Windows Protection Suite

Windows Protection Suite is a new variant of Windows System Suite and Windows Security Suite. This rogue software uses various fraud web sites to promote itself. Trojan Downloader can also drop and install this parasite on target computer without a notice. The said Trojan can penetrate the system by exploiting software vulnerabilities and known security flaw. Once installed, Windows Protection Suite will automatically launch a virus scanner with graphical user interface made to look like a legitimate scan console. It pretends to scan computer for threats and display exaggerated result afterwards. This tactic may mislead computer users into purchasing the registered version of Windows Protection Suite.

To draw more attention from user, Windows Protection Suite extensively displays warnings and alert messages. This is in connection to its objective of persuading people for monetary gains. Things reported by Windows Protection Suite do not really exist on the system. Nevertheless, this does not mean that your computer is free from any harm and risks. In fact, the only remaining threat that you must take out is Windows Protection Suite itself. Run a real anti-malware program as soon as possible to remove presence of rogue security application from your PC.

Screen Shot Images:

windows-protection-suite

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

[expand title="View More" swaptitle="Hide This"]

Characteristics (Analysis)
By adding the following registry entry, Windows Protection Suite will start to load automatically after Windows log-on.
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run “Windows Protection Suite”

Malware Behavior
Although this potentially unwanted program’s payload do not includes damaging or stealing files, it can still bring harm to a compromised computer by altering various configurations. For example, Windows Protection Suite can block Internet access, end security-related process and disables Windows tools like Task Manager and registry editor.

Added Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Windows Protection Suite"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run “WindowsProtectionSuite”
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://search-gala.com/?&uid=7&q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Settings\5.0\User Agent\Post Platform "9877034603"
Associated Files and Folders:
C:\Documents and Settings\All Users\Application Data\512e361
C:\Documents and Settings\All Users\Application Data\512e361\285.mof
C:\Documents and Settings\All Users\Application Data\512e361\mozcrt19.dll
C:\Documents and Settings\All Users\Application Data\512e361\sqlite3.dll
C:\Documents and Settings\All Users\Application Data\512e361\WI345d.exe
C:\Documents and Settings\All Users\Application Data\512e361\WINPS.ico
C:\Documents and Settings\All Users\Application Data\512e361\working.log
C:\Documents and Settings\All Users\Application Data\512e361\WINSPSys
C:\Documents and Settings\All Users\Application Data\512e361\WINSPSys\vd952342.bd
C:\Documents and Settings\All Users\Application Data\WINSPSys
C:\Documents and Settings\All Users\Application Data\WINSPSys\winps.cfg
C:\Program Files\Mozilla Firefox\searchplugins\search.xml 
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Protection Suite.lnk
%UserProfile%\Application Data\Windows Protection Suite
%UserProfile%\Application Data\Windows Protection Suite\cookies.sqlite
%UserProfile%\Application Data\Windows Protection Suite\Instructions.ini
%UserProfile%\Desktop\Windows Protection Suite.lnk
%UserProfile%\Recent\cb.sys
%UserProfile%\Recent\cid.dll
%UserProfile%\Recent\cid.tmp
%UserProfile%\Recent\CLSV.dll
%UserProfile%\Recent\CLSV.tmp
%UserProfile%\Recent\DBOLE.sys
%UserProfile%\Recent\ddv.dll
%UserProfile%\Recent\eb.sys
%UserProfile%\Recent\eb.tmp
%UserProfile%\Recent\energy.drv
%UserProfile%\Recent\energy.sys
%UserProfile%\Recent\exec.tmp
%UserProfile%\Recent\kernel32.drv
%UserProfile%\Recent\PE.drv
%UserProfile%\Recent\PE.tmp
%UserProfile%\Recent\ppal.exe
%UserProfile%\Recent\runddlkey.drv
%UserProfile%\Recent\snl2w.sys
%UserProfile%\Recent\tempdoc.dll
%UserProfile%\Start Menu\Windows Protection Suite.lnk
%UserProfile%\Start Menu\Programs\Windows Protection Suite.lnk

How to Remove Windows Protection Suite

1. Temporarily Disable System Restore (Windows Me/XP). [how to]
2. Open your antivirus application and update the virus definition file. This method ensures that your antivirus program can detect even newer variants of Windows Protection Suite

3. Start Windows in Safe Mode with Networking.
- From a power-off state, turn on the computer and press F8 on your keyboard repeatedly.
- Your computer will display Windows Advanced Boot Options menu. Please select Safe Mode with Networking.
- The system will now boot Windows and loads only necessary drivers and files.

4. Open your antivirus program and run a full system scan. After the scan, delete all infected items. If unable, better place them in quarantine. Once the scan is complete, please proceed with the next step.

Online Virus Scanner:

Another way to remove Windows Protection Suite without the need to install additional antivirus application is to perform a thorough scan with free online virus scanner that can be found on websites of legitimate anti-virus and security provider.

5. Go to Online Virus Scanner list and run a virus scan. This may require plug-ins, add-on or Activex object, please install if you want to proceed with scan.
6. After completing the necessary download, your system is now ready for online virus scanning.
7. Select an option in which you can thoroughly scan the computer to make sure that it will find and delete entirely all infections not detected on previous scan.
8. Remove or delete all detected items.
9. When scanning is finished you may now restart the computer in normal mode.

Automatic Removal of Windows Protection Suite

In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.