How to Remove Ghost Antivirus



Ghost Antivirus is a rogue antivirus application that is the successor to Antivirus Pro. This rogue is pushed through trojan horse activity and aggressive advertising tactics. It makes things very challenging to remove this rogue because it disables task manager, as well as any security programs that it detects. It also installs other malware on your system and terminates explorer.exe which makes the desktop unusable. It is possible to remove this rogue and you need to reboot into safe mode (with networking) in order to do so. Read on for how to remove ghost antivirus.


First you should boot up in safe mode with networking. In order to access the menu to choose how to boot you will need to press F8 when your computer boots up (yet just before the Windows splash screen.) After you have made it into safe mode then you should be able to download and install malwarebytes antimalware. (From the virus removal toolkit page.)

After it is installed, update and perform a full scan. Make sure to remove anything that it finds. For your reference the following files and folders are associated with Ghost antivirus and should be deleted for a manual removal of ghost antivirus. However, due to the nature of the rogue manual removal is not suggested.

If you do delete the following files to remove ghost antivirus then you should follow that up with a scan of your computer by malwarebytes antimalware or superantispyware and then follow that up with a scan with a trusted antivirus application. The files associated with this rogue are:

%docs%All UsersDesktopGhost Antivirus.lnk
%docs%All UsersStart MenuProgramsGhost Antivirus
%docs%All UsersStart MenuProgramsGhost AntivirusGhost Antivirus Home Page.lnk
%docs%sAll UsersStart MenuProgramsGhost AntivirusGhost Antivirus.lnk
%docs%All UsersStart MenuProgramsGhost AntivirusPurchase License.lnk
%user%Application DataGhost Antivirus
%user%Application DataGhost Antivirussettings.ini
%user%Application DataGhost Antivirusuill.ini
%usere%Application DataGhost Antivirusunins000.exe
%user%Application DataGhost AntivirusUninstall Ghost Antivirus.lnk
%user%Application DataGhost Antiviruslib
%user%Application DataGhost Antivirusliblinks.txt
%user%Application DataGhost Antiviruslibproperties
%user%Application DataGhost Antiviruslibtimes.conf
%user%Application DataMicrosoftInternet ExplorerQuick LaunchGhost Antivirus.lnk
%user%Local SettingsApplication DataMicrosoftInternet ExploreriGSh.png
%user%Local SettingsApplication DataMicrosoftInternet ExploreriMSh.png
%user%Local SettingsApplication DataMicrosoftInternet ExploreriPSh.png
%user%Local SettingsApplication DataMicrosoftWindowspguard.ini
%user%Local SettingsApplication DataMicrosoftWindowsservices.exe
RANDOMRANDOMonin.exe
%progfiles%Ghost Antivirus
%progfiles%Ghost AntivirusGhostAV.exe
%progfiles%Ghost Antivirusregister.ico
%progfiles%Ghost Antivirusunins000.dat
%progfiles%Ghost Antivirusuninst.ico
%progfiles%Ghost Antivirusweb.ico
%progfiles%Ghost Antivirusworking.log
%progfiles%Ghost AntivirusLanguages
%progfiles%Ghost Antiviruslib
%progfiles%Ghost Antiviruslibghost.sql
%progfiles%Ghost AntiviruslibInfected.wav
%progfiles%Ghost Antivirusliblisting.cfg
%progfiles%Ghost Antiviruslibversion.db
%progfiles%Ghost AntiviruslibWMILib.dll
%win%system32RANDOM.dll
%win%system32RANDOM.dll

Remember to keep scanning with your malware removal tools and antivirus until the system comes up clean!

Related Posts

Blog Traffic Exchange Related Posts
  • How to Remove Antivirus 360 This should not be confused with Norton 360 which is a legitimate antivirus program (although if you need help removing Norton 360 to reinstall it or another antivirus program you may want to visit my antivirus removal tool list.) What we are talking about this time is a rogue security......
  • How to Remove SecurityFighter | Security Fighter Removal SecurityFighter is making the rounds as yet another rogue security application. It installs itself via trojans and web popups and creates files that it then claims are viral and need to be cleaned out for your computer to be safe. Of course, they never can do that without you first......
  • How to Remove APCSecure | APCSecure Removal Guide APCSecure is yet another rogue antivirus application from the prolific and annoying wini family of rogues. This particular variant also comes with a rootkit called TDL3. Trojans are used to promote this rogue antivirus and you will likely find that it will create multiple empty files on your computer that......
Blog Traffic Exchange Related Websites
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site