Thursday, January 14, 2010

Remove GhostAntivirus - prevent your PC from popups and slowdowns

GhostAntivirus (Ghost Antivirus) is about to be appreciated as the most destructive counterfeit of antivirus released during the winter 2009/2010. Ghost Antivirus removal is strongly recommended to be done in safe mode only and, in most cases, is possible only in safe mode: Ghost Antivirus files are protected from removal in general Windows mode.
Ghost Antivirus preserves tradition of Internet Antivirus Pro family, which is notorious due to its hard oppression of infected computers by its members. It has been concocted, released and is now distributed by the hackers band marinating and developing the said family and, despite of the luck of visual conformity with Internet Antivirus Pro, is the same annoying and destructive thing; in additional, the same trojans are applied for backdoor upload of Ghost Antivirus and Internet Antivirus Pro. The same tool is able to remove Ghost Antivirus and any member of its family. You may need to reboot in safe mode to download it though. Click here to start free system inspection and get rid of Ghost Antivirus and any related parasites using Spyware Doctor.

Ghost Antivirus screenshot:

Ghost Antivirus removal tool:


Ghost Antivirus manual removal instructions:
Delete Ghost Antivirus files:
ghostav.exe
register.ico
unins000.dat
uninst.ico
web.ico
working.log
ghost.sql
Infected.wav
listing.cfg
version.db
WMILib.dll
[random symbols].dll
Ghost Antivirus.lnk
Ghost Antivirus Home Page.lnk
Purchase License.lnk
settings.ini
uill.ini
unins000.exe
Uninstall Ghost Antivirus.lnk
links.txt
properties
times.conf
iGSh.png
iMSh.png
iPSh.png
pguard.ini
services.exe
onin.exe
Delete Ghost Antivirus registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ghost Antivirus_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
HKEY_CURRENT_USER\Software\Microsoft\FTP “SearchDir” = “c:\program files\Ghost Antivirus\”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run “onin”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Ghost Antivirus”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce “3P_UDEC”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent “URIAPRO[1.1.3.9]”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe “Debugger” = “?”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe “RealDebugger” = “?”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon “RealLogonType” = “1″

No comments: