Jump to content

Malwarebytes

2 Probs: SMsystemAnalyzer.exe & Broken.OpenCommand

- - - - -

4 replies to this topic

#1
crispycritter

    New Member

  • Members
  • Pip
  • 3 posts
I am pretty clueless and need help please!

I have 2 concerns...

1) Received the following message box on my screen:

[At top of box it said "Smsystemanalyzer"]
Access violation at address 0042A673 in module 'SMSystemAnalyzer.exe'. Read of address 029BF2FC.

2) These registry data problems keep showing up on malwarebytes log:

Malwarebytes' Anti-Malware 1.37
Database version: 2243
Windows 6.0.6001 Service Pack 1

8/6/2009 12:15:50 PM
mbam-log-2009-08-06 (12-15-50).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 197416
Time elapsed: 1 hour(s), 46 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#2
crispycritter

    New Member

  • Members
  • Pip
  • 3 posts

View Postcrispycritter, on Aug 6 2009, 01:14 PM, said:

I am pretty clueless and need help please!

I have 2 concerns...

1) Received the following message box on my screen:

[At top of box it said "Smsystemanalyzer"]
Access violation at address 0042A673 in module 'SMSystemAnalyzer.exe'. Read of address 029BF2FC.

2) These registry data problems keep showing up on malwarebytes log:

Malwarebytes' Anti-Malware 1.37
Database version: 2243
Windows 6.0.6001 Service Pack 1

8/6/2009 12:15:50 PM
mbam-log-2009-08-06 (12-15-50).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 197416
Time elapsed: 1 hour(s), 46 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Still looking for advice...

Okay, so after I posted here earlier I ran Dell PC Tuneup (by Iolo, I think) and it said I had 14 registry problems to fix. (I just ran the tuneup last night, so how can there be that many problems already???)

I let Dell PC Tuneup repair the problems itself, and then I ran MBAM again. Lo and behold, those 2 "broken.opencommand" thngs appeared again! I get rid of them but they keep coming back. When I run MBAM, I get the message "2 objects infected" within the first 10 seconds of the MBAM scan. I got rid of them again, but I'm sure they'll be back...AGAIN.

Any suggestions? Thank you in advance.

Latest log:

Malwarebytes' Anti-Malware 1.37
Database version: 2243
Windows 6.0.6001 Service Pack 1

8/6/2009 5:16:39 PM
mbam-log-2009-08-06 (17-16-39).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 196669
Time elapsed: 1 hour(s), 35 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#3
crispycritter

    New Member

  • Members
  • Pip
  • 3 posts
Still hoping for some advice...thanks!

#4
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,904 posts
  • Gender:Male
  • Location:US
I apologize for the long delay however the site has been swamped with too many requests and your post appears to have been overlooked in the rush.
If you still require assistance please let us know.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#5
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,904 posts
  • Gender:Male
  • Location:US
Since you appear to no longer be monitoring this post we will assume that you've already addressed the issue and no logner require assistance and we will close the post now.

If however you do still require assistance please send a private message to open the post again.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us