Author Topic: Can't open EXE programs (virus)  (Read 5262 times)

0 Members and 1 Guest are viewing this topic.

Offline country32

  • Newbie
  • *
  • Posts: 47
Can't open EXE programs (virus)
« on: May 13, 2011, 01:17:58 AM »
I've got a problem where I can't open programs.

Earlier today I was checking email  (Hotmail) and  AVG told me there was a threat. Then antivirus  window popped up and did the (fake scan) etc.

I went to safe-mode and ran  malwarebytes and some abbreviated (AVG) scan.   Malware showed problems and deleted.

I also did a (remote) SuperAntiVirus scan.

Now, there are no pop-ups, but I cannot open any of my programs  (.exe) When I click on a desktop program it says (choose program to open) but I cannot.   i also get a  "jqsnotify)

I can get on the net, and all my documents/files, etc are fine.   I just can't click and open programs.

Also, I can't download or run any of the files to post Logs.   

While I could run AVG and Malwarebytes in safe-mode.. now, i cannot.  All desktop programs are shown, but not the normal icon..


What is the best thing to do?



Offline country32

  • Newbie
  • *
  • Posts: 47
Can't open EXE programs (virus)
« Reply #1 on: May 13, 2011, 02:57:30 PM »
I've got a problem where I can't open programs.

Earlier today I was checking email  (Hotmail) and  AVG told me there was a threat. Then antivirus  window popped up and did the (fake scan) etc.

I went to safe-mode and ran  malwarebytes and some abbreviated (AVG) scan.   Malware showed problems and deleted.

I also did a (remote) SuperAntiVirus scan.

Now, there are no pop-ups, but I cannot open any of my programs  (.exe) When I click on a desktop program it says (choose program to open) but I cannot.   i also get a  "jqsnotify)

I can get on the net, and all my documents/files, etc are fine.   I just can't click and open programs.

Also, I can't download or run any of the files to post Logs.   

While I could run AVG and Malwarebytes in safe-mode.. now, i cannot.  All desktop programs are shown, but not the normal icon..


What is the best thing to do?

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Can't open EXE programs (virus)
« Reply #2 on: May 13, 2011, 05:02:34 PM »
Hi, Rick.

Is this the same computer that you had these issues with, explorer problem (no icons/start menu) and Antivirus GT problem?  The last we knew, you were still trying to repair your XP OS.

Before we go further, do you have a full System Restore point prior to this occurrence? 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline country32

  • Newbie
  • *
  • Posts: 47
Re: Can't open EXE programs (virus)
« Reply #3 on: May 13, 2011, 08:06:17 PM »
Hi,

 No, this is a different computer.  I took the old one to a place and they thought the hard drive was cooked.. I found a similar computer cheap so I bought it.  Turns out the old one wasn't cooked, just needed to be wiped clean.

This is the (new) different computer.

all my files are fine, I can even get on internet,   there is the red shield icon in tool bar saying computer might be at risk.   then all desktop programs cannot be opened.

When it first happened, any icon I clicked on desktop would open the (Fake virus scanner)   So when I clicked malwarebytes  the fake program ran.   

I was able to go into safemode and run  malwarebytes and  AVG  (malware found and deleted items) and all desktop ICONS looked normal.. however, after I ran  SuperAntiVirus  is when desktop icons could not work.  (The icons are there, but the are not the normal program images, they are all white.)

All my files/videos/pictures, etc work fine.




Just can't run any programs. (the choose from list  box  opens and nothing works)



Thanks,

Rick

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Can't open EXE programs (virus)
« Reply #4 on: May 13, 2011, 10:30:00 PM »
Ok, well since it is a different computer, what is the Operating System?  That makes a difference if it is necessary to provide  you with a download link for a fix for the file association.  At this point, I don't know if it was caused by a f/p with SAS or the fake/rogue A/V. 

I need to know the Operating System and the name of the Fake A/V.  It may also help if you provide a copy of the MBAM log.

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline country32

  • Newbie
  • *
  • Posts: 47
Re: Can't open EXE programs (virus)
« Reply #5 on: May 14, 2011, 01:08:44 AM »
Sorry, It's basically the same system.


Windows XP.

I'm not sure how to get the MBAM log. I cannot open.


*when I click on an icon it says, in order to open windows needs to know what program it was created with, it can either search the web to find it, or choose from list*   Neither options seem to work..  The only items on list are firefox/IE and then there are video players  listed.

Thanks,

Rick

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Can't open EXE programs (virus)
« Reply #6 on: May 14, 2011, 01:25:10 AM »
Please download rkill from one of the following links and save to your Desktop:

One, Two or Three
  • Double-click rkill to run.
  • A command window will open then disappear upon completion, this is normal.
  • Please leave rkill on the Desktop until otherwise advised.
  • Do NOT restart your computer after running rkill as the malware program(s) will start again.
Notes:

If you you receive security warnings about rkill, please ignore and allow the download to continue.

Now see if you can launch and update MBAM.  If so, post the log, please.

If not, please tell me the name of the fake a/v, as previously requested.

Thanks.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline country32

  • Newbie
  • *
  • Posts: 47
Re: Can't open EXE programs (virus)
« Reply #7 on: May 14, 2011, 05:01:57 PM »
I downloaded  Rkill to desktop, however I could not run  *wouldn't open like other files*

I went to safemode to run  *SuperAntiVirus* again,  I realize before I did it under  Admin, this time I did it under owner.

it's run for an hour and half and found 2 threats  in registry.

it says,

System.BrokenFileAssociation


*I don't know what  fake A/V it is*    When i got the threat, the pop-up  that looks like  my computer with scanning on bottom opened.  I closed right down and went to safe mode, to try and avoid actually getting anything.



-Rick

Offline country32

  • Newbie
  • *
  • Posts: 47
Re: Can't open EXE programs (virus)
« Reply #8 on: May 14, 2011, 05:18:47 PM »
well, I guess the  superantivirus  is stuck .. it's not scanning anymore..

the progress it's stuck on is..

C:Windows\system32\NTDLL.DLL


???

-Rick

Offline country32

  • Newbie
  • *
  • Posts: 47
Re: Can't open EXE programs (virus)
« Reply #9 on: May 14, 2011, 06:20:10 PM »
sorry for all the messages..   Not sure if I should be running  Superantivirus, but it's the only thing I can run, and gives me any type of feedback.

I just ran full scan (not in safe-mode)   it found the following threats   and items detected.

Adware.TrackingCookie....................1 item
Disabled.TaskManager......................2
System.BrokenFileAssociation...........1
Trojan.Agent/Gen-Fake Alert(QNP).....2
Trojan.Agent/Gen-Antispy.................1
Trojan.Agent/Gen-Explorer(Fake)........6
Trojan.Agent/Gen-PEC......................6
Trojan.Agent/Gen-Virut.....................1

On all of them I can see the item location, etc.

For the  System.BrokenFileAssociation

  It says  Registry keys
                 HKCR\.exe


hopefully this will answer some of the questions..  I have not taken any actions on the above threats, yet.


-Rick

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Can't open EXE programs (virus)
« Reply #10 on: May 14, 2011, 06:32:42 PM »
Hi, Rick.

I don't use SAS.  However, as you are able to run it and it has detected those trojans, you should allow SAS to quarantine the findings.  It makes sense that "System.BrokenFileAssociation" points to the registry entry for .exe's. 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline country32

  • Newbie
  • *
  • Posts: 47
Re: Can't open EXE programs (virus)
« Reply #11 on: May 14, 2011, 10:11:14 PM »
I was able to get malwarebytes to work..   first is results of scan last week.  then most recent.

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6515

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/5/2011 4:23:27 PM
mbam-log-2011-05-05 (16-23-27).txt

Scan type: Full scan (C:\|)
Objects scanned: 170897
Time elapsed: 21 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\owner\application data\Sun\Java\deployment\cache\6.0\38\7bbb1226-389a8718 (Trojan.FakeAlert) -> Quarantined and deleted successfully.


i updated and ran most recent scan... results below.

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6579

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/14/2011 6:01:32 PM
mbam-log-2011-05-14 (18-01-32).txt

Scan type: Full scan (C:\|)
Objects scanned: 186043
Time elapsed: 27 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Pboriqoba (IPH.Trojan.Hiloti.B) -> Value: Pboriqoba -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Dxagolalocupuwo (Trojan.Hiloti) -> Value: Dxagolalocupuwo -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\exefile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("C:\Documents and Settings\owner\Local Settings\Application Data\nkx.exe" -a "%1" %*) Good: ("%1" %*) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\icapubik.dll (IPH.Trojan.Hiloti.B) -> Quarantined and deleted successfully.
c:\WINDOWS\uz3dbav.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\documents and settings\owner\application data\Adobe\plugs\mmc5126593.txt (Rogue.Installer.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\owner\application data\Sun\Java\deployment\cache\6.0\55\3e9e6c37-3f50b0a7 (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
c:\documents and settings\owner\local settings\Temp\0.04894478671244262.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.

Offline country32

  • Newbie
  • *
  • Posts: 47
Re: Can't open EXE programs (virus)
« Reply #12 on: May 15, 2011, 01:08:25 AM »
I just ran  AVG and nothing was found.

It's better but I'm not convinced everything is gone.. My computer is making quite a bit of noise (working)

My desktop icons now work, however they still don't have normal icons, they are white.

When i launch firefox it's fine sometimes, other times an additional tab loads which is a (spam) type site.  and one of the "are you sure you want to leave this page type" boxes when I try to close it.

Also, my desktop somewhat has a  (safe-mode) feel to it, especially the tool bar, it's gray.

I can click on Rkil and click run, but nothing happens, there is nothing visual showing it's running, just the (run) box disappears and nothing happens.


Any suggestions what I should do/try now?


Thanks.

Rick

P.S.   is  SUN JAVA  a problem area?  I remember last time when I had computer problems seeing the (Sun) Icon on my screen before I couldn't use my old computer.

I haven't seen anything like that this time, just on my scan last week it said  Sun/Java.

?

Offline country32

  • Newbie
  • *
  • Posts: 47
Re: Can't open EXE programs (virus)
« Reply #13 on: May 15, 2011, 01:12:29 AM »
Also, on my menu bar.. the Windows Security Alerts  (red Shield) is still there.. when I click it it says  Firewall is not monitored and automatic updates is off.   it says virus protection is on  (AVG)

I just want to make sure this  WSA  is legit, and not something that came through with the virus.


should I turn firewall-automatic updates on?

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Can't open EXE programs (virus)
« Reply #14 on: May 15, 2011, 01:27:30 AM »
I really cannot advise you blindly without more substantive information.  Please download random's system information tool (RSIT):
  • Download RSIT by random/random from here and save it to your desktop.
    Note:  For users with 64-bit systems, please download RSIT from here.
  • Double-click RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized).
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.