Xander
05-23-2010, 10:46 PM
Fellow calls me up around noon asking for a housecall; seems he's infected himself with a fake AV. The laptop was a simple infection, found a jibberish filename, end process, delete file. Scan.
The desktop was pretty similar but here's the fun part: He'd gone online and someone had convinced him that he could 'patch' Windows and to paste what I'm assuming was a VBS into Notepad, save and run it. He alleges it turned off the fake AV for a while but all the EXEs started opening in Notepad.
Got rid of the fake AV by renaming combofix to a .com; it couldn't run half its stuff but still did the job.
Fixing the EXE was another matter. Regedit wouldn't open nor would it accept renaming to .com; merging my emergency "exe file association" reg file didn't work either.
I tried a few command line tricks including: assoc.exe=exefile ... nothing. Twas already set to that.
Thinking it might have been a per-user setting, I created a new user profile and logged into that. Right off the bat, it tried to open things in notepad. Fail.
In the end, I logged into Safe Mode w/CMD and got System Restore to run, rolling it back to before he'd run the VBS. Since System Restore ran, and before it did its thing, I opened up Regedit and the associations were fine (of course they were, since I was able to open Regedit and SysRest).
I set him, secondarily, with SAS Pro, Dropbox to keep his files safe, Firefox (over IE) with Weave to sync his bookmarks to the laptop. He was more than pleased with the results and threw another 40% on the bill as a tip.
I'm trying to think of what I might have missed with the association. I hate resorting to System Restore so who has ideas on what else might have worked?
The desktop was pretty similar but here's the fun part: He'd gone online and someone had convinced him that he could 'patch' Windows and to paste what I'm assuming was a VBS into Notepad, save and run it. He alleges it turned off the fake AV for a while but all the EXEs started opening in Notepad.
Got rid of the fake AV by renaming combofix to a .com; it couldn't run half its stuff but still did the job.
Fixing the EXE was another matter. Regedit wouldn't open nor would it accept renaming to .com; merging my emergency "exe file association" reg file didn't work either.
I tried a few command line tricks including: assoc.exe=exefile ... nothing. Twas already set to that.
Thinking it might have been a per-user setting, I created a new user profile and logged into that. Right off the bat, it tried to open things in notepad. Fail.
In the end, I logged into Safe Mode w/CMD and got System Restore to run, rolling it back to before he'd run the VBS. Since System Restore ran, and before it did its thing, I opened up Regedit and the associations were fine (of course they were, since I was able to open Regedit and SysRest).
I set him, secondarily, with SAS Pro, Dropbox to keep his files safe, Firefox (over IE) with Weave to sync his bookmarks to the laptop. He was more than pleased with the results and threw another 40% on the bill as a tip.
I'm trying to think of what I might have missed with the association. I hate resorting to System Restore so who has ideas on what else might have worked?