China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --

Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!

中国DOS联盟论坛
The time now is 2026-08-27 04:21
中国DOS联盟论坛 » 其它操作系统综合讨论区 » [Help] The computer always automatically opens a blank Notepad file when booting. View 3,985 Replies 25
Original Poster Posted 2006-07-15 15:40 ·  中国 山东 青岛 联通
中级用户
★★
Credits 232
Posts 53
Joined 2005-08-24 07:03
21-year member
UID 41889
Gender Male
From 中国
Status Offline
Just now changed to WIN XP SP2, and everything else is fine after installation. It's a pity that every time I start the computer, a blank Notepad will automatically open. It's quite troublesome to close it each time, and I don't know how to make it stop automatically opening this blank Notepad file.
Floor 2 Posted 2006-07-15 15:59 ·  中国 浙江 台州 玉环市 电信
管理员
★★★★
DOS非常爱好者
Credits 6,215
Posts 2,601
Joined 2006-01-20 13:00
20-year member
UID 49256
Status Offline
Haven't seen it. Just cancel it in the startup items!
Floor 3 Posted 2006-07-15 17:24 ·  中国 四川 成都 教育网
铂金会员
★★★★
Credits 7,493
Posts 2,672
Joined 2005-09-02 00:00
20-year member
UID 42173
Gender Male
Status Offline
Infected, it seems there is a file like wincfg in the system32 directory. Just delete it and remove the run in the registry. This kind of virus has no daemon process, so it's easy to delete manually.

C:\>BLOG http://initiative.yo2.cn/
C:\>hh.exe ntcmds.chm::/ntcmds.htm
C:\>cmd /cstart /MIN "" iexplore "about:<bgsound src='res://%ProgramFiles%\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll/10/5432'>"
Floor 4 Posted 2006-07-15 18:04 ·  中国 山东 青岛 联通
中级用户
★★
Credits 232
Posts 53
Joined 2005-08-24 07:03
21-year member
UID 41889
Gender Male
From 中国
Status Offline
I've cleared it. I've cleared many related files in the registry, but I can't find that file in system32. It still appears. Really depressed.
Floor 5 Posted 2006-07-15 22:09 ·  中国 广东 广州 白云区 电信
中级用户
★★
Credits 466
Posts 237
Joined 2005-10-12 20:53
20-year member
UID 43413
Status Offline
It must be infected with a trojan horse. Delete wincfg under DOS.
Floor 6 Posted 2006-07-16 13:16 ·  中国 山东 青岛 联通
中级用户
★★
Credits 232
Posts 53
Joined 2005-08-24 07:03
21-year member
UID 41889
Gender Male
From 中国
Status Offline
Didn't find the wincfg.exe file in the system32 directory, how to delete it?
Floor 7 Posted 2006-07-18 09:50 ·  中国 安徽 芜湖 电信
高级用户
★★★
Credits 866
Posts 415
Joined 2005-12-04 11:19
20-year member
UID 46459
Status Offline
The building owner should pay special attention to the following key value in the registry:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"

See if it has already become:
"shell"="Explorer.exe notepad.exe"
Floor 8 Posted 2006-07-19 00:49 ·  中国 山东 青岛 联通
中级用户
★★
Credits 232
Posts 53
Joined 2005-08-24 07:03
21-year member
UID 41889
Gender Male
From 中国
Status Offline
Floor 9 Posted 2006-07-27 17:25 ·  中国 辽宁 朝阳 联通
新手上路
Credits 9
Posts 5
Joined 2006-07-22 11:20
20-year member
UID 59015
Status Offline
I also encountered a similar situation! Thank you everyone!
Floor 10 Posted 2006-09-19 06:02 ·  中国 北京 海淀区 联通
新手上路
Credits 14
Posts 7
Joined 2006-09-18 08:41
19-year member
UID 62945
Status Offline
Viruses are not difficult to solve and can be manually deleted.
1. End wincfgs in the process.
2. Use hijackthis or sreng to uncheck the relevant items in startup. It seems that msconfig can also be used, but I can't remember clearly.
3. Find wincfgs in the system32 directory. Note that when searching, hidden and system files should be included, then delete it.
4. Restart, and it should be okay.
Many viruses can be solved with the above steps.
Just some processes need to be ended with IceSword.
Floor 11 Posted 2006-09-26 00:01 ·  中国 广东 佛山 三水区 电信
元老会员
★★★★
Credits 5,170
Posts 1,637
Joined 2002-10-16 00:00
23-year member
UID 8
Gender Male
From 广东佛山
Status Offline
It may be that the file is set to hidden and system attributes, and many trojans are like this. Click Tools - Folder Options - View, select "Show all files" and do not select "Hide protected operating system files" to see all files.
我的网志
http://hzmys.blog.163.com/
我的网盘
firststep.qjwm.com
fsmys.ys168.com
ssmys.ys168.com
www.brsbox.com/fsmys
www.brsbox.com/ssmys
www.brsbox.com/ccdos
Floor 12 Posted 2006-09-26 00:41 ·  中国 甘肃 张掖 电信
金牌会员
★★★★
Credits 4,103
Posts 1,744
Joined 2006-01-20 13:00
20-year member
UID 49241
Gender Male
From 甘肃.临泽
Status Offline
Find all run 呵呵
Floor 13 Posted 2006-09-26 09:36 ·  中国 湖南 娄底 新化县 电信
银牌会员
★★★
Credits 1,218
Posts 485
Joined 2006-07-21 21:24
20-year member
UID 58987
From 湖南.娄底
Status Offline
It seems that you have a virus.

To achieve random execution, this virus modifies the registry to load and start with Windows Explorer. Also, did it modify the association of the txt suffix? There is no such item in the RUN startup.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"

Remove notepad.exe from the above key value, and then repair the file association. Find the associated program and delete it. Otherwise, the virus will be activated again.
Floor 14 Posted 2006-09-28 12:40 ·  中国 山东 青岛 联通
中级用户
★★
Credits 232
Posts 53
Joined 2005-08-24 07:03
21-year member
UID 41889
Gender Male
From 中国
Status Offline
3Q
Infected. Figured it out.
Floor 15 Posted 2006-10-03 07:45 ·  中国 河南 洛阳 联通
初级用户
Credits 38
Posts 19
Joined 2006-10-02 03:51
19-year member
UID 64281
Status Offline
I also encountered a similar situation! Thank you everyone!
Forum Jump: