problem with "cmd" and "regedit"

Discussion in 'Malware Help (A Specialist Will Reply)' started by programmer04, Feb 17, 2006.

  1. programmer04

    programmer04 Private First Class

    I've just recently discovered a problem with my computer. If I go to start, run, and type in "regedit" a command prompt will appear and lock up. When I try to close it, I get a "Program Not Responding" message and I have to click "End Now." But what is stranger is that, at first, when I typed in "cmd" or "cmd.exe" or "command" the box would simply flash once on the screen and go away. If I went to start, all programs, accessories, command prompt, I would get a command prompt, but if I typed in "ping" and any address, I got a very strange nonsense message:
    "EXIST filename Specifies a true condition if filename"
    After running several anti-malware programs and restarting the computer a couple of times, now I get a new message in a separate box along with the command prompt every time I type in "cmd" or "regedit" or click on "Command Promt":
    (Title bar): 16 bit MS-DOS Subsystem
    (Text): C:\WINDOWS\System32\regedit.com (or "cmd.com")
    The NTVDM CPU has encountered an illegal instruction.
    CS:055c IP:00b7 OP:65 63 69 66 79 Choose 'Close' to terminate the application.
    Clicking on "Ignore" changes nothing. I am forced to click on "Close". I am running Windows XP. Does anyone know whats going on. Before I ran the anti-malware programs I could at least run other commands without problems, such as "ipconfig". But now I can't do anything.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    Yes! You probably have a few other .com file in system32 besides those. They are all probably 0 bytes in size and they will keep the real applications from being run.

    Look in system32 and provide me a list of all file names ending in .com also give the file sizes. Then look to see if the .exe equivalent exists and what its size is too.

    Exactly what does the below statement mean:
     
  3. programmer04

    programmer04 Private First Class

    chcp.com - 8 kb (none)
    cmd.com - 1 kb (.exe - 367 kb)
    command.com - 50 kb (none)
    diskcomp.com - 9 kb (none)
    diskcopy.com - 7 kb (none)
    edit.com - 69 kb (none)
    format.com - 25 kb (none)
    graftabl.com - 26 kb (none)
    graphics.com - 20 kb (none)
    kb16.com - 15 kb (none)
    loadfix.com - 2 kb (none)
    mode.com - 19 kb (none)
    more.com - 16 kb (none)
    netstat.com - 1 kb (.exe - 30 kb)
    ping.com - 1 kb (.exe - 15 kb)
    regedit.com - 1 kb (none)
    taskkill.com - 1 kb (.exe - 71 kb)
    tasklist.com - 1 kb (.exe - 71 kb)
    tracert.com - 1 kb (.exe - 10 kb)
    tree.com - 11 kb (none)
    win.com - 18 kb (none)

    Also, "ping6.exe - 33 kb" and "regedt32.exe - 4 kb". "none" means no matching .exe file.

    "But now I can't do anything" means that I can't use the command prompt at all due to the error message mentioned before.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is a list of what you need to do. It shows what is valid and what is not.

    chcp.com - 8 kb (none) <--- valid
    cmd.com - 1 kb (.exe - 367 kb) <-- delete cmd.com and leave cmd.exe which is valid
    command.com - 50 kb (none) <--- valid
    diskcomp.com - 9 kb (none) <--- valid
    diskcopy.com - 7 kb (none) <--- valid
    edit.com - 69 kb (none) <--- valid
    format.com - 25 kb (none) <--- valid
    graftabl.com - 26 kb (none) <--- valid
    graphics.com - 20 kb (none) <--- valid
    kb16.com - 15 kb (none) <--- valid
    loadfix.com - 2 kb (none) <--- valid
    mode.com - 19 kb (none) <--- valid
    more.com - 16 kb (none) <--- valid
    netstat.com - 1 kb (.exe - 30 kb) <-- delete netstat.com and leave netstat.exe which is valid
    ping.com - 1 kb (.exe - 15 kb) <-- delete ping.com and leave ping.exe which is valid
    regedit.com - 1 kb (none) <-- delete regedit.com and you need to get regedit.exe back from a CD or another folder on your system
    taskkill.com - 1 kb (.exe - 71 kb) <-- delete taskkill.com and leave taskkill.exe which is valid
    tasklist.com - 1 kb (.exe - 71 kb) <-- delete tasklist.com and leave tasklist.exe which is valid
    tracert.com - 1 kb (.exe - 10 kb) <-- delete tracert.com and leave tracert.exe which is valid
    tree.com - 11 kb (none) <--- valid
    win.com - 18 kb (none) <--- valid

    Also, "ping6.exe - 33 kb" and "regedt32.exe - 4 kb" <--- both are valid

    Use Windows file search to look for another copy of regedit.exe on your PC. There may be one in an i386 folder or a ServicePackInstall folder. Search for only regedit without the .exe extension because sometimes the file will be compressed as regedit.ex_
     
  5. programmer04

    programmer04 Private First Class

    Almost done. I just have one more question. When I searched for "regedit" I recieved some results that I found questionable:

    regedit.com - C:\RECYCLER\S-1-5-21-1957994488-1644491937-839522115-1003
    regedit.com - C:\RECYCLER\S-1-5-21-1957994488-1644491937-839522115-1004
    regedit.com - C:\RECYCLER\S-1-5-21-1957994488-1644491937-839522115-1006
    regedit.com - C:\RECYCLER\S-1-5-21-1957994488-1644491937-839522115-500

    Tje same results also showed up on another drive. Is this normal, or should I delete it?
     
  6. programmer04

    programmer04 Private First Class

    I also seem to have two different regedit.exe. One is 131 kb and the other is 143 kb. The 143 kb is located at C:\WINDOWS\SoftwareDistribution\Download\6ca7b3a8efd5a9b6f87fff395a2eb989.

    The other is located at C:\WINDOWS and C:\WINDOWS\system32\dllcache.

    Any idea which one I should use?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which SP level of WinXP are you running? SP1 or SP2?
     
  8. programmer04

    programmer04 Private First Class

    I bought this computer with SP1. For some reason, I have never been able to install SP2. I don't want to think it, but I've been told by my friends that my version of Windows XP may be a copy. I have been able to update on most everything else at the Microsoft site, though.

    It would really suck to find out that, after spending all kinds of money, I have a bad OS.

    Could this be a part of my problem with the command prompt?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the one that is 131 kb into the system32 folder.

    Doesn't your command prompt work now after deleting cmd.com?
     
  10. programmer04

    programmer04 Private First Class

    The command prompt is working fine now, thanks. What causes this? Should I worry about it happening again if I restart my computer?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are some trojans out there that do this! I would really recommend that you run ALL the steps in the below to make sure you are totally clean. I have seen these problems many times and they often come with other malware.


    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    Make sure you attach the two logs from the scanners in step 6 and then follow step 7 properly and attach a HijackThis log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds