Going from bad to worse! Can't open any programs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by timzahm, Aug 16, 2011.

  1. timzahm

    timzahm Private E-2

    Originally, my computer got some type of virus or malware that made the desktop disappear and just put a blank blue screen over it. I couldn't right click or anything on this "new" desktop. Everything under Start - Programs was gone too. I could, however, click on Start - My Computer and navigate to all my folders, documents, programs, etc. I started going through the steps in the "read and run me first" thread for Windows XP (I'm running XP Pro 2002 SP3 - Build 2600.xpsp_sp3_gdr.101209-1647) and ran a scan using Super Anti Spyware. It detected a few threats, which I cleaned and then was prompted to restart.

    Upon restarting, the desktop was the same, but now I can't run exe files! I can still go through Start - My Computer and double click on a spreadsheet or document, and Excel or Word will load, but any time I double click on an exe file itself (including winword.exe or excel.exe) I get the "Windows cannot open this file" message with the option to use the web service to choose a program or to choose from a list. I rebooted in safe mode and the same thing happened. This is preventing me from going back in to Super Anti Spyware to get the log, or from running any other scanning programs. Any thoughts?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if this helps with the exe file problem:
    http://www.dougknox.com/xp/file_assoc.htm -- scroll down to the 9th file fix.

    Then please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find the items that seemed to be missing?

    Are you able to open task manager? If so, try running malwarebytes antimalware.exe.

    If not, try doing this:
    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
     
  3. timzahm

    timzahm Private E-2

    Those programs did help with restoring .exe funtionality. It seemed at first to work just for the next .exe that I tried to open, then for the second .exe and any additional ones the same original problem happened again. But every time if I ran the program again, I would be able to start one more other program.

    I have since moved on and completed all the other scans in the "Read and run me first" instructions -- except for MGTools. When I double click MGTools.exe, the screen blinks for a second, the MGTools folder is created under C:\, but none of the scans start. Anyway, after running all the scans I could in addition to TimW's instructions, the desktop icons have been restored -- although some are just the "generic" icons similar to: http://blog.gnu-designs.com/images/Windows-default-shortcut-icon.png. Those programs do open if I click the icons, however. The Start menu programs have also reappeared, but some sub-menu items have not. For instance, if I click Start - all programs - Accessories, I can see all the usual programs, but if I click Start - all programs - Games, it comes up with (Empty). Logs are attached. Thanks for your help!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can restore the defaults for the Start Menu, Accessories and Administrative Tools as follows:



    More info can be obtained here:
    http://www.smartestcomputing.us.com...iles-hiddendeleted-by-windows-recovery-virus/

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  5. timzahm

    timzahm Private E-2

    The Restore Accessories utility worked for the accessories group, but there are other programs that still have (Empty) when I mouse over them. These are programs that didn't come with Windows, like Trend Micro Internet Security, Cool Edit Pro, etc.

    The two MGTools scans ran successfully and logs are attached. (Two logs popped up after the scans but I noticed these four files had all been created.)
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will probably have to reinstall those programs. Did you look for and find:
    C:\Users\user_name\AppData\Local\Temp\smtmp .....???

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    [*]Extract avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  7. timzahm

    timzahm Private E-2

    Both scans ran successfully and logs are attached. The machine is running smoother, but sometimes the problem with starting programs will happen again -- I get the same error message asking to choose from a list of programs, etc. Running the xp_exe_fix.reg file fixes it though, and I'm good to go for a while until the errors start again. Certain icons are still generic, even after I double click them and get in to the file/program.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do this again:
    Your logs are clean, but you didn't answer me about whether or not you found:
    C:\Users\user_name\AppData\Local\Temp\smtmp

    Some of your programs may need to be reinstalled. What other issues are you having?
     
  9. timzahm

    timzahm Private E-2

    There is no C:\Users directory on this computer. I did a search for smtmp on the entire computer and it couldn't find anything. Reinstalling programs shouldn't be a problem, the only other issue is that some icons for programs are still the generic one -- not really a problem, just an annoyance.

    One other thing I am noticing now -- the system tray does not show icons for all programs that it used to. For instance, the Trend Micro icon was always in the tray but now it does not show up, even though the program is running (as I verified by getting a blocked webpage).
     
    Last edited: Aug 25, 2011
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may be able to restore some items, but you should post in the software forum for further assistance with those issue.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  11. timzahm

    timzahm Private E-2

    Thanks, I'll check out the software board for those other issues. The original problem came back today - I started the computer and tried to open a program, only to get the same message ("Windows cannot open this file" message with the option to use the web service to choose a program or to choose from a list). I used the xp_exe_fix utility which again worked and let me open programs normally, but if my logs are clean, any thoughts on why this would be happening again?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't done the cleanup yet, re-run SAS and MBAM and then download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe and attach the new C:\MGLogs.zip.
     
  13. timzahm

    timzahm Private E-2

    I ran the scans; here are the logs.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The log is still showing a broken exe key association. Otherwise your logs are clean.

    Go Here and scroll down to the ninth file to try to fix the exe file association.
     
  15. timzahm

    timzahm Private E-2

    I still had the xp_exe_fix utility from earlier and it still works, but only for a while. After I run it, everything is happy until I restart, then exe associations are broken again, I get the "choose a program or choose from a list" message until I run xp_exe_fix again, and so on.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run the below:

    Resetting Registry and File Permissions

    Now please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r
     
  17. timzahm

    timzahm Private E-2

    Both downloads and scans completed. Here's the log.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer and do a search for these files ( they are showing in one of your logs, but not in another, so I don't know if they are really gone):
    C:\Documents and Settings\Radio Richmond\Local Settings\Application Data\3144493194
    C:\Documents and Settings\Radio Richmond\Local Settings\Application Data\4133161817
    C:\Documents and Settings\Radio Richmond\Local Settings\Application Data\4jQKt4bcyWk7v

    Were you running regedit during the last run of MGTools?

    You need to tell me how things are working now.
     
  19. timzahm

    timzahm Private E-2

    All three of those files do exist in the directories you mentioned. They also exist in C:\Documents and Settings\All Users\Application Data and in C:\Avenger, and the 4jQKt4bcyWk7v file also appears in C:\WINDOWS\system32\config\systemprofile\Templates and in C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data.

    The computer is working fine, but just still having the problem of every time I restart, exe associations are lost and trying to start a program results in the "choose from a list" message. But also, every time I run the xp_exe_fix utility, associations are repaired and I can open programs normally.

    I was not running regedit or any other programs during MGTools.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you delete them all? I may have to send you to software for further assistance with the exe association issue.
     
  21. timzahm

    timzahm Private E-2

    I did delete them all, but still every time I restart, exe files do not run until after I run the xp_exe_fix utility.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try using THIS file.
     
  23. timzahm

    timzahm Private E-2

    That program does work to restore the exe associations, but again when I restart they are gone and I have to run exefix_xp or xp_exe_fix again.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  25. timzahm

    timzahm Private E-2

    That works to associate exe files, but even after I took all the steps in this latest link, associations still disappear when I restart.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I think you now need to post in the software forum for this issue. It is beyond the scope of the malware forum. You may need to run a repair install to fix the file association reg. keys.
     
  27. timzahm

    timzahm Private E-2

    Will do. Thanks for all your help.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. I will try to keep an eye on your thread in the software forum. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds