PC Anti Malware Removal Instructions
PC Anti Malware is rogue antispyware designed to scam a user out of his or her money. Although manual infection can happen when an unsuspecting user downloads the file, infection more commonly occurs through a Zlob Trojan disguised as ActiveX video codec. Once on a machine, PC Anti Malware will attempt to convince the user that their PC is riddled with malware by bombarding them with pop ups and fake security alerts urging them to take action by investing in the full version of PC Anti Malware. Users who fall for this scam lose their money and put both their sensitive personal information and the health of their computer at risk. When left resident on a computer, PC Anti Malware will often download more spyware and severely slow the ability of the computer to function properly. Browsers may also be hijacked.
PC Anti Malware file contents:
Stop these running processes:
c:\WINDOWS\system32\bootrem.exe
c:\Program Files\PCAntiMalware\PP.exe
c:\Program Files\PCAntiMalware\PCAM.exe
c:\Program Files\PCAntiMalware\InstUp.exe
c:\Program Files\PCAntiMalware\unins000.exe
Disable These DLLs:
c:\Program Files\PCAntiMalware\atl71.dll
c:\Program Files\PCAntiMalware\AsAgents.dll
c:\Program Files\PCAntiMalware\mfc71.dll
c:\Program Files\PCAntiMalware\msvcp71.dll
c:\Program Files\PCAntiMalware\msvcr71.dll
c:\Program Files\PCAntiMalware\shellext.dll
c:\Program Files\PCAntiMalware\UserAgent.dll
Remove These Registry Entries:
HKEY_CURRENT_USER\Software\PCAntiMalware
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\amshellext.ShellHook
HKEY_CLASSES_ROOT\amshellext.ShellHook.1
HKEY_CLASSES_ROOT\CLSID\{_CLSID_WAShellExecuteCheck}
HKEY_CLASSES_ROOT\CLSID\{4567AB12-EDED-4675-AF10-BA15EDDB4D7A}
HKEY_CLASSES_ROOT\CLSID\{4ADD95DA-B25D-4d21-9C5C-05FC6DE05860}
HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\ExplorerWAS
HKEY_CLASSES_ROOT\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
HKEY_CLASSES_ROOT\TypeLib\{4567AB12-7DFC-4C46-BD8F-41259D169A0D}
HKEY_CLASSES_ROOT\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
HKEY_CLASSES_ROOT\washellext.WASContextMenu
HKEY_CLASSES_ROOT\washellext.WASContextMenu.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSAMAP_is1
HKEY_LOCAL_MACHINE\SOFTWARE\PCAntiMalware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks “{4ADD95DA-B25D-4D21-9C5C-05FC6DE05860}”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “UPSAMAP 4.1.228.0?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “PCAntiMalware”
Remove These Related Files:
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware\Contact customer support.url
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware\PCAntiMalware on the Web.url
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware\PCAntiMalware.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\PCAntiMalware\Uninstall PCAntiMalware.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PCAntiMalware.lnk
%UserProfile%\Desktop\PCAntiMalware.lnk
c:\Program Files\PCAntiMalware\Activate.dat
c:\Program Files\PCAntiMalware\appupdate.dat
c:\Program Files\PCAntiMalware\AsAgents.xml
c:\Program Files\PCAntiMalware\AutoProcess.dat
c:\Program Files\PCAntiMalware\dbupdate.dat
c:\Program Files\PCAntiMalware\lapv.dat
c:\Program Files\PCAntiMalware\license.rtf
c:\Program Files\PCAntiMalware\PCAM.xml
c:\Program Files\PCAntiMalware\pv.dat
c:\Program Files\PCAntiMalware\readme.rtf
c:\Program Files\PCAntiMalware\scanlog.xml
c:\Program Files\PCAntiMalware\settings.ini
c:\Program Files\PCAntiMalware\shellext.xml
c:\Program Files\PCAntiMalware\Summary.dat
c:\Program Files\PCAntiMalware\tasks.dat
c:\Program Files\PCAntiMalware\threatnet.dat
c:\Program Files\PCAntiMalware\threatnet.ini
c:\Program Files\PCAntiMalware\unins000.dat
c:\Program Files\PCAntiMalware\uninstall.ico
c:\Program Files\PCAntiMalware\database\knownfiles.dat
c:\Program Files\PCAntiMalware\database\MalwareDB.dat
c:\Program Files\PCAntiMalware\database\TEBase.dat
c:\Program Files\PCAntiMalware\database\vbpv.dat
c:\Program Files\PCAntiMalware\quaratine.dat
c:\Program Files\PCAntiMalware\quaratine.dat\#post_quarantine
c:\Program Files\PCAntiMalware\RTMonitor.dat
Recommended Action: Immediate removal.
Manual removal is performed by blocking the program’s websites, killing its running processes, unregistering its DLLs and deleting its associated registry values and files. If any of these components are missed during the attempt to destroy PC Anti Malware, the program will simply reinstall itself upon reboot. Caution is advised when attempting this process because the accidental deletion of the wrong file or component could cause further damage to the machine. Automatic removal can be achieved through the use of SpyZooka, the only antispyware guaranteed to remove 100% of malware found on a computer.