CMD.exe Causes Explorer Restart

Discussion in 'Malware Help (A Specialist Will Reply)' started by richbur, Mar 9, 2009.

  1. richbur

    richbur Private E-2

    For some reason or another, on one of my work computers every time I try to open a commad prompt (cmd.exe), windows explorer restarts and I never get a command window. Seemed to have some other problems with the browser going to places other than what I asked. I can get a PowerShell window but I think anything which depends on cmd.exe fails. I am running through the Malware readme right now, but I wondered if anyone had advice as to what's going on here.
     
  2. richbur

    richbur Private E-2

    Here are the logs. Interesting thing though, the 1st time I ran ComboFix my system had a BSOD howver when I rebooted after cmd.exe started working. I then ran again abd have the log here.
     

    Attached Files:

    Last edited: Mar 10, 2009
  3. richbur

    richbur Private E-2

    Last log.
     

    Attached Files:

  4. richbur

    richbur Private E-2

    I removed the combofix log after seeing information in there which I would not like public. Once someone looks at this thread I can provide log.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. Please attach the CF when you can and I will get to work on reviewing your logs. :)

    Thanks
    Kes
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    Whilst I am waiting for your original CF log I'll leave you something to start with:

    1) Please go to Add or Remove programs and uninstall the following old versions of Java:

    • Java(TM) 6 Update 11
    • Java(TM) 6 Update 7

    Are you set up to use this proxy?


    If not please include it in our fix.

    2) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O15 - Trusted Zone: http://www.intergraph.com <--- because no site should be in your TZ

    After clicking Fix exit HJT

    3) Now we need to use ComboFix.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    DeQuarantine:: 
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat.vir
    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat.vir
    
    DirLook::
    C:\4cc632a60c0e4489eafc47d136
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    I see alot of files littering your C Drive like the below:
    • C:\26HOUD22.o

    What are they?

    Also tell me what these are:

    • C:\Documents and Settings\rwburdet\XrxWm.ini
    • C:\Documents and Settings\rwburdet\xwa55ldy.dyc


    4) Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    5) Run Ccleaner!

    6) Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    7) Run the new MGTools.exe > and attach the MGLogs.zip

    8) Attach the log from Combofix after running my above script

    9) Also attach your original CF log

    10) Tell me how your machine is behaving now.

    Thanks
    Kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds