what is “Advanced Virus Removal” ?
|
|
Recently, this Rogue Antispyware called “Advanced Virus Removal” has been spreading in the wild. It give user false indication that the PC is infected wanting them to purchase the full version.
while infected with “Advanced Virus Removal”, a Red x pop up Your computer is infected ! Windows has detected spyware infection!
when the spyware is running you will also see false security alerts appear from the Windows taskbar. These alerts range from warnings that you are infected to a remote computer hacking your computer. Just like the fake scan results, these alerts are just another attempt to scare you into thinking you are infected. The current text of one of these alerts is:
System warning!
Continue working in unprotected mode is very dangerous. Viruses can damage your confidential data and work on your computer. Click here to protect your computer.
application cannot be executed! the file is infected. please activite your anti-virus software.
Associated Advanced Virus Remover Files:
c:\windows\system32\winupdate.exe
c:\windows\system32\winhelper.dll
c:\windows\system32\AVR09.exe
c:\Program Files\AdvancedVirusRemover
c:\Program Files\AdvancedVirusRemover\PAVRM.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
%UserProfile%\Desktop\Advanced Virus Remover.lnk
%UserProfile%\Start Menu\Advanced Virus Remover.lnk
How to get rid of ”Advanced Virus Remover”
Step1: Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
- 1.If you are using Firefox, make sure that your download settings are as follows:
- Tools->Options->Main tab
- Set to "Always ask me where to Save the files".
- 2.During the download, rename Combofix to Combo-Fix as follows:


- 3.It is important you rename Combofix during the download, but not after.
- 4.Please do not rename Combofix to other names, but only to the one indicated.
Step 2:Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix
Step 3:Open notepad and copy/paste the text in the quotebox below into it:
or you can download the cfscript.text here
File::
c:\windows\system32\winupdate.exe
c:\windows\system32\winhelper.dll
c:\windows\system32\AVR09.exe
c:\Program Files\AdvancedVirusRemover\PAVRM.exe
Save this as CFScript.txt, in the same location as ComboFix.exe
Refering to the picture above, drag CFScript into ComboFix.exe
More for detail to using Combofix ,please visit here
Step4: download Regace for other Registry repairing, cleaning errors and problems to optimize your PC. It is an amazing program that I use!
Additional Steps to keep your PC Clear:
PS:using Malwarebytes'Anti-Malware to Remove other spyware ,if you don't have one,here it is :Malwarebytes' Anti-Malware Download Linkgood luck!







August 23, 2009 IP:67.166.50.254
Combo Fix was the ONLY solution I could find on the web that wasn’t an advertisement for another fee based malware product. Ad-aware couldn’t touch it, and Norton was absolutely useless. This malware installed while Norton was installed with a live update performed 30 minutes earlier.
Thank you so much for this fix. 38 minutes, start to finish including reboots.
Reply