Check this:
http://www.2-spyware.
if you still unable to run exe files, then you might want to repair your windows:
http://michaelstev
Main Topics
Browse All TopicsI have a laptop that I cant install malwarebytes or superantispyware to try and remove the AntiVirusPro 2010. When I try to install Malwarebytes I click the Icon to install and I get the window asking my what I want to open it with??? Never seen that before. It seemd like the installer package is messed up because of the AntiVirusPro 2010. Does anybody know of any suggestion or program I might be able to install to remove this. I am not sure I will be able to install anything because it does the same thing when I try to install superantispyware also.
Again, any program I install opens with the window "choose the program you want to open this file".
Thanks
bbbb2
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Check this:
http://www.2-spyware.
if you still unable to run exe files, then you might want to repair your windows:
http://michaelstev
Do you have another PC you can download the files to?
Sometimes you can download mbam-setup.exe and then rename it on another computer to say test.com and then run it on the infected computer. This may well get past the software stopping you.
Can you run msconfig on the problem computer?
Can you kill the two processes that are causing the problems (press CTRL + SHIFT + ESC for task manager - processes tab):
Please do not download combofix from the above link - use this one. The link above may be a link to a dodgy version:
http://www.bleepin
I really cant do much of any thing on the bad laptop, cant go to task manager, cant get on the internet even though it says I am connected, can't install any programs, its asking me to choose the program I wast to open this file. I then clicked on browse ans selected malwarebytes. It then went to install and when I got to update and then run malwarebytes I got an error message saying to contact malwarebytes support. Then The window came up to scan. I clicked on scan and ti said "Preparing to scan" an then just disappeared. I did that twice with the same result.
bbbb2
Okay - it has really got under the bonnet!
Try the following link to restore the ability to run .exe files:
http://support.micro
bbbb2 -
This sounds like quite a problem.
You can try downloading "Stinger" from McAfee - it is a very small executable file which won't have to be loaded on your computer.
Download it on your good computer and then copy it to USB stick drive or a CD, then run it on the bad one.
You might also want to consider pulling the HDD off the bad computer and 'slaving' it on the good one - then running your AV application against it.
I went to install and run Malwarebytes and I get an error message at the very end after it installs and ask me if I want to run Malwarebytes. I click yes and I wait a few seconds and I get an error message stating: Error Code 732(0,0) Please report the following error code the the malwarebytes support team.
You can download MalwareBytes and Combofix using another pc into a USB as already suggested, rename them before saving or before transfering it to the infected pc so malware can't block them from running.
If you can't run any .exes you can also use this fix.
* Download Fixswen and save it to your desktop
* Right-click on the file and choose "install"
http://download.nai.com/pr
Sounds GREAT. rpggamegirl, I dont think I can run any exe. I was going to do a print screen but I couldnt open up paint to copy it to without the open with window opening up and it still would work . Error message was that it was a valid win32 application.Should I download and rename Malwawarebytes and Combofix first or atleast try to or skip it and got to your second and Download Fixswen?
bbbb2
You can try running the renamed tools first if you like, either way won't hurt.
Also try running this diagnostic tool(once you can run .exes) to check if a particular infection is present.
Please download this tool and run it.
http://ad13.geekstogo.com/
Double-click on Win32Diag.exe to run it. If you are using Windows Vista, please right-click and select Run As Administrator
A black command prompt window shall appear.
It will now begin to scan. This may take a while, please be paitent until the scan is complete.
Once it's done, in the black screen it will say "Finished! Press any key to exit....
A log file called Win32KDiag.txt will be created on your desktop.
Please copy and paste the contents of that log file here in your next reply please.
@ alanhardisty,
Thanks for that boost of confidence in me, :)
Here is the Win32Diag log file:
Log file is located at: C:\Documents and Settings\Peter Colby\Desktop\Win32kDiag.t
WARNING: Could not get backup privileges!
Searching 'C:\WINDOWS'...
Found mount point : C:\WINDOWS\$hf_mig$\KB9129
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB9188
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\$hf_mig$\KB9317
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\Native
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\temp\t
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\assembly\tmp\tm
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Config\Config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d1\d1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d2\d2
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d3\d3
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d4\d4
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d5\d5
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d6\d6
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d7\d7
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\CSC\d8\d8
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ftpcache\ftpcac
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\chsime\appl
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\CHTIME\Appl
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imejp\apple
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imejp98\ime
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imjp8_1\app
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imkr6_1\app
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\imkr6_1\dic
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\ime\shared\res\
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Installer\$Patc
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\java\classes\cl
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\java\trustlib\t
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Microsoft.NET\F
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Microsoft.NET\F
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\msapps\msinfo\m
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\ERRORR
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\ERRORR
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpct
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpct
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpct
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpct
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpct
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpct
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\pchealth\helpct
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Registration\CR
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\setup.pss\setup
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistrib
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SoftwareDistrib
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Sun\Java\Deploy
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\SxsCaPendDel\Sx
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1025\1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1028\1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1031\1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1037\1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1041\1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1042\1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\1054\1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\2052\2
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\3076\3
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\3com_d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\appmgm
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\appmgm
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\config
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\dhcp\d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\driver
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\system32\eventl
[1] 2004-08-10 06:00:00 55808 C:\WINDOWS\$NtServicePackU
[1] 2008-04-13 19:11:53 56320 C:\WINDOWS\ServicePackFile
[1] 2008-04-13 19:11:53 61952 C:\WINDOWS\system32\eventl
[2] 2008-04-13 19:11:53 56320 C:\WINDOWS\system32\logeve
[1] 2004-08-10 06:00:00 55808 C:\i386\eventlog.dll (Microsoft Corporation)
Found mount point : C:\WINDOWS\system32\export
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\FxsTmp
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\GroupP
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\GroupP
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\CI
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\PI
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\IME\TI
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\mui\di
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\h
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\h
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\h
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\h
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\oobe\s
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\Reinst
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\ShellE
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\spool\
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\spool\
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\spool\
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\spool\
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\spool\
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\m
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\m
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wbem\s
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\wins\w
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\system32\xircom
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\TempRec\Te
Mount point destination : \Device\__max++>\^
Finished!
Thanks for the log, please follow these steps. The new infection that patched legit system file is present.
What we're doing here is to put a clean copy of the eventlog.dll into the C:\ and then move that(using Avenger) to replace the patched eventlog.dll in the system32 folder.
Once we replaced the patched file you should be able to run the scanners. Let us know if you encounter any problems or have any questions.
Step 1
Click on Start > Run
in the run box type cmd and press Enter.
"A command prompt window will appear. Please copy the below command(bolded text) and paste it the cmd window and press Enter:
copy C:\WINDOWS\system32\logeve
It should say "1 file(s) copied"
Then Close the cmd window.
Step 2
Please download The Avenger by Swandog46 to your Desktop.
http://swandog46.g
* Right click on the Avenger.zip folder and select "Extract All..."
* Follow the prompts and extract the avenger folder to your desktop
* Start up Avenger.
In the "Input script here:" box that opens, copy, then paste the following bolded text:
---------------------
Files to move:
C:\eventlog.dll | C:\WINDOWS\system32\eventl
----
C
Then press OK at the prompt to reboot your PC.
Please copy/paste the content of c:\avenger.txt into your reply.
Step 3:
Click on Start-> Run, and copy-paste the following command into the "Open:" box, and click OK.
"%userprofile%\desktop\
Step 4:
Run a renamed MBAM and renamed Combofix and attach the logs.
I am speaking to you on a desktop and then going to the infected laptop and doing what you ask. I tyed in the command prompt on the infected laptop what you told me to do and I got the results you where expecting. Now I am wondering what you want me to do from here. Are you wanting me to do everything else from the infected laptop?
bbbb2
Yes.
I want you to download Avenger using the desktop into a USB drive and try to put it in the desktop of the infected laptop and run this script in Avenger window.
Files to move:
C:\eventlog.dll | C:\WINDOWS\system32\eventl
then
Click on Start-> Run, and copy-paste the following command into the "Open:" box, and click OK.
"%userprofile%\desktop\
And after you've done those... you should be able to run the renamed MalwareBytes and Combofix to cleanup the infection.
Run a renamed MBAM and renamed Combofix and attach the logs.
MalwareBytes still won't run?
Did Avenger successfully move the file to replace the patched one?
Can you please let us see the Avenger log?
Can we also look at the latest log of the Win32kDiag.txt?
Here's the direct combofix.exe link
ComboFix by sUBs:(rename before saving or rename before installing to the infected pc)
http://download.bleepingco
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here is an Antivirus Pro 2010 removal guide:
http://www.geekpolice.net/
If it doesn't work, scroll down, and delete the listed files manually.
DoctorInferno,
There are a couple of things wrong with the post you just made.
First - that advice has already been posted (MBAM).
Second - please don't try to send our Members to some other web site for assistance.
The Experts here on EE (most of them) know what they are doing and can help our Members - based on what we post - NOT on what you found on some other forum.
rpggamegirl,
Everytime I try to open any program, for example combofix, the open with window asking me to CHoose a program you want to use to oopen this file. I choose Kombophix(renamed) but the it pops up again with Open With File iexplore.exe and saying "Choose the program you wnat to use to open this file. I am confused as to why it is doing this.
Another thing is after I ran Avenger and rebooted I go to c:\avenger and nothing is there.
Please get back with me when you can and the time differences are probably going to be a problem. I am usually up late. I am in central standard time zone. Probably 12 hours dfference.
Talk to you whenever, hopefully soon because the person whose laptop is going to want it back soon.
thanks
bbbb2
There are instructions at the ComboFix download site, but if those don't help try these:
http://www.ctimls.com/Supp
Business Accounts
Answer for Membership
by: PriceDPosted on 2009-09-07 at 15:34:52ID: 25277625
have you tried www.trendmicro.com.
Go to trendmicro.com, go to free tool, and download rootkitbuster. Also, you can try their on-line scanner as well.