Broken.OpenCommand detected in registry by MBAM
#1
Posted 20 January 2013 - 12:50 AM
Registry Data Items Detected: 2
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE "%1") Good: ("%1" /S) -> Quarantined and repaired successfully.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE "%1") Good: (regedit.exe "%1") -> Quarantined and repaired successfully.
Is the registry being reinfected by notepad.exe?
I am using IOLO System Mechanic which has been reported to cause false positives for the Broken.OpenCommand, http://forums.malwar...howtopic=110120. However after I disabled System Mechanics repair registry problems in automated tasks the Broken.OpenCommand keeps showing up in MBAM.
Is Broken.OpenCommand a dangerous trojan as a number of websites say or is it "a shell context menu addition that allows you to open the registry editor by right-clicking on a .reg file. No idea why MBAM objected to the quotes around the regedit command; your existing entry was not broken", http://www.overclock...n-opencommand-s
If it's a serious problem how can I clean my computers? Our university technical support said they could run ComboFix but would first backup my harddisk onto another disk in case ComboFix breaks anything.
Steve
#2
Posted 20 January 2013 - 11:28 AM
This can be caused by Iolo's System Mechanic, and is safe to add to your ignore list.
System Mechanic (and Dell's PC TuneUp) both change Windows File Associations to make certain files open in Notepad instead of with the programs that Windows would normally open them with. One of those types of files is Registry Exports, which experts and companies like ours like to use when helping people online. This breaks certain fixes, and is considered not good, and thus Malwarebytes' Anti-Malware will attempt to fix it.
This is not something that we will likely change, and so we offer the ability to add the entries to the ignore list in order to prevent them from being detected.
As for running Combofix, you should not run such tools without expert advice as this could make things worst if you do not know exactly what you are doing....

Dell Precision T7500, Win7 Ultimate 64bit fully updated, McAfee Corp Edition v8.8,
Watchguard Firewall, Intel Xeon E5606CPU, Dual Quad Core Processors, 16GB Ram,
E5606 @ 2.13GHz, Nvidia Quadro NVS420, Raid-1 Dual 1TB Sata 10000 rpm Hard Drives
Dual DVD Burners, IE10, Opera, MBAM
#3
Posted 20 January 2013 - 01:10 PM
Steve
#4
Posted 20 January 2013 - 10:48 PM
As for adding this to the ignore list...
• Perform another Quick Scan with MBAM and once you're viewing the results of the scan, click once on the item you wish to ignore and click Ignore and do the same for any additional items you want ignored
• When finished, click on Remove Selected (even if there are no more items listed that were detected in the scan)
• Do one more Quick Scan to verify that the items are now ignored

Dell Precision T7500, Win7 Ultimate 64bit fully updated, McAfee Corp Edition v8.8,
Watchguard Firewall, Intel Xeon E5606CPU, Dual Quad Core Processors, 16GB Ram,
E5606 @ 2.13GHz, Nvidia Quadro NVS420, Raid-1 Dual 1TB Sata 10000 rpm Hard Drives
Dual DVD Burners, IE10, Opera, MBAM
#5
Posted 21 January 2013 - 03:34 AM
#6
Posted 21 January 2013 - 01:42 PM
Steve
#7
Posted 21 January 2013 - 02:05 PM

Dell Precision T7500, Win7 Ultimate 64bit fully updated, McAfee Corp Edition v8.8,
Watchguard Firewall, Intel Xeon E5606CPU, Dual Quad Core Processors, 16GB Ram,
E5606 @ 2.13GHz, Nvidia Quadro NVS420, Raid-1 Dual 1TB Sata 10000 rpm Hard Drives
Dual DVD Burners, IE10, Opera, MBAM
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users

Sign In
Create Account
Back to top










