's efficiency at removing Department of Justice Virus (2012-09-25 06:38:27)
dot
Defender Pro Ultimate Security Suite
download
manual required
We are testing Defender Pro Ultimate Security Suite's efficiency at removing Department of Justice Virus (2012-09-25 06:38:27)
dot
STOPzilla
download
manual required
We are testing STOPzilla's efficiency at removing Department of Justice Virus (2012-09-25 06:38:27)
dot
XoftSpySE Anti Spyware

what to do if you failed to remove the infection?
Phone Support to remove Department of Justice Virus
Phone Support to remove Department of Justice Virus
Department of Justice Virus snapshot:
Department of Justice Virus snapshot
 snapshot
 snapshot


QR code for Department of Justice Virus removal instructions:

Department of Justice Virus qrcode
QR is short for Quick Response. They can be read quickly by the mobile phones. QR codes can store more data than standard barcodes, including url links, geo coordinates, and text.

The reason we add QR code to the website is that parasites like Department of Justice Virus are really hard to remove on infected computer. you can quicly scan the QR code with your mobile device and have manual removal instructions to uninstall Department of Justice Virus right in your pocket.

Simply use the QR scanner and read removal instructions from mobile device.

Removal guides in other languages

Information added: 2013-05-20 06:11:21
Information updated: 2013-05-20 06:11:21

Ask us discussions:

Modern viruses are really hard to remove. They have random file names, random registry entries, they can immitale legal products and files. Removal instructions sometimes can't Help to remove infection manually. Please take a look at our discussion where users like you share they experience in fighting the parasite:

Additional resources:

Attention: If you know know a reputable website reated to security threats, please add a link here: add url

7
0
Aubrey
Its actually much simpler to remove this virus. Im no computer nerd or anything, but I effectively removed this virus without all the technical crap.

First, manually shut off your computer.
As your system reboots, constantly hit the F8 key until the Boot screen shows up.
From there, click a Safe Mode option.
Once in Safe Mode, access the internet and download Malware Bytes.
Have the program run a full scan. Once the virus is detected, remove it- then restart your computer.
BLAMO! Virus is gone.

Youre welcome.
1
0
jonathan
it isnt working it says we cant download the malware bytes because we are on safe mode, is there a way to downlaod something on safe mode? get back to me ASAP thanks
3
1
Victor
Run safe mode with network mode
0
0
KELLY
THIS HAPPEN TO ME LAST NIGHT!!!

WWW.YOOCARE.COM - HELP ME REMOVE THE VIRUS. UNFORUNTELY IT COST ME $69.95 BUT NOW I ACCESS TO MY LAPTOP.

SERIOUSLY CONSIDERING GETTING A MAC NOW.
1
0
anon
you gave your cc information to a random company. I would keep a close eye on your statements.
2
0
Hollyg0915
I did as you said and the virus is GONE!! Your solution was so much simpler that the other archaic options out there on the web.

Thank you.
2
0
Ariel
I did this and the virus seemed to be removed, then reappeared three days later. I just did this same method again and its not doing anything! Im in safe mode with networking at the moment.
1
0
Anonymus
Read Aubreys comment. Oh and on my computer it reset the timer that tells you how much time u have to pay everytime we restarted the computer
0
1
AAA
the virus opens now in the safe mode as well ... th only place it doesnt open is a safe mode with the prompt ..
1
1
james
Thank you for your great information, after followed all instruction, now I am free from virus
0
0
kenneth
What happens if you cant get to the start menu??//

Is there an alternate methods???
0
0
Jayson
Great advise. Way faster than the other suggested ways and it only took 15 minutes to get everything fixed. Thanks
0
0
John
If you have an anti-virus program and you should. I have AVAST and ccleaner.

1. Shut your PC off using the off button. Do not try alt/ctrl/delete (three finger salute). It wont work.
You need to shut down manually. Go to control tower and shut it off.

Give it a minute or so and turn it back on. This will give you access to your programs. Do NOT try to get back
on the Net.

2. Run your Anti-Virus program. It may try to block you again. If so? Do all of the above again! and just let it run
until your PC is clean. Avast will clean it.

3. Run ccCleaner and you will get rid of it
0
0
Dutchman
MS Security Essentials caught and quaranteened this
0
0
Computer56
How long should a scan take?
0
0
rashai
i know right like forever
0
0
GH
I (not me actually a co-worker) must have a new version of this it blocks out safe mode now. Cant login as administrator either blocks that to. Any ideas??
0
0
snake
im having the same problem...cant perform any of the fixes suggested. can anyone help? ill try calling the Smartsupport # 888-340-9777
0
0
ssanders519
I started my computer in safe mode and restored computer to previous restore point and virus was gone after restoring.
0
0
Tammy
I did what Aubrey suggested and it worked perfect. The scan took almost 3 hours. I then ran ccleaner after I restarted. I have Avast, aol security and Verizon security, how do I still get a virus. All the software security really slows down my laptop.
0
0
Rachel
It blocks me even in safe mode, I dont know what go do
0
0
Jgdfhk
Same here. Blocked in every safe mode. Any other options?
0
0
Jake
I was infected twice. I was watching streaming video then suddenly DOJ appeared. On my first infection I was puzzled I let the computer running while the DOJ displayed on my screen. That was a fatal mistake! Not only it locks up my windows but also the safe mode. I have to go through safe mode with MS DOS command prompt to transfer my documents then reformat the whole computer. The combofix, AVG and other malware was unable to see the virus.

On my next infection I was watching streaming videos again on a different website, again DOJ came knocking. This time I recognize the banner and immediately turn off the computer. I then boot up on safe mode with network. I run malwarebyte and got rid of the virus.

Lesson learned: Turn off your computer asap dont let it run because the virus would write itself deeper into the system. I have an AVG anti virus and Microsoft Security Essential running when I got the 2nd infection. They are useless against the DOJ virus. Now I installed malwarebytes hope this will protect me from DOJ attack.
0
0
rpuglisi
I booted into safe mode with networking, removed ctfmon from startup, downloaded Malwarebytes and ran a full scan and it was gone.
0
0
toto
So this is just a virus, it has nothing to do with the law?
0
0
Shari
I did f8 got to safe mode with networking hit to desktop and then the message took over again. It comes up before I can get the Internet open. Help!!!!
0
0
Linda
The virus kept showing up during my safe mode too. I ended up using Safe Mode with Command Prompt and did a System Restore. Typed %systemroot%system32restorerstrui.exe in the box and pressed enter. I saw on another site that you can probably just type rstrui.exe.
0
1
Hasmat
Turn your computer off immediately when you see this virus. Does anyone wanna tell where they were at when the virus hit? I was on a computer beside my main computer when it hit. Luckily, I could finish what I started... The virus is a bad one. I was on cam4, and xtube. Then I went to second computer. Moments later the MF DOJ virus got my main computer.
0
0
Chris
I was sleeped in 3 hours.after I woke up,this notice is appeared in my laptop I tried to turn off my laptop and turn on but stil there.after I read this I was so scared.dont know what to do.Im not going to watch Any porn again.damm
0
0
Tedmouse
DARN VIRUS HAS BEEN UPDATED
You cant end process to use antivirus anymore, says illegal process has been noted.
You cant open safe mode, it blocks it and says another illegal process has been noted.
You cant open a other account, crashs laptop and you get back to your main and says illigal process has been noted again.

pay now or your system will be erased.
i refused and my system was erased.

So best info i can give on this is to back everything up all the time.
Or a dirtbag hacker will erase it and laugh.
erase it even if you pay him money which i didnt.
0
0
Tiffany
That was some really quick & easy instructions worked out well. Thanks so much!
0
0
KELLY
I ALSO WANT TO ADD THAT I GOT THIS NASTY VIRUS SURFING WWW.TUMBLR.COM/ IN THE PORN TAG (._.)
BE CAREFUL GUYS!
0
0
chris
I have both Mac and PC. Windows 8 pro is great and better than MAC. Just make sure you have latest virus protection. The intel core processor next gen which is coming out will have security protection built in to the processor. Also MAC is still expensive and gives you all the old operating system functions. I would recommend windows surface or Samsung tablet and windows 8 pro. Windows 7 is also very fast and with the proper virus protection youll be okay. MAC is good as well but what Im starting to see how expensive it is and you dont have many options. Also when things brake you only have limited support and it has to be with MAC or certified MAC place. Im starting to like windows more since you have so many different vendors to choose from and different devices. Also the pricing is great.
0
0
Johnny
I have a MAC and never got this virus, although I did on my Laptop that runs windows. When someone tells you a MAC cannot get a virus, listen to them, its tru.
0
0
ejestrada
I recently fell victim to the Dept. of Justice Virus and freaked out when I first read it. I just upgraded my system to Windows 8 and with the assistance of a Technician, we were able to remove the virus with the hassle of trying to hold my SHIFT key and F-8 or from the Desktop, hit the windows key + R and enter “msconfig” without the quotations which didn’t work for me at all.
WARNING: Back up your files on a frequent basis. I had backed up all my files to an external hard drive, but found that after the process, I didn’t have to restore any of my files but I did have to go back and reinstall my Antivirus and MS Office software so please make sure that you have your product keys available.

Windows 8 Users only:
From the START menu:
1. Move your mouse to the far right of the screen where you can have access to Settings (1 of the 5 options) and click on SETTINGS.

2. Select Change PC Settings

From the SETTINGS Menu:
1. Scroll down to GENERAL and click.

2. Move your mouse to the right side and scroll down to “Refresh your PC without Affecting your Files” and click on Get Started.

3. Read the prompts then click NEXT.

The process took me less than 15 minutes and when the process was complete, all of my files and folders were in tact. My desktop, however, was black and I only had 3 icons, one of them which was a file named Removed Apps. I was able to reinstall my important icons but the most important thing was that my computer was no longer locked. It certainly helps to install an anti-malware software. Good luck to everyone and I hope that this can help someone else like it helped me. Pay it forward!
0
0
James
It wont let me connect to the internet. Now what do I do?
0
0
rlw
A customer of mine called me and told me his PC was infected with the DOJ virus. I picked up the PC and brought it home and began working on it. The solution was really rather simple:

1) Disconnect infected PC from network and internet.
2) Go to Start menu and enter %TEMP%
3) Temp folder will be displayed in Windows Explorer.
4) Delete any .EXE files you find in the root folder, not in any subfolders.
5) Go to Start menu and enter %APPDATA%
6) AppData folder will be displayed in Windows Explorer.
7) Delete CTFMON file
8) Empty your Recycle Bin
9) Re-boot PC, virus should now be removed...

-RW-
0
0
cazzie
DOJ virus wont allow any kind of boot...all safe modes fail, USB fails, etc.

Open for suggestions, although I did see a suggestion of making the infected drive a slave drive in a different computer.
0
0
kenneth
what happens when it will not to safe?

Or which is the best selection in safe, only three on my vista 32 bit..thanks
0
0
Maxim
Hi,

My customer has the same problem (or perhaps its another type of malware problem, but this article seemed to mention it in a similar way).
As soon as my customer saw this virus, she called me and I made sure she rebooted the computer in network mode. After I could remotely control her computer (through our it-system) and scan the computer using "Eset Endpoint Antivirus". The AW looked different, as the layout wouldnt show up, only the client command interface with text would and it started to scan. After that I took Johns advice and installed cCleaner and removed all registries and scanned and analyzed everything else, and removed everything completely from the system. Im not sure yet if this fixed the issue but heres some tips:
1. Restart in safe mode.
2. Go to &appdata% and kill CTFMON if you see it.
3. Go to &username& and make sure you have enable hidden files/folders so you can get to the temp folder and delete everything.
4. Scan with AW + ccleaner.
5. Reboot
6. Hope to profit.

If this problem still occurs for me, then I will post here and relate to this, hoping that someone can solve the issue and update it to the others.

Post Comment:

Attention: Use this form only if you have additional information about Department of Justice Virus parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Like us on Facebook
Latest spyware news:
Subscribe to spyware news
Please enter your e-mail address:
If you do not want to receive our spyware
newsletter please unsubscribe here
47984 Subscribers
Ask us
I failed to remove Department of Justice Virus using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other