1. Home
  2. Computing & Technology
  3. Antivirus Software

Changes to Shell Open Command

By Mary Landesman, About.com

Malware can load from a variety of different places on your PC. In addition to the more common modifications to Windows auto start entry points, malware may leverage the shell open command. This allows it to register itself as the handler for certain file types and thus the virus, worm or Trojan loads when any of these file types are called. (The 2001 Sircam worm was one of the earliest examples of widespread malware using this technique).

Following are the keys typically targeted:

  • HKEY_CLASSES_ROOT\exefile\shell\open\command
  • HKEY_CLASSES_ROOT\comfile\shell\open\command
  • HKEY_CLASSES_ROOT\batfile\shell\open\command
  • HKEY_CLASSES_ROOT\piffile\shell\open\command
  • HKEY_CLASSES_ROOT\htafile\shell\open\command
  • HKEY_CLASSES_ROOT\htfile\shell\open\command

    The default value for each of these should be "%1" %*. If malware has registered itself as the handler, the value would appear similar to the following:

    <malware> %1
    where <malware> represents the filename of the malicious program.

    When manually attempting removal of a virus, worm, Trojan or other malware that has registered itself as the handler in this manner, you must correct the registry value before you attempt to delete the copy of the malware. Otherwise, when you reboot your system you will not have a valid handler for these file types and the system will not load Windows.

    To correct the handler value, replace the contents with:

    "%1" %*

    Symantec also provides a free tool to reset shell\open\command registry keys.

  • Explore Antivirus Software
    About.com Special Features

    Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

    Easy ways to connect two computers for networking purposes. More >

    1. Home
    2. Computing & Technology
    3. Antivirus Software
    4. Windows Tutorials
    5. Changes to Shell Open Command

    ©2009 About.com, a part of The New York Times Company.

    All rights reserved.