Log In · Register

 
ave.exe virus?, how to get rid of it?
creole
post Mar 18 2010, 10:15 AM
Post #1


Senior Member
*******

Group: Staff Alumni
Posts: 4,665
Joined: Aug 2008
Member No: 676,364



this worm/virus thing came out of NOWHERE when i was surfing through firefox.
i looked through google to see how to remove it. I LOOKED at this:
QUOTE
Changing .exe file associations:

Because you're having trouble running exe files (due to associations in the registry) you might actually have trouble accessing the registry to change the associations. TRY:

1. start > run > c:\windows\
2. right click regedit.exe > start (NOT OPEN)
3. In the registry go to HKEY_CLASSES_ROOT\.exe
4. Right Click (default) , modify
5. value = "exefile" (without the quotes & equal sign)
6. Reboot

As previously mentioned, this might not work because of permissions you've changed. You may want to restore permissions and follow the instructions below. Identifying the rootkit, then rebooting, then removing file associations is advisable.

Removing the Virus:

ave.exe is rootkit worm. It changes the association of exefiles within the registry and hijack all the programs. The first step is to remove the rootkit. If you download PREV free version and run it (I know you don't want to download - but this will at least confirm where the rootkit is AND ave.exe will NOT stop you from installing, like it does malware bytes). Subsequently, you will at least be able to find out where that rootkit file is. Likely it is c:\windows\DCEboot.exe.

1. Remove rootkit (c:\windows\DECBoot.exe)
2. Reboot
3. Open up the registry (start > run > regedit)
4. Search for ave.exe
5. Remove any entries for ave.exe (ave.exe ONLY)
6. In the registry go to HKEY_CLASSES_ROOT\.exe
7. Right Click (default) , modify
8. value = "exefile" (without the quotes & equal sign)
9. Reboot

This should give you control back over your machine. Then, if you can, install malware bytes (which you can't install while this virus is operating), and clean up anything remaining. A registry cleaner, might also be advisable. ave.exe, will no longer run.

I suspect, because you've changed permission on ave.exe, the association of .exe (step 7) which is likely executing ave.exe is causing the issue. Change that registry issue and your problems should go away.
Source(s):
Completed the above yesterday (hopefully, we're talking about the same virus). In my research, it looks like this virus has become more prevalent since March 15, so likely we're talking about the same thing.




What should I do?
 
 
Start new topic
Replies
heyo-captain-jac...
post Mar 22 2010, 03:36 PM
Post #2


/人◕‿‿◕人\
*******

Group: Official Member
Posts: 8,283
Joined: Dec 2007
Member No: 602,927



System restore only gets rid of the most primitive viruses. If you really want to do anything, you'll have to reformat.

If you're lucky, you'll be able to edit the registry.
 
creole
post Mar 22 2010, 09:13 PM
Post #3


Senior Member
*******

Group: Staff Alumni
Posts: 4,665
Joined: Aug 2008
Member No: 676,364



QUOTE(itanium @ Mar 22 2010, 12:36 PM) *
If you really want to do anything, you'll have to reformat.

If you're lucky, you'll be able to edit the registry.


can't find the disc to reformat. and i already edited the registry. ;)
 

Posts in this topic


Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members: