Infected with AVE.EXE; Ran SAS; Now can't open .EXE files to continue

Discussion in 'Malware Help (A Specialist Will Reply)' started by txbajabill, Mar 16, 2010.

  1. txbajabill

    txbajabill Private E-2

    My main home computer has been infected with AVE.EXE, or the XP Defender Rogue AV (Trojan horse Agent_r.RD) today. I attempted to run your READ & RUN ME FIRST for Windows XP cleaning. I have downloaded all the necessary applications and began the SuperAntiSpyware sweep.

    It found 3 threats:

    Trojan.Agent/Gen-RogueAV
    C:\DOCUMENTS AND SETTINGS\CHRISTI\LOCAL SETTINGS\APPLICATION DATA\AVE.EXE
    C:\DOCUMENTS AND SETTINGS\CHRISTI\LOCAL SETTINGS\APPLICATION DATA\AVE.EXE
    C:\WINDOWS\Prefetch\AVE.EXE-1D3D510B.pf

    After prompting SAS to quarantine and remove the subject threats, SAS propmpted me to reboot the system to complete cleaning. I did so.

    Upon rebooting, I can no longer open any .EXE file application; windows prompts me to the dialog box "Open With," and asks me to choose the program I want to open this file? I assume my file associations have been compromised or corrupted?

    Please help, so I can continue with your cleaning procedure. Thanks!!!!
     
  2. txbajabill

    txbajabill Private E-2

    I fixed the .exe problem by:

    Tools > Folder Options > File Types > New Extension > Advanced > EXE associated to 'applications'

    It worked, and now I'm continuing the READ ME first cleaning guidelines. If my method is somehow not a good fix, feel free to let me know.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the logs when you are ready.
     
  4. txbajabill

    txbajabill Private E-2

    Ran everything except for RootRepeal, which hanged everytime I tried to run it....

    Everything seems ok now, but I'll go ahead and attach the logs anyway. :cool
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing that I would question are these three new files:
    C:\Documents and Settings\Christi\Local Settings\Application Data\7tg7er4h
    C:\Documents and Settings\All Users\Application Data\7tg7er4h
    C:\Documents and Settings\Christi\Templates\7tg7er4h

    If you don't I would delete them. ( You can right click / properties / and see if it is signed. )
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds