Question:
Window Protection Suite!!! HELP REMOVING! 10 points to whatever works (:?
Share
2009-08-14 12:41:22 UTC
Can anyone help me to remove this program?
the manual seems a bit to complicated
and when I try Spyware doctor it keeps asking me to upgrade

HELP !
please and thank u
Nine answers:
2009-08-17 17:59:36 UTC
I have the exact same problem! I can't get it off! It's really annoying!



EDIT: Use http://www.malwarebytes.org/ It really works! Windows Protection Suite is finally off my computer! Just install, scan, and when it shows the results just delete everything in the list! I'm so happy and so will you!
?
2009-08-17 03:24:10 UTC
I manually removed it but the software or what rode in with it is wicked. It disabled System Restore, the Windows Task Manager (to delete processes), the Command Prompt, Windows Defender (which the software tries to look like), and my Antivirus/Antimalware program. Removing the software by hand did not restore the access to the programs.



My (former) antivirus provider pointed me to ComboFix on BleepingComputer.com to try and repair my system. But seeing its home, I found the description specifically of this malware. There they suggested MalwareBytes to remove this specific program. Although already removed by hand, none of these solutions restored the OS programs or Antivirus software. Still working to do that without resorting to a wipe of the hard disk (this was the second suggestion of my (former) antivirus provider).



To manually remove: (Note: hit "Ignore" and the "x" to close the constant pop-ups from the WPS program during this.)

a) Remove your machine from the network, do not download anymore

b) Open Computer or any (Windows) explorer window to change your global folder search options to view extensions to files and hidden files and system folders

c) Right click on the shortcuts in either start-up, quick-launch or the like to find where the executable was put. On Vista, in ProgramData. The malware protected some of their files from deletion but you can usually rename them; especially in safe mode. Whatever ones you cannot delete, then rename to trash, trash1, etc.

d) Delete the quick launch, desktop and startup icons (this will remove the only registry entry I found)

e) In Vista, under User accounts in the hidden AppData folder, I found a directory "Windows Protection Suite" with a log file being written too. I could not delete the file but could rename the directory.

f) Empty your recycle bin of anything you could delete. Make sure the system is idle and everything closed. Some think you should do a normal shutdown. I usually do a hard shut down by pushing and holding the power button. If the system is idle, your disk state should be good. Doing a normal shutdown risks the software being informed and doing more bad deeds to undo what you just did. Either way is risky

g) Reboot in safe mode. Delete all those renamed "trash" files and directories you could not delete before.

h) reboot normally. The software is gone.



Now you will have to "reinstall" or "repair" your anti-virus and other OS files as it is still prevented from running. Not even Windows defender can be started yet. In my case, I was able to rename (not delete or start) the Antivirus program and then start the renamed file after rebooting. This reconfigured and started the program. But it did not find anything.



Still working on how to restore the OS programs that are still blocked. Must be an additional buried .dll file installed somewhere yet.



It is very odd the Anti-virus vendors do not have more about this on their help websites given the program disables their product completely. It is even odder that this program is able to do that. A nasty beast to say the least. Hope it helps.
PariahMaterial
2009-08-14 12:47:42 UTC
I had good luck removing this sort of problem with:



Malwarebytes.



go to www.malwarebytes.org

Download Free Version

Update



Reboot computer into Safe Mode With Networking (Tap the F8 key before you reach the Welcome Screen at reboot. Screen will be black and white. Choose Safe Mode with Networking)



Run Malwarebytes in safe mode.

Reboot

Run in Normal Mode. Do the FULL scans. They take some time but are well worth it.



Good luck.
2009-08-14 12:45:49 UTC
Windows Protection Suite manual removal:

Kill processes:

snl2w.exe std.exe WindowsProtectionSuite.exe WI345d.exe ppal.exe uninstall.exe WI345d.exe CLSV.exe

HELP:

how to kill malicious processes



Delete registry values:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “WindowsProtectionSuite”

HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}

HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler

HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://search-gala.com/?&uid=7&q={searchTerms}"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "9877034603"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Protection Suite"

HELP:

how to remove registry entries



Unregister DLLs:

energy.dll grid.dll kernel32.dll tempdoc.dll PE.dll runddl.dll SM.dll mozcrt19.dll sqlite3.dll cid.dll CLSV.dll ddv.dll

HELP:

how to unregister malicious DLLs



Delete files:

WI345d.exe CLSV.exe snl2w.exe std.exe WindowsProtectionSuite.exe WI345d.exe ppal.exe tempdoc.dll energy.dll mozcrt19.dll sqlite3.dll cid.dll CLSV.dll ddv.dll tempdoc.dll WINPS.ico working.log vd952342.bd winps.cfg cookies.sqlite Instructions.ini cb.sys cid.tmp CLSV.tmp DBOLE.sys

HELP:

how to remove harmful files



Delete directories:

%UserProfile%\Application Data\Windows Protection Suite
he's dead, jim
2009-08-18 05:57:55 UTC
delete windows protection suite manually, this way you don't need any program and it won't cost you a thing. here's detailed manual removal guide: http://www.spywarevoid.com/remove-windows-protection-suite-windowsprotection-suite-removal.html
M
2009-08-14 12:48:36 UTC
well.First of all I recommend you use Malwarebytes´ Anti-Malware program,Ad-Aware,Kaspersky Anti-virus/Internet Security.

http://www.bleepingcomputer.com/virus-removal/remove-windows-protection-suite



This should help you moer than I would be able to only by writing.
petrosino
2016-10-06 02:19:59 UTC
attempt going to the upload/do away with application. click on your domicile windows initiate menu and then click on the administration panel icon. then you certainly decide for to click the upload/do away with application icon. this would pop up yet another window which will checklist all the courses that are put in you your laptop alphabetically. look down the checklist for domicile windows secure practices Suite. you opt for to spotlight it and then click uninstall.
2009-08-14 12:48:58 UTC
Download this, it will boot infront of that virus so you can remove it with a scan.



http://www.softpedia.com/get/Antivirus/BluePoint-Security.shtml
2009-08-14 15:21:26 UTC
http://www.malwarebytes.org/



http://superantispyware.com/



Manually keep updated .


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...