Overclock.net banner
1 - 20 of 65 Posts

·
Registered
Joined
·
201 Posts
Discussion Starter · #1 ·
So... this is a tricky one, so tricky, that I've been fingering and repeating various nasty phrases at my screen for the greater part of the night.

It all started out when I was visiting a pretty sketchy website, all of a sudden I see an icon that looks like this down on my taskbar:


And then all hell breaks loose, first, I get this warning:



Then, when I close that, I see a supposed 'Virus Scan' window appear saying I have a certain number of infections (obviously fake)


As you can see, it says it's the "Vista Antimalware 2010" (complete bull)

So, I go to my processes, I see an unusual one called 'ave.exe', I googled it, and it turns out it's a nasty virus that takes permissions away.

By now I've **** my pants with joy, as I can just locate the source file, and kill it.
But no.
It's not where it said it was, as I go to the 'ave.exe' properties in processes, it says its hidden, but the checkbox for unhiding it is grayed out



What the f*ck.

So, I then gave up on manually killing it, so I went to turn on AVG 8.0 Free to do a scan, I start AVG and guess what I get? A window saying "Vista Antimalware 2010" and a visit from the 'ave.exe' in my processes. Plus, AVG doesn't start up.

I can kill the process, thus disabling its various annoying pop-ups



So I killed the process, uninstalled avg, I'm going to go redownload it when...
I open up my firefox and it opens up a window saying "Vista Antimalware 2010" and another lovely visit from the 'ave.exe' in my processes.

It turns out that EVERY PROGRAM, WHENEVER I START IT UP, OPENS THIS WINDOW. AND the process.

Now I think to myself; Ohh f*ckin snap, this is a f*ckin tricky mother f*cker.

So, I know where this god forsaken .exe is.
It's hidden, I can't unhide it.
And I can't use any programs without this popping up.

Any web-surfing program takes me to this page where it says 'download Free Scan today (or something), and it won't let me go anywhere.

I've reinstalled all my web surfing programs, doesn't help, same problem.

Whenever I try to install an anti-virus program (any program, actually), this scanning window and process pops up, it doesn't let me install jack *****.

I'm running Flock in safe-mode right now, and this virus doesn't seem to catch me, so I can download thing on here. (and no, safe mode doesnt work on any other browser)

When I go to my firewall, windows firewall picks up this program and wants me to turn it on.

So, I've pretty much tried everything in my mind, including Malwarebits, this virus catches that and kills the installation.

I feel like I'm a subject of some all powerful step-mother, I feel like I'm being ****ted on by a robot, and I feel like the black dude in Law Abiding Citizen when the mayor says "We've got this guy in custody, and he's still killing people?!"

I would really appreciate some help on this one, if anyone is out there kind hearted enough to help me solve this problem, it would be greatly appreciated, +rep for any useful suggestions.

Ask away any questions you need.
Thanks

Eldin
 

·
Registered
Joined
·
1,242 Posts

·
Registered
Joined
·
201 Posts
Discussion Starter · #5 ·
Quote:

Originally Posted by WingedCow View Post
http://www.bleepingcomputer.com/viru...rus-vista-2010
Follow that link for complete removal instructions.
Oh btw, if it doesnt let you go to the link, you'll have to use a second computer. A second computer is required to remove the virus anyways.
Thanks for the guide WingedCow, this is exactly my problem, but it instructs me to download Malwarebytes, which I cannot because this danged virus kills it.

And Platinum, that's a very good idea, I do have another computer. I'll try that if nothing else works. +rep mate
 

·
Registered
Joined
·
2,023 Posts
sounds like you 'ave a nasty one there..............


Does the ave.exe begin if you boot in safe mode?

I think using a laptop, 2nd computer might be the best way forwards.

Do you have all software / installation discs?

Better safe than sorry, perhaps get all data from the HD (using a 2nd machine) and then clean install.
 

·
Registered
Joined
·
2,023 Posts

·
Premium Member
Joined
·
5,653 Posts
If you're able to, reboot into Safe Mode, and delete anything having to do with it. Then, while in Safe Mode, search your registry for anything associated to it as well. Then reboot normally and see what happens. You also might want to do a System Restore from Safe Mode as well, AFTER you remove any trace of that nasty bugger.
 

·
Registered
Joined
·
201 Posts
Discussion Starter · #12 ·
Quote:

Originally Posted by MooMoo View Post
I didnt read that guide, but did you try to kill it from processes? tried to run as safe mode and dl that malwarebytes?
I can kill it from the processes, but it comes back every time I run a program.

I've tried running my browsers in safe mode did not work, not my computer though, that might be a good idea.

I'll see if that works to download Malwarebytes.
 

·
Custom User Title
Joined
·
3,652 Posts
TRY THIS

Click here to download the rkill.com file. Once the download is complete, run it (run it on the desktop, and install Malwarebytes from desktop). The rkill.com file will make sure the the software will be closed for good so it does not interfere with the removal process.

Close all open applications and windows. You now should be on the desktop.

And continue onward and use Malwarebytes to detect the virus/malware.

This has worked for me.
 

·
Overclocker
Joined
·
867 Posts
booting it in safemode will stop it running and then download malwarebytes and do a complete scan. Someone above said plug the drive into another computer to copy data off of it dont do that. I had 3 computers corrupted with a similar vrus a while back trying to copy data from an infected drive
 

·
Registered
Joined
·
1,720 Posts
its prolly infected all your .exe files save all your pics and what not and do a good old reformat
 
  • Rep+
Reactions: wickedout

·
Premium Member
Joined
·
10,928 Posts
download mbam on another PC transfer Via USB key?
 

·
Overclocking
Joined
·
9,253 Posts
1 - 20 of 65 Posts
This is an older thread, you may not receive a response, and could be reviving an old thread. Please consider creating a new thread.
Top