Solved

XP Not Opening EXE files - requests "Open With"

Posted on 2011-03-15
7
789 Views
Last Modified: 2013-11-22
I have a client and who has been receiving prompts to "Open With" when attempting to open EXE files. I have run a full scan with Malwarebytes, and found a number of viruses, which were all removed. I also downloaded and ran a script which corrected the registry to allow these files to be opened. But the problem recurred. I removed the antivirus that was in place, and installed Kaspersky, which immediately found a rootkit, which it removed after reboot. However the problem has referred yet again.

I wonder what could be the root cause of this, and how to get rid of it once and for all.

Any help would be appreciated.
Thanks
Mark
0
Comment
Question by:mlitin
7 Comments
 
LVL 3

Accepted Solution

by:
KenTankrus earned 125 total points
ID: 35140514
The registry sounds like it's been corrupted. There is a simple fix found here:

http://windowsxp.mvps.org/exefile.htm
0
 
LVL 8

Assisted Solution

by:Sean Scissors
Sean Scissors earned 125 total points
ID: 35140564
If the registry is still being broken then its possible the rootkit isn't completely gone. You used kaspersky you said but did you use their actual rootkit tool the "TDSS killer"?  I would suggest trying that and the .exe being broken is very common but thankfully easy to fix. @KenTankrus's link will work just fine. Just download the .reg file and when it prompts "Are you sure" just say yes and that should fix the .exe issue. However after a reboot if it comes back then clearly its still not fixed. So before rebooting again I suggest running TDSS killer if you haven't already done so and also running CCleaner to remove temp files.

TDSSkiller: http://support.kaspersky.com/viruses/solutions?qid=208280684
CCleaner: http://www.piriform.com/ccleaner
0
 
LVL 26

Assisted Solution

by:Thomas Zucker-Scharff
Thomas Zucker-Scharff earned 125 total points
ID: 35140907
As to disabling System Restore, there has been much debate on that here on EE.  I think generally the consensus has been DON'T until you are sure you can reboot into a clean working system.  See these 2 articles on System Restore:

http://www.experts-exchange.com/Software/Internet_Email/Anti-Virus/A_1934-Viruses-in-the-System-Volume-Information-System-Restore.html

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/XP/A_2209-Removing-protected-System-Restore-files-if-they-have-been-infected.html

If you have discovered a rootkit, then TDSSkiller is an excellent tool to run, but you should also run AT LEAST 2 other antirootkit tools.  See my article on rootkits and free antirootkit tools:

http://www.experts-exchange.com/Virus_and_Spyware/Anti-Virus/A_2245-Anti-rootkit-software.html
0
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

 
LVL 24

Expert Comment

by:Dr. Klahn
ID: 35141243
Is this occurring on all .EXE files, or only some files?
0
 
LVL 22

Assisted Solution

by:optoma
optoma earned 125 total points
ID: 35141504
You can try Exehelper which will scan for some rogues and reset exe for you. If prompted to reboot after running Exehelper, do not, and scan with Hitmanpro.
Post both logs.

http://raktor.net/exeHelper/exeHelper.com
http://www.surfright.nl/en/downloads/
0
 

Author Closing Comment

by:mlitin
ID: 35178035
Thanks all.

A synthesis of all suggested resulted in the elimination of this pest.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
where is software market online? 7 92
Videos Blocked on espn.com 7 139
Anti-virus for Linux Server 15 123
Protecting a SKY 4.0 (Android) devise 15 98
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Read about achieving the basic levels of HRIS security in the workplace.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now