Home Malware Programs Rogue Anti-Virus Programs System Antivirus Microsoft 2011

System Antivirus Microsoft 2011

Posted: August 31, 2011

System Antivirus Microsoft 2011 (also known as СИСТЕМНЫЙ АНТИВИРУС MICROSOFT 2011 in its native Russian) is a ransomware Trojan that locks up all major functions on your PC until you pay a ransom fee. Although System Antivirus Microsoft 2011 creates a message that claims that this fee is a legitimate transaction and a penalty for illegal file-trafficking, System Antivirus Microsoft 2011 isn't a legitimate security program and has nothing to do with any form of law enforcement. Like most other ransomware that SpywareRemove.com malware experts have found, System Antivirus Microsoft 2011 can be unlocked with a purchasable deactivation code; however, the preferable course of action is to remove System Antivirus Microsoft 2011 by using appropriate anti-malware strategies and security programs.

Keeping System Antivirus Microsoft 2011's Fake Threats Away from Your PC

SpywareRemove.com malware research team has found that the primary distribution routes for System Antivirus Microsoft 2011 Trojans are Russian websites, particularly sites that pretend to offer adult videos. Instead of offering real content, these sites use fake codec and video player update links to install System Antivirus Microsoft 2011 and other Trojans onto your PC. These websites may also host drive-by-download exploits that install System Antivirus Microsoft 2011 or other kinds of malicious software without requiring you to install anything of your own free will.

As soon as it's on your computer, System Antivirus Microsoft 2011 will launch an attack that's typical of ransomware, by creating a fake warning message that you've been caught performing illegal activities. The original message is in Russian, as well as a rough translation in English are noted below:

КОМПЬЮТЕР ЗАБЛОКИРОВАН!

Внимание! Ваш ПК заблокирован за просмотр и распространение порнографии с
участием несовершеннолетних, элементами насилия, зоофилии. Для разблокировки,

Вам необходимо выполнить следующие действия:

В любом терминале оплаты,в разделе электронная коммерция - WEBMONEY, в поле
номер кошелька введите [], в поле номер телефона введите [],
оплатите через купюроприемник 500 рублей.
По завершению оплаты, на выданном терминалом чеке оплаты, Вам будет выдан
персональный код, после ввода которого, Ваш ПК будет автоматически разблокирован.

После разблокировки ПК, необходимо уничтожить все незаконнно расположенные
видеоматериалы. В случае отказа от оплаты, вся информация на Вашем ПК будет
безвозвратно уничтожена без возможности восстановления
СИСТЕМНЫЙ АНТИВИРУС MICROSOFT 2011

[Approximate English translation]
THE COMPUTER IS BLOCKED!

Attention! Your personal computer is blocked for viewing and propagation of a pornography with
Participation of minors, elements of violence, зоофилии. For a unblocking,

It is necessary for you to execute following actions:

In any terminal of payment, in section electronic commerce - WEBMONEY, in a floor
Number of a purse enter [], into a field a phone number enter [],
Pay through купюроприемник 500 roubles.
On completion of payment, on the check of payment given out by the terminal, to you it will be given out
Personal code after which input, your personal computer will be automatically unblocked.

After a unblocking of the personal computer, it is necessary to destroy all незаконнно located Video data. In default from payment, the information on your personal computer will be
It is irrevocably destroyed without a possibility of restoration
SYSTEM ANTIVIRUS MICROSOFT 2011.

However, System Antivirus Microsoft 2011 Trojans are malicious programs that don't try to monitor your online activities, and paying a System Antivirus Microsoft 2011 fee is an utter waste of money. Although the unlock code to disable System Antivirus Microsoft 2011 hasn't yet been made available on a free basis, other methods can unlock System Antivirus Microsoft 2011 free of charge.

Picking the Lock That System Antivirus Microsoft 2011 Slaps Onto Your OS

Although System Antivirus Microsoft 2011 does its absolute best to lock down every feature that you could think to use, careful use of anti-malware strategies and software can disable and remove System Antivirus Microsoft 2011 from your PC, all without you paying a single cent. Like most forms of ransomware, System Antivirus Microsoft 2011 can't back up its threats with actions and is unable to delete your files even if you refuse to pay its fee or try to delete System Antivirus Microsoft 2011.

Safe Mode or even rebooting from a removable hard drive may be required to deactivate System Antivirus Microsoft 2011. Afterwards, restoration of the relevant system settings and an anti-malware scan will let you delete System Antivirus Microsoft 2011 and move on with your life, free of ransoms.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



[SET OF RANDOM CHARACTERS].exe File name: [SET OF RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ Shell" = "[SET OF RANDOM CHARACTERS].exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ "Shell" = "[SET OF RANDOM CHARACTERS].exe"
Loading...