Executable files won't open or run

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by malibumurray, Aug 14, 2011.

  1. malibumurray

    malibumurray Private E-2

    The problem started about two weeks ago after my daughter says "all I did was plug in my camera and download pictures"...anyway help me if you can, I do not know what else to do and I've tried a multitude of stuff hopefully you'll be able to sort through this for me.

    I have win/xp on a dell optiplex and I have a d-link wireless router and here lately my executable files will not open, I get a file association error and I can't get on the internet. I cannot run in any safe mode option it stops at the mup driver and then I get a blue screen and have to reboot. During the logon process I could have sworn I saw two command windows open and run something which made me think it was malware or a virus. I downloaded a regfix tool from cnet and can open exe files until I reboot and then I'm back at square one. I am using my laptop for posting and downloading tools. I have the professional version of SuperAntiSpyware, I ran mbam, combofix, mgtools, rootrepeal, defogger, and hijack this, panda (which did not find anything) the logs are attached. During running one of the applications (don't remember which one) it said that the microsoft recovery console needed to be installed and I agreed and it downloaded other than that, everything else ran without issue. Thank you Geeks, I have much respect for your talents!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then please attach the C:\MGLogs.zip :)
     
  3. malibumurray

    malibumurray Private E-2

    The post attachment maximum is 4 and I was not certain if I could post again without being reprimanded. Will do today as soon as I make it in from the office which should be around 6:15 cst don't know why I didn't think to bring the flash drive with me. Thank you so much for your speedly reply Kestrel and I look forward to any advice you might have for me in ridding my machine of this nusance
     
  4. malibumurray

    malibumurray Private E-2

    Attached is the MGlogs, I don't know if I'm tired or frustrated because I couldn't find the log and had to run it again fighting malware and viruses is such a draining task and I'm grateful for your assistance.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Running from: E:\ComboFix.exe <--- Move Combofix to your DESKTOP before we continue, please.

    Uninstall the below softwares:
    • Java(TM) 6 Update 26
    • Ask Toolbar
    • iWon Prize Machine

    What are you using for antivirus??

    Well it is very outdated looking at the log.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    c:\windows\003116_.tmp
    C:\Documents and Settings\Elaine\Templates\wpjr38s40b7by47dqdymyn0by7e11rvcp
    c:\windows\SET17E.tmp
    c:\windows\SET172.tmp
    c:\windows\SET16F.tmp
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. malibumurray

    malibumurray Private E-2

    Ok,

    IWon prize machine is a remnant that will not go away, error message says "could not locate INF file" along with the location

    Anti Virus - I do not have one, don't really know which is the best to get, maybe you can recommend one.

    Professional version of AntiSpyWare - don't know what to say, since this computer problem, I manually have to update the definitions because the issue I'm having the program version is 4.34.1000 and if this is not the latest version, I need to see about getting a refund if it is old and outdated.

    ComboFix - ran its course deleted files and rebooted on its own. When the system came back up, I thought it was going to be normal, until I tried to run TDSSkiller and of course I got open with... message for which I ran the regfix I got off CNET on my flash drive and was able to continue

    All other programs ran their course with no issues and the logs are attached.

    I'm still having a problem with the executable files and I can't get on the internet. I can update superantispyware and malwarebytes, but I can't get explorer to open....nothing happens.

    System restore is accessible only for today's date, I cannot boot in safemode

    windows update gives me the error message "windows cannot find '(null)' make sure you typed...."

    I definitely appreciate all your efforts in helping me rectify the problem. I'm glad you all are around to help and assist because it seems like such a daunting task to me, maybe now would be a good excuse to update to Win 7 what do you think about that, will I still have the same issues?
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.

    I use the free version of Avast!
    Release History for SUPERAntiSpyware Professional.

    According to your logs you have version 4.34.1000. I don't know when you purchased it though. I would say your subscription ran out.

    What executables exactly? Which programs? What error if any do you get when you try to connect to the internet?

    Run the below by double clicking on it. It will run very quickly.

    C:\MGtools\FixFa.bat



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Documents and Settings\Elaine\Templates\wpjr38s40b7by47dqdymyn0by7e11rvcp
    c:\windows\003116_.tmp
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. malibumurray

    malibumurray Private E-2

    Thank you again for the reply.

    Revo uninstaller
    I installed and tried to have it uninstall and this is the error message I got “C:\progra˜1\IWon\IWonBar\1.bin\IWonbar.dll The specified module could not be found” and I just ok’d and followed the prompts, thereafter it seems to have removed it.

    First error message….Windows cannot open file cmd.exe, second error message…..reader_el.exe

    Avast – will give it a shot.

    SuperAntiSpyware Professional Lifetime Subscription is what I paid for, so it should never “run out” perhaps since I technically can’t get onto the internet may be that could be why my version hasn’t updated I don’t know what release version it should be my database version core is 7573 and the Trace is 5385, I will contact them to see what the issue is.

    Any .exe file will not open from Word, Internet Explorer to Notepad….nothing until I do the temporary exefix, because once it reboots, I get pretty much the same error that whatever .exe file can’t open or Open with….

    Ran MGTools FIXFA.bat

    OTM, I right clicked and got Run as and selected Elaine(which is the administrator account and the only option), rebooted and got windows cannot open the file OTM.exe (which is no surprise because once the computer reboots I can’t do anything until I run exefix.reg which lasts only until the next boot.

    The logs are attached.

    Thank you!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this file, reboot, and see if it still exists or not.

    C:\Documents and Settings\Elaine\Templates\wpjr38s40b7by47dqdymyn0by7e11rvcp Let me know.

    scroll down to the 9th fix, an EXE file fix. See if it helps or not, and ,et me know. It's the same as what has already been tried though so I doubt it.

    In the mean time I will have a think about what next to try.
     
  10. malibumurray

    malibumurray Private E-2

    I was able to delete the file, one thing I discovered is that many of the folders in documents and settings\Elaine are hidden I was able to unhide some. As a matter of fact after further investigation a lot of folders some system some not, the attritubes are hidden and I can not uncheck them (just an fyi)

    EXEfile fix is the same one that I have been using so the outcome is the same.
    Thank you for your help and I await your next instructions.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  12. malibumurray

    malibumurray Private E-2

    As always, thanks for the speedy response. I'm at work now, but before I begin at home, I got a response back from SuperAntiSpyware support and they sent me instructions and the new link, do you want me to hold off on this and follow your instructions first ... I just don't want to cause further issues. Thanks a bunch!
     
  13. malibumurray

    malibumurray Private E-2

    I ran reset.cmd
    when I first tried to run Win32diag.exe a window popped up saying that it was terminated and I had the option to check the box and give permission to run the program, I did and the log is attached, although I don't believe it's very much because I saw a Warning could not backup privileges, in the command window.

    Thanks and waiting your next instructions
     
  14. malibumurray

    malibumurray Private E-2

    Oops here is the log
     

    Attached Files:

  15. malibumurray

    malibumurray Private E-2

    I updated SuperAntispyware and it found the broken file association virus and cleaned successfully, so I don't have that problem, but I am still having problems with internet explorer when I click on the icon, it does not open but creates a new shortcut on the desktop, windows update is not working but system restore is.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which icon? One on the desktop for example, or one in the start menu, or one you have pinned to your taskbar?

    What errors are you having when you try?
     
  17. malibumurray

    malibumurray Private E-2

    When I double click the internet explorer icon on the desktop, it will create an internet explorer shortcut icon onto the desk, pinned to the start menu, it does absolutely nothing. When I go to the control panel and select network and internet connection then select setup up or change your internet connection, nothing happens. If I try to set up a new connection, I get the error message "an error occurred during configuration of the network on this computer. You can configure your network manually or you can run the wizard again with different settings."

    Windows update error message "windows cannot find '(null)'. make sure you typed the name correctly, and then try again. To search for a file, click the start button and then click search."
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think this is something you should post about in the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  19. malibumurray

    malibumurray Private E-2

    Kestrel,

    Will do! Thanks so much for all your time and assistance it is very much appreciated. After all of this, I've made the decision to switch operating systems. Perhaps Windows 7 will not give me as many security issues virus/malware etc as XP. Guess it's time for backup the document files I wish to keep.

    Happy Puting to All!:wave
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds