Gladiator Security Forum

Welcome Guest ( Log In | Register )

> Forum Rules

Greetings,

Before you post in this forum,please read and follow the instructions in this post: Guidelines for Posting in This Forum

Failure to follow these instructions will only result in delays of the cleaning and removal process.

If you ran other AntiVirus and/or AntiSpyware programs and have the logs available, please post them as well.

Our goal is to help you clean your PC and restore it to pre-infection condition wherever possible.

Thank You

3 Pages V   1 2 3 >  
Reply to this topicStart new topic
> Big Problem
Nebon
post Jan 30 2006, 07:13 PM
Post #1


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



Personally i dont think i am infected but i have a big problem. I am not sure what i have done but i cannot run any .exe files, or whatever it is that runs them isnt working. I cannot post a highjackthis log because i cannot use the program. I think it is something in the registry that may have broke. I dnt no.


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post
Mosaic1
post Jan 30 2006, 07:23 PM
Post #2


Most Respected SuperExpert
Group Icon

Group: Member
Posts: 4576
Joined: 9-June 04
Member No.: 8164



Download the zip here:
http://www.dougknox.com/xp/fileassoc/xp_exe_fix.zip

Save and then extract the file it contains. Run it.

It will repair your exe file association in the registry.

Hope it helps.
Go to the top of the page
 
Quote Post
Nebon
post Jan 30 2006, 07:26 PM
Post #3


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



how do i run it caus i can click on it and it asks me to open it with a program from a list or use web to find appropriate program?


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post
Mosaic1
post Jan 30 2006, 07:28 PM
Post #4


Most Respected SuperExpert
Group Icon

Group: Member
Posts: 4576
Joined: 9-June 04
Member No.: 8164



I had assumed you used WinXP. What's your operating system please?
Go to the top of the page
 
Quote Post
Nebon
post Jan 30 2006, 07:29 PM
Post #5


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



its win xp. I dont know what has happened to it. It wont even let me open notepad.


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post
Mosaic1
post Jan 30 2006, 07:39 PM
Post #6


Most Respected SuperExpert
Group Icon

Group: Member
Posts: 4576
Joined: 9-June 04
Member No.: 8164



Copy notepad exe to your desktop. Then rename notepad.exe as notepad.com


Double click on notepad.com to open an instance of notepad.


Copy the contents of the code box to notepad.
Name the fix fix.reg
Save as Type all Files.
Double click on fix.reg and say yes to the prompt. We'll see if htis will run.

CODE
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

[HKEY_CLASSES_ROOT\.exe\PersistentHandler]
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"

[HKEY_CLASSES_ROOT\exefile]
@="Application"
"EditFlags"=hex:38,07,00,00
"TileInfo"="prop:FileDescription;Company;FileVersion"
"InfoTip"="prop:FileDescription;Company;FileVersion;Create;Size"

[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@="%1"

[HKEY_CLASSES_ROOT\exefile\shell]

[HKEY_CLASSES_ROOT\exefile\shell\open]
"EditFlags"=hex:00,00,00,00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shell\runas]

[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shellex]

[HKEY_CLASSES_ROOT\exefile\shellex\DropHandler]
@="{86C86720-42A0-1069-A2E8-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers]

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PEAnalyser]
@="{09A63660-16F9-11d0-B1DF-004F56001CA7}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PifProps]
@="{86F19A00-42A0-1069-A2E9-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\ShimLayer Property Page]
@="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"
Go to the top of the page
 
Quote Post
Nebon
post Jan 31 2006, 07:25 AM
Post #7


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



Nope no luck. Shall i boot in safe mode and then merge those registry changes then?


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post
Nebon
post Jan 31 2006, 07:31 AM
Post #8


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



Tried in safe mode also no luck. I think nearly all my file associations have gone.


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post
Nebon
post Jan 31 2006, 07:34 AM
Post #9


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



Also if this might help i get these strange error message but i cannot understand them, i think they are in some format that i cannot read so they just come up as boxes. The only way i can use a txt file is by starting it as a new file.


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post
Mosaic1
post Jan 31 2006, 07:41 AM
Post #10


Most Respected SuperExpert
Group Icon

Group: Member
Posts: 4576
Joined: 9-June 04
Member No.: 8164



Were you able to use notepad.com?What happened when you tried to merge the file? Did you get an error?

When you reply, please give me the details of what happened when something doesn't work.


If you make a copy of regedit.exe from your windows folder onto the desktop and then rename that copy as regedit.com you should be able to open the registry by double clicking on regedit.com (unlessthe com file association is cooked too)

Once in the registry, click on file on the toolbar. Click Import.

Guide Windows to the file you created. Now see if your programs will open.

IF so, go to Start >Run and paste in thie command and then press enter:

regsvr32 zipfldr.dll


Wait for the success message.

See if you are able to open a zip file now.

If you are, then go here

http://www.dougknox.com/xp/fileassoc/xp_regfile.zip

and unzip this file, then double click on iot to run it.


Let me know how you do. Please, for each step.
Go to the top of the page
 
Quote Post
Nebon
post Jan 31 2006, 07:43 AM
Post #11


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



notepad.com didnt open it was unable to. No error message occured in its opening. I get the error message when i boot up windows, before i log on, and just before i shut down. I will just try the step you recommened.


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post
Nebon
post Jan 31 2006, 07:45 AM
Post #12


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



regedit.com dosent work for me. No error message, the file just dosent open.


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post
Mosaic1
post Jan 31 2006, 07:54 AM
Post #13


Most Respected SuperExpert
Group Icon

Group: Member
Posts: 4576
Joined: 9-June 04
Member No.: 8164



I think you do have a bigger problem then.


Go to Start <Run and type

cmd
Press enter

Does a command prompt start?

If you go to the programs menu and click on accessories, can you use the command prompt shortcut there to start a command prompt?

It's VERY late here. Almost 3 am and I can't stay much longer.


I wnat to see if you can start a system restore. If not, you may have to repair install windows.
Go to the top of the page
 
Quote Post
Mosaic1
post Jan 31 2006, 07:55 AM
Post #14


Most Respected SuperExpert
Group Icon

Group: Member
Posts: 4576
Joined: 9-June 04
Member No.: 8164



Please think back. Had you been in the registry right before this all happened? And did you delete anything?
Go to the top of the page
 
Quote Post
Nebon
post Jan 31 2006, 07:55 AM
Post #15


Is GSF inventory
Group Icon

Group: Moderating Team
Posts: 1455
Joined: 18-September 05
From: Essex, UK
Member No.: 16312



Nope no command prompt.


--------------------
"If at first you don't succeed; call it version 1.0"

Go to the top of the page
 
Quote Post

3 Pages V   1 2 3 >
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 22nd November 2009 - 03:49 AM


Design by: Skins IPB & Web Browsers