Introduction

For years, ACCDFISA Protection Center has become malware producer. Their products mainly hacked the user’s computer system and lock it down until the user pay some money as a ransom. This time, this ‘malware producer’ gives another threat to computer users with its Malware Protection Ransomware. Users won’t be able to access their computer if it had been already hacked by the malware until they agree to pay the ransom as much as $300. If you were on of these users, never think to give the ransom because you will spend your money useless without getting any solution. Please follow these steps to manually remove the threat and get your computer again but first you should back up your system to prevent any system damage occurred during the removal:

Manual removal process

  1. Right click on the taskbar and left click the “Start Task Manager” option.
  2. After a new window opened, find this process:

aes256crypter.exe

  1. Click on the above process and move your cursor to the lower right section of the window. Find the “End Process” button and click on it.
  2. A new window will be opened. Click on the “End Process” button to terminate the process.
  3. Close the “Task Manager” window.
  4. Left click on the “Start” menu and choose “Run” option.
  5. Type “regedit” at the empty space to open “Registry Editor” window.
  6. After the “Registry Editor” window opened, press Ctrl + F to find these files:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\a5d9a3\SAa5d_8020.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\ac2f91\SAac2_8020.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\57c5bb\SA57c_8020.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\dee81d\SAdee_8006.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\0c6f11\SA0c6_8046.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\837c8c\SA837_8020.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\33e938\SA33e_8046.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\592dba\Quarantine Items\SA592_8033.exe” /s /d
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, Smart Anti-Malware Protection=”[%COMMON_APPDATA%]\7aa02b\SA7aa_8020.exe” /s /d

  1. For each registry file, right click on the file and select “Delete” for the file removal.
    1. Close the “Registry Editor” window after you removed all the registry files.

 

Unregister dll files

  1. Left click on the “Start” button and choose the “Run” option.
  2. Type “cmd” at the empty space to open the “Command Prompt” window.
  3. Type this when the window opened:

Regsvr32 /u vpkswnhisp.dll

Note: vpkswnhisp.dll is the dll file you should remove.

  1. Type “exit” at the window to close the “Command Prompt” window.

 

Delete files or directories

  1. Right click on the “Start” button and select “Open Windows Explorer” option.
  2. Go to the directory where you store all files and folders from Windows Defending Center. If you chose to store the data at default location when you installed the program, the location should be C:\Program Files\Windows Defending Center
  3. Find these files/folders and remove them:

[%DESKTOP%]\Smart Anti-Malware Protection.lnk
[%APPDATA%]\Microsoft\Internet Explorer\Quick Launch\Smart Anti-Malware Protection.lnk
[%PROGRAMS%]\Smart Anti-Malware Protection.lnk

[%APPDATA%]\Smart Anti-Malware Protection

  1. Close the “Windows Explorer” window.
  2. Re-start your system.

HOW TO REMOVE MALWARE PROTECTION RANSOMWARE?

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>