Cryptic Trojan Horse

Status
Not open for further replies.

paultess

New Member
Thread author
Verified
Jan 3, 2013
55
Thank you. Tests attached.
Not sure if it has anything to do with anything but usually when I click an email link /i go to the page. on your new link http://malwaretips.com/Thread-Cryptic-Trojan-Horse?action=newpost
the message I get is:
This file does not have an application attached to it for performing this action. Create an association in the set associations control panel.

I have received this message on a number of occasions today.
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Okay. Just do one thing.. Install Google Chrome and Make Google Chrome as your Default Browser...... After that try to click on the email link...
 

paultess

New Member
Thread author
Verified
Jan 3, 2013
55
kuttus said:
Okay. Just do one thing.. Install Google Chrome and Make Google Chrome as your Default Browser...... After that try to click on the email link...


Google chrome is already installed and default.
Email works perfectly.
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Okay.:biggrin: Are you facing any other issues on the computer now?

STEP 1: Run a scan with ESET Online Scanner
<ol>
<li>Download ESET Online Scanner utility from the below link
<><a title="External link" href="http://download.eset.com/special/eos/esetsmartinstaller_enu.exe" rel="nofollow">ESET ONLINE SCANNER DOWNLOAD LINK</a></> <em>(This link will automatically download ESET Online Scanner on your computer.)</em></li>
<li>Double click on the Eset installer program (esetsmartinstaller_enu.exe).</li>
<li>Check <>Yes, I accept the Terms of Use</></li>
<li>Click the <>Start</> button.</li>
<li>Check <>Scan archives</></li>
<li>Push the <>Start</> button.</li>
<li>ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.</li>
<li>When the scan completes, push <>List of found threats</></li>
<li>Push <>Export to Text file </> and save the file to your desktop using a unique name, such as <>ESET Scan</>. Include the contents of this report in your next reply.Note - when ESET doesn't find any threats, no report will be created.</li>
<li>Push the <>back</> button.</li>
<li>Push <>Finish</></li>
</ol>
<hr />

STEP 2: Run Temp File Cleaner by OldTimer
<ol>
<li>You can download the TFC utility from the below link
<a title="External link" href="http://oldtimer.geekstogo.com/TFC.exe" rel="nofollow external"><>TFC DOWNLOAD LINK</></a> <em>(This link will automatically download Temp File Cleaner on your computer)</em></li>
<li>Please double-click <>TFC.exe</> to run it. (<>Note:</> If you are running on Vista or 7, right-click on the file and choose <>Run As Administrator</>).</li>
<li>It <>will close all programs</> when run, so make sure you have <>saved all your work</> before you begin.</li>
<li>Click the <>Start</> button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. <>Let it run uninterrupted to completion</>.</li>
<li>Once it's finished it should <>reboot your machine</>. If it does not, please <>manually reboot the machine</> yourself to ensure a complete clean.</li>
</ol>
<hr />


STEP 3: Run a scan with AdwCleaner

<ol><li>Download AdwCleaner from the below link.
<><a href="http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner" target="_blank">ADWCLEANER DOWNLAOD LINK</a></> (This link will automatically download Security Check on your computer)</li>

<li>Close all open programs and internet browsers.</li>
<li>Double click on <>adwcleaner.exe</> to run the tool.</li>
<li>Click on <>Delete</>,then confirm each time with <>Ok</>.</li>
<li>Your computer will be rebooted automatically. A text file will open after the restart.</li>
<li>Please post the contents of that logfile with your next reply.</li>
<li>You can find the logfile at <>C:\AdwCleaner[S1].txt</> as well.</li>
</ol>
<hr/>
 
Last edited by a moderator:

paultess

New Member
Thread author
Verified
Jan 3, 2013
55
Just the original problems. I can't access many functions such as sound because of the win32 problem.
Accessing shortcuts is a new problem with the window:
This file does not have an application attached to it for performing this action. Create an association in the set associations control panel.
The first time that happened was when I clicked your link as I told you.

Windows and Google stop working from time to time...2 or 3 times in a 4 hour period. The same with email, but those are not new.
Speed is good. Internet access good.

Shall I start with the new step#1 now?
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Please try the following steps first....


STEP 1: Repair your Windows Registry from this infection malicious changes.

This infection has changed your Windows registry settings so that when you try to run a executable file (ending with .exe ) , it will instead launch the infection rather than the desired program.

  1. Download the registryfix.reg file to fix the malicious registry changes from this infection.
    REGISTRYFIX.REG DOWNLOAD LINK (This link will automatically download the registry fix called registryfix.reg)
  2. Double-click on registryfix.reg file to run it. Click “Yes” for Registry Editor prompt window,then click OK.
<hr />
 

paultess

New Member
Thread author
Verified
Jan 3, 2013
55
I am now receiving the response:
Unable to open this internet shortcut. The protocol "http"does not have a registered program"
 

paultess

New Member
Thread author
Verified
Jan 3, 2013
55
Also with Utorrent, I am receiving the following:
Not connectable. A firewall/router is limiting your network traffic. You need to open a port so others can connect to you.
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Okay... Restart your computer in Safe Mode and check if you are able to open all applications with out problems.....

<h3>STEP 1 : Start your computer in Safe Mode with Networking</h3>
<ol><li>Remove all floppy disks, CDs, and DVDs from your computer, and then <>restart your computer</>.</li>
<li><>Press and hold the F8 key as your computer restarts</>.Please keep in mind that you need to press the F8 key <>before the Windows start-up logo appears</>.
<em>Note</em>: With some computers, if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the "F8 key", <>tap the "F8 key" continuously</> until you get the Advanced Boot Options screen.</li>
<li>On the Advanced Boot Options screen, use the arrow keys to <>highlight Safe Mode with Networking</> , and then <>press ENTER</>.
<img title="Safe Mode with Networking screen" src="http://malwaretips.com/images/removalguide/safemode.jpg" alt="[Image: Safemode.jpg]" width="539" height="292" border="0" /></li>
</ol>
<hr />
 
Last edited by a moderator:

paultess

New Member
Thread author
Verified
Jan 3, 2013
55
The following had messages or did not start:
Itunes -One of the original concerns
Office live workplace - Prot http. does not have etc.
internet and digitalsevices - no response
The audio services icon has an X and message 'not running'
The usual applications Word; Excel; Video players - VLC,MBR are opk except MBR indicates sound incorrectly installed or faulty.
Photofun Studios HD - window telling me to use a display 1024*768 16 bit...

I think I tried all the applications.

When restarting from safe mode the computer turned itself off.
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Please run TDSS Killer Once again and Check if you are getting TDSS File System Physical drive: \Device\Harddisk0/DR0 in the scan result..... if you are getting it Select quarantine and press on Continue...
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Restart the computer and do one more scan and check if you are still getting that same infection.......
 

kuttus

Level 2
Verified
Oct 5, 2012
2,697
Goto Run window. Inside the Run Window type diskmgmt.msc and press on Ok. Now you will be able to see one Disk Management Window... Please send me the Screen Shots of that Disk Management Window...

PS : I would like to see all the Details in the Disk Management Window. Mainly Details of All Volume's, Type, File System, Status & Capacity.


To Take Screen Of Your Screen.
  1. Press PRINT SCREEN (Print Scr) key on Your Keyboard.
  2. Now Open MS Paint
  3. Open Paint by clicking the Start button
    4f6cbd09-148c-4dd8-b1f2-48f232a2fd33_47.png
    , clicking All Programs, clicking Accessories, and then clicking Paint.
  4. In MS Paint Click Edit, and then click Paste.
  5. After this Save the File on your computer by Clicking on File --> Save
Add this Saved File in your next Replay
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top