Results 1 to 5 of 5
  1. #1
    Newbie
    Overall activity: 0%

    Join Date
    Oct 2007
    Posts
    15
    Liked
    0 times
    Points
    4,108
    Hello,

    this machine has gone strange since IE 6 was updated to 7.
    now, its problem is when i open some applications, it will open with notepad.

    Logfile of HijackThis v1.99.1
    Scan saved at 6:15:02 PM, on 10/19/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Altiris\AClient\AClient.exe
    C:\WINDOWS\SYSTEM32\DWRCS.EXE
    C:\WINDOWS\system32\lkcitdl.exe
    C:\WINDOWS\system32\lkads.exe
    C:\WINDOWS\system32\lktsrv.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\National Instruments\MAX\nimxs.exe
    C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
    C:\WINDOWS\system32\nipalsm.exe
    C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
    C:\WINDOWS\system32\nisvcloc.exe
    C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.ex e
    C:\WINDOWS\system32\nipalsm.exe
    C:\WINDOWS\system32\CCM\CcmExec.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SYSTEM32\DWRCST.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Altiris\AClient\AClntUsr.EXE
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
    C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
    C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\3M\PSN2Lite\Psn2Lite.exe
    C:\Program Files\Network Associates\Common Framework\McTray.exe
    C:\PROGRA~1\3M\PSN2Lite\PSNGive.exe
    C:\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Lear Corporation
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: SYNERGY/CM - {A461BD6B-2AC0-4F0E-8594-AAEE7BB4C70B} - C:\Program Files\Telelogic\SYNERGY CM 6.4\bin\CMExplorer.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [AClntUsr] C:\Altiris\AClient\AClntUsr.EXE
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
    O4 - HKLM\..\Run: [niDevMon] C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Post-itŪ Software Notes Lite.lnk = C:\Program Files\3M\PSN2Lite\Psn2Lite.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {0040032C-2988-41F9-9142-B2B5D86DD52E} (BarProgress.ctlProgressBar) - file://C:\Program Files\DDT2000\DST2005\DST2005.CAB
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {DDCC0F8A-C052-421D-B6AE-5100AEFB3D49} (SelectFile.ctlFileSelect) - file://C:\Program Files\DDT2000\DST2005\DST2005.CAB
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.lear.com
    O17 - HKLM\Software\..\Telephony: DomainName = corp.lear.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.lear.com
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = corp.lear.com
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Altiris\AClient\AClient.exe
    O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
    O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
    O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
    O23 - Service: MySql - Unknown owner - //Pet-20-1520/c$/mysql/bin/mysqld-nt.exe
    O23 - Service: Neoteris Setup Service - Juniper Networks - C:\Program Files\Neoteris\Installer Service\NeoterisSetupService.exe
    O23 - Service: NI-488.2 Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
    O23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
    O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
    O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
    O23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
    O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exe
    O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
    O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe

  2. #2
    Administrator
    Overall activity: 46.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,802
    Liked
    1656 times
    Points
    48,740
    Does it happen everytime when you open an .exe file?

    Run regedit and go to:
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command

    Is the data value "%1" %* ?

    If no, refer to this article on how to reset it.
    http://www.raymond.cc/blog/archives/2007/07/01/stop-virus-from-running-automatically-when-you-execute-files/

  3. #3
    Newbie
    Overall activity: 0%

    Join Date
    Oct 2007
    Posts
    15
    Liked
    0 times
    Points
    4,108
    thanks a lot... it was fixed already. what's the cause of this?

    i've updated mcafee then run a full scan on my PC but it didn't found any threat.

  4. #4
    Administrator
    Overall activity: 46.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,802
    Liked
    1656 times
    Points
    48,740
    You fixed it with the solution I gave you? If yes, this problem is caused by virus and as usual, antivirus will remove virus but won't restore the changes made by virus.

  5. #5
    Newbie
    Overall activity: 0%

    Join Date
    Oct 2007
    Posts
    15
    Liked
    0 times
    Points
    4,108
    yes... okay, thanks again.

 

 

Similar Threads

  1. Missing dots from email addresses opens 20GB data leak !!!
    By INDRANIL in forum Spyware/Viruses
    Replies: 2
    Last Post: 09-14-2011, 12:44 AM
  2. .Dll Opens With Notepad
    By Vibhanshu in forum Software
    Replies: 3
    Last Post: 07-11-2010, 09:01 AM
  3. Applications opens and then closes immediately.
    By smalldog in forum Software
    Replies: 14
    Last Post: 10-14-2009, 05:25 PM
  4. Task Manager Opens And Closes Immediately
    By alihs in forum Spyware/Viruses
    Replies: 2
    Last Post: 04-13-2009, 12:31 PM
  5. CMD and REGEDIT opens with notepad!
    By nailv in forum Spyware/Viruses
    Replies: 17
    Last Post: 08-17-2008, 02:18 PM
All times are GMT +8. The time now is 04:58 AM.