@
666HiddenMaster666
@
ChimiBang
Yup, I know how to get rid of that.
Step one, stop the process by pushing:
ALT+CTRL+DEL
Find: ave.exe in the Processes and shut it down.
Remove the registry entries:
HKEY_CURRENT_USER\Software\Classes\secfile\shell\o pen\command | IsolatedCommand = ""%1? %*"
HKEY_CURRENT_USER\Software\Classes\secfile\shell\o pen\command | @ = ""%AppData%\ave.exe" /START "%1? %*"
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = "application/x-msdownload"
HKEY_CURRENT_USER\Software\Classes\.exe | @ = "secfile"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open \command | IsolatedCommand = ""%1? %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open \command | @ = ""%AppData%\ave.exe" /START "%1? %*"
HKEY_CURRENT_USER\Software\Classes\secfile\shell\s tart\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\s tart
HKEY_CURRENT_USER\Software\Classes\secfile\shell\r unas\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\r unas
HKEY_CURRENT_USER\Software\Classes\secfile\shell\o pen\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\o pen
HKEY_CURRENT_USER\Software\Classes\secfile\shell
HKEY_CURRENT_USER\Software\Classes\secfile\Default Icon
HKEY_CURRENT_USER\Software\Classes\secfile
HKEY_CURRENT_USER\Software\Classes\.exe\shell\star t\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\star t
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runa s\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runa s
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open \command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
HKEY_CURRENT_USER\Software\Classes\.exe\shell
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIco n
HKEY_CURRENT_USER\Software\Classes\.exe
Finally: Find and delete this: %AppData%\ave.exe