Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

cmd.exe pops up cant close it , keeps blinking


  • This topic is locked This topic is locked
1 reply to this topic

#1 smurfizina

smurfizina

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:swed
  • Local time:05:18 PM

Posted 10 January 2010 - 06:08 AM

cmd.exe virus
cmd.exe
When all my programs is loaded the c:\windows\system32\cmd.exe promt is poping up,
blinking and inside the black box
the text goes: cant find the search way...
can´t close it, tried a lot of diffrent program, but nothing works.
Its still a live. Im running Vista SP2.
It takes 80% of my CPU

PLEASE HELP !!!
It drive me cracy
crazy.gif

Logfile------


DDS (Ver_09-12-01.01) - NTFSx86
Run by Jonna & Mikael at 12:25:53,52 on 2010-01-10
Internet Explorer: 8.0.6001.18865
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.46.1053.18.2037.876 [GMT 1:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Net iD\iid.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Users\Jonna & Mikael\Program Files\DNA\btdna.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Personal\bin\Personal.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\conime.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Jonna & Mikael\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = www.pointshop.se/default_online.asp?ref=startpage
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sv_se&c=81&bd=Presario&pf=laptop
uSearch Page =
uSearch Bar =
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sv_se&c=81&bd=Presario&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sv_se&c=81&bd=Presario&pf=laptop
mSearchAssistant =
BHO: Länkhjälp till Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.0.0.134\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.0.0.134\coIEPlg.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [Calendarscope] "c:\program files\calendarscope\csde.exe"
uRun: [BitTorrent DNA] "c:\users\jonna & mikael\program files\dna\btdna.exe"
uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe"
mRun: [<NO NAME>]
mRun: [FBSSA] c:\program files\sgpsa\ie3sh.exe
mRun: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Net iD] "c:\program files\net id\iid.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\personal.lnk - c:\program files\personal\bin\Personal.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
Trusted Zone: telia.com\cve.trust
DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: {D462304B-F73E-4DE3-A6F9-A432947FA468} = 80.251.201.177 80.251.201.178
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\3.0.0.134\CoIEPlg.dll
Notify: igfxcui - igfxdev.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0300000.086\SymEFA.sys [2010-1-2 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0300000.086\BHDrvx86.sys [2010-1-2 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0300000.086\cchpx86.sys [2010-1-2 482352]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100106.001\IDSvix86.sys [2010-1-10 343088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-4 102448]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-11-10 54632]
S3 FTLUND;Lundinova Filter Driver;c:\windows\system32\drivers\ftlund.sys [2009-10-3 6828]

=============== Created Last 30 ================

2010-01-10 10:07:17 0 d-----w- c:\users\jonna&~1\appdata\roaming\wsInspector
2010-01-10 10:03:42 0 d-----w- c:\program files\Startup Inspector for Windows
2010-01-10 09:53:21 0 d-----w- c:\program files\CCleaner
2010-01-06 13:17:39 0 d-----w- c:\windows\pss
2010-01-06 10:23:46 0 d-----w- C:\Temp
2010-01-05 10:28:12 0 d-----w- c:\users\jonna&~1\appdata\roaming\Malwarebytes
2010-01-05 10:28:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 10:28:03 0 d-----w- c:\programdata\Malwarebytes
2010-01-05 10:28:00 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 10:28:00 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-05 10:16:31 93056 ----a-w- C:\kxldapog.sys
2010-01-03 13:23:24 0 d-----w- c:\program files\Enigma Software Group
2010-01-03 04:47:12 0 d-----w- c:\windows\system32\N360_BACKUP
2010-01-02 19:59:07 0 d-----r- c:\program files\Norton Support
2010-01-02 19:43:59 0 d-----w- c:\users\jonna&~1\appdata\roaming\Tific
2010-01-02 19:43:14 0 d-----w- c:\program files\Norton PC Checkup
2010-01-02 15:50:47 25136 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2010-01-02 15:50:38 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-02 15:50:38 7386 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-02 15:50:38 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-02 15:50:38 0 d-----w- c:\program files\Symantec
2010-01-02 15:49:51 0 d-----w- c:\windows\system32\drivers\N360
2010-01-02 15:49:49 0 d-----w- c:\programdata\Symantec
2010-01-02 15:49:49 0 d-----w- c:\program files\Norton 360
2010-01-02 15:49:48 0 d-----w- c:\programdata\Norton
2010-01-02 15:45:07 0 d-----w- c:\programdata\NortonInstaller
2010-01-02 15:45:07 0 d-----w- c:\program files\NortonInstaller
2010-01-02 10:07:45 0 d-----w- c:\programdata\IObit
2010-01-02 10:07:34 0 d-----w- c:\program files\IObit
2010-01-02 06:35:49 0 d-----w- c:\programdata\RegCure
2010-01-02 05:43:31 488 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2010-01-01 15:21:54 0 d-----w- c:\programdata\SITEguard
2010-01-01 15:21:02 0 d-----w- c:\programdata\STOPzilla!
2010-01-01 15:21:02 0 d-----w- c:\program files\common files\iS3
2010-01-01 15:04:00 0 d-----w- c:\program files\TrendMicro
2010-01-01 13:21:09 0 d-----w- c:\program files\Startup Optimizer
2010-01-01 10:21:03 0 d---a-w- c:\programdata\TEMP
2010-01-01 09:13:27 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-01 09:13:27 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-01-01 06:26:58 65536 --sha-w- c:\users\jonna & mikael\ntuser.dat{b02c83b5-f69b-11de-a8ec-e768d37e1dc4}.TM.blf
2010-01-01 06:26:58 524288 --sha-w- c:\users\jonna & mikael\ntuser.dat{b02c83b5-f69b-11de-a8ec-e768d37e1dc4}.TMContainer00000000000000000002.regtrans-ms
2010-01-01 06:26:58 524288 --sha-w- c:\users\jonna & mikael\ntuser.dat{b02c83b5-f69b-11de-a8ec-e768d37e1dc4}.TMContainer00000000000000000001.regtrans-ms

==================== Find3M ====================

2010-01-06 10:42:44 5780 ----a-w- c:\users\jonna&~1\appdata\roaming\wklnhst.dat
2010-01-02 15:50:40 51200 ----a-w- c:\windows\inf\infpub.dat
2010-01-02 15:50:40 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-01-02 15:50:40 143360 ----a-w- c:\windows\inf\infstor.dat
2009-12-06 14:58:25 80612 ----a-w- c:\windows\system32\perfc00B.dat
2009-12-06 14:58:25 77100 ----a-w- c:\windows\system32\perfc006.dat
2009-12-06 14:58:25 76390 ----a-w- c:\windows\system32\perfc014.dat
2009-12-06 14:58:25 597836 ----a-w- c:\windows\system32\perfh01D.dat
2009-12-06 14:58:25 454842 ----a-w- c:\windows\system32\perfh006.dat
2009-12-06 14:58:25 443832 ----a-w- c:\windows\system32\perfh014.dat
2009-12-06 14:58:25 427118 ----a-w- c:\windows\system32\perfh00B.dat
2009-12-06 14:58:25 117416 ----a-w- c:\windows\system32\perfc01D.dat
2009-11-21 06:40:20 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34:39 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34:39 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59:58 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 11:53:06 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 11:52:54 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 11:52:46 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-15 15:48:26 141997 ----a-w- c:\windows\hppins20.dat
2009-11-11 21:54:09 19129 ----a-w- c:\windows\hpqins13.dat
2009-11-09 21:35:19 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2009-11-09 12:31:42 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30:03 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-02 19:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-02 15:01:10 138873 ----a-w- c:\windows\hpoins18.dat
2009-10-29 09:17:42 2048 ----a-w- c:\windows\system32\tzres.dll
2008-05-09 11:38:57 35978 ----a-w- c:\windows\inf\perflib\041d\perfd.dat
2008-05-09 11:38:57 35978 ----a-w- c:\windows\inf\perflib\041d\perfc.dat
2008-05-09 11:38:57 290490 ----a-w- c:\windows\inf\perflib\041d\perfi.dat
2008-05-09 11:38:57 290490 ----a-w- c:\windows\inf\perflib\041d\perfh.dat
2008-05-09 11:31:44 35166 ----a-w- c:\windows\inf\perflib\0414\perfd.dat
2008-05-09 11:31:44 35166 ----a-w- c:\windows\inf\perflib\0414\perfc.dat
2008-05-09 11:31:44 294254 ----a-w- c:\windows\inf\perflib\0414\perfi.dat
2008-05-09 11:31:44 294254 ----a-w- c:\windows\inf\perflib\0414\perfh.dat
2008-05-09 11:24:45 36790 ----a-w- c:\windows\inf\perflib\040b\perfd.dat
2008-05-09 11:24:45 36790 ----a-w- c:\windows\inf\perflib\040b\perfc.dat
2008-05-09 11:24:45 274158 ----a-w- c:\windows\inf\perflib\040b\perfi.dat
2008-05-09 11:24:45 274158 ----a-w- c:\windows\inf\perflib\040b\perfh.dat
2008-05-09 11:18:08 36364 ----a-w- c:\windows\inf\perflib\0406\perfd.dat
2008-05-09 11:18:08 36364 ----a-w- c:\windows\inf\perflib\0406\perfc.dat
2008-05-09 11:18:08 300302 ----a-w- c:\windows\inf\perflib\0406\perfi.dat
2008-05-09 11:18:08 300302 ----a-w- c:\windows\inf\perflib\0406\perfh.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 12:31:02,71 ===============




EDIT: Since a log was posted, I moved this topic to the HJT/Malware removal forum. Please be patient until a HJT Team member replies to your log ~ Elise

Attached Files


Edited by smurfizina, 10 January 2010 - 07:23 AM.


BC AdBot (Login to Remove)

 


#2 Pandy

Pandy

    Bleepin'


  • Members
  • 9,559 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:18 PM

Posted 10 January 2010 - 08:20 PM

Since this member has posted elsewhere about this issue, this topic will be closed. http://www.247fixes.com/forums/topic/5947-help/

Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight.

Hide not your talents. They for use were made. What's a sundial in the shade?

~ Benjamin Franklin

I am a Bleeping Computer fan! Are you?

Facebook

Follow us on Twitter





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users