1.

Solve : command.exe?

Answer»

Hey, i was skimming through my system folders recently to see if anything seemed out of the ordinary and noticed that there was a new file in my Local Disk called command.exe. I didn't think it was anything bad until I realized that command.com is the authentic system file that causes no harm and is located in the same folder. I googled it and certain websites said that it's an undesirable file that should be removed immediately.

Due to my hectic schedule I delayed a while in doing anything about it until yesterday when both my Sygate Firewall and WinPatrol notified me about strange behavior resulting from that file. I ran my AVG Free Antivirus but it didn't scan command.exe as a harmful file. I've ALSO got Spybot S+D, SuperAntiSpyware, and Ad-Aware installed on my comp. Should I just scan my computer with each of those programs in order to get rid of it? (I scanned with Superantispyware for an hour but it still hadn't gotten to scan that file and I didn't have anymore time to wait.)

I'll appreciate whatever you have to say, THANK you.  I think this is malware, there shouldn't be a command.exe file in your windows folder. Try uploading the file to this site, the file will be scanned with a range of different AV solutions.
http://www.virustotal.com/Very helpful website, thank you.

Antivirus  Version  Last Update  Result

AntiVir  7.4.1.66  2007.09.02  HEUR/Malware

CAT-QuickHeal  9.00  2007.09.01  (Suspicious) - DNAScan

eSafe  7.0.15.0  2007.09.02  Suspicious Trojan/Worm

Ikarus  T3.1.1.12  2007.09.03  Backdoor.Win32.Prorat.19.i

Panda  9.0.0.4  2007.09.02  Suspicious file

Sophos  4.21.0  2007.09.02  Mal/Heuri-D

Webwasher-Gateway  6.0.1  2007.09.02  Heuristic.Malware

File SIZE: 13824 bytes
MD5: a60aa52b2f1c62390e1b4535355976a5
SHA1: a42d4a966a7f3719e992f21042b4cdd0d08892c 1
packers: PECOMPACT, BINARYRES
packers: PecBundle, PECompact

So, 7 out of 31 engines found it to be harmful. Next?DLoad and run Stinger.
Then DLoad install update and run AVG Anti-Spyware...iight, i ran stinger but not much happened, i'll update as SOON as i'm done with AVGIf the file still exists, you should delete it in Safe Mode.  Then go ahead and post a HijackThis log and we'll see if anything else might running in the background.Good idea, i'll update asap.Due to lack of feedback, I am closing this topic.  If you are the original POSTER and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.



Discussion

No Comment Found