Thursday, April 15, 2010

Antivirus Suite Removal GuideAntivirus Suite Removal Guide

Antivirus Suite Removal Guide
Antivirus Suite (aka AntivirusSuite) is a rogue anti-spyware program which enters a targeted computer via a backdoor created by malware. AntivirusSuite displays similar tactics to its rogue cousin Antivirus Soft. The hackers behind this cyber-scam use malware to redirect Internet users to a fake scan page which produces bogus results claiming the system is infected with all sorts of malware. The fake scanner also produces popup warnings which urge users to purchase Antivirus Suite to remove the so-called threats. Do not fall for this trickery, it is a blatant scam.

Removal Guide
Kill Process
(How to kill a process effectively?)
mrkkuvktssd.exe
wvhstoctssd.exe
[random]tssd.exe

Delete Registry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "val Tool"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\avsuite
HKEY_CURRENT_USER\Software\avsuite

Remove Folders and Files
%UserProfile%\Local Settings\Application Data\[random characters]\[random characters]tssd.exe
%UserProfile%\Local Settings\Application Data\[random characters]

No comments:

Post a Comment