Solved

"has stopped working" virus stops all exe files from running

Posted on 2014-03-20
9
1,698 Views
Last Modified: 2014-03-21
I am a beginner admin for a Windows 2008 Server, R2.  The server has just come down with a virus and I could really use some help.

The virus stops me from running any of the installed programs with the message that the program (that I have clicked on to run) "has stopped working".

The dialog box then gives the standard windows choices of searching online for a solution or closing the program.  

All antiviral programs are blocked and the Dr. Web antivirus for servers that I had running appears to have been uninstalled by the virus.

What is the name of the virus.  What is the best way to remove it?

Any help appreciated.
0
Comment
Question by:ken_b
  • 4
  • 3
  • 2
9 Comments
 
LVL 18

Accepted Solution

by:
web_tracker earned 500 total points
Comment Utility
Download rkill from Bleeping computer, you can download different flavores of this application some are not exe files so you can fool the virus in thinking this is not an exe file. Once rkill is successfully run you can run malwarebytes and rogue killer to kill this virus. http://www.bleepingcomputer.com/download/rkill/   Try the rkill.com or the rkill.scr versions of the application as these are not exe files, at least it fools the virus that they are not executable files.
0
 
LVL 18

Expert Comment

by:web_tracker
Comment Utility
you can also use the fix exe program to repair the damage that prevents you from running excutables. http://www.bleepingcomputer.com/download/fixexec/  This will fix your exe problems. Note there are many flavors of this application as well. Note there are 32 bit and 64 bit versions of the application you need to download the appropriate version that matches your version of the operating system. I keep these tools in my arsenal.

Although I do not know the name of this virus it could go by many names. This will only repair the damage what the virus has done it will not remove the virus you need to run malwarebytes to finish removing the infection, by running malwarebytes you will find the name of this malware/virus.
0
 

Author Comment

by:ken_b
Comment Utility
I will try this in the am.  off to sleep for now...
0
 
LVL 2

Expert Comment

by:IMGIDC
Comment Utility
use kaspersky http://free.kaspersky.com/

after removing virus. search for malware using malwarebytes.
https://www.malwarebytes.org/

malwarebytes works perfect for this kind of situations.
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 

Author Comment

by:ken_b
Comment Utility
6 am and back at it.  

Used Rkill, the one that has a screensaver extension.  It ran.  It didn't find any viruses, but it did seem to make a change, from what I believe was a process where it stated that it reset the exe and com associations.  

After Rkill ran, I was able to run new antivirus programs and am now reinstalling the Dr. Web server anti-viral suite.  It is scanning now.

But I clearly still have a problem: all of the programs that I tried to open, and which came up with the "will not open" message, still will not open and have the same message.  What has changed is that I can now open a new program without the message coming up.

Should I reinstall all the affected programs that currently won't open?

What goes?

I will run some other anti-viral programs like malware bytes when the current scan is done.

Again, any help is appreciated.
0
 
LVL 2

Expert Comment

by:IMGIDC
Comment Utility
once after completing current scan, reboot that machine and check.
if still getting issue. please use MALWARE-BYTES.
0
 
LVL 18

Expert Comment

by:web_tracker
Comment Utility
You need to run the applications i have suggested especially rogue killer it will change all the apps so they run properly.  Also it is important after running rkill to remove the malware using malwarebytes. Rkill just kills the running apps but does not remove the virsus. rogue killer will help change the default applications so that the file associations are back to normal. For example so that MS word will open up doc, adobe pro or adobe reader to open pdf etc.  http://www.bleepingcomputer.com/download/roguekiller/
0
 

Author Closing Comment

by:ken_b
Comment Utility
The rkill worked to stop the virus until I could run other software for removal.  Malware Bytes also worked to quarantine.  Dr. Web worked to quarantine but not remove.  Manual removal worked by deleting the file in the folder: supporter.  The program file was supportersvc.dll
Then a rootkit removed the rest.

Thanks for all the help.

Ken
0
 
LVL 18

Expert Comment

by:web_tracker
Comment Utility
I was happy to offer at least some of the assistance in resolving the issue, I see your hard work did pay off. Good job in sticking it out.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Today, still in the boom of Apple, PC's and products, nearly 50% of the computer users use Windows as graphical operating systems. If you are among those users who love windows, but are grappling to keep the system's hard drive optimized, then you s…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now