Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hello, please bare with me here as i try to explain this, i am new to computers, this is the problem!
Win95 O/S) I received a virus on my computer today which McAfee picked up. It was the Backdoor-g trojan horse virus.
Since that happened I have not been able to open any programs with .exe extension. When I do, the computer says it cannot find the windos.exe file which it needs to open the file. The windos.exe is not a real win/95 file, it is the file that housed the virus. In the file types list in WinExlplorer under application it says that windos.exe is the file that is used to open applications. This is not what it says on other computers I checked. Unfortunately the .exe file type is not allowed to be edited. Does anyone know how to edit this in order to put it back to normal.
The files on my computer still run if they are launched in a different manner. e.g. If i click on an .mp3 file or .txt file in explorer then Winamp or Notepad etc. will open. But if I try to launch Winamp or Notepad etc. from their icon then this does not work. Same with windows explorer, it won't open from the start list, but if I hit the windows key & the 'E' then it opens.In searching for a way to fix this, i came across a post that says how to fix the problem, the porblem is that it's way over my head and i don't understand how to do the procedure, this is what the post said
"hi,
if u want to remove a backdoor the easy way then get the client and log into the server and use the option "REMOVE SERVER"!!!!!!!!
i know u can do this with backdoor-g because i have tryed it!!to get the client goto the website at
http://subseven.slak.org/newclient.zip
this is a link to the client only!!! it doesnt include the server and isnt patched with a server!!!!if u have that run.exe prob after removing it with a virus scanner or by just deleting the file the make a new file called ***.reg and copy and past this into it------------------
REGEDIT4
[HKEY_CLASSES_ROOT\.exe]
"Content Type"="application/x-msdownload"
@="exefile"[HKEY_CLASSES_ROOT\exefile]
"EditFlags"=hex:d8,07,00,00
@="Application"[HKEY_CLASSES_ROOT\exefile\shell]
@=""[HKEY_CLASSES_ROOT\exefile\shell\open]
@=""
"EditFlags"=hex:00,00,00,00[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@="%1"[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe]
"Content Type"="application/x-msdownload"
@="exefile"[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile]
"EditFlags"=hex:d8,07,00,00
@="Application"[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell]
@=""[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open]
@=""
"EditFlags"=hex:00,00,00,00[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
@="\"%1\" %*"[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DefaultIcon]
@="%1"
--------------------------------------------then save, exit and run the file.!!!
Friends, is there an easier way for me to fix the problem then doing what that man explained? please help. thank you for taking the time to read
Regards
Mike Newbie

Yep there is an easier way. First of all if you are new you probobly shouldn't be messing around in the registry.
You could save all your data and then format your drive using the format command at the dos prompt. This will erase your hard drive and you can then start over. the command looks like this.
c:\format /s c:
If you need more info E-Mail me. Good luck

Thanks for the quick reply, i really didn't want to reformat my entire hard drive, if that's the only other option i guess it would just be best to get someone here who knows how to do that procedure explained that i don't understand. Do computer stores offer on location service if your willing to pay?

If you are going to Format your Drive, do a backup of the data you want. When you are prepared to format try the registry trick, experiment, If it works, Yay no Format, if it doesn't you are prepared and you have also learnt a bit about the registry
I will compile the reg entries into a file and send it to ya, I hope you found the right fix for your Operating System
While ya waiting, make sure you have a start up disk that works,
P.S you may want to obtain a Win98 startup disk (It will boot your CD)

I was just thinking, even if were to save and reformat like you said, i would not be able to get into my word pad documents because they wont open, is there any file i can download that would allow me to once again open .exe extension files?

that is a sub7 trojan!
before you reformat..take a look here!
its a PAIN! BUT....better than a reformat!http://discussions.virtualdr.com/Forum2/HTML/013778.html
read carefully and follow all links if necessary! take your time!

This could be a simpler way to dump it? if you'd like to try it?
Step 1.
Click START | RUN
Type SYSEDIT and press ENTERStep 2.
Click on the SYSTEM.INI file and look at the "shell=Explorere.exe" line under the [boot] section. There shouldn't be anything to the right of it. However, if yours looks like "shell=Explorer.exe Task_Bar.exe", then Task_Bar.exe is the server portion of the trojan.Delete Task_Bar.exe from the line, save the change. Skip to the END.
Step 3.
Click on the WIN.INI file and look at the run= and load= lines under the [windows] section. Because it is common to have legitimate programs on either of these lines. You should look at the name of the file that appears on the line and compare it to those above.If you find one, delete it from the line, save the change. Skip to the END
The third and fourth locations - The RegistryStep 1.
Click START | RUN
Type REGEDIT and press ENTERStep 2.
In the left window, click the "+" (plus sign) to the left of the following:
HKEY_LOCAL_MACHINE
Software
Microsoft
Windows
CurrentVersion
RunStep 3.
In the right window, look for a key that has a Value that loads one of the files listed above. If you don't find a file as listed above, it might mean that the server portion was renamed to something else. Note the names of any suspicious files.What you will need to do, is open Windows Explorer and go to the WINDOWS directory. Locate each of the suspicious files that were referenced within the right window of regedit. When you find the file that's 328Kb in size. You've probably found the renamed server portion of SubSeven.
Step 4.
Return to the registry and in the right window, highlight the key that loads the file and hit the DELETE key. Answer YES to delete the entry.Step 5.
Exit the Registry and reboot your computer.Step 6.
After the computer has restarted, open Windows ExplorerStep 7.
Go to the WINDOWS directory and look for the suspicious file(windos.exe etc etc). Once you've found the file, DELETE it.Step 8.
Exit Windows Explorer.
that ought to do it!

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |