View Full Version : av.exe ~Warning~
Hey guys, my laptop was recently infected with a nasty virus name av.exe.
Just thought i should come here and warn you guys about this particular virus, its given me a world of problems and iv had to pass my laptop off to someone i know to get it manually removed.
Now, this virus on my laptop claimed to be an antivirus software along the lines of 'windows 2010', which would automatically start itself up once your computer was turned on.
Not only did this virus pretend to be an antivirus software, it also disabled my internet labling it as a 'threat', my current antivirus software was disabled (everytime i clicked to open my scanner, it opened up the virus's version of the antivirus software).
The real pain was, i managed to locate the virus's exe file and i deleted it, only to find after i deleted it none of my programs would work (everytime i clicked a program, the computer would ask me which program i would like to opent he program in), so i was forced to put the main exe file back onto my computer.
Now im no computer expert, but i know how to get rid of most viruses manually from a computer, this one however had altered something in my registry. I did a little research and found out how to undo whatever changes it made, but i was put off actually doing anything about it because one wrong move and my computer would end up even more messed up then it was before.
Just posting all this up to remind you guys to keep your guard up, this one is nasty and will get through AVG and other free anti-virus software.
Jubei Kibagami
02-17-2010, 04:06 PM
Thanks for that post Khia. My brother recently had this virus on his computer **blames FB and MyS** and he actually got rid of it from his HD but it had already monkeyed around with the registry like you said and disabled all the free versions of antivirus software.
After the "new version" of virus software was downloaded it would scan the whole comp giving it access to all the files, and when it finished it asked "Would you like to clean up the viruses?" If no was clicked it would pop up that several self restoring Trojans were infecting the comp.
If yes was clicked, it would pull up IE ***the worst browser ever, so useless even a caveman gets pissed*** and randomly pop-up adult websites that were infected as well.
We actually did what you did and found that a certain exe file had been changed, but we could do nothing about it since he didn't have the original factory disks so the only other option was to do a full system restore to the earliest save known. All this did was take the computer back to factory settings, but like you said all the paths to programs and documents could not be opened.
He finally took it to a CitiBank IT professional and re-installed the comp disks needed for a full system reload, he lost all his files and didn't have a chance to back them up.
I had this exact same problem about a week ago. Luckily my trusty team of nerds (or rather, one woman army) was on hand to help me out. I was sent some software to remove it. Computer randomly shut itself down and since then everything has been awesomesauce.
juabulb
02-18-2010, 01:41 AM
I had it too. I think it was because of Bleach Wiki's ads, because every time an ad was loading and froze the site, av.exe would pop up. I had to do a system recovery and my files were removed.
Tempest Winds
02-19-2010, 03:26 AM
Wow, this many people on BA got the same virus!? :eek:
And apparently Bleach Wiki is a suspect... good thing I never go there. But WOW, that's really crazy. I'll have to be on the lookout for it.
Jubei Kibagami
02-19-2010, 05:05 AM
Wow, this many people on BA got the same virus!? :eek:
And apparently Bleach Wiki is a suspect... good thing I never go there. But WOW, that's really crazy. I'll have to be on the lookout for it.
Hahaha, and there will still be people who go to Bleach Wiki for "concrete" changeable information to argue with.
I heard that most of the people who get this virus go to social networking sites. A virus, in the digital social networking arena is the equivalent of real world terrorism and should be met with a firing squad.
Rockman-EXE
02-19-2010, 07:07 PM
Wow...thanks so much for posting this! I was hit with the virus yesterday, I think it was along the lines of "Vista Antivirus 2010". And this morning, I experienced the problem when it asks what program you want to use to open whatever I tried to use. I'm guessing I'll need to back everything important up now, right? =o= Perfect...
Woot_etc
02-24-2010, 11:39 PM
yep, its what i thought. malware is circulating around on popular websites. i recently got this (two days ago) just from sitting on thepiratebay website home. from what i hear, if you set your pop up blockers to high, it should help prevent it. oh, and check this out:
http://www.technibble.com/rkill-repair-tool-of-the-week/
Heres instructions:
Download Rkill.exe
Disconnect your internet. (ex. unplug it from your pc)
open up the command prompt, (usually in the accessories folder in start menu)
Run RKILL (NOTE: If you dont know how to navigate through folders in the command prompt, just drag the rkill file into it and press enter.)
wait about a minute. (your folders, explorer windows and programs should close, then your desktop should reappear, and you will get a notepad window.)
this has temporarely purged the malware from your system processes. the files are still there!
now run antivirus software (Prefferably Malware bytes)
then delete your temp files.
if you do not remove the bad files, they will run again after restart.
if this worked, after reboot, you shouldnt see that antivirus 2010 again.
I have also seen a worse version of this. it got so bad, it modified the system files, so when antivirus software removed them, it made the windows installation unbootable.
be careful and get rid of it ASAP. if you dont, it WILL get worse!
denan27
02-26-2010, 10:29 AM
Assuming you somehow got this virus through some Java script auto installing itself into your computer. An example of this is when a search engine such as google starts redirecting your searches to things such as search2.google.com
Then when you check your processes in task manager there would be rubbish such as JUCHECK.exe which you'd have to delete - quite a hassel.
I'm going to use the quote
"The best form of protection is prevention"
Now if your on Morzilla FireFox, theres are two brilliant add-ons you should consider,
These are:
1) No Script (https://addons.mozilla.org/en-US/firefox/addon/722)
2) Ad Block Plus (https://addons.mozilla.org/en-US/firefox/addon/1865)
Mess with settings of these so annoying things such as popups from No Script don't show.
Page not loading? Just click icon and say allow bleachanime.org, then disable particular ads that come from certain URLs etc.
----
These are really useful tools in preventing most forms of java based pests.
However, its not fool proof!
d_razor
03-28-2010, 02:05 PM
The best thing to do is to get Win7 long before you get those viruses, windows 7 is like vista's beauty and xp's "usability and stability" and then put on steroids....most petty viruses wont even affect windows 7, or it will have safeguards in place to prevent such fondling around in the registry by viruses....But no matter how many anti-viruses you have or how safe you try to be, if you have internet or any indirect link to it (media downloads etc) you will sooner or later get a virus...
WingZeroUnit01
04-30-2010, 01:11 AM
I had it too. I think it was because of Bleach Wiki's ads, because every time an ad was loading and froze the site, av.exe would pop up. I had to do a system recovery and my files were removed.
Malewarebytes anti maleware is the best to get rid of fake antivirus software and unwanted things. and no i am not advertising it lol
Belgevain
05-01-2010, 04:43 PM
I find Spybot Search and Destroy works well, it monitors registry files, and prevents them from being changed without permission (Can be annoying during installations, but its a price I'm willing to pay)
davidmorgen19
06-03-2010, 03:38 AM
Use avest anti virus. install it update and run Boot scan then restart pc.
after restart avest scan without loading a win xp that means virus deleted when not active. and after scan your pc working fine.
vBulletin® v3.7.1, Copyright ©2000-2010, Jelsoft Enterprises Ltd.