Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Installs itself without permissions
  • Changes background
  • Connects to the internet without permission

Decrypt Protect virus

A lot of computer infections want to make an impression that you have done something illegal and thus your computer access has been restricted. Decrypt Protect Virus is one of such malicious programs. It is distributed by Trojan Reveton and the malware can be categorized as ransomware infection. The meaning behind the name is rather simple - Decrypt Protect virus holds your computer hostage and expects you to pay a 300 USD ransom fee for something you have not committed. Therefore, it presents the same security threats as other Ukash Virus group infections such as FBI MoneyPak Virus or ICSPA Virus.

What you have to realize is, however, the fact that if you are infected with Decrypt Protect virus, then it means that you have other infections on your PC as well. That is so, because the ransomware infection is distributed by Trojans and other malware, and you may not even notice how or when the infection takes place. The next thing you know, is that your PC is locked and you are asked to transfer money via Green Dop MoneyPak alternative payment system. The same methods are used by a variety of other Ukash infections, for example, Metropolitan Police Virus or EC3 Europol Virus.

Naturally, the fact that you cannot access your desktop can be very disturbing, but even if Decrypt Protect Virus claims that you will be prosecuted if you do not pay the fine within 48 hours, do not panic. This ransomware infection is not concerned with overall online security. It simply wants your money, you should ignore the notification you see on your screen:

You have 48 hours left to enter your payment.
You have lost control over your computer. Your system and all your files has been blocked and encrypted because you were spreading Malware (viruses, trojans, worms).
You are breaking numerous International and USA laws.

The most important thing is to stay calm and keep your money to yourself, because paying Decrypt Protect Virus will not solve anything. In order to unlock your PC and terminate the infection, you have to bypass the malware's defenses first. Follow the instructions below, unlock your desktop and remove Decrypt Protect Virus.

How to restore your desktop access

Windows 8

  1. Press Windows key and metro Start menu will appear.
  2. Click Internet explorer tile.
  3. Enter http://www.pcthreat.com/download-sph into the address bar and click Enter.
  4. Press Run on the download dialog box and install SpyHunter.
  5. Run a full system scan.

Windows Vista & Windows 7

  1. Reboot the PC and press F8 repeatedly until Advanced Boot Options menu appears.
  2. Select Safe Mode with Networking and press Enter.
  3. Access http://www.pcthreat.com/download-sph and download SpyHunter.
  4. Install the program and scan your PC with it.

Windows XP

  1. Follow the steps 1 and 2 above.
  2. Click Yes on confirmation box.
  3. Download SpyHunter.
  4. Open Start menu and launch Run.
  5. Enter "msconfig" and click OK.
  6. Select Startup tab on System Configuration Utility.
  7. Click Disable all and press OK.
  8. Restart the PC in Normal Mode.
  9. Install SpyHunter and scan your system.

Should you have any problem with Decrypt Protect Virus removal, leave us a comment below.

Download Spyware Removal Tool to Remove* Decrypt Protect virus
  • Quick & tested solution for Decrypt Protect virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Decrypt Protect virus

Files associated with Decrypt Protect virus infection:

C87C.exe
Updating.exe
m2PythonLoader.exe
msnmsgrr.exe
%WINDIR%\Temp
00qbipeq.exe
87b2cb3916261d5c807bf44262755cb0.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
%ALLUSERSPROFILE%\Application Data
ctfmon.exe
Task Scheduler.exe
comeo.exe
%APPDATA%\system
scvhost.exe
DLL321.dll
%LOCALAPPDATA%\Temp
puozlkmyj.dll
2084473.dll
install_0_msi.exe
Piranha.exe
msdtmsrd.exe
secproc_isv.exe
SyncHostps.exe
bzsbkotiu.exe
idiokbbrv.exe
xaZYOVJW.exe
96dddda4.dll
oygqyunapnp.exe
3511172082012Build.exe
%TEMP%
gcrwcoak.exe
%WINDIR%\system32
Q3d38543.exe
Firewallservice.exe
acuvzomo.exe
audipbrd.exe
wjthvwjb.dss
pYunY8m4VL3qLc.exe
obvwo.exe
msn.exe
questscan.dll
WinSyncMetastore.exe
n.
wgsdgsdgdsgsd.exe
dyjdl.exe
%AppData%
skype.dat
zqmkrehUkpoKfsafsaZg.exe
securitywindrv.exe
pmstcdjwz.exe
VaultSysUi.exe
xlqbteeb.exe
yaiiwockc.dll
bvhylsviw.exe
msavfit.exe
systemcpl.exe
%APPDATA%\Task Scheduler
ex3b.dll
ifgxpers.exe
Nbt.exe
%ALLUSERSPROFILE%
jsdhlexdqkllnbcxgai.bfg
uenovfiu.exe
%SystemDrive%\????????????
aPr0hY9.exe
ieudator.dll
UpdatePriv.exe
00b5d693.exe
videotwisterSA.exe
DA0B.exe
rool0_pk.exe
bf8h8d02hf.exe
sqlncli.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
b34btbztdb0vavaw.exe
ubvhynpxh.exe
NTServiceManager.exe
TimeDateMUICallback.exe
svchost.exe
crack.exe
%UserProfile%
taskhost.exe.exe
rvcbcyks.exe
UpgradeHelper.exe
csrsss.exe
ACEIEAddOn.dll
Other.res
OmaSG21e.exe
msshell.exe
MusicCollector.exe
魔法桌面第三方主题破解补丁V1.1.exe
xctqakcqbeo.dll
wpbt0.dll
wlsidten.exe
ssntvs.exe
%CommonProgramFiles%
WINDED6.exe
najeoxtt.exe
mplayer2.exe
xmlfilter.exe
dtkmujvo.exe
administration.exe
hwj3ba6j.dss
%LOCALAPPDATA%\lollipop
p1.exe
%APPDATA%\updates
wahneaqa.exe
brenasa.exe
iner.exe
dqnbdq7.dss
50E1.exe
setex.exe
wlsidten.dll
JfCqQ5JC.exe

Decrypt Protect virus DLL's to remove:

DLL321.dll
wpbt0.dll
yaiiwockc.dll
ACEIEAddOn.dll
2084473.dll
questscan.dll
ieudator.dll
puozlkmyj.dll
ex3b.dll
xctqakcqbeo.dll
wlsidten.dll
96dddda4.dll

Decrypt Protect virus processes to kill:

svchost.exe
csrsss.exe
pYunY8m4VL3qLc.exe
aPr0hY9.exe
wgsdgsdgdsgsd.exe
xmlfilter.exe
VaultSysUi.exe
gcrwcoak.exe
msdtmsrd.exe
p1.exe
ubvhynpxh.exe
comeo.exe
secproc_isv.exe
taskhost.exe.exe
brenasa.exe
msavfit.exe
install_0_msi.exe
bzsbkotiu.exe
bf8h8d02hf.exe
bvhylsviw.exe
wahneaqa.exe
UpdatePriv.exe
systemcpl.exe
najeoxtt.exe
acuvzomo.exe
oygqyunapnp.exe
securitywindrv.exe
Q3d38543.exe
audipbrd.exe
wlsidten.exe
mplayer2.exe
Updating.exe
WinSyncMetastore.exe
msn.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
dtkmujvo.exe
rool0_pk.exe
pmstcdjwz.exe
Nbt.exe
scvhost.exe
ifgxpers.exe
videotwisterSA.exe
NTServiceManager.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
3511172082012Build.exe
rvcbcyks.exe
TimeDateMUICallback.exe
00b5d693.exe
zqmkrehUkpoKfsafsaZg.exe
dyjdl.exe
87b2cb3916261d5c807bf44262755cb0.exe
xaZYOVJW.exe
msshell.exe
ctfmon.exe
OmaSG21e.exe
魔法桌面第三方主题破解补丁V1.1.exe
administration.exe
uenovfiu.exe
iner.exe
Task Scheduler.exe
WINDED6.exe
ssntvs.exe
obvwo.exe
C87C.exe
50E1.exe
crack.exe
setex.exe
msnmsgrr.exe
UpgradeHelper.exe
xlqbteeb.exe
00qbipeq.exe
m2PythonLoader.exe
Piranha.exe
b34btbztdb0vavaw.exe
MusicCollector.exe
DA0B.exe
idiokbbrv.exe
Firewallservice.exe
sqlncli.exe
SyncHostps.exe
JfCqQ5JC.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.