PDA

View Full Version : Interesting anti-rogue anti-virus program...



13_CBS
2010-03-15, 09:30 PM
Recently, my computer was infected with ave.exe, which seems to be similar to av.exe. Long story short, they're both viruses/malware programs that, once they infect your computer, will try to further infect your computer with fake images of your computer getting attacked by viruses. The best (worst?) ones are the ones that are tricky to distinguish from legitimate anti-virus stuff.

Ave.exe seemed to be particularly dangerous: I immediately downloaded stuff like Avast and AVG, but they were apparently rendered useless by ave.exe--AVG just kinda sat around doing nothing, while everytime Avast tried to do something, ave.exe would pop up again and prevent anything from happening.

Luckily, I found something called Killbox (http://killbox.net/). Basically, it Kills With Fire and deletes programs and files from your computer.

How to use:

1) Download, install, and open Killbox. It's only 90.5 Kilobytes.

2) Open Task Manager.

3) Right click on ave.exe and go to "Properties".

4) When the "Properties" box is open, highlight everything under "Location", and Copy it (Ctrl + V).

5) Paste the text into the white text box found in Killbox (under "Full Path of File to Delete").

6) At the end of the Location address, add the name of the file you want to delete. For example, if my ave.exe virus was located in C:\users\admin\AppData\Local, then I'd simply add "ave.exe" to the end. The result would look like this:

C:\users\admin\AppData\Local\ave.exe

7) Press the little red button at the far right of the Killbox window: this is the "Delete File" button.

Wait for a bit, and you're done! You might want to run any other anti-virus programs again just in case, but so far ave.exe seems to be gone from my computer.

Edit: As I've just found out, killing ave.exe does not automatically uninstall spyware that it might have put into computer. :smallannoyed: I'm going to try Search and Destroy and see if that works.

Surfing HalfOrc
2010-03-15, 10:26 PM
I prefer Malwarebytes for that type of problem, followed by Spybot Search and Destroy. Avast is my primary AV, and I keep a few others handy on thumbdrives.

Flickerdart
2010-03-15, 10:29 PM
There's a similar program called Unlocker that kills all processes using a file and then deletes it.

13_CBS
2010-03-15, 10:29 PM
I prefer Malwarebytes for that type of problem, followed by Spybot Search and Destroy. Avast is my primary AV, and I keep a few others handy on thumbdrives.

That may be true, but it seems that ave.exe is capable of, essentially, preventing such programs from working. Killbox gives you an alternative to such methods.