How To Remove Windows Security Suite - (Removal Guide)
Article by George Norman
On 17 Feb 2010
From the family of rogues that spawned Malware Destructor 2009, Security Antivirus, Fast Antivirus 2009, Virus Shield 2009, Virus Alarm, Virus Doctor, Malware Catcher 2009, and Virus Sweeper comes yet another rogue security program – Windows Security Suite. Just like its siblings, the Windows Security Suite rogue says it can provide “full protection against potentially unwanted software, viruses and malware.” And just like its siblings, it can do nothing of the sorts.

The Windows Security Suite has zero malware detection/protection capabilities. It only says it can detect, remove and protect against malware to scam you out of your hard earned money. You see, once it has been installed on your system, Windows Security Suite will do its best to scare you into thinking your system is infected. In this regard it will hijack your browser, bombard you with popups and phony security alerts, and perform a fake system scan each and every time you boot up your computer. Once you’re nice and scared, Windows Security Suite says that if you pay for a license it can remove the infection and make things all better again.

Advertising

You are well advised to ignore the rogue’s scare tactics and just remove it from your system. Whatever you do, do not pay for a license. You would only be lining the pockets of the people with malicious intent that came up with the Windows Security Suite rogue.



Automatic removal guide
Step 1. If you have a printer, make sure to print out this tutorial. If you do not have a printer, save this tutorial, go out to a copy center and print it out there. If you do not have a printer and do not want to go out, then use the pen and paper method: grab a pen and a piece of paper and write down the instruction presented in the steps below. In the process of eliminating Windows Security Suite from your machine you will need to shut down the browser. And since this will also shut down the tutorial, you need to know what you should do next.

Step 2. You will have to install Malwarebytes’ Anti-Malware. In this regard you need to download the software’s setup executable. Just click this link and save the .exe file on your computer (preferably on your desktop).

Step 3. Double click the Malwarebytes’ Anti-Malware setup executable. It should be on the desktop under the name mbam-setup. This will launch the installation process. If you already know how to install a piece of software, proceed to step 4. If you do not know how to do this, we’ll walk you though it all:



- The Select Setup Language window should have popped up. By default, the language in which the software will be installed is set to English, but you can change this. The software provides support for 30+ languages. After selecting the language of your choice, click OK. It would be best to just leave it set to English though.



- The Malwarebytes’ Anti-Malware Setup Wizard will now popup. Just click Next.



- You will be presented with the License Agreement. Click I accept the agreement and then click Next. If you do not accept the agreement you will not be able to continue.



- Keep clicking Next until you get to the Ready to install window. Now click Install. After the installation process completes click Finish. Do not uncheck the boxes next to Update Malwarebytes’ Anti-Malware or Launch Malwarebytes’ Anti-Malware.















Step 4. The Malwarebytes’ Anti-Malware application will launch automatically. The Perform quick scan option should be checked by default – if it isn’t then check it and then click Scan. You are well advised to close all running apps before clicking scan. This will ensure the scan for Windows Security Suite will complete swiftly.



Malwarebytes’ Anti-Malware will start scanning your files for signs of Windows Security Suite. This may take a while, so be patient. It all depends on how powerful your computer is and how many files Malwarebytes’ Anti-Malware has to scan.



When the scan for Windows Security Suite is complete you will be presented with a notification box. Click OK to close the notification box and go to the main Scanner screen. Click Show Results and you will be presented with a list of all the infected files Malwarebytes’ Anti-Malware has detected.





Step 5. Click Remove Selected and Malwarebytes’ Anti-Malware will remove all the infected files it has detected. It may be necessary to restart your computer in order to remove some of these files. After Malwarebytes’ Anti-Malware is done removing all the infected files, it will open Notepad and present the scan log to you. You can review the log at your leisure – save it If you want.



Step 6. Close Malwarebytes’ Anti-Malware and you’re done. No traces of Windows Security Suite should be left on your computer.

Manual removal guide

Stop and remove the processes:

std.exe
snl2w.exe
CLSV.exe
WI345d.exe


Access the Windows Registry Editor and delete the following registry keys:

HKEY_CLASSES_ROOT/CLSID/{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT/WI345d.DocHostUIHandler
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/User Agent/Post Platform "698909210803"
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run "Windows Security Suite"


Locate and delete the following files:

c:/ADWARE_LOG
c:/Documents and Settings/All Users/Application Data/345d567
c:/Documents and Settings/All Users/Application Data/345d567/WINSSSys
c:/Documents and Settings/All Users/Application Data/WINSSSys
c:/Documents and Settings/All Users/Application Data/345d567/26.mof
c:/Documents and Settings/All Users/Application Data/345d567/mozcrt19.dll
c:/Documents and Settings/All Users/Application Data/345d567/sqlite3.dll
c:/Documents and Settings/All Users/Application Data/345d567/WI345d.exe
c:/Documents and Settings/All Users/Application Data/345d567/WINSS.ico
c:/Documents and Settings/All Users/Application Data/345d567/working.log
c:/Documents and Settings/All Users/Application Data/345d567/WINSSSys/vd952342.bd
c:/Documents and Settings/All Users/Application Data/WINSSSys/winss.cfg
%UserProfile%/Application Data/Microsoft/Internet Explorer/Quick Launch/Windows Security Suite.lnk
%UserProfile%/Application Data/Windows Security Suite
%UserProfile%/Application Data/Windows Security Suite/cookies.sqlite
%UserProfile%/Application Data/Windows Security Suite/Instructions.ini
%UserProfile%/Desktop/Windows Security Suite.lnk
%UserProfile%/Recent/ANTIGEN.drv
%UserProfile%/Recent/CLSV.exe
%UserProfile%/Recent/DBOLE.drv
%UserProfile%/Recent/dudl.sys
%UserProfile%/Recent/energy.dll
%UserProfile%/Recent/grid.dll
%UserProfile%/Recent/grid.sys
%UserProfile%/Recent/kernel32.dll
%UserProfile%/Recent/PE.dll
%UserProfile%/Recent/PE.tmp
%UserProfile%/Recent/runddl.dll
%UserProfile%/Recent/SM.dll
%UserProfile%/Recent/snl2w.exe
%UserProfile%/Recent/std.exe
%UserProfile%/Recent/tempdoc.dll
%UserProfile%/Start Menu/Windows Security Suite.lnk
%UserProfile%/Start Menu/Programs/Windows Security Suite.lnk
c:/Program Files/Mozilla Firefox/searchplugins/search.xml


Unregister the following DLL libraries:


tempdoc.dll
energy.dll
grid.dll
kernel32.dll
PE.dll
runddl.dll
SM.dll
mozcrt19.dll
sqlite3.dll


Block access to the domain(s):

windowssecuritysuite.com


Tags:
About the author: George Norman
.
You can follow him on Google+, Facebook or Twitter

I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular Removal Guide
By George Norman on 19 Feb 2010
If you did not manually install XP Micro Antivirus and the software just showed up on your computer one day, it means that a Trojan
By George Norman on 19 Feb 2010
Software Antivirus, unlike what the name may suggest, is not a security software solution nor is it an antivirus program. Software Antivirus is nothing more
By George Norman on 19 Feb 2010
The irony here is that the name WiniFighter would lead you to believe this is a security software application that will keep malware from the
By George Norman on 19 Feb 2010
PC Security 2009, a rogue antispyware program, is usually distributed by malware that installs the rogue on your system without your consent. The rogue’s installer
By George Norman on 18 Feb 2010
The people with malicious intent that put out the Internet Security 2010 rogue have rolled out another fake security software application, mainly Security
By George Norman on 18 Feb 2010
Personal Anti Malware, a rogue security software application, is usually distributed by Trojans. A Trojan manages to compromise your system, then installs the rogue without
Advertising
Hot Software Updates
Top Downloads
Become A Fan!
Link To Us!

HTML Linking Code