Scan Spyware on Twitter
Saturday, March 20, 2010

Bookmark and Share



advancedvirusremover


Type: rogue

Alias: advanced virus remover

Company: 2008 Advanced Virus Remover.

Description: AdvancedVirusRemover is a rogue anti-spyware. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats. AdvancedVirusRemover is also known as Advanced Virus Remover.

Malware Threat

advancedvirusremover

Directories

  • C:\Documents and Settings\user-account-name\Start Menu\Programs\AdvancedVirusRemover
  • C:\Program Files\AdvancedVirusRemover

Files

  • C:\Windows\System32\AVR09.exe
  • C:\Windows\System32\AVR10.exe
  • C:\Documents and Settings\user-account-name\Start Menu\AVR09.exe
  • C:\Documents and Settings\user-account-name\Start Menu\AdvancedVirusRemover.lnk
  • C:\Documents and Settings\user-account-name\Start Menu\Advanced Virus Remover.lnk
  • %quicklaunchdir%\AdvancedVirusRemover.lnk
  • %quicklaunchdir%\Advanced Virus Remover.lnk
  • *.exe (md5:b0ea874a21d18bf8540ca7...)
  • *.exe (md5:0fb47313365db737b7b664...)
  • C:\Documents and Settings\user-account-name\Desktop\AdvancedVirusRemover.lnk
  • C:\Documents and Settings\user-account-name\Desktop\Advanced Virus Remover.lnk
  • C:\Program Files\AdvancedVirusRemover\PAVRM.exe
  • C:\Program Files\AdvancedVirusRemover\Viruses.bdt
  • C:\Program Files\AdvancedVirusRemover\AdvancedVirusRemover.exe
  • C:\Program Files\AdvancedVirusRemover\AdvancedVirusRemover.lnk

Registry Keys

  • HKEY_CURRENT_USER\Software\AVR

Registry Values

  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AdvancedVirusRemover
  • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Advanced Virus Remover
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Advanced Virus Remover