Monday, April 12, 2010

Firm AV


Firm-av.comalso called as the Firm AV website is a fake security site that promotes the rogue anti-virus sofware Antivirus suite.

Why firm-av is a scam
It is already known that this Security suite antivirus is fake virus and spyware protection software. Fake antiviruses are characterized by bogus system scans, constant popups and browser hijacking, which may explain why the firm av virus redirect you to the rogue http:// firm-av.com site.

Do not even think about paying for the firm-av.com license key that may be offered to you. The fake antivirus protection software that firm-av com offers will not get rid of viruses, trojans and other malwares in your computer.

Firm av removal
To get get rid of the firm av virus, you must remove the following firm av files and registry entries. You may also want to read the post on Antivirus suite infection removal.



* %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe
* %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]ftav.exe
* %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]tssd.exe
* HKEY_LOCAL_MACHINE\SOFTWARE\avsuite
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1?
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555?
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1?
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = “no”
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” = “1?
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”[random string].exe”
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”[random string].exe”

0 comments:

 
design by suckmylolly.com