Tuesday, April 28, 2009

PCAntiMalware (PC AntiMalware) Removal Instructions

PCAntiMalware (PC AntiMalware) is advertised in two stages if considering its adware. At first, the trojan is installed that shows alerts at the desktop toolbar. These alerts report computer security problem and ask to install PCAntiMalware redirecting users to downloading link of the rogue antispyware trial version or directly to the purchase form that requires user to pay registration free and get full version. Normally, trialware is installed after with trojan from the backdoor. The adware is more complex advertising device that plays fake scan and shows a variety of security alerts. PCAntiMalware belongs to the family of rogue security tools that includes such adware as Cleaner 2009 and AntiMalwareSuite. PCAntiMalware removal in manual mode is rather impracticable. Use reliable professional to get rid of PCAntiMalware. The one that has been tested to show its ability to remove PCAntiMalware is available for download right here. Click here to start free scan and remove PCAntiMalware using Spyware Doctor with antivirus.

PCAntiMalware screenshot:

PCAntiMalware removal tool:


PCAntiMalware manual removal guide:
Delete PCAntiMalware files:
Contact customer support.url
PCAntiMalware on the Web.url
Uninstall PCAntiMalware.lnk
PCAntiMalware
Activate.dat
appupdate.dat
AsAgents.dll
AsAgents.xml
atl71.dll
AutoProcess.dat
dbupdate.dat
InstUp.exe
lapv.dat
license.rtf
mfc71.dll
msvcp71.dll
msvcr71.dll
PCAM.exe
PCAM.xml
PP.exe
pv.dat
readme.rtf
scanlog.xml
settings.ini
shellext.dll
shellext.xml
Summary.dat
tasks.dat
threatnet.dat
threatnet.ini
unins000.dat
unins000.exe
uninstall.ico
UserAgent.dll
database
knownfiles.dat
MalwareDB.dat
TEBase.dat
vbpv.dat
quaratine.dat
RTMonitor.dat
bootrem.exe

Delete PCAntiMalware registry entries:
HKEY_CURRENT_USER\Software\PCAntiMalware
HKEY_CLASSES_ROOT\\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\amshellext.ShellHook
HKEY_CLASSES_ROOT\amshellext.ShellHook.1
HKEY_CLASSES_ROOT\CLSID\{_CLSID_WAShellExecuteCheck}
HKEY_CLASSES_ROOT\CLSID\{4567AB12-EDED-4675-AF10-BA15EDDB4D7A}
HKEY_CLASSES_ROOT\CLSID\{4ADD95DA-B25D-4d21-9C5C-05FC6DE05860}
HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
HKEY_CLASSES_ROOT\TypeLib\{4567AB12-7DFC-4C46-BD8F-41259D169A0D}
HKEY_CLASSES_ROOT\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
HKEY_CLASSES_ROOT\washellext.WASContextMenu
HKEY_CLASSES_ROOT\washellext.WASContextMenu.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\PSAMAP_is1
HKEY_LOCAL_MACHINE\SOFTWARE\PCAntiMalware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\ShellExecuteHooks “{4ADD95DA-B25D-4D21-9C5C-05FC6DE05860}”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Internet Settings\5.0\User Agent\Post Platform “UPSAMAP 4.1.228.0?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run “PCAntiMalware”

No comments: