Return to Forum

Переключиться на русский

Преключитися на українську

Introduction

This is a simplified, author's version of an article located on the forum.

 

A miner is a program that uses a computer's resources to mine cryptocurrency and is often installed as malware without the user's knowledge. It can cause serious damage to the system due to overheating of components, reduce its performance, and increase power consumption.

Description of Malware

It consists of a complex of logically related files. It practically does not mask itself in the system, relying more on aggressive methods of embedding in the system and resisting its removal.

Infection Paths

Installation of software, games, activators, free programs downloaded from unreliable sources. The most "beloved" distribution path is warez and non-licensed games. There have been incidents where the miner was distributed through Fitgirl repacks and/or on well-known torrent trackers. In general, it's a lottery for fans of "free software."

Common Symptoms

Removing the Miner and Restoring Computer Functionality

If you want to remove this malware and restore your computer's functionality, you can use the specially prepared AV block remover utility. This utility automatically finds and removes files and registry entries associated with this malware.

Description of the AV block remover Utility

AV block remover (AVbr) is a script based on the AVZ antivirus utility that allows you to remove a miner that blocks the installation and operation of antivirus software and access to antivirus sites. The script was created to remove a specific miner. It is updated daily.

Features of AV block remover

Instructions for Using AV block remover

  1. Download the utility archive from one of these links: AV block remover or from a mirror.
  2. Extract the archive to any folder on your computer (the executable file should be in a subfolder with a random name, not on the desktop or in the Downloads folder).
  3. Rename the file AVBR.exe (for example: AV_b_r.exe), or use a version with a random filename.
  4. Run the renamed AVBR.exe file as an administrator.
  5. Wait for the utility to finish; the computer will be automatically restarted.
  6. In the utility folder, a file named AV_block_remove_date-time.log will be created. If you seek help on the forum, attach it to your post.

After restarting, your computer should be free from blocking antivirus programs. You can check this by trying to run any antivirus program or scanner.

Since the malware author actively monitors cure forums and actively makes changes to their product, we cannot guarantee 100% successful removal. If the symptoms persist (or even if they are gone), we recommend seeking help in the malware removal section on the forum. Don't forget to prepare a log archive for system analysis and attach the AV_block_remove_date-time.log file (or files if there were multiple runs).