How to remove Antivirus Suite

Thursday, April 1st, 2010 at 1:23 am
Home » Rogue Antispyware » Antivirus Suite

Antivirus Suite description

Antivirus Suite is a deceptive program designed in the same way as the infamous Antivirus Soft. The user interface of the program makes this fraud look legitimate, but the actions of AntivirusSuite tell the different story.

Antivirus Suite prevents victims from surfing the web by loading fabricated security notifications instead of web pages. Another set of counterfeit alerts is prepared for when user tries to run some real security program. And yet another bunch of alerts are meant to supposedly inform people about infections. Do not trust Anti-Virus Suite and do not hesitate to delete it.

Below are some examples of Antivirus Suite pop-ups. Keep in mind that each of them is fabricated.

Security Warning
Application cannot be executed. The file hijackthis.exe is infected. Do you want to activate your antivirus software now?

Windows Security alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan you computer. Your system might be at risk now.

Antivirus software alert
INFILTRATION ALERT
– Virus Attack
Your computer is being attacked by an internet virus. It could be a password-stealing attack, a trojan – dropper or similar.
Threat: Win32/Nuqel.E
Do you want block this attack?

Internet Explorer Warning – visiting this website may harm your computer!
Most likely causes:
* The website contains exploits that can launch a malicious code on your computer
* Suspicious network activity detected
* There might be an active spyware running on your computer
What you can try:
* Purchase for secure Internet surfing (recommended).
* Check your computer for viruses and malware.
* More information

Threat Information
Threat: Downloader.Win32.Delf.cgx
Risk level: Hight
Description: Category Trojan: This trojan downloads other files via Internet and launches them for execution on victim machine without the user’s knowledge or consent. It is a Windows PE EXE files. It is 48128 bytes in size. It is packed using PECompact. The unpacked file is approximately 131KB in size.

Antivirus Suite is a Rogue Antispyware software

How to manually remove Antivirus Suite

To remove Antivirus Suite spyware you must block Antivirus Suite sites, stop and remove processes, unregister DLL files, search and delete all other Antivirus Suite files and registry utility. Follow the Antivirus Suite detection and removal instructions below.

The most typical software removal method is to remove Antivirus Suite by using "Add or Remove Programs" service. However there may be hidden Antivirus Suite files, running processes and registries in your computer, so Antivirus Suite may recreate all other files after reboot.

Antivirus Suite manual removal instructions

Block Antivirus Suite sites:
avprotectsoft.com
antivirus-protectsoft.net
protectedlife.net
life-soft.net
antivirus-protectsoft.microsoft.com
avtivirus-fortress.com
antivirus-armature.com
av-armor.com
firm-av.com
avprocess.com
Read more how to block Antivirus Suite sites

Stop and remove Antivirus Suite processes:
tssd.exe Read more how to kill Antivirus Suite processes

Locate and delete Antivirus Suite registry entries:
HKEY_CURRENT_USER\Software\avsuite
HKEY_LOCAL_MACHINE\SOFTWARE\avsuite
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ""
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"
Read more how to delete Antivirus Suite registry entries
Download RegistryBooster 2010 to scan errors caused by Antivirus Suite

Detect and delete other Antivirus Suite files:
%UserProfile%\Local Settings\Application Data\\
%UserProfile%\Local Settings\Application Data\\tssd.exe

We strongly recommend you to use spyware remover to track Antivirus Suite and automaticaly remove Antivirus Suite processes, registries and files as well as other spyware threats.

Download does not start? Try a mirror download here

Tags: , ,

15 Responses to

Antivirus Suite

  1. Robbie

    thank you so much dude

    Reply

    Tim Reply:

    This virus will not allow any executables in normal mode and the removal tools do not work in safe mode. Is there a simple work around to get around this issue? I am running Vista.

    Reply

    Luciana Reply:

    Well, you can always use the manual removal guide posted above. This way you don’t need to run any programs.

    Reply

  2. Pat

    Worked like a champ, thank you for the information!!!!

    Reply

  3. dave

    umm this removal thing isnt working for me. maybe im using it wrong?

    Reply

  4. dave

    just want to see followups

    Reply

  5. mb

    Greetings,

    I am still receiving pop-ups after running MalwareBytes, removing all listed items above … I am not able to run Spyware Doctor however … in normal mode. And this means that I am still seeing the pop-ups Application cannot be executed etc and Windows Security alert and Infiltration Alert. Please HELP!

    Reply

    Luciana Reply:

    Run Spyware Doctor in a safe mode. If you deleted Antivirus Suite and the pop-ups are still there, there’s a big chance you got other malware onboard.

    Reply

  6. Andover man

    avsuite doesn’t install such obvious folders/files as to be named ‘avsuite’… maybe they did ages ago but they’ve long since learned to hide them.

    One suggestion I saw (albeit for future problems) is to install, say, Firefox to give you an alternative way to be able to load spybot, etc.

    Reply

    rdu Reply:

    Firefox is also prevented from accessing the internet with the same error messages.

    Reply

  7. Kami Teeter

    Thanks for sharing excellent informations. Your web site is so cool. I’m impressed by the details that you’ve on this blog. It reveals how nicely you understand this subject. Bookmarked this web page, will come back for more articles. You, my friend, ROCK! I found just the information I already searched everywhere and simply couldn’t come across. What a perfect web-site.

    Reply

Trackbacks

Leave a Reply

Download does not start? Try a mirror download here