|
Free malware removal tool for Windows Protection Suite
|
|
Written by Administrator |
Wednesday, 02 December 2009 16:43
|
|
Windows Protection Suite is a rogue, ie malware that pretends to be an Antivirus when in reality it is the malware. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares in your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is Windows Protection Suite. It invites you to purchase a license to remove malware, do not, it's a scam, you need a license for a virus? This so-called Antivirus he tries to scam you.

To remove Windows Protection Suite
- Download this removal tool
- Extract
- Launch
- Click on the delete button
This malware will be removed from your system in 10s. Restart your computer when it’s finished.
After running the patch, your homepage Internet Explorer becomes search.net-studio.org, done deliberately to erase all traces of then malware, BHOs (Browser Helper Object) are also deleted. You can always restore this setting in Internet Explorer options.
- WindowsProtectionSuite.exe
- WI345d.exe
- Windows Protection Suite.exe
- WI345d.exe
- CLSV.exe
- %Program Files%\WindowsProtectionSuite\WindowsProtectionSuite.exe
- %AppData%\345d567\WI345d.exe
- %UserProfile%\Recent\std.exe
- %UserProfile%\Recent\snl2w.exe
- %UserProfile%\Recent\CLSV.exe
- %UserProfile%\Desktop\WindowsProtectionSuite.exe
- %AppData%\WINSSSys\winss.cfg
- %AppData%\345d567\WINSSSys\vd952342.bd
- %AppData%\345d567\working.log
- %AppData%\345d567\WINSS.ico
- %AppData%\345d567\WI345d.exe
- %AppData%\345d567\sqlite3.dll
- %AppData%\345d567\mozcrt19.dll
- %AppData%\345d567\26.mof
- %AppData%\WINSSSys
- %AppData%\345d567\WINSSSys
- %AppData%\345d567
- %UserProfile%\Application Data\Windows Protection Suite 2009\Instructions.ini
- %UserProfile%\Application Data\Windows Protection Suite 2009
- %UserProfile%\Desktop\WindowsProtectionSuite.exe
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Protection Suite 2009.lnk
- %Programs%\Windows Protection Suite.lnk
- %UserProfile%\Desktop\Windows Protection Suite 2009.lnk
- %Programs%\Windows Protection Suite 2009.lnk
- %UserProfile%\Start Menu\Windows Protection Suite 2009.lnk
- %Programs%\WindowsProtectionSuite\WindowsProtectionSuite Website.lnk
- %Programs%\WindowsProtectionSuite\WindowsProtectionSuite.lnk
- %StartMenu%\WindowsProtectionSuite.lnk
- %Programs%\WindowsProtectionSuite
- %Program Files%\Mozilla Firefox\searchplugins\search.xml
- %Program Files%\WindowsProtectionSuite\WindowsProtectionSuite.url
- %Program Files%\WindowsProtectionSuite\WindowsProtectionSuite.exe
- %UserProfile%\Recent\std.exe
- %UserProfile%\Recent\snl2w.exe
- %UserProfile%\Recent\grid.sys
- %UserProfile%\Recent\dudl.sys
- %UserProfile%\Recent\DBOLE.drv
- %UserProfile%\Recent\ANTIGEN.drv
- %UserProfile%\Application Data\Windows Protection Suite\Instructions.ini
- %UserProfile%\Application Data\Windows Protection Suite\cookies.sqlite
- %UserProfile%\Application Data\Windows Protection Suite
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Protection Suite.lnk
- %UserProfile%\Desktop\Windows Protection Suite.lnk
- %UserProfile%\Application Data\Windows Protection Suite
- %UserProfile%\Recent\cb.sys
- %UserProfile%\Recent\cid.dll
- %UserProfile%\Recent\cid.tmp
- %UserProfile%\Recent\CLSV.dll
- %UserProfile%\Recent\CLSV.tmp
- %UserProfile%\Recent\DBOLE.sys
- %UserProfile%\Recent\ddv.dll
- %UserProfile%\Recent\eb.sys
- %UserProfile%\Recent\eb.tmp
- %UserProfile%\Recent\energy.drv
- %UserProfile%\Recent\energy.sys
- %UserProfile%\Recent\exec.tmp
- %UserProfile%\Recent\kernel32.drv
- %UserProfile%\Recent\PE.drv
- %UserProfile%\Recent\PE.tmp
- %UserProfile%\Recent\ppal.exe
- %UserProfile%\Recent\runddlkey.drv
- %UserProfile%\Recent\snl2w.sys
- %UserProfile%\Recent\tempdoc.dll
- %AppData%\345d567\sqlite3.dll
- %AppData%\345d567\mozcrt19.dll
- %UserProfile%\Recent\SM.dll
- %UserProfile%\Recent\tempdoc.dll
- %UserProfile%\Recent\runddl.dll
- %UserProfile%\Recent\PE.dll
- %UserProfile%\Recent\grid.dll
- %UserProfile%\Recent\energy.dll
- %UserProfile%\Recent\kernel32.dll
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- WindowsProtectionSuite = "%Program Files%\WindowsProtectionSuite\WindowsProtectionSuite.exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent
- Post Platform = "9877034603"
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
- HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
- HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes
- “URL” = “http://search-gala.com/?&uid=7&q={searchTerms}”

|
Comments
RSS feed for comments to this post.