Jack Murphy
asked on
TS Server 2008 R2 will not open any applications. This File does not have a program associated with it for performing this action.......
ASKER
I do not....
Has Malware recently been detected or removed?
ASKER
I removed a retired Citrix XenApp recently, and the uninstall did not go well.
I have not had any hits on any of my anti-virus programs.
Scanned by both Webroot SecureAnywhere and Malwarebytes.
I have not had any hits on any of my anti-virus programs.
Scanned by both Webroot SecureAnywhere and Malwarebytes.
ASKER
I just ran rogue killer and received this report:
RogueKiller V12.12.6.0 (x64) [Feb 26 2018] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows Server 2008 R2 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : mackeyadmin [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKil ler64.exe
Mode : Scan -- Date : 02/27/2018 22:10:00 (Duration : 00:34:00)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 31 ¤¤¤
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Softwar e\Microsof t\Windows\ CurrentVer sion\Unins tall\OpenI t Open It! -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Internet Explorer\Main | Start Page : http://www.bing.com/?pc=U280 -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Internet Explorer\Main | Start Page : http://www.bing.com/?pc=U280 -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Internet Explorer\Main | Default_Page_URL : http://companyweb -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Internet Explorer\Main | Default_Page_URL : http://companyweb -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Internet Explorer\Main | Default_Page_URL : http://companyweb -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Internet Explorer\Main | Default_Page_URL : http://companyweb -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ ControlSet 001\Servic es\Tcpip\P arameters\ Interfaces \{237B4018 -7219-46CA -A4C1-CEB1 5C44C8AA} | NameServer : 10.56.1.11 ([]) -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ ControlSet 002\Servic es\Tcpip\P arameters\ Interfaces \{237B4018 -7219-46CA -A4C1-CEB1 5C44C8AA} | NameServer : 10.56.1.11 ([]) -> Found
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Softwar e\Microsof t\Windows\ CurrentVer sion\Polic ies\System | ConsentPromptBehaviorAdmin : 0 -> Found
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Softwar e\Microsof t\Windows\ CurrentVer sion\Polic ies\System | ConsentPromptBehaviorAdmin : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyPics : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyMusic : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyGames : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowRecentDocs : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowSetProgramAccess AndDefault s : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyPics : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyMusic : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyGames : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowRecentDocs : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1156 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowSetProgramAccess AndDefault s : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyPics : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyMusic : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyGames : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowRecentDocs : 0 -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowSetProgramAccess AndDefault s : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyPics : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyMusic : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowMyGames : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowRecentDocs : 0 -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212 722-157968 2251-18994 97987-1173 \Software\ Microsoft\ Windows\Cu rrentVersi on\Explore r\Advanced | Start_ShowSetProgramAccess AndDefault s : 0 -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 3 ¤¤¤
[PUP.Gen1][Folder] C:\Users\mackeyadmin\AppDa ta\Roaming \Download Manager -> Found
[PUP.Gen1][Folder] C:\ProgramData\Microsoft\W indows\Sta rt Menu\Programs\Open It! -> Found
[PUP.Gen1][File] C:\$Recycle.Bin\S-1-5-21-5 25212722-1 579682251- 1899497987 -1168\$REE 3LBR.lnk [LNK@] C:\PROGRA~2\OpenIt\OPENIT~ 1\openit.e xe -> Found
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: VMware Virtual disk SCSI Disk Device +++++
--- User ---
[MBR] 14557b1e5ea79518ec56d3163c fc4700
[BSP] 25b0f044c1698d1ed2a53ce231 053087 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 190361 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([1] Incorrect function. )
RogueKiller V12.12.6.0 (x64) [Feb 26 2018] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com
Operating System : Windows Server 2008 R2 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : mackeyadmin [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKil
Mode : Scan -- Date : 02/27/2018 22:10:00 (Duration : 00:34:00)
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 31 ¤¤¤
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Softwar
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Softwar
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Softwar
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-525212
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 3 ¤¤¤
[PUP.Gen1][Folder] C:\Users\mackeyadmin\AppDa
[PUP.Gen1][Folder] C:\ProgramData\Microsoft\W
[PUP.Gen1][File] C:\$Recycle.Bin\S-1-5-21-5
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: VMware Virtual disk SCSI Disk Device +++++
--- User ---
[MBR] 14557b1e5ea79518ec56d3163c
[BSP] 25b0f044c1698d1ed2a53ce231
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 190361 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([1] Incorrect function. )
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Received an answer from another thread / question I created.
See the answer at this link:
https://www.experts-exchange.com/questions/29086478/Anyone-know-how-why-I-cannot-open-exe-files-after-a-malware-removal.html
See the answer at this link:
https://www.experts-exchange.com/questions/29086478/Anyone-know-how-why-I-cannot-open-exe-files-after-a-malware-removal.html
Do you have some logs of recent malware removal?