Home Malware Programs Ransomware ‘POLITIE, Onwettige activiteiten gedetecteerd!!!’ Ransomware

‘POLITIE, Onwettige activiteiten gedetecteerd!!!’ Ransomware

Posted: November 21, 2011

'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware is a typical form of ransomware Trojan that demands that you pay an electronic fee in order to regain access to your PC. 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware will create a fake legal warning to lend an appearance of legitimacy to its ransom request, but SpywareRemove.com malware researchers very firmly note that 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware isn't a legitimate form of legal authority and shouldn't be treated as such. Instead of shelling out money to get back what's yours, it's recommended that you remove 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware infections by using basic anti-malware techniques to prevent the ransomware from launching, and then use your choice of anti-malware program to delete all of the ransomware's components.

Why You Shouldn't Respect or Obey 'POLITIE, Onwettige activiteiten gedetecteerd!!!' Ransomware

The initial 'POLITIE, Onwettige activiteiten gedetecteerd!!!' message that's provided by 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware is a mere pretense that tries to make you believe that you've been caught in the act of some crime. Although the warning message does try hard to look realistic, you should never consider following any of the advice shown in this example below:

POLITIE
Let op!!!
Onwettige activiteiten gedetecteerd!!!
Uw operationele systeem is geblokkeerd wegens inbreuk op de de Nederlandse wetgeving! Volgende inbreuken zijn gedetecteerd: Uw IP adres is geregistreerd op de websites met clandestien en/of pornografische content, die pedofilie, zoöfilie en geweld tegen kinderen aanmoedigen! Op uw PC zijn er videobestanden met pornografische inhoud en elementen van geweld en kinderporno ontdekt!
Tevens worden illegale SPAM berichten van terroristische aard van uw PC automatisch overal heen verspreid.
Deze blokkering heeft in het oog de verspreiding van deze gegeven van uw PC op het Internet tegen te gaan.

[English translation - paraphrased for your convenience]
POLICE
Warning!!!
Illegal activities detected!!!
Your operating system has been blocked for infringement of Dutch law! The following infringements are detected: your IP address is recorded on websites with illegal and/or pornographic content, including paedophilia, zoöfilie and encourage violence against children! Pornographic contents and elements of violence and child pornography have been discovered on your PC!
There may also be illegal SPAM messages of terrorist nature automatically being propagated from your PC.
In the face of this propagation, your PC has been prevented from accessing the Internet.

This message isn't, of course, sent by any form of real legal authority, and 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware is incapable of detecting any real files on your PC (legal or otherwise). Despite this complete lack of real crime-detecting features, 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware still encourages you to pay a hefty fine to restore access to your PC. This Paysafecard-based fine (over a hundred dollars, once converted from Euros) is only a fee that's paid to criminals who will, in theory, give you the key to unlock the ransomware Trojan, after they receive payment. SpywareRemove.com malware research team strongly discourages doing this, since it will allow 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware's criminal masterminds to profit and encourage them to increase the propagation of this Windows-locking Trojan.

The Safe Fix for a 'POLITIE, Onwettige activiteiten gedetecteerd!!!' Ransomware Attack

There are two ways to put a stop to 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware and unlock your operating system – and the good news is that both methods are free of charge:

  • In mild cases of infection, you may be able to stop the 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware from launching itself, by using a Safe Mode boot. Safe Mode can be accessed from the relevant menu by tapping F8 during a reboot before Windows starts to load.
  • In more extreme instances that involve rootkit-derived infection techniques, SpywareRemove.com malware experts recommend that you use an external system boot via a CD or USB storage drive. By doing this, you completely-avoid the Registry entries that would allow 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware to start in the first place.

Either of the above methods will allow you to access Windows and avoid 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware's system lockout. However, a normal boot will still direct you to 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware's fake warning screen, and so you should scan your PC and remove 'POLITIE, Onwettige activiteiten gedetecteerd!!!' ransomware with an anti-malware program, before you relax.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



[SET OF RANDOM CHARACTERS].exe File name: [SET OF RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run = "vasja"

Additional Information

The following messages's were detected:
# Message
1 POLITIE Let op!!! Onwettige activiteiten gedetecteerd!!! Uw operationele systeem is geblokkeerd wegens inbreuk op de de Nederlandse wetgeving! Volgende inbreuken zijn gedetecteerd: Uw IP adres is geregistreerd op de websites met clandestien en/of pornografische content, die pedofilie, zoöfilie en geweld tegen kinderen aanmoedigen! Op uw PC zijn er videobestanden met pornografische inhoud en elementen van geweld en kinderporno ontdekt! Tevens worden illegale SPAM berichten van terroristische aard van uw PC automatisch overal heen verspreid. Deze blokkering heeft in het oog de verspreiding van deze gegeven van uw PC op het internet tegen te gaan.
2Warning! Illegal activities detected! Your operating system is blocked for violation of Dutch law! Following violations were detected: Your IP address is registered on the websites of clandestine and / or pornographic content, which pedophilia, zoophilia and encouraging violence against children! On your PC, there are video files with pornographic content and elements of violence and child pornography discovered! SPAM messages are also illegal terrorist nature of your PC automatically scattered everywhere. This lock is in the eye of the spread of this information from your PC to the Internet to counter.

Loading...