Title: Antimalware PC Safety
Also known as: Anti malware PC Safety, AntimalwarePCSafety

Remove Antimalware PC Safety
Removal instructions

 
Severity scale:Antimalware PC Safety severity is 80  (80 / 100)
 

Antimalware PC Safety is a dangerous rogue anti-spyware program that was designed to steal money from PC users. Once installed the rogue program starts displaying continuous fake alerts and scanners that claim about tons of malware found on your computer. This bogus program is designed to report non-existent viruses that have nothing to do with a real computer's state, so you can safely ignore them. What makes it different from other rogues is that this one is capable to change the language on its alerts according to country and language settings found on compromised PCs. As soon as you notice fake security alerts, remove Antimalware PC Safety using our anti-spyware program suggested below. Please do not purchase the rogue program, full or whatever it is called version of Antimalware PC Safety. You will simply lose your money together with your credit card details and other sensitive information.

Antimalware PC Safety belongs to the family of rogue anti-spyware applications that are usually promoted via Trojans and fake online scanners. Trojan horses get inside the system through security vulnerabilities found and additionally set the malware to start once you start your computer. That helps for Antimalware PC Safety to become a really dominating program on your system. In addition to annoying alerts and scanners, it may also disconnect the compromised computer from the Internet and may block other legitimate programs found running on machine. The only website user is able to reach when Antimalware PC Safety is inside is the purchase page which agressively offers to buy the license.

To make you concerned about your computer, this malware claims:

Warning! Virus Detected
Threat Detected: Trojan-Spy.HTML.BankFraud.ra
Recommended: Please click "Remove All" button to erase all infected files and protect your PC.

Address space conflict
Warning! Access conflict detected
An unidentified program is trying to access system process address space.

As you can see, the main goal of detecting and reporting non-existent viruses is really simple - Antimalware PC Safety tries to make users buy its license by scaring infected users into believing that their computers got infected by malware. Because of it, you will get tons of system tray notifications and security scanners that will report malware on your computer. To remove this rogue anti-spyware program, you are highly recommended to use our recommended malware removal tool. If you can't run it in normal mode, then restart your computer in safe mode with networking and run it again. 

Automatic Antimalware PC Safety removal:

It might be that we are affiliated with any of our recommended products. Full disclosure can be found in our Agreement of Use.
By downloading any of provided Anti-spyware software to remove Antimalware PC Safety you agree with our Privacy Policy and Agreement of Use.
SpyHunter is recommended remover to uninstall Antimalware PC Safety. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

If you failed to remove Antimalware PC Safety using SpyHunter, submit question to our support team and provide as much details as possible.
dot
STOPzilla
download
manual required
We are testing STOPzilla's efficiency at removing Antimalware PC Safety (2012-03-06 09:35:45)
dot
Malwarebytes Anti Malware
download
manual required
We are testing Malwarebytes Anti Malware's efficiency at removing Antimalware PC Safety (2012-03-06 09:35:45)
dot
XoftSpySE Anti Spyware
download
manual required
We are testing XoftSpySE Anti Spyware's efficiency at removing Antimalware PC Safety (2012-03-06 09:35:45)
dot
Defender Pro Ultimate
download
manual required
We are testing Defender Pro Ultimate's efficiency at removing Antimalware PC Safety (2012-03-06 09:35:45)

what to do if you failed to remove the infection?
Virus Removal
Phone Support
Help Line to remove Antimalware PC Safety
Antimalware PC Safety snapshot:

Antimalware PC Safety manual removal:

Kill processes:
[random].exe
AV9c5_8046.exe
scandsk211d_8046.exe
ASa76.exe
eb.exe
runddlkey.exe
Delete registry values:
HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
Default = Implements DocHostUIHandler
LocalServer32 = %AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe
ProgID = AS9c5_8046.DocHostUIHandler
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\
Debugger = svchost.exe
HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\
Debugger = svchost.exe
Unregister DLLs:
mozcrt19.dll

Delete files:
%AllUsersProfile%\Application Data\5c678c\
%AllUsersProfile%\Application Data\5c678c\sqlite3.dll
%AllUsersProfile%\Application Data\5c678c\ASPSys\
%AllUsersProfile%\Application Data\5c678c\BackUp\
%AllUsersProfile%\Application Data\5c678c\Quarantine Items\
%AllUsersProfile%\Application Data\5c678c\582.mof
%AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe
%AllUsersProfile%\Application Data\5c678c\ASP.ico
%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll
%AllUsersProfile%\Application Data\ASLNP\
%AllUsersProfile%\Application Data\ASLNP\ASUUDJRRJXP.cfg
%AppData%\AV Security Essentials\
%AppData%\AV Security Essentials\cookies.sqlite
%AppData%\Microsoft\Internet Explorer\Quick Launch\AV Security Essentials.lnk
%UserProfile%\Desktop\AV Security Essentials.lnk
%Temp%\scandsk211d_8046.exe
%UserProfile%\Start Menu\AV Security Essentials.lnk
%UserProfile%\Start Menu\Programs\AV Security Essentials.lnk

QR code for Antimalware PC Safety removal instructions:

Antimalware PC Safety qrcode
QR is short for Quick Response. They can be read quickly by the mobile phones. QR codes can store more data than standard barcodes, including url links, geo coordinates, and text.

The reason we add QR code to the website is that parasites like Antimalware PC Safety are really hard to remove on infected computer. you can quicly scan the QR code with your mobile device and have manual removal instructions to uninstall Antimalware PC Safety right in your pocket.

Simply use the QR scanner and read removal instructions from mobile device.
Information added: 2012-03-06 09:35:45
Information updated: 2012-03-06 09:35:45

Additional resources:

Attention: If you know know a reputable website reated to security threats, please add a link here: add url

Post Comment:

Attention: Use this form only if you have additional information about Antimalware PC Safety parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Like us on Facebook
Latest spyware news:
Subscribe to spyware news
Please enter your e-mail address:
If you do not want to receive our spyware
newsletter please unsubscribe here
48646 Subscribers
Ask us
I failed to remove Antimalware PC Safety using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight against computer parasites on the Internet alone. If you have a website, we would be more than happy if you would like to cooperate and help us spread the information about latest threats. Remember, knowledge is the most powerful weapon. Help your visitors protect their computers!
add text box
rss feed
help other