Home Malware Programs Rogue Anti-Virus Programs Antivirus Suite 2010

Antivirus Suite 2010

Posted: November 2, 2010

Antivirus Suite 2010 is a fake security application. Antivirus Suite 2010 will create a start-up registry entry and block a victim's access to certain security programs and websites. Then the trial version of Antivirus Suite 2010 will display fake scan reports, pop-up warnings and security alerts in order to convince the victim that his/her system is infected and the only solution is to purchase its so-called full version. Of course this is a scam and users should ignore all the fake security warnings displayed by Antivirus Suite 2010. Additionally, the full version of Antivirus Suite 2010 does not exist therefore users should not waste their time and money ordering this rogueware.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 [random]tssd.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"HKEY_CURRENT_USER\Software\avsuiteHKEY_LOCAL_MACHINE\SOFTWARE\avsuiteHKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesAttachments "SaveZoneInformation" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"
Loading...