techPowerUp! Forums

Go Back   techPowerUp! Forums > Software > General Software

Reply
 
Thread Tools
Old Feb 21, 2010, 05:31 PM   #1
Kantastic
3500 Posts
 
Kantastic's Avatar
 
Join Date: May 2009
Location: The Big Apple
Posts: 4,976 (3.39/day)
Thanks: 1,252
Thanked 930 Times in 739 Posts

System Specs

Hi I'm a virus magnet.

My dads lappy was infected with some trojans (Avast! was disabled/not working and wouldn't start) so I did what I usually do and yanked the HDD out and blasted the viruses to hell with Kaspersky on my comp, but when I put the HDD back in the laptop and tried to run some apps (like internet explorer/calculator/paint) it kept asking me what program I wanted to use to open the.. program.

If you guys need pictures let me know, I'm not sure how I can take a pic when paint won't open.
__________________
Heatware
Kantastic is offline  
Reply With Quote
Old Feb 21, 2010, 05:34 PM   #2
Exeodus
500 Posts
 
Exeodus's Avatar
 
Join Date: Oct 2005
Location: A suburb of Chicago, IL
Posts: 581 (0.21/day)
Thanks: 196
Thanked 156 Times in 88 Posts

System Specs

Did you try to run the application from the directory on the hard drive?
Exeodus is offline  
Reply With Quote
Old Feb 21, 2010, 05:35 PM   #3
Kantastic
3500 Posts
 
Kantastic's Avatar
 
Join Date: May 2009
Location: The Big Apple
Posts: 4,976 (3.39/day)
Thanks: 1,252
Thanked 930 Times in 739 Posts

System Specs

Quote:
Originally Posted by Exeodus View Post
Did you try to run the application from the directory on the hard drive?
Just did, wouldn't work.

PS - What's ssvagent.exe?
__________________
Heatware
Kantastic is offline  
Reply With Quote
Old Feb 21, 2010, 05:40 PM   #4
Exeodus
500 Posts
 
Exeodus's Avatar
 
Join Date: Oct 2005
Location: A suburb of Chicago, IL
Posts: 581 (0.21/day)
Thanks: 196
Thanked 156 Times in 88 Posts

System Specs

It looks like part of a Java update.
Exeodus is offline  
Reply With Quote
The Following User Says Thank You to Exeodus For This Useful Post:
Old Feb 21, 2010, 05:43 PM   #5
Exeodus
500 Posts
 
Exeodus's Avatar
 
Join Date: Oct 2005
Location: A suburb of Chicago, IL
Posts: 581 (0.21/day)
Thanks: 196
Thanked 156 Times in 88 Posts

System Specs

Do you have any system restore points you can try? But keep in mind the virus might have placed itself in the restore file so that it puts itself back on when you go to a previous restore point.
Exeodus is offline  
Reply With Quote
The Following User Says Thank You to Exeodus For This Useful Post:
Old Feb 21, 2010, 05:44 PM   #6
newmodder
500 Posts
 
newmodder's Avatar
 
Join Date: Sep 2005
Location: british columbia
Posts: 606 (0.22/day)
Thanks: 2
Thanked 7 Times in 7 Posts
Send a message via MSN to newmodder

System Specs

try windows repair option,and yes that file is part of java update..try uninstalling java and reinstall
__________________
phenom 9950 x4 black edition
msi ms-7309
BFG GTX 260 Maxcore
2 gb ddr
Sony dvd r/rwLogitech x530 spkrs 6.1
160gig sata2/Antec 550 watt psu
newmodder is offline  
Reply With Quote
The Following User Says Thank You to newmodder For This Useful Post:
Old Feb 21, 2010, 05:50 PM   #7
Kantastic
3500 Posts
 
Kantastic's Avatar
 
Join Date: May 2009
Location: The Big Apple
Posts: 4,976 (3.39/day)
Thanks: 1,252
Thanked 930 Times in 739 Posts

System Specs

Uninstalling Java didn't do any good, and right now I can't open IE so reinstalling isn't an option. I'll try the recovery but first I need to back up some stuff.

Edit: Sunnuvagun! System restore gives me the same "Open With" popup. Next up, system recovery!
__________________
Heatware
Kantastic is offline  
Reply With Quote
Old Feb 21, 2010, 06:00 PM   #8
Boyfriend
75 Posts
 
Join Date: Nov 2008
Posts: 128 (0.08/day)
Thanks: 33
Thanked 35 Times in 32 Posts

System Specs

Here are some of the tips to restore the windows to work properly:

1. Download Virus Effect Remover 3.2.1.26 from MajorGeeks. It is free, use it to restore most of the settings to default/working condition.
2. Open Control Panel --> Programs --> Default Programs and set your defaults.
3. There is a program named File Association Fixer. Use to fix association problems.
4. Restore IE to default in Tools --> Internet Options --> Advanced --> Reset Advance Settings. Also reset security zone to defaults. This will not damage his bookmarks/favourites
5. Check startup programs. Either use msconfig utility or Autoruns.
6. Make sure to install good Antivirus and update it regularly (automatic is good option).
7. Delete all previous restore points. They are useless as virus might have rendered them useless
8. Symantec has developed UnHookExec to restore registry and some association to typical default. Try it
9. Need more help. Ask here or PM

Which version of IE are you using? Update it if you are on IE 6/7. If IE 8, you can reinstall it. BTW, you haven't mentioned his OS

Last edited by Boyfriend; Feb 21, 2010 at 06:07 PM. Reason: System restore is useless if real virus hits
Boyfriend is offline  
Reply With Quote
The Following User Says Thank You to Boyfriend For This Useful Post:
Old Feb 21, 2010, 06:04 PM   #9
Kantastic
3500 Posts
 
Kantastic's Avatar
 
Join Date: May 2009
Location: The Big Apple
Posts: 4,976 (3.39/day)
Thanks: 1,252
Thanked 930 Times in 739 Posts

System Specs

Quote:
Originally Posted by Boyfriend View Post
Here are some of the tips to restore the windows to work properly:

1. Download Virus Effect Remover 3.2.1.26 from MajorGeeks. It is free, use it to restore most of the settings to default/working condition.
2. Open Control Panel --> Programs --> Default Programs and set your defaults.
3. There is a program named File Association Fixer. Use to fix association problems.
4. Restore IE to default in Tools --> Internet Options --> Advanced --> Reset Advance Settings. Also reset security zone to defaults. This will not damage his bookmarks/favourites
5. Check startup programs. Either use msconfig utility or Autoruns.
6. Make sure to install good Antivirus and update it regularly (automatic is good option).
7. Delete all previous restore points. They are useless as virus might have rendered them useless
8. Need more help. Ask here or PM

Which version of IE are you using? Update it if you are on IE 6/7.


The problem here (after xferring some of the programs you mentioned to the laptop via USB) is that none of them will open. They all give me the "Open With" popup.

I'm using IE 8.
__________________
Heatware
Kantastic is offline  
Reply With Quote
Old Feb 21, 2010, 06:05 PM   #10
blkhogan
1000 Posts
 
blkhogan's Avatar
 
Join Date: Aug 2007
Location: If I told u.. I'd have to kill u
Posts: 1,845 (0.88/day)
Thanks: 823
Thanked 648 Times in 446 Posts

System Specs

Has it identified what viruses you are dealing with. We can help more if we knew what we are dealing with.
blkhogan is offline  
Reply With Quote
The Following User Says Thank You to blkhogan For This Useful Post:
Old Feb 21, 2010, 06:06 PM   #11
erocker
Senior Moderator
 
erocker's Avatar
 
Join Date: Jul 2006
Location: Milwaukee, WI.
Posts: 31,879 (12.78/day)
Thanks: 2,779
Thanked 12,249 Times in 7,804 Posts

System Specs

Sound like the virus took out some essential Windows files, explorer files, etc. If System Restore isn't getting it done, you'll probablly need to reinstall the O/S. Save your files.
erocker is offline  
Reply With Quote
The Following User Says Thank You to erocker For This Useful Post:
Old Feb 21, 2010, 06:07 PM   #12
Kantastic
3500 Posts
 
Kantastic's Avatar
 
Join Date: May 2009
Location: The Big Apple
Posts: 4,976 (3.39/day)
Thanks: 1,252
Thanked 930 Times in 739 Posts

System Specs

Quote:
Originally Posted by blkhogan View Post
Has it identified what viruses you are dealing with. We can help more if we knew what we are dealing with.
No idea what the exact virus is, I just checked Kaspersky's quarantine and got HEUR:Trojan.Script.IFramer.
__________________
Heatware
Kantastic is offline  
Reply With Quote
Old Feb 21, 2010, 06:08 PM   #13
Boyfriend
75 Posts
 
Join Date: Nov 2008
Posts: 128 (0.08/day)
Thanks: 33
Thanked 35 Times in 32 Posts

System Specs

What OS??
Boyfriend is offline  
Reply With Quote
Old Feb 21, 2010, 06:08 PM   #14
blkhogan
1000 Posts
 
blkhogan's Avatar
 
Join Date: Aug 2007
Location: If I told u.. I'd have to kill u
Posts: 1,845 (0.88/day)
Thanks: 823
Thanked 648 Times in 446 Posts

System Specs

http://malwarecrawler.com/?tag=detected
blkhogan is offline  
Reply With Quote
Old Feb 21, 2010, 06:09 PM   #15
Boyfriend
75 Posts
 
Join Date: Nov 2008
Posts: 128 (0.08/day)
Thanks: 33
Thanked 35 Times in 32 Posts

System Specs

Symantec has developed UnHookExec to restore registry and some associations to typical default. Try it. It will restore *.exe files execution.
Boyfriend is offline  
Reply With Quote
Old Feb 21, 2010, 06:10 PM   #16
Lazzer408
2000 Posts
 
Lazzer408's Avatar
 
Join Date: Jan 2007
Location: Illinois
Posts: 2,394 (1.03/day)
Thanks: 80
Thanked 320 Times in 242 Posts

System Specs

Try this. Paste between the lines into notepad. Save as exe_fix.reg run it merge the key then reboot.

__________________________________________________

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"
"IsolatedCommand"="\"%1\" %*"

__________________________________________________ _
__________________
Assuming the many universes theory of quantum mechanics is accurate, everything I say will remain relevant in another reality for all of eternity.

Heatware - http://www.heatware.com/user_directo...uery=lazzer408
Lazzer408 is offline  
Reply With Quote
The Following User Says Thank You to Lazzer408 For This Useful Post:
Old Feb 21, 2010, 06:11 PM   #17
blkhogan
1000 Posts
 
blkhogan's Avatar
 
Join Date: Aug 2007
Location: If I told u.. I'd have to kill u
Posts: 1,845 (0.88/day)
Thanks: 823
Thanked 648 Times in 446 Posts

System Specs

Quote:
Originally Posted by Lazzer408 View Post
Try this. Paste between the lines into notepad. Save as exe_fix.reg run it merge the key then reboot.

__________________________________________________

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"
"IsolatedCommand"="\"%1\" %*"

__________________________________________________ _
LoL. I was just typing that out. You beat me to it.
blkhogan is offline  
Reply With Quote
Old Feb 21, 2010, 06:11 PM   #18
oily_17
2000 Posts
 
oily_17's Avatar
 
Join Date: Sep 2006
Location: Norn Iron
Posts: 2,056 (0.85/day)
Thanks: 214
Thanked 679 Times in 516 Posts

System Specs

What OS is the laptop running ??
__________________

oily_17 is offline  
Reply With Quote
Old Feb 21, 2010, 06:12 PM   #19
Boyfriend
75 Posts
 
Join Date: Nov 2008
Posts: 128 (0.08/day)
Thanks: 33
Thanked 35 Times in 32 Posts

System Specs

Open notepad and copy following text

[Version]
Signature="$Chicago$"

[DefaultInstall]
AddReg=UnhookRegKey

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"reg edit.exe ""%1"""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""% 1"" %*"
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies \System,DisableRegistryTools,0x00000020,0

Save it as "Restore.inf" and right click and select install.
Boyfriend is offline  
Reply With Quote
Old Feb 21, 2010, 06:13 PM   #20
blkhogan
1000 Posts
 
blkhogan's Avatar
 
Join Date: Aug 2007
Location: If I told u.. I'd have to kill u
Posts: 1,845 (0.88/day)
Thanks: 823
Thanked 648 Times in 446 Posts

System Specs

Quote:
Originally Posted by Boyfriend View Post
Open notepad and copy following text

[Version]
Signature="$Chicago$"

[DefaultInstall]
AddReg=UnhookRegKey

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"reg edit.exe ""%1"""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""% 1"" %*"
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies \System,DisableRegistryTools,0x00000020,0

Save it as "Restore.inf" and right click and select install.
Ive heard of "unhook", have you actually used it? Does it work?
blkhogan is offline  
Reply With Quote
Old Feb 21, 2010, 06:14 PM   #21
Boyfriend
75 Posts
 
Join Date: Nov 2008
Posts: 128 (0.08/day)
Thanks: 33
Thanked 35 Times in 32 Posts

System Specs

It works very well on systems having severe file association problems. I have used it to restore things back on some clients computers.

He should at least mention his OS
Boyfriend is offline  
Reply With Quote
The Following User Says Thank You to Boyfriend For This Useful Post:
Old Feb 21, 2010, 06:17 PM   #22
Kantastic
3500 Posts
 
Kantastic's Avatar
 
Join Date: May 2009
Location: The Big Apple
Posts: 4,976 (3.39/day)
Thanks: 1,252
Thanked 930 Times in 739 Posts

System Specs

Quote:
Originally Posted by Boyfriend View Post
What OS??
Vista Home Premium 32bit

Working on everything else right now, will post updates when finished.
__________________
Heatware
Kantastic is offline  
Reply With Quote
Old Feb 21, 2010, 06:18 PM   #23
oily_17
2000 Posts
 
oily_17's Avatar
 
Join Date: Sep 2006
Location: Norn Iron
Posts: 2,056 (0.85/day)
Thanks: 214
Thanked 679 Times in 516 Posts

System Specs

Bookmark this, for some file ext fixes -

http://www.winhelponline.com/article...ows-Vista.html
__________________

oily_17 is offline  
Reply With Quote
Old Feb 21, 2010, 06:20 PM   #24
Kantastic
3500 Posts
 
Kantastic's Avatar
 
Join Date: May 2009
Location: The Big Apple
Posts: 4,976 (3.39/day)
Thanks: 1,252
Thanked 930 Times in 739 Posts

System Specs

Quote:
Originally Posted by Lazzer408 View Post
Try this. Paste between the lines into notepad. Save as exe_fix.reg run it merge the key then reboot.

__________________________________________________

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"
"IsolatedCommand"="\"%1\" %*"

__________________________________________________ _
Failed! =[

Quote:
Originally Posted by oily_17 View Post
What OS is the laptop running ??
Vista Home Premium 32bit

Quote:
Originally Posted by Boyfriend View Post
Open notepad and copy following text

[Version]
Signature="$Chicago$"

[DefaultInstall]
AddReg=UnhookRegKey

[UnhookRegKey]
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""% 1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"reg edit.exe ""%1"""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""% 1"" %*"
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies \System,DisableRegistryTools,0x00000020,0

Save it as "Restore.inf" and right click and select install.
Failed!
__________________
Heatware
Kantastic is offline  
Reply With Quote
Old Feb 21, 2010, 06:20 PM   #25
pantherx12
Eligible for custom title
 
pantherx12's Avatar
 
Join Date: Jan 2009
Location: ENGLAND-LAND-LAND
Posts: 8,443 (5.29/day)
Thanks: 1,188
Thanked 1,705 Times in 1,375 Posts

System Specs

Sounds like when you took the virsues out they took some of the files out with them, damn embed viruses!
pantherx12 is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus - Please solve me how to deal with this virus freebird_9924 General Software 72 Dec 3, 2009 03:03 AM
Dust magnet? NONYA General Hardware 7 Feb 5, 2008 03:50 AM
virus replace wallpaper with fake virus protection advertisement HiddenStupid General Software 2 Dec 23, 2007 09:00 PM
New Magnet Keyboard Concept Floats Keys Easy Rhino News 8 Jul 28, 2007 11:14 PM


All times are GMT. The time now is 05:13 AM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts