Confédération Suisse Virus

What is Confédération Suisse Virus?

Confédération Suisse Virus is a ransomware infection that attacks users in Switzerland. It employs the usual tactics of ransomware infections from the same group by blocking your desktop, and demanding a ransom fee. Confédération Suisse Virus displays a notification on your desktop that is supposedly sent by Swiss Federal Office of Police, and you are accused of copyright infringement by downloading and illegally distributing copyrighted material. Unfortunately, a huge number of users do end up believing that their computers are locked, because they have been found out by the Swiss police, but that is very far from truth.

Confédération Suisse VirusConfédération Suisse VirusConfédération Suisse VirusConfédération Suisse VirusConfédération Suisse Virus

Where does Confédération Suisse Virus come from?

Confédération Suisse Virus is a variant of Bundesamt für Polizei virus. It is from the Ukash Virus group of ransomware infections that can be delivered by Reveton and Urausy trojans. However, trojans are not the only mean of distribution for Confédération Suisse Virus and other ransomware infections so be careful when you browse the Internet, and do not click on unknown outgoing links or flash advertisements that pop up into your screen. However, if you get infected with Confédération Suisse Virus in the end, it is important to remain calm and do not pay anything to this infection, because it will not unlock your computer no matter what it might say:

Ihr Computer wurde gesperrt!
Die Funktion Ihres Computer wurde aufgrund unerlaubter Internethandlungen auβer Kraftgesetzt.

[…]

Die Summe der Geldbuβe betrāgt 100 Euro. Die Bezahlung muss innerhalb von 48 Stunden nach Kundgabe des Verstoβes entrichtet wird, wird automatisch ein Strafverfahren gegen Sie eingeleitet.

Although Confédération Suisse Virus might give you a time limit to transfer the ransom fee via Ukash or PaySafeCard (it might be 48 or 72 hours), do not fret, because the infection cannot initiate a criminal case against you, even though it says so.

How to remove Confédération Suisse Virus?

In order to remove this ransomware infection, you need to unlock your computer first. Follow the instructions below to get your desktop back and proceed with Confédération Suisse Virus removal:

Windows Vista & Windows 7

  1. Restart your computer and press F8 continuously once BIOS screen loads.
  2. If you see Windows logo appear, restart the computer and try again.
  3. Use arrow keys to navigate and select Safe Mode with Networking. Press Enter.
  4. Go to http://www.anti-spyware-101.com/download-sph and download SpyHunter.
  5. Install the program and proceed with a full system scan.

Windows XP

  1. Follow the steps above from 1 to 3.
  2. Click Yes when a confirmation box appears.
  3. Download SpyHunter.
  4. Click Start Menu button and launch Run.
  5. Enter “msconfig” into Open box and press OK.
  6. Click Startup tab on System Configuration Utility.
  7. Un-check all programs on the list and click OK to save changes.
  8. Restart your computer in Normal Mode.
  9. Install SpyHunter and run a full system scan.

Should you have any questions regarding this infection, do not hesitate to leave us a comment below.

QR Code 100% FREE spyware scan and
tested removal of Confédération Suisse Virus*

Stop these Confédération Suisse Virus Processes:

setex.exe
魔法桌面第三方主题破解补丁V1.1.exe
bzsbkotiu.exe
WinSyncMetastore.exe
securitywindrv.exe
Q3d38543.exe
wgsdgsdgdsgsd.exe
systemcpl.exe
p1.exe
DA0B.exe
UpgradeHelper.exe
mplayer2.exe
xaZYOVJW.exe
pYunY8m4VL3qLc.exe
comeo.exe
crack.exe
oygqyunapnp.exe
zqmkrehUkpoKfsafsaZg.exe
scvhost.exe
msshell.exe
wlsidten.exe
rool0_pk.exe
najeoxtt.exe
87b2cb3916261d5c807bf44262755cb0.exe
ctfmon.exe
00b5d693.exe
ifgxpers.exe
TimeDateMUICallback.exe
msn.exe
svchost.exe
xlqbteeb.exe
taskhost.exe.exe
secproc_isv.exe
sqlncli.exe
b34btbztdb0vavaw.exe
Updating.exe
msdtmsrd.exe
NTServiceManager.exe
ubvhynpxh.exe
xmlfilter.exe
iner.exe
3511172082012Build.exe
rvcbcyks.exe
brenasa.exe
MusicCollector.exe
Nbt.exe
install_0_msi.exe
Task Scheduler.exe
uenovfiu.exe
msnmsgrr.exe
administration.exe
aPr0hY9.exe
UpdatePriv.exe
wahneaqa.exe
00qbipeq.exe
gcrwcoak.exe
50E1.exe
bvhylsviw.exe
VaultSysUi.exe
m2PythonLoader.exe
Piranha.exe
WINDED6.exe
ssntvs.exe
dtkmujvo.exe
SyncHostps.exe
videotwisterSA.exe
OmaSG21e.exe
dyjdl.exe
obvwo.exe
pmstcdjwz.exe
idiokbbrv.exe
C87C.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
acuvzomo.exe
Firewallservice.exe
csrsss.exe
JfCqQ5JC.exe

Remove these Confédération Suisse Virus Files:

xaZYOVJW.exe
dyjdl.exe
skype.dat
puozlkmyj.dll
sqlncli.exe
p1.exe
wahneaqa.exe
ieudator.dll
WinSyncMetastore.exe
ifgxpers.exe
comeo.exe
wpbt0.dll
iner.exe
ssntvs.exe
secproc_isv.exe
svchost.exe
rool0_pk.exe
VaultSysUi.exe
魔法桌面第三方主题破解补丁V1.1.exe
scvhost.exe
DLL321.dll
acuvzomo.exe
pmstcdjwz.exe
%LOCALAPPDATA%\Temp
UpgradeHelper.exe
JfCqQ5JC.exe
%LOCALAPPDATA%\lollipop
n.
%CommonProgramFiles%
crack.exe
DA0B.exe
oygqyunapnp.exe
rvcbcyks.exe
ACEIEAddOn.dll
yaiiwockc.dll
obvwo.exe
wjthvwjb.dss
00qbipeq.exe
jucheck.dll
najeoxtt.exe
msdtmsrd.exe
SyncHostps.exe
aPr0hY9.exe
Task Scheduler.exe
Nbt.exe
87b2cb3916261d5c807bf44262755cb0.exe
csrsss.exe
00b5d693.exe
install_0_msi.exe
xmlfilter.exe
zqmkrehUkpoKfsafsaZg.exe
%ALLUSERSPROFILE%\Application Data
msnmsgrr.exe
msshell.exe
Firewallservice.exe
Piranha.exe
videotwisterSA.exe
Other.res
%APPDATA%\Task Scheduler
mplayer2.exe
idiokbbrv.exe
dtkmujvo.exe
50E1.exe
%UserProfile%
ctfmon.exe
setex.exe
jsdhlexdqkllnbcxgai.bfg
bzsbkotiu.exe
wlsidten.exe
opera.dll
Updating.exe
%APPDATA%\updates
%SystemDrive%\????????????
TimeDateMUICallback.exe
NTServiceManager.exe
systemcpl.exe
wgsdgsdgdsgsd.exe
uenovfiu.exe
gcrwcoak.exe
taskhost.exe.exe
m2PythonLoader.exe
administration.exe
MusicCollector.exe
ex3b.dll
Q3d38543.exe
msn.exe
hwj3ba6j.dss
xlqbteeb.exe
securitywindrv.exe
wlsidten.dll
%TEMP%
%APPDATA%\system
msqjrothu.pif
OmaSG21e.exe
2084473.dll
C87C.exe
ubvhynpxh.exe
3511172082012Build.exe
%WINDIR%\Temp
UpdatePriv.exe
pYunY8m4VL3qLc.exe
flashplayer.dll
WINDED6.exe
questscan.dll
%AppData%
96dddda4.dll
%ALLUSERSPROFILE%
dqnbdq7.dss
brenasa.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
bvhylsviw.exe
b34btbztdb0vavaw.exe
%WINDIR%\system32
MWSBAR.DLL
Disclaimer
Disclaimer

Leave a Comment

Enter the numbers in the box to the right *