advancedvirusremover
Type: rogue
Alias: advanced virus remover
Company: 2008 Advanced Virus Remover.
Description: AdvancedVirusRemover is a rogue anti-spyware. It may give exaggerated threat reports on the compromised computer then ask the user to purchase a registered version to remove those reported threats. AdvancedVirusRemover is also known as Advanced Virus Remover.

advancedvirusremover
Directories
- C:\Documents and Settings\user-account-name\Start Menu\Programs\AdvancedVirusRemover
- C:\Program Files\AdvancedVirusRemover
Files
- C:\Windows\System32\AVR09.exe
- C:\Windows\System32\AVR10.exe
- C:\Documents and Settings\user-account-name\Start Menu\AVR09.exe
- C:\Documents and Settings\user-account-name\Start Menu\AdvancedVirusRemover.lnk
- C:\Documents and Settings\user-account-name\Start Menu\Advanced Virus Remover.lnk
- %quicklaunchdir%\AdvancedVirusRemover.lnk
- %quicklaunchdir%\Advanced Virus Remover.lnk
- *.exe (md5:b0ea874a21d18bf8540ca7...)
- *.exe (md5:0fb47313365db737b7b664...)
- C:\Documents and Settings\user-account-name\Desktop\AdvancedVirusRemover.lnk
- C:\Documents and Settings\user-account-name\Desktop\Advanced Virus Remover.lnk
- C:\Program Files\AdvancedVirusRemover\PAVRM.exe
- C:\Program Files\AdvancedVirusRemover\Viruses.bdt
- C:\Program Files\AdvancedVirusRemover\AdvancedVirusRemover.exe
- C:\Program Files\AdvancedVirusRemover\AdvancedVirusRemover.lnk
Registry Keys
- HKEY_CURRENT_USER\Software\AVR
Registry Values
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AdvancedVirusRemover
- HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Advanced Virus Remover
- HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Advanced Virus Remover