Green AV Security Suite

By Domesticus in Rogue Anti-Spyware Program

Green AV Security Suite is a rogue anti-spyware program designed to pilfer money from unwary computer owners. Green AV Security Suite uses Trojans to spread via network systems and corrupt websites. The Trojans redirect the browser to a fake scan page which produces bogus results claiming the PC is infected with malware. Soon the system will be bombarded by popups urging the purchase of Green AV Security Suite to remove the so-called threats. Do not become a another hapless victim of cyber crime and have Green AV Security Suite removed from the compromised computer immediately using reliable anti-spyware software.

File System Details

Green AV Security Suite may create the following file(s):
# File Name Detections
1. %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\[random characters].exe
2. %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\[random characters]tssd.exe

Registry Details

Green AV Security Suite may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random characters]"
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random characters]"
HKEY_CURRENT_USER\Software\avsuite
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" ="1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKEY_CURRENT_USER\Software\AvScan
HKEY_CURRENT_USER\Software\avsoft
HKEY_LOCAL_MACHINE\SOFTWARE\avsuite
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"

1 Comment

seems like maybe my computer wasn't fully infected. Once I shut down and restarted, it doesn't appear or halt other programs. I was 'infected' by clicking the Libertarian Revolution link to google news.

Trending

Most Viewed

Loading...