中国DOS联盟论坛

China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --
Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
Guest | Log in | Register | Members | Search | China DOS Union
中国DOS联盟论坛
The time now is 2026-08-27 02:24
47,812 topics / 349,912 posts / today 2 new / 48,264 members
其它操作系统综合讨论区 » [Help] The computer always automatically opens a blank Notepad file when booting.
Printable Version  3,980 / 25
Floor1 badcfqtd Posted 2006-07-15 15:40
中级用户 Posts 53 Credits 232 From 中国
Just now changed to WIN XP SP2, and everything else is fine after installation. It's a pity that every time I start the computer, a blank Notepad will automatically open. It's quite troublesome to close it each time, and I don't know how to make it stop automatically opening this blank Notepad file.
Floor2 雨露 Posted 2006-07-15 15:59
管理员 Posts 2,601 Credits 6,215
Haven't seen it. Just cancel it in the startup items!
Floor3 electronixtar Posted 2006-07-15 17:24
铂金会员 Posts 2,672 Credits 7,493
Infected, it seems there is a file like wincfg in the system32 directory. Just delete it and remove the run in the registry. This kind of virus has no daemon process, so it's easy to delete manually.
Floor4 badcfqtd Posted 2006-07-15 18:04
中级用户 Posts 53 Credits 232 From 中国
I've cleared it. I've cleared many related files in the registry, but I can't find that file in system32. It still appears. Really depressed.
Floor5 Scott0902 Posted 2006-07-15 22:09
中级用户 Posts 237 Credits 466
It must be infected with a trojan horse. Delete wincfg under DOS.
Floor6 badcfqtd Posted 2006-07-16 13:16
中级用户 Posts 53 Credits 232 From 中国
Didn't find the wincfg.exe file in the system32 directory, how to delete it?
Floor7 htysm Posted 2006-07-18 09:50
高级用户 Posts 415 Credits 866
The building owner should pay special attention to the following key value in the registry:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"

See if it has already become:
"shell"="Explorer.exe notepad.exe"
Floor8 badcfqtd Posted 2006-07-19 00:49
中级用户 Posts 53 Credits 232 From 中国
Floor9 cccfish Posted 2006-07-27 17:25
新手上路 Posts 5 Credits 9
I also encountered a similar situation! Thank you everyone!
Floor10 heroyb Posted 2006-09-19 06:02
新手上路 Posts 7 Credits 14
Viruses are not difficult to solve and can be manually deleted.
1. End wincfgs in the process.
2. Use hijackthis or sreng to uncheck the relevant items in startup. It seems that msconfig can also be used, but I can't remember clearly.
3. Find wincfgs in the system32 directory. Note that when searching, hidden and system files should be included, then delete it.
4. Restart, and it should be okay.
Many viruses can be solved with the above steps.
Just some processes need to be ended with IceSword.
Floor11 MYS Posted 2006-09-26 00:01
元老会员 Posts 1,637 Credits 5,170 From 广东佛山
It may be that the file is set to hidden and system attributes, and many trojans are like this. Click Tools - Folder Options - View, select "Show all files" and do not select "Hide protected operating system files" to see all files.
Floor12 vkill Posted 2006-09-26 00:41
金牌会员 Posts 1,744 Credits 4,103 From 甘肃.临泽
Find all run 呵呵
Floor13 pengfei Posted 2006-09-26 09:36
银牌会员 Posts 485 Credits 1,218 From 湖南.娄底
It seems that you have a virus.

To achieve random execution, this virus modifies the registry to load and start with Windows Explorer. Also, did it modify the association of the txt suffix? There is no such item in the RUN startup.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"

Remove notepad.exe from the above key value, and then repair the file association. Find the associated program and delete it. Otherwise, the virus will be activated again.
Floor14 badcfqtd Posted 2006-09-28 12:40
中级用户 Posts 53 Credits 232 From 中国
3Q
Infected. Figured it out.
Floor15 x412637729 Posted 2006-10-03 07:45
初级用户 Posts 19 Credits 38
I also encountered a similar situation! Thank you everyone!
1 2  Next
[ Contact the Union admin team - 中国DOS联盟 - Standard version ]
Sponsored by ifanr Inc | © 2001–2023