Solved

command prompt restarts explorer.exe

Posted on 2009-04-07
10
2,873 Views
Last Modified: 2012-05-06
I am unable to open the command prompt using start -> run -> cmd. When i do this, it restarts explorer.exe.  However, when i do start->run->command  the command propt opens up fine.
0
Comment
Question by:bman21
  • 3
  • 2
  • 2
  • +2
10 Comments
 
LVL 7

Expert Comment

by:Sappbrosts
ID: 24090532
does it also happen when you  do start > run > regedit ?

you may want to look at this
http://www.bleepingcomputer.com/forums/topic215025.html
0
 
LVL 1

Expert Comment

by:bindnera
ID: 24090576
Your infected; or were infected at some point. The file is corrupted.
 
Run a file check on the O/S.

If you have an XP CD:
Click START, RUN, type in:

sfc /purgecache

(This ensures that system files are copied from your Windows installation media, and files which may be infected with malware or are corrupted are not copied from your drive.)

Then type in:

sfc /scannow

Have your XP CD handy.


If you don't have an XP CD:
Click START, RUN, type in:

sfc /scannow
0
 
LVL 59

Accepted Solution

by:
LeeTutor earned 500 total points
ID: 24090619
You have a corrupted CMD.EXE file, presumably.  You can put your XP installation CD in the drive, then type this command at the COMMAND.COM prompt:

expand d:\i386\cmd.ex_ c:\windows\system32

(where d: is the drive of your CD-ROM)

This will expand the compressed version of the CMD.EXE file into the system32 directory.  You will probably need to rename the current cmd.exe to something else.  And while you're doing that, take a look and see if you have a file call CMD.COM in the folder.  This invalid version of CMD is put there by malware, and should be deleted.
0
 
LVL 7

Expert Comment

by:Sappbrosts
ID: 24090770
those are great answers, but replacing the file, and sfc /scannow wont clean the infection


you may want to look at this
http://www.bleepingcomputer.com/forums/topic215025.html
0
 
LVL 59

Expert Comment

by:LeeTutor
ID: 24090890
I agree that there is most likely an infection and that needs to be done also.
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 2

Author Comment

by:bman21
ID: 24090962
yes, it does restart explorer.exe when i run regedit.  I'm not able to use a cd at the moment, i am working on this computer from a remote location.  as soon as i can get the computer i will give LeeTutor's and bindnera's solution a try.  Thanks for the quick response!
0
 
LVL 2

Author Comment

by:bman21
ID: 24091154
also, on a side note.  i was able to install avg free, but wasn't able to update it's virus database.  I went ahead and ran avg, but all it found were the usual cookies and no infections (more than likely because the database can't be updated...)
0
 
LVL 2

Author Closing Comment

by:bman21
ID: 31567673
i went ahead and reinstalled my OS.
0
 
LVL 1

Expert Comment

by:fcar807
ID: 24613027
sounds like MS anti-virus 2009, malware program

Antivirus2009 (Antivirus 2009) Removal Instructions


Antivirus 2009 Descriptions:


Here we go again! Antivirus2009, also known as Antivirus 2009, is one of the latest counterfeit antispyware that devastates the Internet community. Antivirus 2009 is a clone of the infamous Antivirus 2008 that previously reported by us. Antivirus 2009 usually come up after you installed a video codec that come with Trojan, malware and virus. Antivirus 2009 normally generates fake and misleading system popup error messages so end-users will be tricked into purchase Antivirus 2009.

It is very important to remove all the components of of the Antivirus 2009 and all the malware and trojans that it might have come bundle with (such as zlob.trojan, trojan.vundo and Trojan.Downloader). To effectively remove Antivirus 2009, we have created a manual removal instructions which is easy to understand.



Manual Antivirus 2009 Removal Instructions:

Unregister Antivirus 2009 DLL Files:
(Learn how to do this)
shlwapi.dll
wininet.dll

Stop Antivirus 2009 Processes:
(Learn how to do this)
av2009.exe
Antivirus 2009.lnk
Uninstall Antivirus.lnk
Antivirus2009.exe

Find and Delete these Antivirus 2009:
(Learn how to do this)
av2009.exe
Antivirus2009.exe
shlwapi.dll
wininet.dll
Antivirus 2009.lnk
Uninstall Antivirus 2009.lnk

Remove Antivirus 2009 Registry Values:
(Learn how to do this)
HKEY_CURRENT_USER\Software\Antivirus
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Antivirus = %ProgramFiles%\Antivirus 2009\Antvrs.exe

You can try this article xpantivirus-2009-removal-guide/othersoftware this one remove-antivirus-2009/othersoftware

You can also download Kaspersky antivirus, Kaspersky Anti-Virus Products

You can also download the free version of Avira Antivir to remove the spyware (update) to remove the spyware (update) another option are this one: MaleWareBytes antivirus

0
 
LVL 1

Expert Comment

by:fcar807
ID: 24613037
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Migration of Exchange mailbox can be done with the ExProfre.exe tool. But at times, when the ExProfre.exe tool migrates the Exchange Server user profile, it results in numerous synchronization problems. Synchronization error messages appear in the e…
For both online and offline retail, the cross-channel business is the most recent pattern in the B2C trade space.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now