Recently, a number of computer users are being infected by an application referred to as the Green AV virus. For those who want to know what is “green av” , this article aims to provide details about this program. It also gives information on Green AV removal.
What is Green AV?
Green AV Virus, also called Green Antivirus 2009 or green-av, is a kind of rogue antivirus program that tells users that it gives a portion of every Green AV software sold to environmental causes. While the prospect of doing something good for the environment by purchasing the green a v is good and enticing, it is not recommended that you buy the green av program. It is unfortunate but this Green AV software is a bogus antivirus application and users who purchase this AV Green virus are at risk of exposing their credit card information to the fraudster developers of windows green av.
Green AV Causes Unsolicited Pop Ups and Warnings
The green av antivirus will cause a stream of pop ups in the computer that result in slower computer performance. These green virus 2009 pop ups often show bogus scans and alerts and urging the user to buy the av green software. The Green av virus windows can also be very annoying to users who may be disturbed by the av green virus pop ups and warnings. If your PC is infected with the green-av malware, you can prevent further damage to your computer by removing green av ASAP.
How do I Remove Green AV?
Green AV removal can be done without having to purchase the fake green av spyware antivirus application. Thanks to Milton for providing a working solution to manually remove green av virus.
How to Remove Green AV Manually:
Log into Windows Safe Mode. To get to safe mode reboot your computer and start pressing the F8 key repeatedly until the Safe Mode options screen appears. You want Safe Mode which is the first option, not Safe Mode with Networking.
If any user id’s how up select the Administrator, if not don’t worry about it. Once safe mode is up Click on My Computer and open your C: drive. Click on Tools/Folder Options/View. Then click on Show Hidden Files and Folders.
Green AV is normally located by navigating to the following directories: C:\Program Files\Documents and Settings\All Users\Application Data\GAV\gav.exe
1. Delete gav.exe which is the executable module for the virus
2. Delete mgrdll.exe this is the messenger for gav that keeps sending you the messges and popups
3. Delete the folder GAV (just hit your back arrow one time to get back to folder Application Data then you will be able to see and delete folder GAV
4. Right Click on your Recycle Bin and select Empty Recycle Bin or Double Click on your Recycle Bin and select Empty Recycle BinNow reboot your system and you should be rid of the pesky virus
Green AV Remove Option:
One of the free tools that you can use as a green AV remover is Malwarebytes. More information on how to use this application as a green av removal tool can be found in this link:
Malwarebites:
malware removal free tool
Comments below also provide other options in removing the Green AV virus.
Related Post:
Control Center Virus
Eco AV virus
Related posts:
- Fake Green Av disguises as security software with a cause If you are receiving alerts from a so called green antivirus, be advised that the Greenantivirus 2009 does not provide protection to your computer and people who have purchased this program may put their credit card information at risk. This...
- Cyber Protection Center Virus Removal This fake antivirus protection software is not your cyber protection against viruses. This article provides information on how to remove cyber antivirus fake av. ...
- Uninstall Green AV Antivirus The number of rogue anti virus protection applications is increasing this year and among these fake pc security programs is the green av anti virus. Like most other rogue softwares, green av pc security is advertised through unsolicited and oftentimes...
- Privacy Center Virus PrivacyCenter av is a bogus antivirus antispam that causes your system to display system scans that popup to tell you there are system threats in your system. These PrivacyCenter popups will then prompt you to purchase Privacy Center online protection....
- Virus Doctor Removal Virus Doctor Online Protection You will have a hard time using your PC if your computer screen is constantly bombarded by virus doctor online protection pop ups. What is a virus doctor anyway? Is it a legitimate computer virus software?...
- Windows Smart Security Virus Removal Windows Smart Security Virus is a new form of computer infection that displays fake systems scans and alert pop ups to deceive people into purchasing a rogue anti virus protection software called the Windows Smart Security antivirus. If you need...
- Control Center Virus Control Center Antivirus may not be a legitimate antivirus protection software as you may think. Read on and learn about the controlcenter virus and how to remove it from your pc....
August 30th, 2009 at 10:08 pm
I finally found the registry file folder containing GAV and gra registry files. Deleted them all and the bogus green av link pages no longer show up! Good riddance!
August 30th, 2009 at 9:17 pm
I had this garbage show up on my PC yesterday after logging in. I could find no gav.exe programs running, but I did locate the same bogus program named gra.exe in a folder of the same name located in the same area as the gav.exe file Milton and others have noted already. I was able to delete the folder and its contents (gra.exe, uninstall.exe, mgrdll.exe, etc.). The pop ups for the bogus Green AV are gone, but the saga isn’t over yet! Arrggg! I’m still getting a substitute web page that sporadically replaces a web page I’m actually trying to go to. This bogus web page comes at random and includes this text on a gray background: “Reported Attack Site! This web site has been reported as an attack site and has been blocked based on your security preferences.
Attack sites try to install programs that steal privat information, use your computer to attack others, or demadge your system. Some attack sites intentionally distribute harmfull software, but many are compromised without the knowledge or permission of their owners.” (the 3 misspelled words shown are as they appeared. Apparently the jack a$$ who wrote that page can’t spell either!). Two hot buttons are also shown “Get me out of here” and “How can i be protected?” and another link “Resolve this warning”. All three are links that direct you to the following web address: http://green-av-pro.com/presale.html
I haven’t found what’s causing this bogus web page to come up, but I guess that has to do with the registry files and I haven’t located the one causing this. Anyone have help for fixing that area?
August 30th, 2009 at 9:16 am
My aunt called me today and she has this infection. She is running Vista. I did what Milton did, except I did not enter Safe Mode. Instead, I went to and then and then typed in msconfig in the empty field. The window that opens will have various tabs at the top, click on the one that says Startup. You will see a list of items that are starting up with your computer and each item will have a box that is checked. Most items in this list will have actual names, while the virus will have a line of numbers as a name. I found three of these items and they were together in the list. I unchecked the boxes for these three items, then clicked then and was prompted to reboot. I rebooted then did as Milton did except I deleted the entire folder in the directory. (While you are in msconfig where you uncheck the boxes, you will also be able to see the exact directory where the folder is located!) The folder is hidden, so follow Milton on making this folder viewable.
August 30th, 2009 at 7:06 am
Thank you so much Milton… I have been trying to fix my step-mothers computer for the last 5 hrs and finally found this site and did everything you said and it worked… I couldn’t thank you enough!!!
August 30th, 2009 at 7:04 am
I used Milton’s instruction- thank you very much. But the name has changed since he posted. The files I deleted were mradll.exe, and gra.exe.
August 30th, 2009 at 5:09 am
I’ve tried to download 3 of the different progs to get this stupid thing off and it didn’t work. So I tried to do as Milton wrote to do, but I found when I got to: C:\Program Files\Documents and Settings\All Users\Application Data\GAV\gav.exe
I don’t have the docs and setting, so I had to go to Prog Data\ GRA
From there I was able to delete:
MRADLL
Viruses.dat
WSAV
WSGA05
But I wasn’t able to delete GRA, it told me I need permission. I also tried to just delete the GRA folder, but that also told me I need permission.
Anyone know know the heck to get this darn thing off my computer.
Thanks
August 27th, 2009 at 3:42 am
Thanks Milton, your instructions worked perfectly!
August 26th, 2009 at 5:16 am
I helped a friend take care of this, I used Malware Bytes, and it caught the problem, and was able to get rid of it, however it had hijacked internet explorer making it unable download any apps. It also caused problems with windows installer, I tried to install AVG and Spybot’s Teatimer but they would not allow me to install and update correctly thus they did not work. I finally had to restore the PC to a point prior to the appearance of GAV. Luckally there was such a point on this PC.
August 26th, 2009 at 4:10 am
Miltons solution is not working for me, I am trying. I cant get it into safe mode. Also, there is no Tools/Options/View button. I cannot access the Hidden Folders section. Spybot and Malawarebites is not picking up this Green AV. I tried to look for it by going to Program Files but my computer wont let me access the Document and Settings tab. I am really frustrated, someone please help!
August 25th, 2009 at 12:02 pm
Milton you are an angel! For anyone battling with the Green AV virus… try Milton’s resolution — IT WORKS!!!