I recently received an email from a co-worker that said Malwarebytes was the source of a particularly vexing problem that’s been encountered recently. The problem is that once someone has been infected with one of those fake Security Centre viruses, and subsequently cleaned and rebooted, no programs will launch. This didn’t sit right with me, so I decided to investigate a bit. I’ve confirmed that Malwarebytes is not the cause of this issue. Well, at least not directly.
By confirmed I mean that the root cause of the issue is present before any anti-malware work is done on a computer that will eventually exhibit this issue. I’ve tested this on three machines that were infected, one accidentally infected physical machine and on two purposefully infected VM’s (XP and 7) I have.
Short version:
The problem
The issue is caused by this latest security centre virus variant, and when Malware Bytes removes the infection the associations that it sets are removed, and can no longer be run.
The fix:
WARNING: Don’t muck about in the registry if you’re not sure how it works, don’t edit anything that ‘doesn’t look right’ without checking that it isn’t right first. You should know this, but I don’t want people yelling at me when they just followed the short version and broke something.
Open up regedit and make sure HKCR\.exe points to exefile and that the command extensions for exefile are set to “%1” %*
The looooooong version:
Seriously, unless you actually care how the Windows registry works and are interested in some registry information this is for sure tl;dr. Read More »
Posted by RobbieCrash / nerd