Home Malware Programs Ransomware ‘Bundesamt für Sicherheit in der Informationstechnik’ Ransomware

‘Bundesamt für Sicherheit in der Informationstechnik’ Ransomware

Posted: March 17, 2014

Threat Metric

Threat Level: 10/10
Infected PCs: 12
First Seen: March 17, 2014
OS(es) Affected: Windows


The 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware is a Trojan specialized in assaulting residents of German-speaking nations with fake copyright warnings that block the infected PC's desktop. While the Bundesamt für Sicherheit in der Informationstechnik or the Federal Office for Information Security, is a legitimate organization, it hasn't endorsed these computer-blocking attacks, which trigger even for machines that are innocent of any wrongdoing. Meanwhile, malware researchers recommend the same solutions they'd call for with any other fake Police Trojan: using appropriate security steps to disable and then delete the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware.

The Trojan that Keeps Your Information Under Lock and Key

The 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware is one of dozens of examples of Windows-locking Trojans taking advantage of first world intellectual property systems to attack their residents with threats of copyright violation. Although you may or may not be guilty of such crimes, the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware loads its warning message even if the PC in question has not been used for illegal activities. Malware experts have found that these warnings, like those of most similar ransomware attacks, are pop-ups modified to be difficult to close (by removing borders, minimize buttons and other interface details).

The 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware's auto-launching pop-up will block your desktop, seemingly until you pay its demanded legal fee. As usual, the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware demands its fee through channels like Paysafecard or Ukash, which should be a clear sign that the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware is a threatening software, rather than a legitimate disciplinary action from the German government. Paying this fee isn't recommended; however, in the meantime, you'll temporarily be blocked by the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware from accessing most other programs.

Taking the Lock out of a Windows-Locking Trojan

The 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware doesn't diverge significantly from old examples of fake copyright-protecting programs, but its ability to launch automatically and proceed to block most other applications does make its removal somewhat non-simplistic. In these cases, malware researchers suggest restarting your PC from Safe Mode or from a peripheral device, whichever is necessary to disable all threats, including the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware. When you've launched your PC without the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware's pop-up or software barricade in the way, you can feel free to delete the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware with any anti-malware product that you favor.

Distribution methods for the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware have yet to be isolated by malware researchers. All but identical types of threatening software have been known to use multiple strategies to infect other PCs, including spam e-mail attachments and social networking spam. In all cases, a mixture of reliable anti-malware protection, good browser security and safe browsing behavior will let you avoid the most probable ways of getting the 'Bundesamt für Sicherheit in der Informationstechnik' Ransomware installed automatically.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



9efc878ac5303570ce905850848d9efc File name: 9efc878ac5303570ce905850848d9efc
Size: 23.55 KB (23552 bytes)
MD5: 9efc878ac5303570ce905850848d9efc
Detection count: 93
Group: Malware file

Additional Information

The following messages's were detected:
# Message
1ACHTUNG! Ihr Computer ist aus einem oder mehreren der unten aufgeführten Gründe gesperrt.
Sie haben gegen das Gesetz über “Urheberrecht und verwandte Schutzrechte” (Video, Musik, Software) verstoßen un unrechtmaßig urheberrechtliche inhalte genutzt, bzw, verbreitet und somit gegen Art. 128 des Strafgesetzbuches der Bundesrepublik Deutschland verstoßen.

Loading...