Monday, June 14, 2010

AV Security Suite

AV Security Suite will provide scare tactics on its victims. This fake security program was developed by cyber criminals and spread using infested web pages, spam emails and Trojans. With these methods, AV Security Suite will be installed on your computer without your knowledge. When inside the computer, this rogue program will play as a virus scanner that will detect a number of threats which are not really present on the computer. As you can see, it misleads computer users in the purpose of convincing them to purchase the registered version of AV Security Suite.


Most vulnerable to this threat are those that has outdated operating system, internet browser and anti-virus programs. It is important to always update your software to strengthen virus attacks such as this. AV Security Suite will find vulnerabilities on the system that it will exploit in order to download additional malware files that will enhance its presence. This added infection may caused Windows to malfunction rendering some of its tools unusable. This way, AV Security Suite will be impossible to remove from the infected computer.


Symptoms:

If infected with AV Security Suite a display of fake alerts and warning messages can be notice on the system.
Windows Security alert
Application cannot be executed. The file mbam.exe is infected.
Do you want to active your antivirus software now?

Spyware Alert
Application infected! The file rundll32.exe is infected. Do you want to ALLOW this application now?

Windows Security alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan your computer. Your system might be at risk now.

Antivirus software alert
Infiltration Alert
Your computer is being attacked by an internet virus. It could be a password-stealing attack, a trojan-dropper or similar.

AV Security Suite Snap Shot:



















Files Related to AV Security Suite:
%UserProfile%\Local Settings\Application Data\\
%UserProfile%\Local Settings\Application Data\\.exe


Registry Entries Created By AV Security Suite:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:1041"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"
HKEY_CURRENT_USER\Software\avsoft
HKEY_CURRENT_USER\Software\avsuite
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft
HKEY_LOCAL_MACHINE\SOFTWARE\avsuite
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ""


Automatic Removal of AV Security Suite:
We can recommend an AV Security Suite removal tool in the presence of MalwareBytes Antimalware, it is a free tool to remove virus and malware. There is a licensed version available and with this one you can be able to protect your computer from AV Security Suite infection in the future. Once MBAM is downloaded, install and update it. Do your complete scan in SafeMode to ensure that this malware will not be loaded into memory.

0 comments: