Removed a trojan off but now I'm getting "This file does not have a program associated with it for performing this action"

jsarinana
jsarinana used Ask the Experts™
on
Looks like the registry is broken, This user got his laptop infected with the Rogue trojan, ran malwarebytes and reomved finfections. Now I have the "This file does not have a program associated with it for performing this action" issue.

Please advise
Thanks
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Please download this, right click it, and select merge.
xp-exe-fix.reg

Commented:
Please provide more details, What program or programs are you trying to open when you get that message? The more details you provide the better chances to get a solution. Thank you.
Author of the Year 2011
Top Expert 2006

Commented:
There are a lot of malware variants that could be called 'rogue trojans'.
Look through the list here and see if you recognize any of the names:
http://www.bleepingcomputer.com/virus-removal/

If you find it, follow the exact instructions as written by "Grinler".

You can also try the various menu options in "RogueKiller".
See my EE Articles at these links:

http://www.experts-exchange.com/A_4922.html (Rogue-Killer-What-a-great-name)
http://www.experts-exchange.com/A_5124.html (Stop-the-Bleeding-First-Aid-for-Malware)
http://www.experts-exchange.com/A_1940.html (Basic Malware Troubleshooting)

Success in ‘20 With a Profitable Pricing Strategy

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author of the Year 2011
Top Expert 2006

Commented:
@WalrusSoup,
Probably best to post your Registry fix as a "Text" file and let the user view the instructions.
We've had some past problems with downloaded executables and .reg files.
@younghv
Ok, thank you for letting me know. I assume that this is the proper registry fix since rogue trojans often replace the registry entry for opening .exe files so it, in fact, opens the virus once again. I will make sure to post the registry fixes in .TXT format from now on with instructions on how to save as a .reg.
Author of the Year 2011
Top Expert 2006

Commented:
:)
I'm a little paranoid about downloading anything, but if your file looks anything like what I attaching as "Code", it will be what I've been using for all of these variants.

BTW - Welcome to EE! We're always looking for a few good Experts.
Windows Registry Editor Version 5.00

[-HKEY_CLASSES_ROOT\.exe\shell]

[-HKEY_CLASSES_ROOT\.exe\DefaultIcon]

[HKEY_CLASSES_ROOT\.exe]
@="exefile"

[HKEY_CLASSES_ROOT\exefile]
"Content Type"=-

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"
"IsolatedCommand"=-

[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
"IsolatedCommand"=-

[HKEY_CLASSES_ROOT\.bat]
@="batfile"

[HKEY_CLASSES_ROOT\batfile\shell\open\command]
@="\"%1\" %*"

[-HKEY_CURRENT_USER\SOFTWARE\Classes\.exe]

[-HKEY_CURRENT_USER\Software\Classes\exefile]

[-HKEY_CLASSES_ROOT\secfile]

[-HKEY_CURRENT_USER\Software\Classes\secfile]

[-HKEY_CLASSES_ROOT\pezfile]

[-HKEY_CURRENT_USER\Software\Classes\pezfile]

[-HKEY_CLASSES_ROOT\sezfile]

[-HKEY_CURRENT_USER\Software\Classes\sezfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command]
@="firefox.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command]
@="firefox.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]
@="iexplore.exe"

Open in new window

I think this tool might do the same correction http://www.winhelponline.com/exefix_xp.com
jsarinanaI.T. Manager

Author

Commented:
Thanks WalrusSoup
This is all I needed, worked like a charm

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial