Removal Instructions for Windows Security Suite
Like most rogue security applications, Windows Security Suite uses Trojans to infect computers. However, this rogue has the capability to disable other security applications that are weak in order to defend itself. It will also install a BHO in order to install a toolbar into the browser. This toolbar will hijack the browser when searches are done so that Windows Security Suite can forcibly be promoted.
Windows Security Suite also uses traditional rogue promotion methods, such as using fake security warnings and fake system scan with false scan results. All of the previous methods are used in order to scare the infected user into paying to register the program in order to remove imaginary threats. However, the so-called “full version” of this rogue will only hinder the Internet connection and the computer’s performance. It will generate pop-ups and alter security settings.
If Windows Security Suite has infected your computer, you should remove it manually or with an antispyware program. In order to remove it manually, you should stop the following processes:
WI345d.exe
CLSV.exe
snl2w.exe
std.exe
Relative file contents :
26.mof,
mozcrt19.dll,
sqlite3.dll,
WI345d.exe,
WINSS.ico,
working.log,
vd952342.bd,
winss.cfg,
Windows Security Suite.lnk,
cookies.sqlite,
Instructions.ini,
ANTIGEN.drv,
CLSV.exe, DBOLE.drv,
dudl.sys,
energy.dll,
grid.dll, grid.sys,
kernel32.dll,
PE.dll,
PE.tmp,
runddl.dll,
sm.dll,
snl2w.exe, std.exe,
tempdoc.dll,
search.xml
Delete these registry entries:
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “698909210803”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Windows Security Suite”
Then, you should unregister these DLLs:
mozcrt19.dll
sqlite3.dll
energy.dll
grid.dll
kernel32.dll
PE.dll
runddl.dll
SM.dll
tempdoc.dll
Delete the following files:
26.mof
mozcrt19.dll
sqlite3.dll
WI345d.exe
WINSS.ico
working.log
vd952342.bd
winss.cfg
Windows Security Suite.lnk
cookies.sqlite
Instructions.ini
ANTIGEN.drv
CLSV.exe
DBOLE.drv
dudl.sys
energy.dll
grid.dll
grid.sys
kernel32.dll
PE.dll
PE.tmp
runddl.dll
SM.dll
snl2w.exe
std.exe
tempdoc.dll
search.xml
Finally, you should delete these directories:
c:\ADWARE_LOG
c:\Documents and Settings\All Users\Application Data\345d567
c:\Documents and Settings\All Users\Application Data\345d567\WINSSSys
c:\Documents and Settings\All Users\Application Data\WINSSSys
%UserProfile%\Application Data\Windows Security Suite
While this will remove Windows Security Suite, it will not ensure that your computer is safe from malware. Since this program is installed by a Trojan, your computer will still be infected and could have plenty of other infections as well. The best way to ensure your computer’s safety is to use an antispyware application that you can trust.
SpyZooka is an authentic antispyware app that you can trust. It was developed by a member in good standing with the Better Business Bureau. It is always kept up to date by a robot that hunts down new forms of malware every day. That is why SpyZooka is the only antispyware guaranteed to remove 100% of spyware and malware. If you are looking for real protection from rogues like Windows Security Suite as well as other malware, then SpyZooka is the antispyware for you.
I like this antispyware protection very much. It’s easy to use and works well. Definitely, I recommend SpyZooka to all my family and friends!