How to troubleshoot this malware

Victek

New member
Guru
Local time
9:48 AM
Messages
587
I have a customer running XP who apparently was hit with malware. It was intercepted by the AV, but something went wrong. Now the system boots to the desktop, however almost all EXE files will not run - clicking an EXE produces an error where Windows asks what application is associated with the extension. There is no way to access the registry and F8 boot key options are disabled blocking access to SAFE mode and Hidden Admin account. I'm not sure how to troubleshoot. Task Manager runs but doesn't show an obvious malware process. All the usual malware load points, such as Startup folders and App Data folders for current user and All Users are clean. I've prepared the customer for a backup and complete reinstall, but if there's a way to get antimalware running on the system I'd like to try and check it. TIA
 

My Computer My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb

My Computer My Computer

Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
Hi,

You can use the following registry key to reset the .exe association in XP
View attachment xp_exe_fix.reg

If you have access to external media (USB, HDD) then you can do the following...
  1. Copy the reg key and MalwareBytes install file to the drive.
  2. Plug into the XP machine and copy both files to the HDD
  3. Double click the .reg file and accept any messages
  4. Run the MalwareBytes install and perform a full system scan
This should sort the issue out.


OS
 

My Computer My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
Thanks for these responses. I will try them tomorrow and post the results. Meanwhile if anyone else has an idea please chime in :geek:
 

My Computer My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
Hi,

You can use the following registry key to reset the .exe association in XP
View attachment 145201

If you have access to external media (USB, HDD) then you can do the following...
  1. Copy the reg key and MalwareBytes install file to the drive.
  2. Plug into the XP machine and copy both files to the HDD
  3. Double click the .reg file and accept any messages
  4. Run the MalwareBytes install and perform a full system scan
This should sort the issue out.


OS

I'm happy to say that this did sort it out. Thanks for the .REG file - it was the most convenient solution :geek:
 

My Computer My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
:( my link had the same reg file in it. I just didn't directly link it, I was told that's against the rules here.
 

My Computer My Computer

Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
:( my link had the same reg file in it. I just didn't directly link it, I was told that's against the rules here.

Sorry, I didn't mean to leave you out. I've added to your REP along with Orbital Shark as you both pointed me in the right direction. Thanks for linking to the tutorial. :geek:
 

My Computer My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
I'm happy to say that this did sort it out. Thanks for the .REG file - it was the most convenient solution :geek:

You're welcome, I'm glad it worked :)

:( my link had the same reg file in it. I just didn't directly link it, I was told that's against the rules here.

You'll find that I uploaded the actual .reg file rather than linking to a site. However, a link to a site giving assistance would not be against the rules as it would be for .reg files which are not against forum policy or illegal in any way :)
 

My Computer My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
Back
Top