Jun 26

Malware Analysis:

Being a seemingly normal website on the outside, Av-look.net is quite a fraud inside. It has a direct relation to the program known as AV Security Suite which is malicious software designed by the bad computer geeks who crave for some extra money during the world financial crisis. FYI: AV Security Suite has been quickly spreading through the cyber space infesting more and more computers daily. It attempts to scare its victims with the help of some deceitful popup alerts, fake scanners and browser hijacking. In terms of the latter aspect of AV Security Suite’s activity, Av-look.net is the instrument of its realization. If the rogue anti-spyware program manages to inject your computer, it will take control of your web browser by modifying its settings. This will enable the malware to determine the specificity of your Internet sessions further on. It means you will be suffering from browser diverts to Av-look.net now and again. So you will be visiting the corrupt site under consideration whether you want to or not. When on Av-look.net, you receive some instructions as to what you should do to have your PC properly protected against viruses and potential privacy issues that AV Security Suite had previously ‘found’ on your system. As you must have guessed, you will have to pay some money first. That’s precisely what Av-look.net is meant for. It is a payment processor domain for AV Security Suite scamware. So you are strongly advised to get rid of Av-look.net hijacker completely before it becomes a threat you can’t cope with.

Determine if your PC is infected with Av-look.net hijacker and affiliated malware (AV Security Suite scareware):

Av-look.net Screenshot:

Av-look.net Screenshot

AV Security Suite Counterfeit Warning Page Screenshot:

Av-look.net

How to remove Av-look.net hijacker manually:

To perform manual removal of Av-look.net hijacker and related rogue trialware, you should do the following:

Delete the following corrupt files:

  • %UserProfile%\Local Settings\Application Data\[random string]\
  • %UserProfile%\Local Settings\Application Data\\[random string]tssd.exe

Remove Av-look.net related registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]“
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random]“
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = “no”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” = “1″

Please, note that manual removal of Av-look.net hijacker is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Av-look.net Hijacker Removal Tool

Leave a Reply