January 15, 2011

AV Security Suite Removal

AV Security Suite is fake anti-spyware program which imitates a legitimate antimalware application and belongs to the notorious Antivirus Live family of rogue malware. It acts in the same manner as its predecessors, Antivirus Soft and Antispyware Soft, by trying to convince users to buy a license for the software. AV Security Suite enters a user’s computer via Trojans that arrive at the user’s system via infected PDF files. Once it has been installed on the user’s system, AV Security Suite starts performing fake system scans at regular intervals, returning results that claim that the user’s system is under serious threat. It also creates a number of harmless files that it later detects as dangerous viruses. AV Security Suite uses a Windows-style GUI and pop-ups generated from the Windows taskbar to convince users that this is the real thing. Then it claims that the currently installed ‘trial’ version is inadequate to remove the previously detected false ‘threats and urges the user the pay for the ‘full’ version of the software. However, the ‘full’ version is no more capable of cleaning a user’s system than the ‘trial’ version; therefore no user should ever purchase the false license to this rogue software.

As soon as you find a copy of this malicious software installed on your computer, you should take steps to delete AV Security Suite. AV Security Suite removal involves the stopping of processes, removal of files and folders and the deletion of registry entries. However, before attempting this you should restart your computer in Safe Mode.
File Removal Procedures:
The first step you need to take in order to remove AV Security Suite from your computer is to kill the following processes:
  1. [random characters]tssd.exe
  2. [random characters].exe
Next, it is necessary to remove the following files and folders from the hard disk in order to continue with AV Security Suite removal:
  1. %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\[random characters]tssd.exe
  2. %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\[random characters].exe
  3. Windows Vista/7
  4. %USER%\AppData\[random characters ]\[random characters]tssd.exe
  5. %USER%\AppData \[random characters ]\[random characters].exe
Once the above steps have been completed, it is safe to say that there are no more files belonging to AV Security Suite on your hard disk. In order to make sure of this fact, especially when working within a sensitive environment that contains a lot of personal data and work related files, it is recommended to scan the entire PC using genuine antivirus software such as Spyware Doctor with Antivirus.
Registry Removal Procedures
  1. File deletion alone is not sufficient to completely remove AV Security Suite. The following keys and settings should be removed from the Windows Registry for complete AV Security Suite removal:HKEY_CURRENT_USER\Software\AvScan
  2. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random characters]
  3. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random characters]“
  4. HKEY_CURRENT_USER\Software\avsoft
  5. HKEY_CURRENT_USER\Software\avsuite
  6. HKEY_LOCAL_MACHINE\SOFTWARE\avsoft
  7. HKEY_LOCAL_MACHINE\SOFTWARE\avsuite
  8. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” =”1″
  9. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
  10. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555″
  11. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
  12. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″
After the registry cleaning portion of AV Security Suite removal has been completed, your computer is safe from this rogue software.
Conclusion
Manual Security Center AV removal is not recommended for inexperienced users as any wrong move made during removal could cause damage to the system. The best tactic that inexperienced users can employ is to make use of web-based computer scanning/cleaning service or legitimate antivirus software such as Spyware Doctor with Antivirus to ensure complete and safe AV Security Suite removal.

0 comments:

Post a Comment

Related Posts Plugin for WordPress, Blogger...

Search This Blog

Followers

Categories

Twitter Delicious Facebook Digg Stumbleupon Favorites More