CLICK FOR FULL PAGE


I recently encountered the above trojan while visiting Piratebay. OK, I know it was naughty visiting that site, but the trojan may turn up elsewhere so I shall describe how I got around it.
AV.EXE is a false virus checker, possibly with a trojan payload. When infected it warns you that you have a virus and runs a bogus virus check, also putting a little icon in your taskbar. It also intercepts most of your executable associations. It probably asks for money as well, but I never got as far as reading anything, deleting the web page immediately it appeared.

You can use alt+control+delete to run the task manager and stop av.exe but in doing so you lose those associations and most of your programs no longer work, including the restore function!
After picking up this nasty I was left without Internet Explorer as well as the Windows restore function.

Fortunately Windows explorer worked. I entered google in Windows explorer which called IE directly. Now I was online, I did a google search for 'restore associations'. This turned up
http://www.dougknox.com/xp/file_assoc.htm
I downloaded the one for executables. I've now got a copy on my desktop in case it happens again.
Clicking on the file unzipped it (fortunately the zip association was still intact but there's an entry for zips in case you lose that one)
I clicked on the file inside the zip which entered the associations into the registry, getting back the all important 'restore' function.
A Windows restore got me back my system.
I then did a windows search for av.exe, deleting its entry in the documents folder and also the prefetch folder. I also did a regedit search for av.exe in case there were any "run" commands there but that was clean.

Thanks for that, Eccles.  :thumbs

At least we can be prepared now. It's getting to be a dangerous place out there!

I've just switched to Miscrosoft Security Essentials because my old standby AVG's latest version was putting a major drag on my system.

MSE has good reviews, and is free, but if you try it be sure you only download it from Microsoft -- seems there are fakes out there!

Oh, and your copy of windows has to be "valid".

Well mine is valid.... ;)

I too have moved on from AVG because its latest was a pain.  I now use Avast! but that also seems to slow things down at times.  Thanks for the heads-up Hags :thumbs

Oh I shall look at that. I switched from AVG to Avast because AVG was becoming a pain, but when Avast updates (frequently) it too tends to take over a bit.



Hosted by Arvixe