Link to home
Start Free TrialLog in
Avatar of Jack Murphy
Jack MurphyFlag for United States of America

asked on

TS Server 2008 R2 will not open any applications. This File does not have a program associated with it for performing this action.......

Please see the attached screenshot?  User generated image
Avatar of Mal Osborne
Mal Osborne
Flag of Australia image

I have seen similar before, with partly removed Malware.  Basically, settings in in the registry or an app running in the background  are attempting to kick of an executable installed somehow. This has been deleted or is being blocked by some antimalware software.

Do you have some logs of recent malware removal?
Avatar of Jack Murphy

ASKER

I do not....
Has Malware recently been detected or removed?
I removed a retired Citrix XenApp recently, and the uninstall did not go well.    

I have not had any hits on any of my anti-virus programs.

Scanned by both Webroot SecureAnywhere and Malwarebytes.
I just ran rogue killer and received this report:

RogueKiller V12.12.6.0 (x64) [Feb 26 2018] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows Server 2008 R2 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : mackeyadmin [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 02/27/2018 22:10:00 (Duration : 00:34:00)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 31 ¤¤¤
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\OpenIt Open It! -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.bing.com/?pc=U280  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.bing.com/?pc=U280  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://companyweb  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://companyweb  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://companyweb  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://companyweb  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{237B4018-7219-46CA-A4C1-CEB15C44C8AA} | NameServer : 10.56.1.11 ([])  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{237B4018-7219-46CA-A4C1-CEB15C44C8AA} | NameServer : 10.56.1.11 ([])  -> Found
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0  -> Found
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1156\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyPics : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyMusic : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212722-1579682251-1899497987-1173\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 3 ¤¤¤
[PUP.Gen1][Folder] C:\Users\mackeyadmin\AppData\Roaming\Download Manager -> Found
[PUP.Gen1][Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Open It! -> Found
[PUP.Gen1][File] C:\$Recycle.Bin\S-1-5-21-525212722-1579682251-1899497987-1168\$REE3LBR.lnk [LNK@] C:\PROGRA~2\OpenIt\OPENIT~1\openit.exe -> Found

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: VMware Virtual disk SCSI Disk Device +++++
--- User ---
[MBR] 14557b1e5ea79518ec56d3163cfc4700
[BSP] 25b0f044c1698d1ed2a53ce231053087 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 190361 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([1] Incorrect function. )
ASKER CERTIFIED SOLUTION
Avatar of Jack Murphy
Jack Murphy
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Received an answer from another thread / question I created.

See the answer at this link:

https://www.experts-exchange.com/questions/29086478/Anyone-know-how-why-I-cannot-open-exe-files-after-a-malware-removal.html