Click on screenshot to zoom
Danger level 9
Type: Malware
Common infection symptoms:
  • Installs itself without permissions
  • Changes background
  • Connects to the internet without permission

Decrypt Protect virus

A lot of computer infections want to make an impression that you have done something illegal and thus your computer access has been restricted. Decrypt Protect Virus is one of such malicious programs. It is distributed by Trojan Reveton and the malware can be categorized as ransomware infection. The meaning behind the name is rather simple - Decrypt Protect virus holds your computer hostage and expects you to pay a 300 USD ransom fee for something you have not committed. Therefore, it presents the same security threats as other Ukash Virus group infections such as FBI MoneyPak Virus or ICSPA Virus.

What you have to realize is, however, the fact that if you are infected with Decrypt Protect virus, then it means that you have other infections on your PC as well. That is so, because the ransomware infection is distributed by Trojans and other malware, and you may not even notice how or when the infection takes place. The next thing you know, is that your PC is locked and you are asked to transfer money via Green Dop MoneyPak alternative payment system. The same methods are used by a variety of other Ukash infections, for example, Metropolitan Police Virus or EC3 Europol Virus.

Naturally, the fact that you cannot access your desktop can be very disturbing, but even if Decrypt Protect Virus claims that you will be prosecuted if you do not pay the fine within 48 hours, do not panic. This ransomware infection is not concerned with overall online security. It simply wants your money, you should ignore the notification you see on your screen:

You have 48 hours left to enter your payment.
You have lost control over your computer. Your system and all your files has been blocked and encrypted because you were spreading Malware (viruses, trojans, worms).
You are breaking numerous International and USA laws.

The most important thing is to stay calm and keep your money to yourself, because paying Decrypt Protect Virus will not solve anything. In order to unlock your PC and terminate the infection, you have to bypass the malware's defenses first. Follow the instructions below, unlock your desktop and remove Decrypt Protect Virus.

How to restore your desktop access

Windows 8

  1. Press Windows key and metro Start menu will appear.
  2. Click Internet explorer tile.
  3. Enter http://www.pcthreat.com/download-sph into the address bar and click Enter.
  4. Press Run on the download dialog box and install SpyHunter.
  5. Run a full system scan.

Windows Vista & Windows 7

  1. Reboot the PC and press F8 repeatedly until Advanced Boot Options menu appears.
  2. Select Safe Mode with Networking and press Enter.
  3. Access http://www.pcthreat.com/download-sph and download SpyHunter.
  4. Install the program and scan your PC with it.

Windows XP

  1. Follow the steps 1 and 2 above.
  2. Click Yes on confirmation box.
  3. Download SpyHunter.
  4. Open Start menu and launch Run.
  5. Enter "msconfig" and click OK.
  6. Select Startup tab on System Configuration Utility.
  7. Click Disable all and press OK.
  8. Restart the PC in Normal Mode.
  9. Install SpyHunter and scan your system.

Should you have any problem with Decrypt Protect Virus removal, leave us a comment below.

Download Spyware Removal Tool to Remove* Decrypt Protect virus
  • Quick & tested solution for Decrypt Protect virus removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Decrypt Protect virus

Files associated with Decrypt Protect virus infection:

%LOCALAPPDATA%\Temp
%WINDIR%\Temp
setex.exe
wjthvwjb.dss
msn.exe
m2PythonLoader.exe
rool0_pk.exe
%SystemDrive%\????????????
iner.exe
cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
wgsdgsdgdsgsd.exe
DLL321.dll
wlsidten.exe
VaultSysUi.exe
00b5d693.exe
obvwo.exe
msshell.exe
b34btbztdb0vavaw.exe
%WINDIR%\system32
skype.dat
acuvzomo.exe
oygqyunapnp.exe
crack.exe
p1.exe
mplayer2.exe
puozlkmyj.dll
uenovfiu.exe
gcrwcoak.exe
msnmsgrr.exe
scvhost.exe
50E1.exe
%LOCALAPPDATA%\lollipop
wahneaqa.exe
SyncHostps.exe
secproc_isv.exe
sqlncli.exe
administration.exe
xlqbteeb.exe
najeoxtt.exe
svchost.exe
3511172082012Build.exe
xaZYOVJW.exe
MusicCollector.exe
securitywindrv.exe
dqnbdq7.dss
Nbt.exe
systemcpl.exe
%AppData%
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
wlsidten.dll
Piranha.exe
msdtmsrd.exe
audipbrd.exe
ACEIEAddOn.dll
96dddda4.dll
ex3b.dll
bzsbkotiu.exe
brenasa.exe
install_0_msi.exe
C87C.exe
csrsss.exe
pmstcdjwz.exe
87b2cb3916261d5c807bf44262755cb0.exe
taskhost.exe.exe
xctqakcqbeo.dll
videotwisterSA.exe
hwj3ba6j.dss
Task Scheduler.exe
DA0B.exe
%APPDATA%\system
comeo.exe
ssntvs.exe
ubvhynpxh.exe
TimeDateMUICallback.exe
rvcbcyks.exe
ctfmon.exe
JfCqQ5JC.exe
UpdatePriv.exe
wpbt0.dll
yaiiwockc.dll
%ALLUSERSPROFILE%\Application Data
bvhylsviw.exe
aPr0hY9.exe
Firewallservice.exe
xmlfilter.exe
pYunY8m4VL3qLc.exe
idiokbbrv.exe
2084473.dll
%APPDATA%\Task Scheduler
Q3d38543.exe
ieudator.dll
jsdhlexdqkllnbcxgai.bfg
dtkmujvo.exe
bf8h8d02hf.exe
%UserProfile%
UpgradeHelper.exe
%APPDATA%\updates
%TEMP%
OmaSG21e.exe
%CommonProgramFiles%
WINDED6.exe
WinSyncMetastore.exe
dyjdl.exe
Updating.exe
00qbipeq.exe
zqmkrehUkpoKfsafsaZg.exe
Other.res
questscan.dll
ifgxpers.exe
%ALLUSERSPROFILE%
NTServiceManager.exe
msavfit.exe
n.
魔法桌面第三方主题破解补丁V1.1.exe

Decrypt Protect virus DLL's to remove:

wpbt0.dll
questscan.dll
xctqakcqbeo.dll
yaiiwockc.dll
DLL321.dll
ieudator.dll
ex3b.dll
2084473.dll
puozlkmyj.dll
wlsidten.dll
96dddda4.dll
ACEIEAddOn.dll

Decrypt Protect virus processes to kill:

cf6640a77ed4926a4c6be661ab93def9d13408753dd07e8d02836996a2f247b6.exe
VaultSysUi.exe
MusicCollector.exe
wlsidten.exe
crack.exe
NTServiceManager.exe
Firewallservice.exe
setex.exe
install_0_msi.exe
administration.exe
OmaSG21e.exe
Piranha.exe
wgsdgsdgdsgsd.exe
Nbt.exe
xmlfilter.exe
87b2cb3916261d5c807bf44262755cb0.exe
mplayer2.exe
acuvzomo.exe
魔法桌面第三方主题破解补丁V1.1.exe
csrsss.exe
securitywindrv.exe
00qbipeq.exe
C87C.exe
brenasa.exe
msnmsgrr.exe
svchost.exe
m2PythonLoader.exe
wahneaqa.exe
dyjdl.exe
rvcbcyks.exe
DA0B.exe
videotwisterSA.exe
pYunY8m4VL3qLc.exe
msshell.exe
p1.exe
UpgradeHelper.exe
taskhost.exe.exe
obvwo.exe
msn.exe
uenovfiu.exe
rool0_pk.exe
xlqbteeb.exe
JfCqQ5JC.exe
00b5d693.exe
gcrwcoak.exe
bf8h8d02hf.exe
TimeDateMUICallback.exe
scvhost.exe
Updating.exe
ifgxpers.exe
Q3d38543.exe
msdtmsrd.exe
WinSyncMetastore.exe
ubvhynpxh.exe
idiokbbrv.exe
xaZYOVJW.exe
najeoxtt.exe
dtkmujvo.exe
{097444e7-2d87-ba3c-2efe-9f54812d824a}.exe
bzsbkotiu.exe
WINDED6.exe
SyncHostps.exe
zqmkrehUkpoKfsafsaZg.exe
UpdatePriv.exe
iner.exe
50E1.exe
pmstcdjwz.exe
aPr0hY9.exe
audipbrd.exe
ssntvs.exe
Task Scheduler.exe
b34btbztdb0vavaw.exe
secproc_isv.exe
comeo.exe
msavfit.exe
bvhylsviw.exe
oygqyunapnp.exe
ctfmon.exe
systemcpl.exe
3511172082012Build.exe
sqlncli.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.