|
Answer» Hey, i was skimming through my system folders recently to see if anything seemed out of the ordinary and noticed that there was a new file in my Local Disk called command.exe. I didn't think it was anything bad until I realized that command.com is the authentic system file that causes no harm and is located in the same folder. I googled it and certain websites said that it's an undesirable file that should be removed immediately.
Due to my hectic schedule I delayed a while in doing anything about it until yesterday when both my Sygate Firewall and WinPatrol notified me about strange behavior resulting from that file. I ran my AVG Free Antivirus but it didn't scan command.exe as a harmful file. I've ALSO got Spybot S+D, SuperAntiSpyware, and Ad-Aware installed on my comp. Should I just scan my computer with each of those programs in order to get rid of it? (I scanned with Superantispyware for an hour but it still hadn't gotten to scan that file and I didn't have anymore time to wait.)
I'll appreciate whatever you have to say, THANK you. I think this is malware, there shouldn't be a command.exe file in your windows folder. Try uploading the file to this site, the file will be scanned with a range of different AV solutions. http://www.virustotal.com/Very helpful website, thank you.
Antivirus Version Last Update Result
AntiVir 7.4.1.66 2007.09.02 HEUR/Malware
CAT-QuickHeal 9.00 2007.09.01 (Suspicious) - DNAScan
eSafe 7.0.15.0 2007.09.02 Suspicious Trojan/Worm
Ikarus T3.1.1.12 2007.09.03 Backdoor.Win32.Prorat.19.i
Panda 9.0.0.4 2007.09.02 Suspicious file
Sophos 4.21.0 2007.09.02 Mal/Heuri-D
Webwasher-Gateway 6.0.1 2007.09.02 Heuristic.Malware
File SIZE: 13824 bytes MD5: a60aa52b2f1c62390e1b4535355976a5 SHA1: a42d4a966a7f3719e992f21042b4cdd0d08892c 1 packers: PECOMPACT, BINARYRES packers: PecBundle, PECompact
So, 7 out of 31 engines found it to be harmful. Next?DLoad and run Stinger. Then DLoad install update and run AVG Anti-Spyware...iight, i ran stinger but not much happened, i'll update as SOON as i'm done with AVGIf the file still exists, you should delete it in Safe Mode. Then go ahead and post a HijackThis log and we'll see if anything else might running in the background.Good idea, i'll update asap.Due to lack of feedback, I am closing this topic. If you are the original POSTER and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.
If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
|