dainfamusgc
asked on
Absolutely nothing works - all .exe --> .lnk; lost all file associations
Ok I have a serious problem with my PC, yesterday I was in the middle of an install for the ipod software, when a virus was detected and i clicked on heal. Several minutes later the computer started the freeze up and the desktop "refreshed" and all the .exe's on the desktop were changed into .lnk's. Every single file on the drive lost its file association so basically I can click on nothing and nothing works. I found a regfile fix but i cant run the file it wont let me. I cant access my computer, msconfig, regedit, cant run .bat files. Basically nothing works. Dont want to reformat and reinstall xp b/c i cannot find the disk had it, was installed when xp first came out and had sp1 no sp2. Is there anyone who can help m?!?! Thanks in advance for your time and hlp it is greatly appreciated.
Try the system restore.Select some distant restore point....
dainfamusgc,
You can give this .exe file association fix a try...
http://www.dougknox.com/xp/fileassoc/xp_exe_fix.zip
Hope this helps!
You can give this .exe file association fix a try...
http://www.dougknox.com/xp/fileassoc/xp_exe_fix.zip
Hope this helps!
ASKER
sorry if i wasnt clear before but it wont let me open up control panel either so system restore is out there, and i cant run any .exe file or any file for that matter. Just unzipped the file in that link and its a .reg file wont let me run that either
thanks for your help
thanks for your help
try this:
put the following into a reg file and import it into your registry:
****Begin Source****
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdow nload"
[HKEY_CLASSES_ROOT\.exe\Pe rsistentHa ndler]
@="{098f2470-bae0-11cd-b57 9-08002b30 bfeb}"
[HKEY_CLASSES_ROOT\exefile ]
@="Application"
"EditFlags"=hex:38,07,00,0 0
"TileInfo"="prop:FileDescr iption;Com pany;FileV ersion"
"InfoTip"="prop:FileDescri ption;Comp any;FileVe rsion;Crea te;Size"
[HKEY_CLASSES_ROOT\exefile \DefaultIc on]
@="%1"
[HKEY_CLASSES_ROOT\exefile \shell]
[HKEY_CLASSES_ROOT\exefile \shell\ope n]
"EditFlags"=hex:00,00,00,0 0
[HKEY_CLASSES_ROOT\exefile \shell\ope n\command]
@="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile \shell\run as]
[HKEY_CLASSES_ROOT\exefile \shell\run as\command ]
@="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile \shellex]
[HKEY_CLASSES_ROOT\exefile \shellex\D ropHandler ]
@="{86C86720-42A0-1069-A2E 8-08002B30 309D}"
[HKEY_CLASSES_ROOT\exefile \shellex\P ropertyShe etHandlers ]
[HKEY_CLASSES_ROOT\exefile \shellex\P ropertyShe etHandlers \PEAnalyse r]
@="{09A63660-16F9-11d0-B1D F-004F5600 1CA7}"
[HKEY_CLASSES_ROOT\exefile \shellex\P ropertyShe etHandlers \PifProps]
@="{86F19A00-42A0-1069-A2E 9-08002B30 309D}"
[HKEY_CLASSES_ROOT\exefile \shellex\P ropertyShe etHandlers \ShimLayer Property Page]
@="{513D916F-2A8E-4F51-AEA B-0CBC76FB 1AF8}"
****End Source****
if you can't import it in windows, put it on a floppy and boot your machine into recovery console. Then use the REG IMPORT command to import his fix.
If this does not work, try these tools:
http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.removal.tool.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.removal.tool.html
http://home.earthlink.net/~rmbox/Reticulated/Only_IE.html (Download EXEfix08.com)
put the following into a reg file and import it into your registry:
****Begin Source****
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdow
[HKEY_CLASSES_ROOT\.exe\Pe
@="{098f2470-bae0-11cd-b57
[HKEY_CLASSES_ROOT\exefile
@="Application"
"EditFlags"=hex:38,07,00,0
"TileInfo"="prop:FileDescr
"InfoTip"="prop:FileDescri
[HKEY_CLASSES_ROOT\exefile
@="%1"
[HKEY_CLASSES_ROOT\exefile
[HKEY_CLASSES_ROOT\exefile
"EditFlags"=hex:00,00,00,0
[HKEY_CLASSES_ROOT\exefile
@="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile
[HKEY_CLASSES_ROOT\exefile
@="\"%1\" %*"
[HKEY_CLASSES_ROOT\exefile
[HKEY_CLASSES_ROOT\exefile
@="{86C86720-42A0-1069-A2E
[HKEY_CLASSES_ROOT\exefile
[HKEY_CLASSES_ROOT\exefile
@="{09A63660-16F9-11d0-B1D
[HKEY_CLASSES_ROOT\exefile
@="{86F19A00-42A0-1069-A2E
[HKEY_CLASSES_ROOT\exefile
@="{513D916F-2A8E-4F51-AEA
****End Source****
if you can't import it in windows, put it on a floppy and boot your machine into recovery console. Then use the REG IMPORT command to import his fix.
If this does not work, try these tools:
http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.removal.tool.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.removal.tool.html
http://home.earthlink.net/~rmbox/Reticulated/Only_IE.html (Download EXEfix08.com)
boot into safe mode, and run sfc /scannow
can you provide the name of the virus this may help us to assist you with any known solutions for infections from it.
any chance of slaving the hdd this way you can run more scans for any viruses,check the disk for errors.etc?
if the association for .reg files is gone, you can try importing it from the command prompt.
Type "REGEDIT /S xp_exe_fix.reg"
Type "REGEDIT /S xp_exe_fix.reg"
If you cant run exe's you will need to copy regedit.exe to regedit.com then you will be able to run regedit from the command prompt.
Then follow some of the steps in the other posts
Then follow some of the steps in the other posts
ASKER
I believe the virus/troja was healed b/c somehow the only thing that works ironically is AVG anti-virus i did the scan and deleted/healed alot of infected files some were trojans like a0.collected.5 and some others. Just i think the effect of those are the screwed up .exe's.
if it was a malware, issue, i suggest running ALL these in safe mode, sytem restore turned off
Spybot : http://www.download.com/3000-8022-10122137.html
adaware : http://www.lavasoftusa.com/
http://housecall.trendmicro.com/ online scan for trojans
CWshredder http://www.majorgeeks.com/download4086.html
http://www.spychecker.com/program/hijackthis.html download
http://www.hijackthis.de/index.php?langselect=english check the log
Spybot : http://www.download.com/3000-8022-10122137.html
adaware : http://www.lavasoftusa.com/
http://housecall.trendmicro.com/ online scan for trojans
CWshredder http://www.majorgeeks.com/download4086.html
http://www.spychecker.com/program/hijackthis.html download
http://www.hijackthis.de/index.php?langselect=english check the log
ASKER
Will try it later when i get home, and let you guys know. Hijackthis was ran like a few hours b4 this problem occurred and is ran almost everyday, my log normally only has like 15 or so entries and all are system related. Will try to do it again later thogh. But 1 problem it wont let me go into safe mode either though?!?!
>> it wont let me go into safe mode either though << hit the F8 key during boot rapidly
system restore is not run from the control panel but from
start/programs/accessories /system tools/system restore
start/programs/accessories
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
ok ricgoalie thx alot you guys are great over here will go try it now
ASKER
hat sux finally got all that to work and now its saying the same thing as if i was clicking on something from the desktop. :( "this file does not have a program associated with it for performing this action. Create an association in the folder options control panel." which is what it has been saying all along, with any other file
ASKER
ok now i tried it again and now it says access denied and that was logged in as administrator?!?!? what do i do now
ASKER
dont know you guys know of anything to do with this but in safe mode i can access regedit
ASKER
UPDATE yet again sorry im seem like im annoying now but i got the permissions changed and everything, ran the .reg file like you said but still didnt work, dont really no what else to do. Cant do the xp disn repair b/c i cant find that disk anywhere
ASKER
Just wanted to say thank you to everyone who contributed after messing with the registry and the permissions i finally got it to work thanks again everyone