|
Free malware removal tool to remove AntiMalware
|
|
Écrit par Administrator |
Mercredi, 06 Janvier 2010 18:30
|
|
There are no translations available.
AntiMalware is a rogue Antispyware, a scamware, it's a malware that pretends to be an Antivirus. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares on your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is AntiMalware. It invites you to purchase a license to remove malware, do not, it's a scam, you need a license for a malware? This so-called Antivirus tries to scam you.

To remove AntiMalware
- Download this free removal tool for AntiMalware
- Extract it
- Launch
- Click on the delete button
AntiMalware will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :
Files :
- %DesktopDir%\AntiMalware Support.lnk
- %DesktopDir%\AntiMalware.lnk
- %Temp%\uac138e.tmp
- %ProgramFiles%\AntiMalware\amext.dll
- %Temp%\uac14b7.tmp
- %ProgramFiles%\AntiMalware\uninstall.exe
- %Temp%\uac1572.tmp
- %ProgramFiles%\AntiMalware\antimalware.exe
- %Temp%\uace058.tmp
- %ProgramFiles%\AntiMalware\malw.db
- %Programs%\AntiMalware\AntiMalware Support.lnk
- %Programs%\AntiMalware\AntiMalware.lnk
- %Programs%\AntiMalware\Uninstall AntiMalware.lnk
- %ProgramFiles%\AntiMalware\help.ico
Registry
Registry keys created
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SimpleShlExt
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\SimpleShlExt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMalware
- HKEY_LOCAL_MACHINE\SOFTWARE\AntiMalware
Registry values created
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SimpleShlExt
- (Default) = "{5E2121EE-0300-11D4-8D3B-444553540000}"
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32
- (Default) = "C:\PROGRA~1\ANTIMA~1\amext.dll"
- ThreadingModel = "Apartment"
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
- (Default) = "SimpleShlExt Class"
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\SimpleShlExt
- (Default) = "{5E2121EE-0300-11D4-8D3B-444553540000}"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
- {5E2121EE-0300-11D4-8D3B-444553540000} = "AntiMalware extension"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMalware
- DisplayIcon = "%ProgramFiles%\AntiMalware\antimalware.exe"
- DisplayName = "AntiMalware"
- DisplayVersion = "1.0"
- Publisher = "AntiMalware Software"
- UninstallString = "%ProgramFiles%\AntiMalware\Uninstall.exe"
- URLInfoAbout = "http://support.activesecuritys.org"
- HKEY_LOCAL_MACHINE\SOFTWARE\AntiMalware
- License = "85108357713673677262162845570576027004153211"
- FD = 0x00000001
- Settings_2 = 0x00000001
- Settings_0 = 0x00000000
- RV = 0x00000001

|