WARNING: "Advanced Virus Removal" is a virus itself!

PC Software. Anything to do with PC Games & software!

WARNING: "Advanced Virus Removal" is a virus itself!

Postby JBaymore » Mon Nov 16, 2009 8:25 am

Warning here for everyone:

SOMEHOW.... I just got a "driveby" installation of this AWFUL piece of malware / virus.  (Search the net..... it is a BAD persistent one.)  It fakes that your computer is stuffed full of viruses and trojans.  Then it tries to get you to buy this great new package.  But it is totally BOGUS and a ripoff attempt. 

DO NOT PAY FOR IT!!!!!!!!!!!!

I had to go into the registry multiple times, download some utilities, download Malwarebytes freeware spyware killer, manually delete tons of crap, use the "run" option to start stuff it was blocking form working, run WinXP in safe mode, and finally use an old restore point to get this thing killed. 

It starts restricting your access to your own computer as you try to stop it.  VERY devious piece of software.  And the people who wrote it are reading the online tactics being posted ....and writing blocks as fast as people are suggesting them.

It took me a full day of literally full time work to get the D$#@ thing off my PC!  And I have active antivirus and spyware blockers running.  First time something like this EVER got thru the "walls".

Beware.

Malwarebytes remover seem to work for the last of it (after I did a lot of manual work), but the November 2010 version of the virus now will not let you install that remover once you are infected.  THAT took some gymnastics to get around!!!!!!   

It even eventually blocks stuff like Google searches!  It disables TaskManager so you can't kill processes.  It infects Internet Explorer and Firefox.  It hides multiple copies in all sorts of places.  It is all over the Registry.  It installs folders everywhere.  It is a real bugger!

So get that abovementioned piece of FREE software on your machine NOW....before you catch this one.  And likel soon it won't just block the installation of the program... it'll block it working.  So this is just an interim solution.

best,

.....................john
Image ImageIntel i7 960 quad 3.2G LGA 1366, Asus P6X58D Premium, 750W Corsair, 6 gig 1600 DDR3, Spinpoint 1TB 720
User avatar
JBaymore
Global Moderator
Global Moderator
 
Posts: 10020
Joined: Sat May 24, 2003 9:15 am
Location: New Hampshire

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby The Snake 87 » Mon Nov 16, 2009 3:29 pm

Thanks for the heads up, I will definitely keep this in mind!
Phoenix Coyotes fan in Michigan. Yeeeaah booii.
User avatar
The Snake 87
2nd Lieutenant
2nd Lieutenant
 
Posts: 145
Joined: Tue Nov 03, 2009 7:12 pm
Location: Michigan

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby SubZer0 » Mon Nov 16, 2009 6:06 pm

Thanks for the heads up, I will definitely keep this in mind!

Wow... that sounds like a real B*tch, John. Glad you were able to get that thing taken care of... I could only imagine the damage it would have caused on your sim and the time it would have taken to reinstall all of that and your simpit :o

I've been using Malwarebytes since Nick recommended... great little program that is. ;)
[center][img]http://www.simviation.com/phpupload/uploads/1369006030.jpg[/img][/center]
User avatar
SubZer0
Major
Major
 
Posts: 3722
Joined: Fri May 04, 2007 9:29 pm
Location: KLNA

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby a1 » Mon Nov 16, 2009 6:47 pm

Thanks for the heads up. :)
Image
790i : QX9650 : 4Gb DDR3 : GeForce 8800 GTX : 1 WD Raptor : 1 WD VelociRaptor 150
User avatar
a1
Lieutenant Colonel
Lieutenant Colonel
 
Posts: 7608
Joined: Thu Jan 04, 2007 9:16 pm

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby jaime » Tue Dec 01, 2009 1:28 pm

I wonder if I had this at one point before reformatting my system...well not reformatting compleatly but rebuilding the file system...


cus my PC slowly started BSODing and other things like that...and then installer programs (well some times) wouldnt work correctly...hmmmm...


I use malwarebytes, spywareblaster and a few other utilities for antivirus (don't plan on mentioning what incase the idiots who like being shit heads and doing shit like this do happen to read this)...


oh and for the shit head who do this to others and happen to read threads like this...be warned your being watched...by who...you won't know...
one of the starters of the burner pandemic
jaime
2nd Lieutenant
2nd Lieutenant
 
Posts: 247
Joined: Mon Nov 16, 2009 10:15 pm

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby flaminghotsauce » Thu Dec 03, 2009 11:07 am

This is hysterical to me. I never get anything like this. I am coming up on two years with no anti-virus, and only the wireless router as a firewall. Behind this firewall I've been running two Vista machines, one is now W7, several XP machines, a few Linux machines, and there are still a couple of windows 2000 machines.
I strongly urge Linux for surfing, online banking etc. as it's HARD to have an infection, intruder, etc. get hold of the machinery. But of course my gaming is on Windows....

I routinely work on other's machines and remove Norton and McCafee AV as I view them as viruses. I tell people to not go to questionable sites, buy a router, and not run AV. I have not had anyone yet complain that this simple formula hasn't worked. It all gets down to what you do while online.
There are sites out there that will spawn windows that look just like XP or VISTA windows that warn of stuff on your computer. It's especially funny when surfing on a Linux distribution to see an XP window pop up!
flaminghotsauce
2nd Lieutenant
2nd Lieutenant
 
Posts: 181
Joined: Tue May 04, 2004 6:59 pm

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby machineman9 » Thu Dec 03, 2009 4:27 pm

Any software popping up claiming you have viruses/asking you to pay, is usually a virus itself. They have been going around for years. If you didn't get the program yourself, then it is going to be fake. I did not install 'Antivirus 2009', so when it pops up telling me I have a virus, it is clearly a fake as I never installed it on my computer (if it was legit, which it isn't).

Old tricks, but they still catch people out. Also, read, to the letter, what a lot of those pop ups say. Usually there are quite a few typing mistakes which is another sign that they are fake.
User avatar
machineman9
Major
Major
 
Posts: 4816
Joined: Fri Sep 17, 2004 9:05 am

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby ShaneG_old » Fri Dec 04, 2009 7:34 am

Some of these pop-ups are designed to install the virus to your system, if you click the 'Red X'  to close the window.

If one pops up, it's best to close the window from the task bar.
ShaneG_old
Lieutenant Colonel
Lieutenant Colonel
 
Posts: 9700
Joined: Tue Mar 11, 2008 11:52 am

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby JBaymore » Sun Dec 06, 2009 1:59 pm

[quote]Some of these pop-ups are designed to install the virus to your system, if you click the 'Red X'
Image ImageIntel i7 960 quad 3.2G LGA 1366, Asus P6X58D Premium, 750W Corsair, 6 gig 1600 DDR3, Spinpoint 1TB 720
User avatar
JBaymore
Global Moderator
Global Moderator
 
Posts: 10020
Joined: Sat May 24, 2003 9:15 am
Location: New Hampshire

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby Steve M » Sun Dec 06, 2009 2:36 pm

I have had a couple of these buggers in past years. I used to push the power button on the case and shut down immediatly. Last spring that didnt even work. I just tossed my hard drive and formatted a new one. Nothing I had in my arsenal wanted to recognize what it was. Whatever it was it moved through the system slowly over three days, corrupting one program after another, untill finally I couldn't boot anymore. I even disconnected the ethernet cable at the first sign of trouble.
Image
User avatar
Steve M
Major
Major
 
Posts: 4765
Joined: Sun Aug 31, 2008 1:02 pm
Location: Cambridge On.

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby machineman9 » Sun Dec 06, 2009 9:10 pm

I have had a couple of these buggers in past years. I used to push the power button on the case and shut down immediatly. Last spring that didnt even work. I just tossed my hard drive and formatted a new one. Nothing I had in my arsenal wanted to recognize what it was. Whatever it was it moved through the system slowly over three days, corrupting one program after another, untill finally I couldn't boot anymore. I even disconnected the ethernet cable at the first sign of trouble.

Destruction is not the best means of recovering.

Booting into safe mode and running a variety of anti-virus and other clean-up programs should clear up most of those issues as it will stop the virus from activating/hiding/moving around/infecting, so then you can remove it.
Last edited by machineman9 on Sun Dec 06, 2009 9:11 pm, edited 1 time in total.
User avatar
machineman9
Major
Major
 
Posts: 4816
Joined: Fri Sep 17, 2004 9:05 am

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby Steve M » Mon Dec 07, 2009 5:50 pm

I have had a couple of these buggers in past years. I used to push the power button on the case and shut down immediatly. Last spring that didnt even work. I just tossed my hard drive and formatted a new one. Nothing I had in my arsenal wanted to recognize what it was. Whatever it was it moved through the system slowly over three days, corrupting one program after another, untill finally I couldn't boot anymore. I even disconnected the ethernet cable at the first sign of trouble.

Destruction is not the best means of recovering.

Booting into safe mode and running a variety of anti-virus and other clean-up programs should clear up most of those issues as it will stop the virus from activating/hiding/moving around/infecting, so then you can remove it.



I know, but I couldn't boot in safe mode at all. Turned out to be a blessing in disguise, I got rid of a bunch of junk I didn't need.
Image
User avatar
Steve M
Major
Major
 
Posts: 4765
Joined: Sun Aug 31, 2008 1:02 pm
Location: Cambridge On.

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby jaime » Sat Dec 12, 2009 8:30 pm

This is hysterical to me. I never get anything like this. I am coming up on two years with no anti-virus, and only the wireless router as a firewall. Behind this firewall I've been running two Vista machines, one is now W7, several XP machines, a few Linux machines, and there are still a couple of windows 2000 machines.
I strongly urge Linux for surfing, online banking etc. as it's HARD to have an infection, intruder, etc. get hold of the machinery. But of course my gaming is on Windows....

I routinely work on other's machines and remove Norton and McCafee AV as I view them as viruses. I tell people to not go to questionable sites, buy a router, and not run AV. I have not had anyone yet complain that this simple formula hasn't worked. It all gets down to what you do while online.
There are sites out there that will spawn windows that look just like XP or VISTA windows that warn of stuff on your computer. It's especially funny when surfing on a Linux distribution to see an XP window pop up!



Same here, Though I do use AV...just not as much...hehe


Any software popping up claiming you have viruses/asking you to pay, is usually a virus itself. They have been going around for years. If you didn't get the program yourself, then it is going to be fake. I did not install 'Antivirus 2009', so when it pops up telling me I have a virus, it is clearly a fake as I never installed it on my computer (if it was legit, which it isn't).

Old tricks, but they still catch people out. Also, read, to the letter, what a lot of those pop ups say. Usually there are quite a few typing mistakes which is another sign that they are fake.


I actually purposly went to a site that I knew had one of these things on it just so I could grab the source HTML code...interesting code and well....it was a good laugh...love them...sad there are people who would do some thing as dumb as this but hey could be worse...


*mockingly* OOOOO You're infected, buy our software which is a virus, it will protect you....



YEA RIIIIIIIIIIGHT...Ill just "borrow" your code and see how it could be used to stop idiots from doing stuff like this....or better yet educate every one I can....that's a better idea....LOL!!!


I have had a couple of these buggers in past years. I used to push the power button on the case and shut down immediatly. Last spring that didnt even work. I just tossed my hard drive and formatted a new one. Nothing I had in my arsenal wanted to recognize what it was. Whatever it was it moved through the system slowly over three days, corrupting one program after another, untill finally I couldn't boot anymore. I even disconnected the ethernet cable at the first sign of trouble.

Destruction is not the best means of recovering.

Booting into safe mode and running a variety of anti-virus and other clean-up programs should clear up most of those issues as it will stop the virus from activating/hiding/moving around/infecting, so then you can remove it.



I know, but I couldn't boot in safe mode at all. Turned out to be a blessing in disguise, I got rid of a bunch of junk I didn't need.


Safe mode (if you can get to it) is good for that IF you can get your anti virus and what not updated to the most current defitions with out causeing the intruder to activate...

as for the HDD...hope you took a hammer to it before tossing it...cus I love people who just toss the old hard drives out and don't take a hammer to them...hehe



Oh and for those of you who are unfortunate enough to get this evil...sick...low down POS "program" installed on your PC...keep reading...the following will be helpful and DO IT QUICKLY (as in first time you notice it find it and kill it with vengeance...)

Advanced Virus Remover manual removal:

Kill processes:
AVR.exe

HELP:
how to kill malicious processes: Ctrl + Alt + Del, then locate the process you need to kill and right click on that process, then hit END PROCESS TREE

Delete registry values:
HKEY_CURRENT_USER\software\avr lastd
HKEY_CURRENT_USER\software\avr lastscan
HKEY_CURRENT_USER\software\avr lastvfc
HKEY_CURRENT_USER\software\avr virlist
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run advanced virus remover
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run advanced virus remover
HKEY_CURRENT_USER\Software\AVR
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU

Delete files:
AVR.exe Advanced Virus Remover.lnk

HELP:
how to remove harmful files: use a drive eraser utility like eraser (allows you to erase and over write files)

Delete directories:
C:\Program Files\AdvancedVirusRemover


again if this pops up on your screen, close it and immeadiatly go on a hunt for its parts...
Last edited by jaime on Sat Dec 12, 2009 8:38 pm, edited 1 time in total.
one of the starters of the burner pandemic
jaime
2nd Lieutenant
2nd Lieutenant
 
Posts: 247
Joined: Mon Nov 16, 2009 10:15 pm

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby JBaymore » Sat Dec 12, 2009 9:33 pm

jamie,

The newer versions of this one shut off your access to using Task Manager.
Last edited by JBaymore on Sat Dec 12, 2009 9:34 pm, edited 1 time in total.
Image ImageIntel i7 960 quad 3.2G LGA 1366, Asus P6X58D Premium, 750W Corsair, 6 gig 1600 DDR3, Spinpoint 1TB 720
User avatar
JBaymore
Global Moderator
Global Moderator
 
Posts: 10020
Joined: Sat May 24, 2003 9:15 am
Location: New Hampshire

Re: WARNING: "Advanced Virus Removal" is a virus itself!

Postby jaime » Sun Dec 13, 2009 6:02 pm

indeed, thats true....as for fixes its sad they are stupid enough they are doing stuff like that to try and make people think they are infected and all that...

thats why when ever I get a call like this at my work I educate the person about this stuff so they don't get all scared (plus they use macs not PCs)
one of the starters of the burner pandemic
jaime
2nd Lieutenant
2nd Lieutenant
 
Posts: 247
Joined: Mon Nov 16, 2009 10:15 pm

Next

Return to Computer Games & Software

Who is online

Users browsing this forum: No registered users and 544 guests