SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics > PC Hardware/Software forum
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 03-17-10, 09:52 AM   #1
SteamWake
Rear Admiral
 
Join Date: Mar 2005
Posts: 13,224
Downloads: 5
Uploads: 0
Default ave.exe

Check your processes and if this rascal is in there do everything in your power to get rid of it.

This is one of the most insidious pieces of malware I have ever come accross.

If you simply delete the ave.exe file you will lose all associations for all programs and not be able to run anything

It is a root kit virus "Rouge Antivirus" that pops up stern warning about how your machine is a seething pit of viruses and spyware. It is of course bull **** and just trying to scare you into buying their 'protection'.

It looks very 'offical' and very much like a windows operating system warning.

I'm running malwarebytes on the afflicted machine right now but I will probably have to go do some manual registry edits.
__________________
Follow the progress of Mr. Mulligan : http://www.subsim.com/radioroom/showthread.php?t=147648
SteamWake is offline   Reply With Quote
Old 03-17-10, 10:07 AM   #2
krashkart
Navy Seal
 
Join Date: Jan 2010
Posts: 5,292
Downloads: 100
Uploads: 0


Default

Ouch! Thanks for the heads-up, SteamWake.
__________________
sent from my fingertips using a cheap keyboard
krashkart is offline   Reply With Quote
Old 03-17-10, 12:12 PM   #3
SteamWake
Rear Admiral
 
Join Date: Mar 2005
Posts: 13,224
Downloads: 5
Uploads: 0
Default

Malwarebytes (MBT) got rid of it and its registry shenanigans.

You have to play a bit of cat and mouse with ave.exe with the task manager stopping its process a few times while getting MBT installed.

I saved some grief by downloading MBT on a clean machine then copying the install file for MBT to a disk (or a thumbdrive). You can then load MBT on the afflicted machine with a lot less fuss. You will still have to joust with ave.exe as it starts when explorer is started to open MBT's install file.

Oh this was on a Vista machine.
__________________
Follow the progress of Mr. Mulligan : http://www.subsim.com/radioroom/showthread.php?t=147648
SteamWake is offline   Reply With Quote
Old 03-17-10, 03:29 PM   #4
stabiz
Silent Hunter
 
Join Date: Jun 2006
Location: Norway
Posts: 4,224
Downloads: 14
Uploads: 0
Default

Knock on wood, I have not had any (unintentional) crap on my computer since 2004 (yeah, i really remember that one). Maybe because I reinstall Windows at least twice a year.

Good to hear you killed the bugger.
__________________
stabiz is offline   Reply With Quote
Old 03-17-10, 05:31 PM   #5
Arclight
Navy Seal
 
Join Date: Jun 2008
Location: Land of windmills, tulips, wooden shoes and cheese. Lots of cheese.
Posts: 8,467
Downloads: 53
Uploads: 10
Default

Think I tangled with that one once, 1.5 year ago or so.

Took me longer to restore all my shortcuts than to kill the bugger.
__________________

Contritium praecedit superbia.
Arclight is offline   Reply With Quote
Old 03-17-10, 07:13 PM   #6
kiwi_2005
Eternal Patrol
 
Join Date: May 2004
Location: Aeoteroa
Posts: 7,382
Downloads: 223
Uploads: 1
Default

I just fixed a PC last night that had that PC security virus, i mention while back on here of a pc i fixed that was riddled with trogans 300+ all up, this one was the same except far less Trojans and in desperation they must of got conned into thinking by installing PC security scanner you can grab online they would be safe - little did they know that pc security you can download for free is a scam that installs a trogan and disables your desktop in a way where you have to right-click and choose in the menu 'Open' if you want to run a program, will also give the user a hard time using the internet with timeouts every couple of minutes, you also cannot delete PC scanner in add/remove it wont let you instead numerous windows popup trying to get you to pay and if you check the install folder there's only 1 file (PC.exe) in their that is a pain to delete - keeps coming back on restart.


I think im getting popular these people i help are from the poor side of town they can't afford to pay the local tech $65 an hour so they bring their sick pcs to me and i just charge them $20 for the whole job. Scan pc get rid of viruses, download and install Avast free edition, and ccleaner, defrag hdd, update anything that needs updating like windows updates and double check that the pc is clean before they pick it up.
__________________
RIP kiwi_2005



Those who can't laugh at themselves leave the job to others.



kiwi_2005 is offline   Reply With Quote
Old 03-18-10, 09:08 AM   #7
SteamWake
Rear Admiral
 
Join Date: Mar 2005
Posts: 13,224
Downloads: 5
Uploads: 0
Default

Quote:
Originally Posted by kiwi_2005 View Post
I just fixed a PC last night that had that PC security virus, i mention while back on here of a pc i fixed that was riddled with trogans 300+ all up, this one was the same except far less Trojans and in desperation they must of got conned into thinking by installing PC security scanner you can grab online they would be safe - little did they know that pc security you can download for free is a scam that installs a trogan and disables your desktop in a way where you have to right-click and choose in the menu 'Open' if you want to run a program, will also give the user a hard time using the internet with timeouts every couple of minutes, you also cannot delete PC scanner in add/remove it wont let you instead numerous windows popup trying to get you to pay and if you check the install folder there's only 1 file (PC.exe) in their that is a pain to delete - keeps coming back on restart.


I think im getting popular these people i help are from the poor side of town they can't afford to pay the local tech $65 an hour so they bring their sick pcs to me and i just charge them $20 for the whole job. Scan pc get rid of viruses, download and install Avast free edition, and ccleaner, defrag hdd, update anything that needs updating like windows updates and double check that the pc is clean before they pick it up.

Heh I got two or three that could use a good cleaning... I'lll be right over
__________________
Follow the progress of Mr. Mulligan : http://www.subsim.com/radioroom/showthread.php?t=147648
SteamWake is offline   Reply With Quote
Old 03-18-10, 03:10 PM   #8
AVGWarhawk
Lucky Jack
 
AVGWarhawk's Avatar
 
Join Date: Jun 2005
Location: In a 1954 Buick.
Posts: 27,343
Downloads: 90
Uploads: 0


Default

My daughters computer go this. It comes in two names AVE.EXE or just AV.EXE. We got both. Yes, shutting it off in task manager works. This exe file is found in your prefetch folder. You can delete it there. There is a small .exe file that you can put on a thumb drive or burn to DVD that will make the registry entries to shut this muther-fer off. I forget the name of it. Anway, I used that the first time. The second time it I just deleted the exe file in prefetch and ran Malwarebytes. I think I will purchase MWB so it protects real time. My daughter got the damn thing twice while looking at Facebook. Facebook is a fun place for virus makers to get their jollies in placing viruses on links and crap.
__________________
“You're painfully alive in a drugged and dying culture.”
― Richard Yates, Revolutionary Road
AVGWarhawk is offline   Reply With Quote
Old 03-26-10, 09:16 PM   #9
kiwi_2005
Eternal Patrol
 
Join Date: May 2004
Location: Aeoteroa
Posts: 7,382
Downloads: 223
Uploads: 1
Default

Quote:
Originally Posted by AVGWarhawk View Post
Facebook is a fun place for virus makers to get their jollies in placing viruses on links and crap.
Why you should not invite friends to My Space...
__________________
RIP kiwi_2005



Those who can't laugh at themselves leave the job to others.



kiwi_2005 is offline   Reply With Quote
Old 03-27-10, 07:40 AM   #10
AVGWarhawk
Lucky Jack
 
AVGWarhawk's Avatar
 
Join Date: Jun 2005
Location: In a 1954 Buick.
Posts: 27,343
Downloads: 90
Uploads: 0


Default

That is about what it is Kiwi! People take such a simple friendly site and completely destroy it with a virus or dumb groups to join.
__________________
“You're painfully alive in a drugged and dying culture.”
― Richard Yates, Revolutionary Road
AVGWarhawk is offline   Reply With Quote
Old 03-27-10, 11:12 AM   #11
Task Force
Rear Admiral
 
Join Date: Jul 2008
Location: SPACE!!!!
Posts: 10,142
Downloads: 85
Uploads: 0
Default

Lol, no issues here, ever infact... (*knocks on wood, guess particalboard counts as wood)
__________________
Task Force industries "Taking control of the world, one mind at a time"
Task Force is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 01:50 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright © 1995- 2024 Subsim®
"Subsim" is a registered trademark, all rights reserved.