AV Security Suite

AV Security Suite is a bogus anti-virus application that arises as the successor to widely-spread Antispyware Soft. To gain user’s confidence, the program used to detect an estimated number of threats familiarly issued by other variants. Intimidating victims is its major fashion to attract attention and promote itself as legitimate protection software.

AV Security Suite virus extends infection while facilitating strength of Trojan. This threat was designed to break its way by abusing software vulnerabilities and install itself without user’s acquaintance. If AV Security Suite manages to gain spot on the computer, timely revision is implemented to system settings confidently allowing the rogue software to run on its own when Windows is started. Once functional, it attempts to convince computer users to procure AV Security Suite activation key committing that it will stop annoyances and other unpleasant activities happening on the compromised computer. What’s more, AV Security suite it also excessively displays simulated warning alert messages talking about presence of various security risks. The phony application repeatedly tries to mislead users into getting the full version generating random messages like:

This website has been reported as unsafe
We recommend that you do not continue to this website. This website has been reported to Microsoft for containing threats to your computer that might reveal personal or financial information.

Spyware Alert
Application infected! The file rundll32.exe is infected. Do you want to ALLOW this application now?

Pay no attention to above mentioned warnings. At this point, it is vital to remove AV Security Suite virus immediately. Any instance of this or presence of Trojan that tries to redirect web browser to its own website must be dealt at once. Otherwise, this unwanted program will link-up to a remote server and pull down additional threats. Use only legitimate anti-malware application to take out this malicious software out of the system.

Screenshot Image:

AV Security Suite

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista

Technical Details and Additional Information:

Malware Behavior

Warning messages coming from Windows taskbar will pop-up stating that computer is being attacked. This is AV Security Suite’s tactics to mislead its victims.

To prevent itself from being removed from a computer, AV Security Suite will block applications particularly security software. It will display an error when a program is executed such as:

Windows Security alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan your computer. Your system might be at risk now.

Antivirus software alert
Infiltration Alert
Your computer is being attacked by an internet virus. It could be a password-stealing attack, a trojan-dropper or similar.

What comes with AV Security Suite is a Trojan that has a main goal of redirecting Internet traffic to payment processing page. While this rogue program exists on the system, it constantly attempts to force victim to purchase the registration key. In addition, pop-up alerts, warning messages and even scan result will point user to this transaction page at antivirback.com and antivirback.net.

Web site of AV Security Suite

Added Registry Entries:
HKCU\Software\avsoft
HKCU\Software\avsuite
HKLM\SOFTWARE\avsoft
HKLM\SOFTWARE\avsuite
HKCU\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKCU\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:1041"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run "[random characters]"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random characters]"
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"
Associated Files and Folders:
%UserProfile%\Local Settings\Application Data\[random characters]\
%UserProfile%\Local Settings\Application Data\[random characters]\[random characters].exe
File Location for Windows Versions:
  • %UserProfile% for Vista/7 user is C:\Users\<Current User> for Windows Vista/7, for Windows XP/2000 this is C:\Documents and Settings\<Current User>.

How to Remove AV Security Suite

Manual Removal Procedure

1. Press Ctrl+Alt+Del on keyboard to stop the process associated to "AV Security Suite". When Windows Task Manager opens, go to Processes tab. Find and end this process.
(random characters).exe

2. You need to update your installed antivirus software. Please connect to the Internet and download the most recent database. This is a one-click process from your AV program’s console.

3. Thoroughly scan the computer and remove any threats found by your antivirus program. If delete option is not available, your best next choice is to quarantine the infected file. There is also a need to manually locate and delete malicious files. Please see the file section for items that are relevant to AV Security Suite.

4. Next, you need to remove registry entries created by AV Security Suite. Please refer to registry section to view entries related to the rogue program.
- (Windows 2000/XP) Go to Start > Run, type "regedit" on dialog box then press Enter on keyboard.
- (Windows Vista/7) Go to Start > Search Program and Files, type "regedit" and press Enter.

5. Exit registry editor when you are done.

6. Get rid of AV Security Suite start-up entry by going to Start > Run, type msconfig on the "Open" dialog box. It will launch a new window containing System Configuration Utility. Click on the Startup tab and uncheck the following item.
(random characters).exe

7. Click Apply. You need to restart the computer.

AV Security Suite Removal Tool

To remove the threat from your computer completely, we suggest scanning it with Malwarebytes Anti-Malware. This is a free tool. Some Trojans will block the downloading of MBAM to avoid removal. If that happens, download the tool from a clean computer and rename the executable file before executing on the infected machine.

What to do next...