Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Block exe files from running
  • Changes background
  • Connects to the internet without permission

CashU Virus

CashU Virus is variation of Ukash Virus intended for Arab countries, because CashU is an alternative payment system popular in Arab countries. In case of this CashU virus, it targets users in United Arab Emirates, claiming that it displays a message from Abu Dhabi Police GHQ, and that your computer has been locked because of illegal cyber activity. That is why CashU Virus is classified as ransomware. It means that computer malware gets into your PC, locks you out of your desktop and then displays a fake notification that asks you to pay money for something you have not committed. The bottom line is that you need to remove CashU Virus from your PC at once, otherwise the malware will continue to terrorize you.

The infection is distributed by Urausy Trojan, so this infection is actually only another version of such threats as Urausy FBI Moneypak Virus, Policia Boliviana Virus or Dirección General de la Policía Virus. The only difference is that CashU Virus presents its security notification in Arabic, but other than that, the message displayed is practically the same. The creators of this infection simply take one text, run it through an automatic translator, and then paste it into the message that gets distributed by the Urausy Trojan. That is why there are usually grammatical and syntactic discrepancies in the message.

To sum the notification up, CashU Virus says that your computer has been locked, because you have been engaged in storing and distributing copyrighted material (such as music, video or software). It also says that illegal files of child pornography and bestiality have been detected on your computer, and it also means that you have breached several laws in the United Arab Emirates. CashU Virus claims that you need to pay a fine of 500 dirham, 100 USD or 100 EUR within 72 hours since the infringement, otherwise your computer will be locked permanently, and your information will be sent to law enforcement authorities.

Needless to say, that you must not do so. If you transfer your money via CashU, you will never get it back, and your computer will remain infected with CashU Virus. You need to restore your desktop access and remove CashU Virus yourself.

How to unlock your PC

Instructions for Windows 8

  1. Press Windows key for metro Start menu to appear. Move mouse cursor to the bottom right corner of the screen.
  2. When Charms bar appears, click Settings and click Change PC Settings. Select General and scroll down to Advanced Startup.
  3. Click Restart Now and go to Troubleshoot. Select Advanced Options and click Startup Settings.
  4. Click Restart and wait for BIOS to load.
  5. Press F5 to choose Safe Mode with Networking.
  6. Access http://www.pcthreat.com/download-sph and download SpyHunter.
  7. Install the program and perform and full system scan.

Instructions for Windows Vista & Windows 7

  1. Restart the PC and tap F8 repeatedly.
  2. Select Safe Mode with networking and press Enter.
  3. Go to http://www.pcthreat.com/download-sph and download SpyHunter.
  4. Install the program and run a full system scan.

Instructions for Windows XP

  1. Follow the steps 1 and 2 above.
  2. Click Yes and when confirmation box appears.
  3. Download SpyHunter.
  4. Open Start Menu and launch Run.
  5. Type "msconfig" into Open box and click OK.
  6. Select Startup tab on System Configuration Utility.
  7. Select Disable all and press OK.
  8. Restart the PC in Normal mode.
  9. Install SpyHunter and scan your computer.

Should you have any question about CashU Virus removal, leave us a comment below.

Download Spyware Removal Tool to Remove* CashU Virus
  • Quick & tested solution for CashU Virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove CashU Virus

Files associated with CashU Virus infection:

xaZYOVJW.exe
wlsidten.dll
%LOCALAPPDATA%\lollipop
%CommonProgramFiles%
UpgradeHelper.exe
skype.dat
scvhost.exe
ACEIEAddOn.dll
Task Scheduler.exe
UpdatePriv.exe
rool0_pk.exe
87b2cb3916261d5c807bf44262755cb0.exe
msavfit.exe
obvwo.exe
msn.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
audipbrd.exe
SyncHostps.exe
ex3b.dll
crack.exe
setex.exe
secproc_isv.exe
C87C.exe
DLL321.dll
msnmsgrr.exe
wgsdgsdgdsgsd.exe
%SystemDrive%\????????????
dyjdl.exe
wjthvwjb.dss
2084473.dll
00qbipeq.exe
ubvhynpxh.exe
iner.exe
魔法桌面第三方主题破解补丁V1.1.exe
sqlncli.exe
acuvzomo.exe
mplayer2.exe
Other.res
pYunY8m4VL3qLc.exe
najeoxtt.exe
bf8h8d02hf.exe
00b5d693.exe
%WINDIR%\Temp
%UserProfile%
NTServiceManager.exe
bvhylsviw.exe
msshell.exe
xctqakcqbeo.dll
csrsss.exe
bzsbkotiu.exe
puozlkmyj.dll
3511172082012Build.exe
gcrwcoak.exe
%LOCALAPPDATA%\Temp
aPr0hY9.exe
svchost.exe
uenovfiu.exe
%WINDIR%\system32
dtkmujvo.exe
securitywindrv.exe
xlqbteeb.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
OmaSG21e.exe
MusicCollector.exe
DA0B.exe
Piranha.exe
pmstcdjwz.exe
%AppData%
%APPDATA%\updates
JfCqQ5JC.exe
%ALLUSERSPROFILE%
videotwisterSA.exe
ssntvs.exe
comeo.exe
n.
b34btbztdb0vavaw.exe
msdtmsrd.exe
ifgxpers.exe
%APPDATA%\system
administration.exe
wlsidten.exe
yaiiwockc.dll
WINDED6.exe
wpbt0.dll
TimeDateMUICallback.exe
WinSyncMetastore.exe
%ALLUSERSPROFILE%\Application Data
idiokbbrv.exe
Q3d38543.exe
hwj3ba6j.dss
Nbt.exe
96dddda4.dll
ctfmon.exe
zqmkrehUkpoKfsafsaZg.exe
p1.exe
rvcbcyks.exe
VaultSysUi.exe
questscan.dll
%APPDATA%\Task Scheduler
dqnbdq7.dss
jsdhlexdqkllnbcxgai.bfg
oygqyunapnp.exe
systemcpl.exe
xmlfilter.exe
Firewallservice.exe
ieudator.dll
Updating.exe
50E1.exe
wahneaqa.exe
brenasa.exe
%TEMP%
install_0_msi.exe
m2PythonLoader.exe
taskhost.exe.exe

CashU Virus DLL's to remove:

wlsidten.dll
wpbt0.dll
xctqakcqbeo.dll
ACEIEAddOn.dll
2084473.dll
questscan.dll
DLL321.dll
yaiiwockc.dll
ex3b.dll
puozlkmyj.dll
ieudator.dll
96dddda4.dll

CashU Virus processes to kill:

xmlfilter.exe
WinSyncMetastore.exe
ctfmon.exe
pYunY8m4VL3qLc.exe
gcrwcoak.exe
DA0B.exe
VaultSysUi.exe
ubvhynpxh.exe
TimeDateMUICallback.exe
systemcpl.exe
securitywindrv.exe
svchost.exe
msshell.exe
WINDED6.exe
videotwisterSA.exe
setex.exe
UpgradeHelper.exe
87b2cb3916261d5c807bf44262755cb0.exe
pmstcdjwz.exe
crack.exe
wgsdgsdgdsgsd.exe
Q3d38543.exe
C87C.exe
00qbipeq.exe
Nbt.exe
taskhost.exe.exe
NTServiceManager.exe
p1.exe
acuvzomo.exe
audipbrd.exe
msdtmsrd.exe
uenovfiu.exe
install_0_msi.exe
aPr0hY9.exe
SyncHostps.exe
wlsidten.exe
bvhylsviw.exe
Piranha.exe
brenasa.exe
csrsss.exe
OmaSG21e.exe
iner.exe
魔法桌面第三方主题破解补丁V1.1.exe
dtkmujvo.exe
najeoxtt.exe
sqlncli.exe
ifgxpers.exe
msn.exe
Firewallservice.exe
scvhost.exe
msnmsgrr.exe
b34btbztdb0vavaw.exe
oygqyunapnp.exe
xaZYOVJW.exe
50E1.exe
administration.exe
comeo.exe
MusicCollector.exe
secproc_isv.exe
rvcbcyks.exe
bf8h8d02hf.exe
mplayer2.exe
idiokbbrv.exe
UpdatePriv.exe
dyjdl.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
msavfit.exe
bzsbkotiu.exe
obvwo.exe
3511172082012Build.exe
zqmkrehUkpoKfsafsaZg.exe
xlqbteeb.exe
JfCqQ5JC.exe
ssntvs.exe
Updating.exe
00b5d693.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
Task Scheduler.exe
wahneaqa.exe
rool0_pk.exe
m2PythonLoader.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.