Green AV Security Suite

Green AV Security Suite Description

Green AV Security Suite is a rogue anti-spyware program designed to pilfer money from unwary computer owners. Green AV Security Suite uses Trojans to spread via network systems and corrupt websites. The Trojans redirect the browser to a fake scan page which produces bogus results claiming the PC is infected with malware. Soon the system will be bombarded by popups urging the purchase of Green AV Security Suite to remove the so-called threats. Do not become a another hapless victim of cyber crime and have Green AV Security Suite removed from the compromised computer immediately using reliable anti-spyware software.

Technical Information

File System Details

Green AV Security Suite creates the following file(s):
# File Name Detection Count
1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\[random characters].exe N/A
2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\[random characters]tssd.exe N/A

Registry Details

Green AV Security Suite creates the following registry entry or registry entries:
Registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random characters]"
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random characters]"
HKEY_CURRENT_USER\Software\avsuite
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" ="1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKEY_CURRENT_USER\Software\AvScan
HKEY_CURRENT_USER\Software\avsoft
HKEY_LOCAL_MACHINE\SOFTWARE\avsuite
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"

One Comment

  • james:

    seems like maybe my computer wasn't fully infected. Once I shut down and restarted, it doesn't appear or halt other programs. I was 'infected' by clicking the Libertarian Revolution link to google news.