Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Sep 2017

How to remove Ukash virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Ukash virus blocks access to the computer, asks to pay a “fine” to regain it

Ukash virus is a malicious computer program that belongs to ransomware and Trojan categories. Once installed, such virus restricts access to the PC or encrypts files on the system and then displays a full-screen message urging to pay a ransom[1]. There are many versions of this ransomware, including versions for Mac and Android. The majority of these viruses state that the computer has been locked for violation of federal law. The malicious program creates an image that a particular institution located in victim's country was informed about his/hers illegal activities, such as watching illegal content, distributing malware[2]. To convince victims that these malicious programs are work of law enforcement agencies, these programs display names and logos of legal authorities. Some of these programs are even capable of taking control of victim's webcam and showing live view just to convince the user that his/hers activity is being recorded. The most preeminent and infamous examples of such malware are FBI virus[3], Police virus, “Your computer has been blocked” virus. These deceptive viruses usually provide a list of accusations and try to scare the victim by promising to put him/her behind bars for a long time if one fails to pay the forfeit within given time. The malicious virus asks the victim to collect the required amount of money, visit store and exchange it for a Ukash voucher. The coupon contains a code that needs to be entered into the malicious program. If the victim enters the right code, the computer gets unlocked. The virus is almost identical to MoneyPak ransomware group. However, these viruses do not seem to be active nowadays, because now the majority of ransom-demanding viruses urge to pay the ransom via Bitcoin payment system.

Main facts about Ukash virus

Ukash virus is a typical extortion tool used by cyber criminals and the only difference that distinguishes it from typical ransomware that it pretends to be a legal program rather than clearly asking for ransom. There are two types of such ransomware viruses – those that block access to the computer, and those that encrypt your files[4]. The second type is far more dangerous because once such viruses run encryption algorithms on personal records, they become corrupted and the only way to reverse the process is to use a private key, which is stored at criminals' private servers. In most cases, data recovery is impossible. Luckily, the majority of viruses that fall into the aforementioned malware category just display a screenlocker, which can be disabled easily. Sadly, sometimes victims pay the ransom before looking for information about these programs online, or even if they have never done anything illegal. It is apparent that the developers of these virtual extortion tools use social engineering[5] to convey the sense of urgency, scare the victim and force one to pay the ransom. If you fell victim to a similar virus, we suggest you remove Ukash from the system using a strong and trustworthy anti-malware software like FortectIntego. Before you start the removal process, make sure you read instructions provided by our expert team.Examples of Ukash virus

The most infamous versions of Ukash malware

FBI virus. FBI ransomware is a malicious Trojan that has been infecting computer users since 2012. It is one of the oldest ransom-demanding viruses that are still active in 2017. The virus blocks access to the computer by launching a full-screen message with Federal Bureau of Investigation – Department of Justice logo on it. The alert demands a ransom paid in the form of either MoneyPak or Ukash voucher. The dangerous Trojan requests $100-$200, although it can be removed just by ending the malicious process and deleting the malicious program. Versions of this virus are actively attacking Android users as well.

Metropolitan Police Ukash virus. The virus was first spotted back in 2012, around the same time as FBI virus showed up. The virus displays victim's IP address, and states that “the process of illegal activity is detected.” The virus accuses the victim of sending spam containing terroristic materials and also visiting websites that provide illegal content. The virus asks to buy a prepaid card worth £100 and enter its code into the ransomware's program window. Since this virus works as screenlocker that doesn't encrypt files, the victim only needs to delete the virus to start using the PC again. Considering that it is a profoundly malevolent program, experts advise removing it with a professional anti-malware product.

Royal Canadian Mounted Police Ukash virus. This virus launches the scary alert message via Safari browser, and it mostly attacks Mac users. The browser tab shows “Your browser has been locked” line, and the website itself says that all activities of the computer are being recorded. The virus typically accuses the victim of violating copyright laws, distributing prohibited pornography contents and ironically, neglectful use of the computer. This ransomware variant asks for $50 although it can be deleted just by closing the Safari window and scanning Mac OS with compatible anti-malware software.

Android ransomware. Smartphones running Android operating system are vulnerable to Android Ukash virus. This virus also asks to pay the ransom using described prepaid cards. The latest variants of this virus are even capable of attacking IoT devices – LG Smart TVs. Versions of this virus typically accuse the victim of watching illegal content and ask to pay a ransom in order to unlock the device. People who fall victim to attacks against mobile devices should perform a factory reset for the device. There is no necessity to pay the ransom because these viruses typically cannot corrupt data on the compromised device.

Be aware of malware distribution methods to keep malicious programs away from your computer

All ransomware that belongs to this malware family are spread with the help of trojans that can come either with infected downloads or through spam emails and their attachments. Of course, the user has no idea about Ukash virus and discovers it only when this virus restricts access to the computer. Besides, the victim is welcomed by a huge message titled 'Attention! Illegal activity was revealed' and said that there are some serious law violations found. Scammers suggest dropping the charges if the victim pays a “fine” within 24 hours or a week. However, you must be aware that no such official organization collects fines paid in prepaid cards. Besides, such organizations NEVER lock computers down and leave users without the Internet connection. We have some tips for computer users that can help to keep ransomware viruses away from the smart devices:

    • No matter what kind of programs you have on your computer, keep all of them up-to-date. This way, attackers won’t be able to exploit vulnerabilities in outdated software to execute commands on your PC.
    • Install a proper security software. If you want to block ransomware attacks, you need to use a program that can identify malicious attempts to infect your system.
    • Do not open suspicious email attachments. If you ever receive an email letter from someone you do not know, firstly lookup for information about the sender online or, if needed, contact the company the sender claims to be working for.

Expert tips on how to remove Ukash viruses

If you lost access to the computer due to ransomware attack, we suggest you use our instructions on how to remove Ukash virus. Keep in mind that we recommend removing the virus using professional malware removal programs. It is hard to uninstall ransomware because such malicious programs never leave an uninstaller. Carefully read all steps provided in Ukash removal guide below and follow them to rescue your PC from ransomware. In case you were infected with the virus that targets Mac operating system, simply run a scan with security software that is compatible with Macs, for example, MalwarebytesMalwarebytes or SpyHunterCombo Cleaner. Victims who use Android operating system should follow instructions provided here.

Did this guide help?

3 comments

  1. Rich

    Sorry, this is a little outdated now - Ukash is preventing me from loading safe mode.

    Factory format required!

  2. dave christie

    none of the above methods worked for me. safe mode with command prompt is inaccessable because the ransomware screen blocks it out, its b*ggered. my only recouse is a new hard drive.

  3. mrsem

    How do you remove the virus from a mobile phone?

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.