Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Installs itself without permissions
  • Changes background
  • Connects to the internet without permission

Windows заблокирован virus

Windows заблокирован virus is a computer infection that is part of the Ukash Virus group. It is a ransomware program and it infects computer users in Russia. Once you get infected with this malicious threat you are denied desktop access and then you are forced to pay a ransom fee that is called a “fine”. According to Windows заблокирован virus, you need to pay the so-called fine, because you have been involved in a number of illegal activities. Unless you remove Windows заблокирован virus from your computer, the notification will remain on your screen, so get rid of the ransomware program right now!

We have not encountered Ukash viruses intended for Russian market before, but judging from such related programs as FBI MoneyPak virus, GVU Virus, Poliisin Tekniikkakeskus virus and the like, the infection pretends to be a legal representative of a law enforcement authority, or simply tries to make you think that you need to pay a particular sum of money in order to unlock your operating system. Naturally, these claims are not real, and there is no need to believe anything Windows заблокирован virus says. If you pay the fine you will only lose your money, so you need to ignore the message you seen on your screen:

Windows заблокирован!
Microsoft Security обнаружил нарушения использования сети интернет.
Причина: Просмотр ДЕТСКОГО и гей порно, посещение порно-сайтов.
Для разблокировки Windows необходимо:
Пополнить номер абонента БИЛАЙН: 8-906-418-29-47 на сумму 500 руб.

As you can see, you are asked to pay 500 rubles by paying for a pre-paid number. Windows заблокирован virus claims that once you pay the fine, your computer will be unlocked. However, you can obviously see that the notification on your screen barely looks like an official notice from security forces or from Windows operating system. It is an obvious scam that has been devised to steal your money, and should you transfer the fine to these cyber criminals, you will never see your money again, and your computer will remain locked.

You need to unlock the PC right now in order to remove Windows заблокирован virus for good. Keep in mind that the ransomware infection arrived at your PC probably because you have been infected with Trojans prior to the Windows заблокирован virus arrival. It means that you need to invest in a powerful antimalware tool to terminate all the potentially hazardous programs and files.

How to restore desktop access

Windows 8

  1. Press Windows key and metro GUI will open.
  2. Click Internet Explorer tile and enter http://www.pchtreat.com/download-sph into address bar.
  3. Press Enter and click Run on download dialog box.
  4. Install SpyHunter and run a full system scan.

Windows Vista & Windows 7

  1. Restart your computer and tap F8 repeatedly.
  2. Select Safe Mode with Networking from Advanced Boot Options menu. Press Enter.
  3. Access http://www.pcthreat.com/download-sph and download SpyHunter.
  4. Install the program and scan your computer.

Windows XP

  1. Follow the steps above 1 and 2.
  2. Click Yes on Confirmation dialog box.
  3. Download SpyHunter.
  4. Open Start menu and launch Run.
  5. Enter “msconfig” into Open box and click OK.
  6. Select Startup tab on System Configuration Utilities.
  7. Click Disable all and press OK.
  8. Reboot the PC in Normal mode.
  9. Install SpyHunter and launch a full system scan.

In case you need any assistance with Windows заблокирован virus, leave us a comment below.

Download Spyware Removal Tool to Remove* Windows заблокирован virus
  • Quick & tested solution for Windows заблокирован virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Windows заблокирован virus

Files associated with Windows заблокирован virus infection:

%APPDATA%\system
acuvzomo.exe
zqmkrehUkpoKfsafsaZg.exe
gcrwcoak.exe
2084473.dll
%APPDATA%\Task Scheduler
WinSyncMetastore.exe
rvcbcyks.exe
DA0B.exe
xaZYOVJW.exe
NTServiceManager.exe
bvhylsviw.exe
%CommonProgramFiles%
C87C.exe
p1.exe
brenasa.exe
96dddda4.dll
msnmsgrr.exe
csrsss.exe
wahneaqa.exe
SyncHostps.exe
wgsdgsdgdsgsd.exe
hwj3ba6j.dss
Updating.exe
%APPDATA%\updates
systemcpl.exe
ex3b.dll
mplayer2.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
bzsbkotiu.exe
%AppData%
ctfmon.exe
JfCqQ5JC.exe
jsdhlexdqkllnbcxgai.bfg
msavfit.exe
dtkmujvo.exe
ubvhynpxh.exe
3511172082012Build.exe
%WINDIR%\Temp
%ALLUSERSPROFILE%
wlsidten.dll
pYunY8m4VL3qLc.exe
Piranha.exe
aPr0hY9.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
taskhost.exe.exe
wpbt0.dll
securitywindrv.exe
UpdatePriv.exe
%UserProfile%
najeoxtt.exe
b34btbztdb0vavaw.exe
87b2cb3916261d5c807bf44262755cb0.exe
videotwisterSA.exe
wlsidten.exe
scvhost.exe
xctqakcqbeo.dll
%ALLUSERSPROFILE%\Application Data
questscan.dll
WINDED6.exe
TimeDateMUICallback.exe
ssntvs.exe
skype.dat
administration.exe
msshell.exe
50E1.exe
DLL321.dll
svchost.exe
Q3d38543.exe
%LOCALAPPDATA%\Temp
crack.exe
ifgxpers.exe
uenovfiu.exe
dqnbdq7.dss
dyjdl.exe
wjthvwjb.dss
OmaSG21e.exe
bf8h8d02hf.exe
ieudator.dll
comeo.exe
Other.res
Firewallservice.exe
VaultSysUi.exe
00b5d693.exe
pmstcdjwz.exe
00qbipeq.exe
sqlncli.exe
Task Scheduler.exe
msn.exe
xlqbteeb.exe
secproc_isv.exe
%LOCALAPPDATA%\lollipop
%SystemDrive%\????????????
oygqyunapnp.exe
puozlkmyj.dll
obvwo.exe
setex.exe
yaiiwockc.dll
ACEIEAddOn.dll
audipbrd.exe
m2PythonLoader.exe
%TEMP%
install_0_msi.exe
idiokbbrv.exe
n.
MusicCollector.exe
iner.exe
rool0_pk.exe
Nbt.exe
魔法桌面第三方主题破解补丁V1.1.exe
UpgradeHelper.exe
xmlfilter.exe
msdtmsrd.exe
%WINDIR%\system32

Windows заблокирован virus DLL's to remove:

wlsidten.dll
wpbt0.dll
ex3b.dll
ieudator.dll
xctqakcqbeo.dll
puozlkmyj.dll
DLL321.dll
2084473.dll
ACEIEAddOn.dll
96dddda4.dll
yaiiwockc.dll
questscan.dll

Windows заблокирован virus processes to kill:

TimeDateMUICallback.exe
OmaSG21e.exe
xlqbteeb.exe
xmlfilter.exe
Q3d38543.exe
comeo.exe
Updating.exe
wgsdgsdgdsgsd.exe
systemcpl.exe
b34btbztdb0vavaw.exe
uenovfiu.exe
dyjdl.exe
rvcbcyks.exe
administration.exe
pYunY8m4VL3qLc.exe
bvhylsviw.exe
UpdatePriv.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
Task Scheduler.exe
mplayer2.exe
oygqyunapnp.exe
audipbrd.exe
50E1.exe
NTServiceManager.exe
idiokbbrv.exe
najeoxtt.exe
MusicCollector.exe
install_0_msi.exe
msdtmsrd.exe
bzsbkotiu.exe
SyncHostps.exe
3511172082012Build.exe
ctfmon.exe
87b2cb3916261d5c807bf44262755cb0.exe
C87C.exe
msavfit.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
xaZYOVJW.exe
p1.exe
m2PythonLoader.exe
svchost.exe
secproc_isv.exe
dtkmujvo.exe
pmstcdjwz.exe
csrsss.exe
sqlncli.exe
WINDED6.exe
Firewallservice.exe
00qbipeq.exe
msn.exe
gcrwcoak.exe
VaultSysUi.exe
brenasa.exe
msnmsgrr.exe
acuvzomo.exe
JfCqQ5JC.exe
UpgradeHelper.exe
Nbt.exe
crack.exe
WinSyncMetastore.exe
ubvhynpxh.exe
iner.exe
00b5d693.exe
zqmkrehUkpoKfsafsaZg.exe
obvwo.exe
DA0B.exe
魔法桌面第三方主题破解补丁V1.1.exe
wlsidten.exe
rool0_pk.exe
Piranha.exe
aPr0hY9.exe
ifgxpers.exe
videotwisterSA.exe
msshell.exe
setex.exe
ssntvs.exe
scvhost.exe
wahneaqa.exe
securitywindrv.exe
taskhost.exe.exe
bf8h8d02hf.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.