Removal of the AFP(Australian Federal Police) virus

This is a ransom-ware type of virus that demand you pay $100 to “ucash”. Now really why would the AFPwant you to pay money to someone called ucash? It doesn’t. This is a scam to try to trick you out of your hard earned cash.


This virus is very tricky to remove. About a month ago you could use this really good little program that runs on start-up called hitman.kickstart pro. You just register for the one month trial version. That when I tried it this morning it did not work for this virus anymore. I also tried the Kaspersky rescue disk with no luck. And whats really bad about this virus is when you boot to safe mode the computer restarts itself.
What I did to get rid of it is boot to safe mode with command prompt. To do that as the computer is starting up press the “F8” key repeatedly and the windows boot options will appear.  Select “safe mode with command prompt”. Now it will boot up and open a command prompt window.
We need to make a new user by using the command “net user virusremoval /add” this will create a new user called virusremoval.
Now we want to add the user to the local administrators group by using the command “net localgroup administrators virusremoval /add”.
Now you can reboot the PC by using the command “shutdown /r /t 0”
Once the PC has rebooted log in as the new user that we have just created as this user will not be infected. From here we will need to do a system restore.
After the system restore on PC is finished you will only have the original users again anf you will be able to log in as your normal user again.
Once logged in as your normal user follow the instructions on this post about how to remove the virus. I would run combofix fir this virus, after running mbam I still got a hit on combo fix today when removing this virus.