Unable to run EXE Files

A customer's computer was the victim of a fake alert virus.  The virus was pretty much blocking me from doing anything.  I cleaned the virus by installing the drive in another computer and running Malwarebytes.  When I put the drive back in the original computer, I was unable t run ANY executable files.  Regedit, CMD, and IE8 will not run.

I can get into Safe mode, but it behaves the same way.

I found exefix.com for WIndows XP, but I have not been able to find a similar program for Windows 7.

How can I get EXE files to run?
LVL 1
rhaveyAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

LHT_STCommented:
have you tried?

http://www.winhelponline.com/blog/file-asso-fixes-for-windows-7

if not i can probably create a .reg file for you if needs be.
0
hunartCommented:
You have to re-scan Malwarebytes and any other software to clean the virus under Safe Mode.  Most spywares or viruses will replicate themselves behind the scene using Windows services or processes.  Try to do under Safe Mode.

If you read removal instructions, they are mostly suggested that you run in Safe Mode.
0
rhaveyAuthor Commented:
You are probably on to something.  I had to create a new profile to get EXE files to actually execute.  Then Malwarebytes would not install in Normal mode.

I managed to get Malwarebytes to run in safe mode on the new profile.  All that turned up were a couple of things in the System Restore files - which I thought did not exist.

Superantispyware found a lot of tracking cookies, but nothing else.

Combofix will not run because I have a 64 bit system.

I think that I may be at the point of having to capture the user's profile and reinstall.
0
The 7 Worst Nightmares of a Sysadmin

Fear not! To defend your business’ IT systems we’re going to shine a light on the seven most sinister terrors that haunt sysadmins. That way you can be sure there’s nothing in your stack waiting to go bump in the night.

phototropicCommented:
Rename Mbam BEFORE you download it to the infected pc.  Rename the "File name" and download.  If that does not work, try renaming to something like "xyz.bat" and change the entry in "Save as type" to All Files.

If exe.'s will not run, you are probabley still infected. Try running Rkill:

http://www.bleepingcomputer.com/forums/topic308364.html

Download all seven different file types and try each one until it will run.

Or try Rogue Killer:

http://www.geekstogo.com/forum/files/file/413-roguekiller/

Good article here:

http://www.experts-exchange.com/Virus_and_Spyware/Anti-Virus/A_4922-Rogue-Killer-What-a-great-name.html?sfQueryTermInfo=1+10+30+killer+rogu

Running Mbam ( or anything else) in safe mode will only have limited effrectiveness against current malware.  There is a thread about this:

http://www.experts-exchange.com/Virus_and_Spyware/Anti-Virus/Q_24860646.html

If you can run Mbam in normal mode, post a log here for review.
0
rpggamergirlCommented:
ComboFix is 64bit compatible. If it didn't run it's more likely because the system has AVG or CA antivirus installed(these need to be uninstalled first in order for CF to run).

Another reason for ComboFix not being able to run is IF it's blocked my malware, try downloading ComboFix but rename it before actually saving the file to your desktop.


OR:
Use OTL and post the log for us to review, we'll then post a script if we find bad files to be removed.

Download OTL to your desktop.
http://oldtimer.geekstogo.com/OTL.exe

http://ottools.noahdfear.net/OTL.com

Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
0
rhaveyAuthor Commented:
Unfortunately, I had already done the reinstallation before I saw the last 2 comments.  This particuar user did not have any critical data or operation on this computer, but I had to get it back to him.

I had the machine more or less running before the reinstall, but I did not consider it stable.

I will try Combofix on a test machine.  I would have sworn that I tried it before and it would not run on 64 bit.

Thank you for your comments.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
rhaveyAuthor Commented:
Reinstallation - no solution before I had to get the computer off my bench.
0
phototropicCommented:
My post appeared about 6 hours after your question went online.
You need to leave at least 24 hours to collate responses at ee.

Anyway, I'm glad your problem is now resolved.

"... I had to get the computer off my bench..."  If you are fixing/cleaning pcs professionally, you really should take a look at the links in mine and rpggamergirl's posts - they will save you a lot of workshop time...
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Legacy OS

From novice to tech pro — start learning today.