|
Free malware removal tool to remove AV Security Suite
|
|
Écrit par Administrator |
Jeudi, 03 Juin 2010 00:00
|
|
There are no translations available.
AV Security Suite is another rogue Antispyware from the Antispyware Soft and Antivirus Suite, that tries to get money from users by prompting them to register and buy their Fake products. Some old malwares often return to the front of the stage and AV Security Suite is replacing Antivirus Live and Antivirus Soft. Remove AV Security Suite immediately from your system.

To remove AV Security Suite (Uninstall AV Security Suite)
- Download this free removal tool for AV Security Suite
- Extract it
- Launch
- Click on the delete button
AV Security Suite will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :
- [random]sysguard.exe
- [random]sftav.exe
- [random]tssd.exe
Files :
- %AppData%\[random]\[random]sftav.exe
- %AppData%\[random]\[random]sysguard.exe
- %AppData%\[random]\[random]tssd.exe
- %AppData%\[random]
Registry
Registry keys created
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
- HKEY_CURRENT_USER\Software\Microsoft\Windows Script
- HKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings
- HKEY_CURRENT_USER\Software\avsoft
- HKEY_CURRENT_USER\Software\avsuite
- HKEY_LOCAL_MACHINE\Software\avsoft
- HKEY_LOCAL_MACHINE\Software\avsuite
Registry values created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- [random] = "%AppData%\agolui\[random]sftav.exe"
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download
- RunInvalidSignatures = 0x00000001
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
- LowRiskFileTypes = ".exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
- SaveZoneInformation = 0x00000001
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- [random = "%AppData%\[random]\[random]sftav.exe"
- HKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings
- HKEY_CURRENT_USER\Software\avsoft
Registry value deleted
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Registry value modified
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download
- CheckExeSignatures = ""/ Original value =" yes"

- Restart your computer in safe mode using your usual account
- Open Explorer
- Type %AppData% on the address bar
- Remove all RANDOM CHARACTERS folder
- Click on the Start menu
- Click on Run
- Type msconfig and enter
- Go to StartUp tab
- Uncheck all RANDOM CHARACTERS values which point to a process under %AppData%\[random characters]\
- Restart your computer in normal mode
|