Media Player activates with any .exe file

Solved/Closed
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015 - Mar 31, 2015 at 06:33 PM
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015 - Apr 2, 2015 at 06:32 PM
I have updated Java and somehow it attached itself to the Windows Media Player. So, any file on my computer is useless as it brings up the media player.
So I uninstalled all Java programs. I uninstalled Windows Media Player.
Neither programs reside on my computer anywhere.
But still windows media player activates with any .exe file.
It has changed a lot of my icons to windows media icons.
I have a suspicion the problem resides in the registry. Regedit will not activate, only windows media player. I don't know if this is even fixable without a complete re-install.
I managed to get Avast to scan with a rescue disk. It found 113 infected files and deleted them. Still the problem exists. Please Help!
Related:

5 responses

Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Mar 31, 2015 at 06:37 PM
Hello,

I would love to help you but I must log off till the morning.

In the meantime, if you wish:

To help you and prescribe the remedy, I must make a diagnostic and to do so, I require a log.

1. Open this link and download ZHPDiag2 :

https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

(Don't be alarmed is the site is in French, it sometimes happens, the tool will take your system language and allow the download if you get a warning message, ignore it.)

2. Save the file on your Desktop.

3. Double click on ZHPDiag.exe and follow the installation instructions.

(For Vista and Win 7 users, click right to ensure you execute with admin right)

The tool creates three icons ZHPDiag, MRB, and ZHPFix (If necessary,we will use ZHPFix after log analysis).

4. Double click on the short cut ZHPDiag on your Destktop.

5. If you need to change the language, click on the little house, (bottom right) and change to English

6. Click on Full.

Wait for the tool to finished (maybe a long time)

7. Close ZHPDiag.

8. To transmit the report, click on this link :

https://authentification.site

9. Search the directory where you installed ZHPDiag (usually C:\desktop\zhpdiag.txt).
Ambucias
Moderator and Virus/Security Contributor
1
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Apr 1, 2015 at 05:09 AM
What is your operating system?
1
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 1, 2015 at 08:28 AM
Windows 7 Home Premium
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169 > hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 1, 2015 at 04:11 PM
Can you launch ZPH Diag by clicking right to run as administrator?
If not can, you boot in safe mode with networking (tapping F8 while restarting) ?
If not, can you open your task manager (alt+ctrl+del) ?
0
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 1, 2015 at 05:27 PM
Neither of those three options work. The virus simply will not let me in. I'm sure there's a back door some where but I can't find it.
I am about ready to give up as unsolvable, replace the hard drive and reload system. I don't know what this virus is, but it's well hidden.
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169 > hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 1, 2015 at 05:44 PM
Don't despair. Have I given-up? Have a nice cup of Earl Grey tea and sip it while taking deep breaths.
Remind me of your operating system.
Remind me of the make and model of your computer.
Do you have access to your files, like through explorer to be able to read a pen drive?
0
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 1, 2015 at 05:56 PM
OK, Operating system is Windows 7 Home Premium, Computer is Lenovo G780, i5 processor, 16gb ram. I can get to my files thru "start, computer", and can access all my files. I can bring up any file except an .exe file.
0
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Mar 31, 2015 at 06:44 PM
It is in french and I don't know what to click on
0
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Mar 31, 2015 at 06:55 PM
I got it downloaded and saved to my desktop. However when I double click it, it brings up the Windows Media Player. Any .exe file will do that. Drat!
0

Didn't find the answer you are looking for?

Ask a question
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Apr 1, 2015 at 06:18 PM
Okay,

This a last resort solution and nobody else on this forum should try it unless I advise it. It is at their own risk an peril.

1. Download Combofix on your desktop. (if it

https://www.bleepingcomputer.com/download/combofix/

(click on the download @ bleeping computer button)

2.Close all open Windows including this one.

Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix.

3. Double click on the ComboFix icon.

Windows is issuing this prompt because ComboFix does not have a digital signature. This is perfectly normal and safe and you can click on the Run button to continue.

If Combofix gets you to Media Player, download it to a pen drive and launch it from there.

4. Accept the disclaimer and the recovery

5.You should now press the Yes button to continue. If at any time during the Recovery Console installation you receive a message stating that it failed to install, please allow ComboFix to continue with the scan of your computer.

ComboFix will disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.

While the program is scanning your computer, it will change your clock format, so do not be concerned when you see this happen. When ComboFix is finished it will restore your clock settings to their previous settings.

If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.

During the process, please do not mouse click nor must you tap on the keyboard. Let the tool run.

Good luck
0
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 1, 2015 at 06:29 PM
I'll give it a try...nothing else to loose. Thanks
0
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 1, 2015 at 06:43 PM
I have done as suggested. It will not launch from desktop OR a thumb drive. Both give me the Media Player.
I give up! Thanks for your help. I'm scrapping the HD, replacing it with a TB and reloading the system. I don't think this is solvable, nothing personal on your part. You have been very responsive to my problem.
Thanks Ambucias
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169 > hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 2, 2015 at 03:52 AM
Why not restore to factory settings?
0
hookset Posts 9 Registration date Tuesday March 31, 2015 Status Member Last seen April 2, 2015
Apr 2, 2015 at 06:32 PM
Thank you Ambucias and everyone who was involved in my problem. You have all been so responsive to my needs. Thank you more than I can say.
0