View Full Version : File association in vista - teatimer problem
aarongroves103
2008-03-28, 22:06
Hi,
When i booted up my computer the teatimersa registry thing went crazy. I denied all the changes but only shortly after i got the message on everything i open ... "the file does not have a program associated with it for performing this action".
Im sure its to do with the file association however i foolishly thought that removing spybot would solve this but unfortunatley it didnt so now im stuck with a laptop that cant open anything...
please please help as this is driving me crazy...
I have a site with file association fixes for Vista,but we should look and see what is needed first,so looking at your resident log might help.
Could you please post your resident.log?You probably can't open Spybot,so please follow this path to it:
C:\ProgramData\Spybot - Search & Destroy\Logs
ProgramData is a hidden folder,so please follow this if you cannot see it:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html#vista
(You can rehide hidden files and folders once you're done by reversing those instructions.)
Once you're at the C:\ProgramData\Spybot - Search & Destroy\Logs sction,please doubleclick Resident.log,go to edit,then Select All,then go to edit once again and select Copy,then paste it here.
aarongroves103
2008-03-29, 14:09
Hi, thanks for the reply but i only have the plugins folder which hosts a load of .dll files!
Did you go into ProgramData,or did you go into Program Files?
Were you having any other problems on your computer around the time teatimer prompted you?
All right,since nothing will open on your computer,it's a pretty safe bet that you may need to fix .exe files so you could give this a try.Please go here:
http://www.winhelponline.com/articles/105/1/File-association-fixes-for-Windows-Vista.html
Click on exe and save it to your desktop.Rightclick exe_fixvista.zip,then select Extract All...,and make sure 'Show extracted files when complete' is checkmarked.Then,doubleclick exefix_vista.reg.You may get a security warning,please select Run to continue.Then,User Account control may prompt you,please select Continue to continue,then you will probably get a window entitled Registry Editor asking if you'd like to continue,select Yes if you would like to continue.This will hopefully fix .exe file associations.Please post back and let me know how it all goes,and let me know if you were in Program Files or Program Data.
aarongroves103
2008-03-30, 23:07
Hi! Ive tried, the .reg file wont extract as it does the same thing, the dreaded error message comes up! Arghhh this is driving me crazy!
Yes,I know this is difficult and frustrating,it's a bit of a doozy.I know of an app that helps scan,find and fix file associations,but changing it to the .com extension isn't working out for me on Vista,so I do not want to use it here if it isn't working out for me.
It would be easier if I could see what file association problems there are on your computer.The resident.log does show a log of Teatimer's actions,so seeing that would help out a lot.
When uninstalling Spybot,I believe that the resident.log should stay on your computer unless you went in and removed it.So,that is why it would be helpful if you clarified where you were when you saw just a plugins folder,were you in ProgramData,or were you in Program Files\Spybot - Search & Destroy?
aarongroves103
2008-03-31, 17:06
Hi, ive managed to reinstall spybot - basically when I left click it gives me the option to run as administrator and so I can run a limited number of apps which means I could possibly sort out the tea timer. ANy ideas? I cant find where its stored...
aarongroves103
2008-03-31, 17:07
Ahhhh! Here is the list of logs!
24/03/2008 21:25:08 Denied (based on user decision) value "FlashPlayerUpdate" (new data: "C:\Windows\system32\Macromed\Flash\GetFlash.exe") added in System Startup user entry!
25/03/2008 10:11:04 Allowed (based on user decision) value "IDMan" (new data: "") deleted in System Startup user entry!
25/03/2008 11:21:18 Allowed (based on user decision) value "{6414512B-B978-451D-A0D8-FCFDF33E833C}" (new data: "") deleted in ActiveX Distribution Unit!
25/03/2008 11:21:19 Allowed (based on user decision) value "{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}" (new data: "") deleted in ActiveX Distribution Unit!
25/03/2008 14:15:28 Denied (based on user decision) value "IDMan" (new data: "C:\Program Files\Internet Download Manager\IDMan.exe /onboot") added in System Startup user entry!
26/03/2008 18:55:18 Denied (based on user decision) value "IDMan" (new data: "C:\Program Files\Internet Download Manager\IDMan.exe /onboot") added in System Startup user entry!
27/03/2008 10:36:02 Denied (based on user decision) value "IDMan" (new data: "C:\Program Files\Internet Download Manager\IDMan.exe /onboot") added in System Startup user entry!
27/03/2008 10:40:11 Allowed (based on user decision) value "BitTorrent DNA" (new data: ""C:\Program Files\DNA\btdna.exe"") added in System Startup user entry!
27/03/2008 18:04:22 Denied (based on user decision) value "WMPNSCFG" (new data: "C:\Program Files\Windows Media Player\WMPNSCFG.exe") added in System Startup user entry!
28/03/2008 00:27:25 Denied (based on user decision) value "WMPNSCFG" (new data: "C:\Program Files\Windows Media Player\WMPNSCFG.exe") added in System Startup user entry!
28/03/2008 01:46:26 Denied (based on user decision) value "IDMan" (new data: "C:\Program Files\Internet Download Manager\IDMan.exe /onboot") added in System Startup user entry!
28/03/2008 18:44:42 Allowed (based on authenticode whitelist) value "SpybotSD TeaTimer" (new data: "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe") added in System Startup user entry!
28/03/2008 18:45:19 Denied (based on user decision) value "BitTorrent DNA" (new data: ""C:\Program Files\DNA\btdna.exe"") added in System Startup user entry!
28/03/2008 18:45:20 Denied (based on user decision) value "Local Page" (new data: "C:\Windows\system32\blank.htm") added in Browser page!
28/03/2008 18:45:24 Denied (based on user decision) value "Search Page" (new data: "http://www.google.com") added in Browser page!
28/03/2008 18:45:25 Denied (based on user decision) value "Start Page" (new data: "http://www.google.com") added in Browser page!
28/03/2008 18:45:26 Denied (based on user decision) value "Local Page" (new data: "%SystemRoot%\system32\blank.htm") added in Browser page!
28/03/2008 18:45:26 Denied (based on user decision) value "Start Page" (new data: "http://www.google.com") added in Browser page!
28/03/2008 18:45:27 Denied (based on user decision) value "Default_Page_URL" (new data: "http://www.google.com") added in Browser page!
28/03/2008 18:45:27 Denied (based on user decision) value "SearchAssistant" (new data: "http://www.google.com/ie") added in Browser page!
28/03/2008 18:45:27 Denied (based on user decision) value "CustomizeSearch" (new data: "http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm") added in Browser page!
28/03/2008 18:45:28 Denied (based on user decision) value "" (new data: ""%1" %*") added in BAT Extension handler!
28/03/2008 18:45:28 Denied (based on user decision) value "" (new data: ""%1" %*") added in COM Extension handler!
28/03/2008 18:45:29 Denied (based on user decision) value "" (new data: ""%1" %*") added in EXE Extension handler!
28/03/2008 18:45:29 Denied (based on user decision) value "IsolatedCommand" (new data: ""%1" %*") added in EXE Extension handler!
28/03/2008 18:45:29 Denied (based on user decision) value "" (new data: ""%1" %*") added in PIF Extension handler!
28/03/2008 18:45:30 Denied (based on user decision) value "" (new data: ""%1" /S") added in SCR Extension handler!
28/03/2008 18:45:31 Denied (based on user decision) value "" (new data: "regedit.exe "%1"") added in REG Extension handler!
28/03/2008 18:45:31 Denied (based on user decision) value "" (new data: ""%1" %*") added in CMD Extension handler!
28/03/2008 18:45:32 Denied (based on user decision) value "load" (new data: "") added in NT startup!
28/03/2008 18:45:33 Denied (based on user decision) value "programs" (new data: "com exe bat pif cmd") added in NT startup!
28/03/2008 18:45:33 Denied (based on user decision) value "UserInit" (new data: "C:\Windows\system32\userinit.exe,") added in Winlogon!
28/03/2008 18:45:37 Denied (based on user decision) value "Shell" (new data: "explorer.exe") added in Winlogon!
md usa spybot fan
2008-03-31, 18:28
Hi! Ive tried, the .reg file wont extract as it does the same thing, the dreaded error message comes up! Arghhh this is driving me crazy!
Did you try the zip fix (http://www.winhelponline.com/fileasso/zipfix_vista.reg) so you can extract the other fixes?
Note: If you have problems executing the .reg file for the zip fix (http://www.winhelponline.com/fileasso/zipfix_vista.reg), perhaps the following technique which works in XP will also work in Vista:
If your EXE file associations are corrupted, it can be difficult to open REGEDIT, or to even import REG files. To work around this, press CTRL-ALT-DEL and open Task Manager. Once there, click File, then hold down the CTRL key and click New Task (Run). This will open a Command Prompt window. Enter REGEDIT.EXE and press Enter.
aarongroves103
2008-03-31, 22:39
Sorted it - I was able to open up the reg editor through tuneup, from there I was able to change the registry HKEY_CLASSES_ROOT\exefile\shell\open\command "%1" %*
as the default value wasnt set!
Anyway,. thanks for all your replies chaps, appreciate the help - its always nice to know help is at hand if needed.
Cheers
I'm glad you got the .exe problem fixed.You might possibly have problems with some other extensions,though.Would you like to check on those?
sklimberg5
2009-01-01, 04:39
Hi, I am having the same exact problem Aaron Groves was having. My Resident log on my laptop (I am operating on Vista) is:
12/16/2008 12:22:53 PM Denied (based on user decision) value "{DBC80044-A445-435b-BC74-9C25C1C588A9}" (new data: "") added in Browser Helper Object!
12/16/2008 12:22:59 PM Allowed (based on user decision) value "{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}" (new data: "") added in ActiveX Distribution Unit!
12/16/2008 12:23:09 PM Allowed (based on user decision) value "SunJavaUpdateSched" (new data: ""C:\Program Files\Java\jre6\bin\jusched.exe"") changed in System Startup global entry!
12/16/2008 12:23:20 PM Allowed (based on user decision) value "{DBC80044-A445-435b-BC74-9C25C1C588A9}" (new data: "") added in Browser Helper Object!
12/16/2008 1:26:30 PM Allowed (based on user decision) value "Add to Google Photos Screensa&ver" (new data: "") added in Browser menu extension!
12/16/2008 1:26:53 PM Allowed (based on user decision) value "Search Page" (new data: "http://www.google.com") changed in Browser page!
12/16/2008 1:26:56 PM Allowed (based on user decision) value "Search Bar" (new data: "http://www.google.com/ie") added in Browser page!
12/16/2008 1:26:57 PM Allowed (based on user decision) value "Default_Search_URL" (new data: "http://www.google.com/ie") added in Browser page!
12/16/2008 1:26:58 PM Allowed (based on user decision) value "" (new data: "http://www.google.com/search?q=%s") added in Browser page!
12/18/2008 10:14:24 AM Denied (based on user decision) value "BootExecute" (new data: "autocheck autochk *
lsdelete
") added in Session manager!
12/18/2008 10:14:31 AM Allowed (based on user decision) value "BootExecute" (new data: "autocheck autochk *
lsdelete
") added in Session manager!
12/18/2008 10:14:34 AM Allowed (based on user decision) value "ExcludeFromKnownDlls" (new data: "") added in Session manager!
12/18/2008 10:30:18 AM Allowed (based on lassh blacklist) value "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" (new data: "C:\Program Files\Google\Gmail Notifier\gnotify.exe") added in System Startup global entry!
12/31/2008 12:12:34 AM Denied (based on user decision) value "Start Page" (new data: "http://go.microsoft.com/fwlink/?LinkId=69157") added in Browser page!
12/31/2008 12:12:35 AM Denied (based on user decision) value "" (new data: ""%1" %*") added in BAT Extension handler!
12/31/2008 12:12:36 AM Denied (based on user decision) value "" (new data: ""%1" %*") added in COM Extension handler!
12/31/2008 12:12:37 AM Denied (based on user decision) value "" (new data: ""%1" %*") added in EXE Extension handler!
12/31/2008 12:12:38 AM Denied (based on user decision) value "IsolatedCommand" (new data: ""%1" %*") added in EXE Extension handler!
12/31/2008 12:12:43 AM Denied (based on user decision) value "" (new data: ""%1" %*"") added in PIF Extension handler!
12/31/2008 12:12:54 AM Denied (based on user decision) value "" (new data: "regedit.exe "%1"") added in REG Extension handler!
12/31/2008 12:12:55 AM Denied (based on user decision) value "" (new data: ""%1" %*") added in CMD Extension handler!
12/31/2008 12:12:56 AM Denied (based on user decision) value "load" (new data: "") added in NT startup!
12/31/2008 12:12:56 AM Denied (based on user decision) value "programs" (new data: "com exe bat pif cmd") added in NT startup!
12/31/2008 12:12:59 AM Denied (based on user decision) value "Start Page" (new data: "http://go.microsoft.com/fwlink/?LinkId=69157") added in Browser page!
Can anyone help? And, I was having no other problems with my computer before all of this.
Though they were denied and I didn't check them thouroughy,from a few things I see in your resident log,I think it might be best if you asked for help in malware removal.
The instructions to follow are here:
http://forums.spybot.info/showthread.php?t=288
As you will most probably not be able to follow all those steps,anything you cannot do,post in malware removal,and let them know.They may be able to help you rename hijackthis to enable you to run it,etc.,but please try to go by a helper's instructions,that would be best.
Malware removal:
http://forums.spybot.info/forumdisplay.php?f=22