Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Block exe files from running
  • Installs itself without permissions
  • Connects to the internet without permission
  • Normal system programs crash immediatelly
  • Slow internet connection
  • System crashes
  • Slow Computer

NSA Virus

NSA Virus is a dangerous ransomware infection which installs itself without the user’s permission. The infection creates new registry entries in the Registry, drops its files in various locations, and modifies the running process so that you cannot access the desktop and use the PC as usual. The only mission of NSA Virus is to lure the computer user into paying the so-called fine of $300.  Once you find that your computer is afflicted by NSA Virus, which is also labeled as PRISM Virus, ignore the information provided its warning and take immediate measures to remove it from the PC.

According to the bogus warning, you are contacted by the National Security Agency (NSA) which implements the PRISM program. Moreover, the warning contains the logo of the Federal Bureau of Investigation (FBI) and the Department of Justice. The emblems are supposed to convince the user that the warning is legitimate.

Furthermore, the ransom warning contains false accusations. The computer is said to be locked because you are said to be suspected of downloading, using, and distributing illegal content, such as child pornography. It is highlighted in red that the individuals who are related to this type of crime may be imprisoned and obliged to pay a fine up to $250.000.

You will find that the warning indicates the status of the payment, which reads “Waiting for payment”. There is no need to pay $300 for the money will be received by the criminals hiding behind NSA Virus. MoneyPak, which is presented as the method of paying, can be used on the partner’s websites or in some other ways indicated on the official website of the service. In the present situation, your computer is affected by a dangerous Trojan horse, which you should remove right now.

The removal will be an easy procedure if you use a powerful spyware removal tool. We recommend that you install SpyHunter as this application has already removed different ransomware infections, including Ministerul Afacerilor Interne virus, Služba Kriminální Policie a Vyšetřování virus, and many others. The instructions below will help you install the application in the right way so that you can discover how this time-saving program works.

NSA Virus Removal

Windows Vista and Windows 7

  1. Restart the computer.
  2. Once the BIOS splash screen loads, tap the F8 key.
  3. Using the up/down arrow keys, select the Safe Mode with Networking option and press Enter.
  4. Go to http://www.pcthreat.com/download-sph and download the anti-spyware program.
  5. Install it and launch a system scan.

Windows XP

  1. Restart the computer.
  2. Tap the F8 key once the BIOS splash screen loads.
  3. Select Safe Mode with Networking using the up/down arrow keys and press Enter.
  4. Click Yes on the dialog box.
  5. Open the Start menu.
  6. Launch the Run command and type msconfig in the Open box.
  7. Click OK.
  8. Open the Startup tab and click the Disable All button.
  9. Click Apply.
  10. Download SpyHunter from our website.
  11. Restart the PC.
  12. Install the program and remove NSA Virus.

Windows 8

  1. Press the Windows key.
  2. Once in Metro mode, click the Internet Explorer tile.
  3. Go to http://www.pcthreat.com/download-sph and download SpyHunter.
  4. Install the application and scan the PC.
Download Spyware Removal Tool to Remove* NSA Virus
  • Quick & tested solution for NSA Virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove NSA Virus

Files associated with NSA Virus infection:

cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
securitywindrv.exe
dyjdl.exe
魔法桌面第三方主题破解补丁V1.1.exe
TimeDateMUICallback.exe
00qbipeq.exe
skype.dat
C87C.exe
setex.exe
%WINDIR%\system32
xaZYOVJW.exe
%AppData%
UpgradeHelper.exe
%APPDATA%\updates
msdtmsrd.exe
puozlkmyj.dll
b34btbztdb0vavaw.exe
pmstcdjwz.exe
msnmsgrr.exe
Task Scheduler.exe
00b5d693.exe
audipbrd.exe
ifgxpers.exe
%LOCALAPPDATA%\lollipop
jsdhlexdqkllnbcxgai.bfg
msn.exe
yaiiwockc.dll
%TEMP%
wlsidten.exe
Other.res
sqlncli.exe
%ALLUSERSPROFILE%\Application Data
hwj3ba6j.dss
%ALLUSERSPROFILE%
uenovfiu.exe
2084473.dll
p1.exe
n.
crack.exe
OmaSG21e.exe
%APPDATA%\system
UpdatePriv.exe
questscan.dll
%APPDATA%\Task Scheduler
%CommonProgramFiles%
gcrwcoak.exe
wpbt0.dll
systemcpl.exe
bvhylsviw.exe
wahneaqa.exe
wlsidten.dll
mplayer2.exe
administration.exe
xctqakcqbeo.dll
msavfit.exe
zqmkrehUkpoKfsafsaZg.exe
obvwo.exe
%WINDIR%\Temp
ex3b.dll
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
m2PythonLoader.exe
scvhost.exe
comeo.exe
dtkmujvo.exe
taskhost.exe.exe
wjthvwjb.dss
Piranha.exe
WinSyncMetastore.exe
Updating.exe
aPr0hY9.exe
msshell.exe
VaultSysUi.exe
bzsbkotiu.exe
Firewallservice.exe
ieudator.dll
csrsss.exe
96dddda4.dll
DLL321.dll
MusicCollector.exe
oygqyunapnp.exe
Q3d38543.exe
%SystemDrive%\????????????
rvcbcyks.exe
SyncHostps.exe
acuvzomo.exe
ACEIEAddOn.dll
idiokbbrv.exe
%UserProfile%
ubvhynpxh.exe
bf8h8d02hf.exe
ssntvs.exe
Nbt.exe
svchost.exe
install_0_msi.exe
50E1.exe
wgsdgsdgdsgsd.exe
xmlfilter.exe
iner.exe
NTServiceManager.exe
JfCqQ5JC.exe
ctfmon.exe
87b2cb3916261d5c807bf44262755cb0.exe
DA0B.exe
secproc_isv.exe
WINDED6.exe
najeoxtt.exe
3511172082012Build.exe
pYunY8m4VL3qLc.exe
videotwisterSA.exe
xlqbteeb.exe
%LOCALAPPDATA%\Temp
dqnbdq7.dss
brenasa.exe
rool0_pk.exe

NSA Virus DLL's to remove:

questscan.dll
ieudator.dll
ACEIEAddOn.dll
puozlkmyj.dll
2084473.dll
wlsidten.dll
96dddda4.dll
ex3b.dll
DLL321.dll
wpbt0.dll
yaiiwockc.dll
xctqakcqbeo.dll

NSA Virus processes to kill:

gcrwcoak.exe
UpgradeHelper.exe
bvhylsviw.exe
sqlncli.exe
dyjdl.exe
msdtmsrd.exe
comeo.exe
wgsdgsdgdsgsd.exe
SyncHostps.exe
Q3d38543.exe
Updating.exe
taskhost.exe.exe
MusicCollector.exe
wahneaqa.exe
TimeDateMUICallback.exe
WinSyncMetastore.exe
C87C.exe
najeoxtt.exe
msn.exe
m2PythonLoader.exe
xaZYOVJW.exe
brenasa.exe
audipbrd.exe
DA0B.exe
setex.exe
rool0_pk.exe
scvhost.exe
iner.exe
魔法桌面第三方主题破解补丁V1.1.exe
xmlfilter.exe
UpdatePriv.exe
wlsidten.exe
87b2cb3916261d5c807bf44262755cb0.exe
ctfmon.exe
uenovfiu.exe
dtkmujvo.exe
bf8h8d02hf.exe
rvcbcyks.exe
pYunY8m4VL3qLc.exe
systemcpl.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
xlqbteeb.exe
NTServiceManager.exe
WINDED6.exe
install_0_msi.exe
msavfit.exe
bzsbkotiu.exe
aPr0hY9.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
Firewallservice.exe
50E1.exe
ssntvs.exe
pmstcdjwz.exe
secproc_isv.exe
mplayer2.exe
Task Scheduler.exe
ifgxpers.exe
ubvhynpxh.exe
acuvzomo.exe
videotwisterSA.exe
oygqyunapnp.exe
3511172082012Build.exe
b34btbztdb0vavaw.exe
zqmkrehUkpoKfsafsaZg.exe
csrsss.exe
Piranha.exe
JfCqQ5JC.exe
Nbt.exe
msshell.exe
crack.exe
idiokbbrv.exe
00b5d693.exe
msnmsgrr.exe
VaultSysUi.exe
obvwo.exe
p1.exe
svchost.exe
securitywindrv.exe
OmaSG21e.exe
administration.exe
00qbipeq.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.