Green AV Remove | Remove Green Antivirus 2009
I’m seeing a lot of searches for how to remove the rogue antivirus green AV. It looks like it’s the latest flavor of the minute in the rogue security application crowd. My usual path for removing a rogue antivirus or antispyware application is the same as any other malware, try to get other malware removal software on the system (such as malware bytes antimalware or super antispyware, AVG, spybot etc.) and get them running scans to eliminate it. (Make sure to get updates for the software first.) (Virus Removal Toolkit for links.) If that approach doesn’t get you anywhere then it’s time to find the name of the program file that’s running. It appears that with Green AV to remove it from the running processes you need to kill of the process called gav.exe. You may need to reboot into safe mode, then you can rename (or just delete) the offending program executable…. here’s a suggestion for you.
After booting into safe mode delete or rename C:\Program Files\Documents and Settings\All Users\Application Data\GAV\gav.exe since that’s the main program executable.
Look for mgrdll.exe and delete it and also take out the \Application Data\GAV folder.
From what I see, for some users they may find GRA instead of GAV for the filename.
Green antivirus 2009 may also go under the name greenav2009.exe in the process manager. Look for anything similar or related to this name if you can’t find one of the items specifically mentioned.
Also if it is named differently than above look to delete or rename the files that you find acting as green av to successfully remove it.
After you have a “foothold” of sorts and have made some progress against a pest like this continue to make sure you get respected malware removal like malware bytes antimalware, sypbot, AVG, etc. on the system and update them, run full scans and test with a few reboots to make sure the baddie doesn’t resurface.
–update–
I’m also now seeing a lot of people referring to this as the Green AV virus – which is fitting as these rogue security applications are as bad as a virus (if not worse than some.)
One path to getting things working again may be to use System Restore to roll back to a a system setting date before Green AV was installed on the system. If you are able to do that, go ahead and download the free tools as mentioned to make sure you clean any remaining files off the hard drive. System restore will not remove all the files from your drive associated with green AV, but it will roll back the registry and other applications that launch at boot back to that point in time which should give you a chance to disinfect.