By George Norman
Added on 20 Nov 2009(151 Views)



classification: Rogue AntiSpyware Programs
AntiMalwareSuite (also known as Anti Malware Suite) is a rogue security software application that hails from the same family of rogues that gave us Cleaner2009. The fact that it is a rogue means it has no genuine security software capabilities, it means it cannot detect, remove and protect against security threats. The reason why it claims to do so is to scam you out of some money. Once AntiMalwareSuite makes its way onto your computer (usually distributed by malicious sites that claim to be able to scan your system for infection signs – after the pretend scan is over, you are advised to get AntiMalwareSuite to remove whatever pretend infection the online scanner claims to have found) it will perform fake system scans that will detect numerous phony infections. Then the rogue will ask the user to purchase an AntiMalwareSuite license to remove the infection.
Do not part with your hard earned money! What you should do is remove AntiMalwareSuite from your system immediately. The fact that it scares you into thinking your system is infected is one reason why you should remove it – but not the only one. Here are some other reasons: it may crash your system, it will cause performance loss (because it constantly runs in the background), it will hijack your browser and it may cause genuine security software applications to stop working.

Automatic removal guide
Step 1. If you have a printer, make sure to print out this tutorial. If you do not have a printer, save this tutorial, go out to a copy center and print it out there. If you do not have a printer and do not want to go out, then use the pen and paper method: grab a pen and a piece of paper and write down the instruction presented in the steps below. In the process of eliminating AntiMalwareSuite from your machine you will need to shut down the browser. And since this will also shut down the tutorial, you need to know what you should do next.

Step 2. You will have to install Malwarebytes’ Anti-Malware. In this regard you need to download the software’s setup executable. Just click this link and save the .exe file on your computer (preferably on your desktop).

Step 3. Double click the Malwarebytes’ Anti-Malware setup executable. It should be on the desktop under the name mbam-setup. This will launch the installation process. If you already know how to install a piece of software, proceed to step 4. If you do not know how to do this, we’ll walk you though it all:



- The Select Setup Language window should have popped up. By default, the language in which the software will be installed is set to English, but you can change this. The software provides support for 30+ languages. After selecting the language of your choice, click OK. It would be best to just leave it set to English though.



- The Malwarebytes’ Anti-Malware Setup Wizard will now popup. Just click Next.



- You will be presented with the License Agreement. Click I accept the agreement and then click Next. If you do not accept the agreement you will not be able to continue.



- Keep clicking Next until you get to the Ready to install window. Now click Install. After the installation process completes click Finish. Do not uncheck the boxes next to Update Malwarebytes’ Anti-Malware or Launch Malwarebytes’ Anti-Malware.















Step 4. The Malwarebytes’ Anti-Malware application will launch automatically. The Perform quick scan option should be checked by default – if it isn’t then check it and then click Scan. You are well advised to close all running apps before clicking scan. This will ensure the scan for AntiMalwareSuite will complete swiftly.



Malwarebytes’ Anti-Malware will start scanning your files for signs of AntiMalwareSuite. This may take a while, so be patient. It all depends on how powerful your computer is and how many files Malwarebytes’ Anti-Malware has to scan.



When the scan for AntiMalwareSuite is complete you will be presented with a notification box. Click OK to close the notification box and go to the main Scanner screen. Click Show Results and you will be presented with a list of all the infected files Malwarebytes’ Anti-Malware has detected.





Step 5. Click Remove Selected and Malwarebytes’ Anti-Malware will remove all the infected files it has detected. It may be necessary to restart your computer in order to remove some of these files. After Malwarebytes’ Anti-Malware is done removing all the infected files, it will open Notepad and present the scan log to you. You can review the log at your leisure – save it If you want.



Step 6. Close Malwarebytes’ Anti-Malware and you’re done. No traces of AntiMalwareSuite should be left on your computer.

Manual removal guide

Using Task Manager, shut down and remove the processes:

AntiMalwareSuite.exe
bootrem.exe
unins000.exe
PaymentPage.exe
InstUp.exe
AMS.exe
AMS_FreeSetup.exe
QuickInstallPack.exe


Access the Windows Registry Editor and delete the following registry keys:

HKEY_CURRENT_USER/Software/AntiMalwareSuite
HKEY_CLASSES_ROOT/amshellext.ShellHook
HKEY_CLASSES_ROOT/amshellext.ShellHook.1
HKEY_CLASSES_ROOT/AppID/{3A9377A6-BE7F-485D-908C-D44114691389}
HKEY_CLASSES_ROOT/AppID/iercpt.DLL
HKEY_CLASSES_ROOT/CLSID/{4567AB12-EDED-4675-AF10-BA15EDDB4D7A}
HKEY_CLASSES_ROOT/CLSID/{4ADD95DA-B25D-4d21-9C5C-05FC6DE05860}
HKEY_CLASSES_ROOT/CLSID/{D4CDC21D-43BE-4101-A1EF-E379F134771E}
HKEY_CLASSES_ROOT/iercpt.iercptbho
HKEY_CLASSES_ROOT/iercpt.iercptbho.1
HKEY_CLASSES_ROOT/Interface/{4567AB12-A884-4CA6-B739-CEDB12FEF096}
HKEY_CLASSES_ROOT/Interface/{59C345BA-3D5E-44E3-9D10-D3848AF15D73}
HKEY_CLASSES_ROOT/TypeLib/{4567AB12-7DFC-4C46-BD8F-41259D169A0D}
HKEY_CLASSES_ROOT/TypeLib/{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
HKEY_CLASSES_ROOT/TypeLib/{A6FBD2E4-1C7E-4EAB-80DD-01DE2645566A}
HKEY_CLASSES_ROOT/washellext.WASContextMenu
HKEY_CLASSES_ROOT/washellext.WASContextMenu.1
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Explorer/Browser Helper Objects/{D4CDC21D-43BE-4101-A1EF-E379F134771E}
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Uninstall/AMS_is1
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Uninstall/QuickInstallPack
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run "QuickInstallPack"
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Explorer/ShellExecuteHooks "{4ADD95DA-B25D-4D21-9C5C-05FC6DE05860}"
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/User Agent/Post Platform "UAMS 4.1.221.0"
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run "AntiMalwareSuite"


Locate and delete the following files:

c:/My Downloads
c:/Documents and Settings/All Users/Application Data/AntiMalwareSuite
c:/Documents and Settings/All Users/Application Data/AntiMalwareSuite/Data
c:/Documents and Settings/All Users/Application Data/AntiMalwareSuite/Data/Abbr
c:/Documents and Settings/All Users/Application Data/AntiMalwareSuite/Data/ProductCode
c:/Documents and Settings/All Users/Start Menu/Programs/AntiMalwareSuite
c:/Documents and Settings/All Users/Start Menu/Programs/AntiMalwareSuite/AntiMalwareSuite on the Web.url
c:/Documents and Settings/All Users/Start Menu/Programs/AntiMalwareSuite/AntiMalwareSuite Online Manual.url
c:/Documents and Settings/All Users/Start Menu/Programs/AntiMalwareSuite/AntiMalwareSuite.lnk
c:/Documents and Settings/All Users/Start Menu/Programs/AntiMalwareSuite/Contact customer support.url
c:/Documents and Settings/All Users/Start Menu/Programs/AntiMalwareSuite/Uninstall AntiMalwareSuite.lnk
%UserProfile%/Application Data/update.log
%UserProfile%/Desktop/AntiMalwareSuite.lnk
%UserProfile%/Desktop/Install AntiMalwareSuite.lnk
%UserProfile%/Desktop/QuickInstallPack.lnk
%UserProfile%/Local Settings/Application Data/qip
%UserProfile%/Local Settings/Application Data/qip/AMS_FreeSetup.exe.ini
%UserProfile%/Local Settings/Application Data/qip/data.ini
%UserProfile%/Local Settings/Application Data/qip/iercpt.dll
%UserProfile%/Local Settings/Application Data/qip/QuickInstallPack.exe
%UserProfile%/Local Settings/Application Data/UAMS_QIP
%UserProfile%/Local Settings/Application Data/UAMS_QIP/data.ini
%UserProfile%/Local Settings/Temp/AMS_FreeSetup.exe
%UserProfile%/Start Menu/Programs/QuickInstallPack
%UserProfile%/Start Menu/Programs/QuickInstallPack/QuickInstallPack on the Web.url
%UserProfile%/Start Menu/Programs/QuickInstallPack/QuickInstallPack.lnk
%UserProfile%/Start Menu/Programs/QuickInstallPack/Uninstall QuickInstallPack.lnk
c:/Program Files/AntiMalwareSuite
c:/Program Files/AntiMalwareSuite/quaratine.dat
c:/Program Files/AntiMalwareSuite/Activate.dat
c:/Program Files/AntiMalwareSuite/AMS.exe
c:/Program Files/AntiMalwareSuite/AMS.xml
c:/Program Files/AntiMalwareSuite/appupdate.dat
c:/Program Files/AntiMalwareSuite/AsAgents.dll
c:/Program Files/AntiMalwareSuite/AsAgents.xml
c:/Program Files/AntiMalwareSuite/atl71.dll
c:/Program Files/AntiMalwareSuite/AutoProcess.dat
c:/Program Files/AntiMalwareSuite/dbupdate.dat
c:/Program Files/AntiMalwareSuite/InstUp.exe
c:/Program Files/AntiMalwareSuite/lapv.dat
c:/Program Files/AntiMalwareSuite/license.rtf
c:/Program Files/AntiMalwareSuite/manual.pdf
c:/Program Files/AntiMalwareSuite/mfc71.dll
c:/Program Files/AntiMalwareSuite/msvcp71.dll
c:/Program Files/AntiMalwareSuite/msvcr71.dll
c:/Program Files/AntiMalwareSuite/PaymentPage.exe
c:/Program Files/AntiMalwareSuite/ps.dat
c:/Program Files/AntiMalwareSuite/pv.dat
c:/Program Files/AntiMalwareSuite/readme.rtf
c:/Program Files/AntiMalwareSuite/scanlog.xml
c:/Program Files/AntiMalwareSuite/settings.ini
c:/Program Files/AntiMalwareSuite/shellext.dll
c:/Program Files/AntiMalwareSuite/shellext.xml
c:/Program Files/AntiMalwareSuite/Summary.dat
c:/Program Files/AntiMalwareSuite/tasks.dat
c:/Program Files/AntiMalwareSuite/threatnet.dat
c:/Program Files/AntiMalwareSuite/threatnet.ini
c:/Program Files/AntiMalwareSuite/unins000.dat
c:/Program Files/AntiMalwareSuite/unins000.exe
c:/Program Files/AntiMalwareSuite/uninstall.ico
c:/Program Files/AntiMalwareSuite/up.dat
c:/Program Files/AntiMalwareSuite/updateapp.dat
c:/Program Files/AntiMalwareSuite/updatedb.dat
c:/Program Files/AntiMalwareSuite/UserAgent.dll
c:/Program Files/AntiMalwareSuite/database
c:/Program Files/AntiMalwareSuite/database/knownfiles.dat
c:/Program Files/AntiMalwareSuite/database/MalwareDB.dat
c:/Program Files/AntiMalwareSuite/database/TEBase.dat
c:/Program Files/AntiMalwareSuite/database/vbpv.dat
c:/Program Files/AntiMalwareSuite/Download
c:/Program Files/AntiMalwareSuite/quaratine.dat/#post_quarantine
c:/Program Files/AntiMalwareSuite/RTMonitor.dat
c:/Program Files/Mozilla Firefox/plugins/nprcpt.dll
c:/WINDOWS/system32/bootrem.exe


Disable the following DLL libraries:

nprcpt.dll
UserAgent.dll
shellext.dll
msvcr71.dll
mfc71.dll
msvcp71.dll
atl71.dll
AsAgents.dll
iercpt.dll


Block access to the domain:


pcantimalwaresolution.com




Don't forget to:

Tags:

Link to this article:



Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Removal Guide Articles
How To Remove XP Micro Antivirus
If you did not manually install XP Micro Antivirus and ...
19 Feb 2010
How To Remove Software Antivirus
Software Antivirus, unlike what the name may suggest, is not ...
19 Feb 2010
How To Remove WiniFighter
The irony here is that the name WiniFighter would lead ...
19 Feb 2010
How To Remove PC Security 2009
PC Security 2009, a rogue antispyware program, is usually distributed ...
19 Feb 2010
How To Remove Security Essentials 2010
The people with malicious intent that put out the ...
18 Feb 2010
How To Remove Personal Anti Malware
Personal Anti Malware, a rogue security software application, is usually ...
18 Feb 2010
Recommended Tools

Top Downloads