Apr 30

PCAntiMalware ( aka PC AntiMalware ) is a trojan/adware program that masquerades as legitimate anti-spyware software and may change Windows Desktop and other settings. The program is generally installed by a trojan that automatically downloads and installs the program.

Risk Level : High ( Dangerous )

Note :- To safely & quickly detect PCAntiMalware, We highly recommend you to use the Removal Tool for PCAntiMalware.

Download – Removal Tool for PCAntiMalware

Screenshots:

PCAntiMalware

PCAntiMalware Screenshot

Symptoms of PCAntiMalware

Pop up balloon warning messages claiming that your PC is infected.

  • "Critical System Error",
  • "Your computer is infected",
  • Hijacked homepage to obscure webpage.
  • Flashing icons appear on your system tray (Near of your system clock).

Manual Removal Process: ( How to get rid of PCAntiMalware )

Search and kill the following processes (Learn Here)

PCAM.exe, InstUp.exe, PP.exe, bootrem.exe

Remove PCAntiMalware files & folders (Learn Here)

c:\Documents and Settings\All Users\Application Data\PCAntiMalware
c:\Documents and Settings\All Users\Application Data\PCAntiMalware\Data
c:\Documents and Settings\All Users\Application Data\PCAntiMalware\Data\Abbr
c:\Documents and Settings\All Users\Application Data\PCAntiMalware\Data\ProductCode
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware\Contact customer support.url
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware\PCAntiMalware on the Web.url
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware\PCAntiMalware.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware\Uninstall PCAntiMalware.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PCAntiMalware.lnk
%UserProfile%\Desktop\PCAntiMalware.lnk
c:\Program Files\PCAntiMalware
c:\Program Files\PCAntiMalware\Activate.dat
c:\Program Files\PCAntiMalware\appupdate.dat
c:\Program Files\PCAntiMalware\AsAgents.dll
c:\Program Files\PCAntiMalware\AsAgents.xml
c:\Program Files\PCAntiMalware\atl71.dll
c:\Program Files\PCAntiMalware\AutoProcess.dat
c:\Program Files\PCAntiMalware\dbupdate.dat
c:\Program Files\PCAntiMalware\InstUp.exe
c:\Program Files\PCAntiMalware\lapv.dat
c:\Program Files\PCAntiMalware\license.rtf
c:\Program Files\PCAntiMalware\mfc71.dll
c:\Program Files\PCAntiMalware\msvcp71.dll
c:\Program Files\PCAntiMalware\msvcr71.dll
c:\Program Files\PCAntiMalware\PCAM.exe
c:\Program Files\PCAntiMalware\PCAM.xml
c:\Program Files\PCAntiMalware\PP.exe
c:\Program Files\PCAntiMalware\pv.dat
c:\Program Files\PCAntiMalware\readme.rtf
c:\Program Files\PCAntiMalware\scanlog.xml
c:\Program Files\PCAntiMalware\settings.ini
c:\Program Files\PCAntiMalware\shellext.dll
c:\Program Files\PCAntiMalware\shellext.xml
c:\Program Files\PCAntiMalware\Summary.dat
c:\Program Files\PCAntiMalware\tasks.dat
c:\Program Files\PCAntiMalware\threatnet.dat
c:\Program Files\PCAntiMalware\threatnet.ini
c:\Program Files\PCAntiMalware\unins000.dat
c:\Program Files\PCAntiMalware\unins000.exe
c:\Program Files\PCAntiMalware\uninstall.ico
c:\Program Files\PCAntiMalware\UserAgent.dll
c:\Program Files\PCAntiMalware\database
c:\Program Files\PCAntiMalware\database\knownfiles.dat
c:\Program Files\PCAntiMalware\database\MalwareDB.dat
c:\Program Files\PCAntiMalware\database\TEBase.dat
c:\Program Files\PCAntiMalware\database\vbpv.dat
c:\Program Files\PCAntiMalware\quaratine.dat
c:\Program Files\PCAntiMalware\quaratine.dat\#post_quarantine
c:\Program Files\PCAntiMalware\RTMonitor.dat
c:\WINDOWS\system32\bootrem.exe

Remove/Modify corrupt Registry Entries (Learn Here)

HKEY_CURRENT_USER\Software\PCAntiMalware
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\amshellext.ShellHook
HKEY_CLASSES_ROOT\amshellext.ShellHook.1
HKEY_CLASSES_ROOT\CLSID\{_CLSID_WAShellExecuteCheck}
HKEY_CLASSES_ROOT\CLSID\{4567AB12-EDED-4675-AF10-BA15EDDB4D7A}
HKEY_CLASSES_ROOT\CLSID\{4ADD95DA-B25D-4d21-9C5C-05FC6DE05860}
HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
HKEY_CLASSES_ROOT\TypeLib\{4567AB12-7DFC-4C46-BD8F-41259D169A0D}
HKEY_CLASSES_ROOT\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
HKEY_CLASSES_ROOT\washellext.WASContextMenu
HKEY_CLASSES_ROOT\washellext.WASContextMenu.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSAMAP_is1
HKEY_LOCAL_MACHINE\SOFTWARE\PCAntiMalware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks “{4ADD95DA-B25D-4D21-9C5C-05FC6DE05860}”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “UPSAMAP 4.1.228.0″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “PCAntiMalware”


Download – Removal Tool for PC AntiMalware

Tags: , , ,

Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word