• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove ave.exe malware

Myantispyware team March 19, 2010    

Ave.exe is the main component of each program from fake antispyware group, which includes the following programs: Total Vista Security, Vista Security Tool 2010, XP Security Tool 2010, XP Antimalware 2010, XP Defender Pro , Total XP Security, Vista Smart Security 2010, Vista Defender Pro, Vista Antimalware 2010, XP Smart Security 2010. Ave.exe infiltrate computers through the use of trojans. Once the trojan is installed and started, it will download ave.exe and save it to %AppData% folder (%AppData% is the C:\Document and Settings\[your username]\Application Data). After that, the same trojan will configure ave.exe to run automatically when you start any program by changing the file associations with “.exe” extension.

When ave.exe is started, it will imitate a system scan. Once finished, the malware will state that your computer is infected with trojans, adware or malware and that you should purchase the full version of the program to remove these infections. Important to know, the malicious program is unable to find the infections, as will not protect you from possible infection in the future. So, do not trust the scan results, simply ignore them.

While ave.exe is running, it can block execution of other programs as an attempt to scare you into thinking that your computer in danger. The program will also flood your computer with nag screens, fake security alerts and notifications from your Windows taskbar. A few examples:

Virus intrusion!
Your computer security is risk. Spyware, worm and trojans
were detected in the background. Prevent data corruption and
credit card information theft. Safeguard your system and
perform a free security scan now.

Threat detected!
Security alert! Your computer was found to be infected with
privacy-threatening software. Private data may get stolen
and system damage may be severe. Recover your PC from
the infection right now, perform a security scan.

However, all of these alerts, warnings and notifications are fake and like false scan results supposed to scare you into purchasing so-called “full” version of the malicious program. You should ignore all of them!

As you can see ave.exe is very dangerous and can lead to a complete paralysis of your computer, as well as leakage of your personal data in the hands of the authors of the malicious program. Need as quickly as possible to check your computer and remove all found components of this malware. Use the removal guide below to remove ave.exe and any associated malware from your computer for free.

Use the following instructions to remove ave.exe

Step 1. Fix “.exe” file associations.

Method 1

Click Start, Run. Type command and press Enter. Type notepad and press Enter.
Notepad opens. Copy all the text below into Notepad.

Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Classes\.exe]
[-HKEY_CURRENT_USER\Software\Classes\secfile]
[-HKEY_CLASSES_ROOT\secfile]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command]

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

Save this as fix.reg to your Desktop (remember to select Save as file type: All files in Notepad.)
Double Click fix.reg and click YES for confirm.
Reboot your computer.

Method 2

Click Start, Run. Type command and press Enter. Type notepad and press Enter.
Notepad opens. Copy all the text below into Notepad.

[Version]
Signature="$Chicago$"
Provider=Myantispyware.com

[DefaultInstall]
DelReg=regsec
AddReg=regsec1

[regsec]
HKCU, Software\Classes\.exe
HKCU, Software\Classes\secfile
HKCR, secfile
HKCR, .exe\shell\open\command

[regsec1]
HKCR, exefile\shell\open\command,,,"""%1"" %*"
HKCR, .exe,,,"exefile"
HKCR, .exe,"Content Type",,"application/x-msdownload"

Save this as fix.inf to your Desktop (remember to select Save as file type: All files in Notepad.)
Right click to fix.inf and select Install. Reboot your computer.

Step 2. Remove ave.exe associated malware.

Download MalwareBytes Anti-malware (MBAM). Once downloaded, close all programs and windows on your computer.

Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MalwareBytes Anti-malware onto your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to “Update Malwarebytes’ Anti-Malware” and Launch “Malwarebytes’ Anti-Malware”. Then click Finish.

MalwareBytes Anti-malware will now automatically start and you will see a message stating that you should update the program before performing a scan. If an update is found, it will download and install the latest version.

As MalwareBytes Anti-malware will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main menu. You will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Make sure the “Perform quick scan” option is selected and then click on the Scan button to start scanning your computer for ave.exe infection. This procedure can take some time, so please be patient.

When the scan is finished a message box will appear that it has completed scanning successfully. Click OK. Now click “Show Results”. You will see a list of infected items similar as shown below.
Note: list of infected items may be different than what is shown in the image below.


Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove ave.exe. MalwareBytes Anti-malware will now remove all of associated ave.exe files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Ave.exe malware creates the following files and folders

%AppData%\ave.exe

Ave.exe malware creates the following registry keys and values

HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CURRENT_USER\Software\Classes\.exe\shell
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command
HKEY_CURRENT_USER\Software\Classes\secfile
HKEY_CURRENT_USER\Software\Classes\secfile\shell
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\start
HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = “”%AppData%\ave.exe” /START “%1″ %*”
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = “”%1″ %*”
HKEY_CURRENT_USER\Software\Classes\.exe | @ = “secfile”
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = “application/x-msdownload”
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | @ = “”%AppData%\ave.exe” /START “%1″ %*”
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | IsolatedCommand = “”%1″ %*”

Malware removal Rogue Anti Spyware

 Previous Post

How to remove Vista Antimalware 2010 (Uninstall instructions)

Next Post 

How to remove User Protection (Uninstall instructions)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

159 Comments

  1. Patrik
    ― April 7, 2010 - 7:20 am  Reply

    Jaqs, scan your computer with SuperAntispyware, or open a new topic in our Spyware removal forum. I will check your PC.

  2. Patrik
    ― April 7, 2010 - 7:27 am  Reply

    it just brings up the open with box everytime i try and open up a program.

    Pablo, try repeat first step. If it does not help, than ask for help in our Spyware removal forum.

  3. cain
    ― April 7, 2010 - 1:45 pm  Reply

    the question remains how does this infect when a system and it’s software are all patched up to date, including third party apps like acrobat, flash, … which the hackers have been using lately. what is the open window that this virus is coming from, that’s the frustrating part, sometimes you are helpless when they are using an exploit to infect and there’s no patch for that exploit. you will get infected no matter what protection you have.

    Thanks, Cain

  4. Shawn
    ― April 8, 2010 - 2:23 am  Reply

    Well, I’ve been hacking at this virus all night, and while I seem to have gotten rid of the ave.exe instances, my regedit is still locked. I looked in task manager and ave.exe is not running, but I still can’t get regedit going for the life of me. To answer your question in advance as to how I was able to initially clear the registry stuff up, I used a boot CD with regedit- I still can’t seem to get it unlocked on the system normally however! Help!

  5. Patrik
    ― April 8, 2010 - 11:32 am  Reply

    Shawn, you have tried run Malwarebytes ? It should fix your trouble.

  6. Aneeth
    ― April 8, 2010 - 5:24 pm  Reply

    Hey Patrik,

    Thanks so much!! The two easy steps worked and everything looks to be normal again. However I don’t want to be lulled into thinking everything is fine when its not…

    When I ran the Anti-malware, it only brought up 1 infected file: the original ave.exe file. Should I be concerned that it didn’t bring up any (possibly) corrupted registry files?

    Just a concern!
    Thanks,
    Aneeth

  7. Patrik
    ― April 9, 2010 - 11:34 am  Reply

    Aneeth, its ok.

  8. Mike
    ― April 9, 2010 - 4:01 pm  Reply

    Thanks! When all I had was my iPhone to search the web, you got me going again.

    It didn’t completely remove everything, but it was a big help. VMA came back after a day or two…

    First it installed VMA.EXE in a documents directory, then changed the iexplore registry entry to point to that. At some point it also changed the .EXE registry entry and pointed it to VMA.EXE. When I deleted VMA.EXE, no more programs worked – I was sweating bullets until I got the .EXE file association fixed, which isn’t that difficult, but I was just guessing at it.

    Once I got the .EXE association working again(open My Computer, then Tools | Folder Options | File Association | File Types | New, enter EXE and set to “application”), I went through the registry (twice!) to make sure it wasn’t still there.

    What pisses me off is that Norton 360 fails to catch this, and then they want to charge $150 to clean the virus from your computer (and break things along the way, like the hibernate function). They charge you $20-30 for the virus protection, and use it to market their virus removal service (which they charge a lot more for). I think Symantec has a “new virus team” secretly hidden in Bulgaria that releases new viruses every few months…

  9. Coolbhu
    ― April 9, 2010 - 7:54 pm  Reply

    Fantastic instructions. followed it and got rid of XP defender pro 🙂

  10. filled with glee
    ― April 11, 2010 - 12:17 am  Reply

    Thank you so much. you made my day. I cannot express the utter extacy I am experiencing at the liberation of my soul from the foul clutches of the beasts called hackers.ymmd

  11. Precise_1993
    ― April 11, 2010 - 11:03 am  Reply

    Work like a charm!
    I have Vista Home Premium SP2

  12. happy person
    ― April 11, 2010 - 5:19 pm  Reply

    Thanks a ton! I used method 1 and it works fine as a quick solution. I hope nothing comes back. Either way, we need more people out there like yourself. Thank you

  13. Angela
    ― April 12, 2010 - 9:02 am  Reply

    I used method 2 to remove get rid of ave.exe…I then installed the malwarebytes…and though it shows it has installed on my computer…it won’t open to do a scan…I’ve tried renaming the file…I’ve even tried redownloading it…what am I doing wrong…can someone please help me!!
    Thanks!

  14. christian
    ― April 12, 2010 - 11:22 am  Reply

    hi patrick,

    as for method #1, I get an error stating the file is not a registry script, “you can only import binary files from within the registry editor.” suggestions?

    thanks

  15. Aurelio Marsili
    ― April 12, 2010 - 2:22 pm  Reply

    Thanks for your instructions, it has very useful !!!
    Greetings from Italy.
    Bye.

  16. rob
    ― April 12, 2010 - 6:14 pm  Reply

    Thank you for saving my laptop from certain death! Method one worked perfect and the malwarebytes removed 8 infected files associated with ave.exe. its nice to know there’s good genuine advice still out there. Thanks again!

  17. Rufus Xavier
    ― April 12, 2010 - 10:37 pm  Reply

    Thanks babe! It really cleaned up my machine so that it is up and running. Back to the porn sites.

  18. Patrik
    ― April 12, 2010 - 10:55 pm  Reply

    Angela, boot your computer in Safe mode, after that try perform a scan once again. If it does not help, then open a new topic in our Spyware removal forum. I will help you.

  19. Patrik
    ― April 12, 2010 - 10:57 pm  Reply

    Christian, try method 2.

  20. Kurtis
    ― April 13, 2010 - 2:53 pm  Reply

    I fixed internet explorer by my self but fire fox was stubborn as all hell lol. That fixed firefox, thanks. Having damnest time trying to figure out where else i missed removing =\ Thanks again

  21. Intr0
    ― April 13, 2010 - 5:13 pm  Reply

    Thanks so much. I’m a pretty advanced user and luckily I’m on XP so this was not as bad for me as some others. The second I saw the scan starting I knew it was a fake and end-tasked it, and went and deleted the culpret.

    The .exe extension redefinition was a 1st for me. But my pc seemed to find a way around it somehow. When I got the message \cannot open firefox no program is associated with the extension .exe\, I used firefox to \open\ firefox. and then after a couple of error messages it opened about 3 firefox windows. The same worked for me with notepad (open notepad with notepad).

    After that I just followed the steps above with the .reg file.

    Thanks again!

  22. Intr0
    ― April 13, 2010 - 5:18 pm  Reply

    Christian, I got that message too (using fix 1). But I forgot to include this “Windows Registry Editor Version 5.00” at the top of the text file. Try it again, with that at the top of your code. If you’re on XP I bet that’s the problem.

  23. Jason
    ― April 13, 2010 - 6:01 pm  Reply

    Thank you so much man! This helped!

  24. Leah
    ― April 13, 2010 - 8:09 pm  Reply

    I want to say thanks!!! Method 2 works!!! Before I wasn’t able to install run ANYTHING and could only copy/paste links in to a messed up Firefox, but now I can run all my diagnostic programs. Again i give my thanks!!!!

  25. Adam
    ― April 13, 2010 - 10:10 pm  Reply

    THIS IS AMAZING. Thank you soo much I don’t think you understand how much of a GENIUS you are! x

  26. Joey
    ― April 14, 2010 - 6:43 am  Reply

    Thanks mate. Tried Method 1 after many previous attempts to clear and it work first time.

    Pox on the author of this Trojan.

  27. Bruce Pierre
    ― April 14, 2010 - 10:04 am  Reply

    Thanks for the valuable info. on system recovery after vma.exe infection. Worked a treat. Thanks again.

  28. Altec Lansing
    ― April 14, 2010 - 8:06 pm  Reply

    I had run into this little nasty before, and it was a royal pain. Ended up doing a system restore from my Toshiba CD. This time around, I thought “Oh no, not again!” But your clear, step-by-step directions fixed things up in short order. No restore needed. Worked like a charm! A LOT less grief for me. You have my sincere, heartfelt thanks.

  29. SHARON
    ― April 14, 2010 - 8:34 pm  Reply

    I DON’T KNOW WHO YOU ARE THAT PUT THIS FIX ON HERE BUT…YOU ARE THE MAN (OR WOMAN) THANKS ALOT!!

  30. Altec Lansing
    ― April 14, 2010 - 10:19 pm  Reply

    Incidentally, here’s a recent Reuters article, “Inside A Global Cybercrime Ring”, that tells the story behind the folks who put this little bugger together:

    http://www.reuters.com/article/idUSTRE62N29T20100324?type=technologyNews

« Previous 1 2 3 4 5 6 Next »

Leave a Reply Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

How to reset Google Chrome settings to default
search.yahoo.com
Remove Search.yahoo.com Redirect Virus ✅ (Quick & Easy) in 2024
How to remove pop-up ads [Chrome, Firefox, IE, Opera, Edge]
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide

Recent Guides

How to remove Vista Antimalware 2010 (Uninstall instructions)
How to remove Vista Defender Pro (Removal guide)
How to remove Security Guard (Removal instructions)
How to remove Vista Smart Security 2010 (Removal guide)
How to remove Total XP Security

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.