Virus or Trojan utilizes cmd.exe for nearly 100 percent

Virus or Trojan utilizes cmd.exe for nearly 100 percent

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Virus or Trojan utilizes cmd.exe for nearly 100 percent Evert 09-17-2007
Posted by =?Utf-8?B?RXZlcnQ=?= on September 17, 2007, 9:40 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Since a week or two our nt4 PC's and servers are haven a problem with a vitus
or trojan that uses cmd.exe . it uses nearly 100 percent of the cpu making
the computer sluggish and it also causes problems with dhcp and dns.
It started with a program called dirx9.exe and an entry in the registry that
started this program at startup. After startup it takes awhile before the
program starts cmd.exe . When unseen or undetected it starts even more
instances of cmd.exe and dividing the cpu time nicely between all these
instances. The first time i was able to stop the process dirx9.exe and
removed the entry from the registry and after a restart the computers
functions normally. After two days dirx9.exe shows up in the processes and
starts cmd.exe again. This time i could not stop the process, there was no
entry in the registry and i had to clean the computers in VGA mode. Again one
or two days later cmd.exe was started and used almost 100 percent but this
time there is no dirx9.exe as a process, there is no entry in the registry
and the only thing i can do is rename cmd.exe to prevent it from being
started. For the pc's this is a workable way but on the server are some
programs that need cmd.exe so i cannot rename it.
I scanned the computers and servers with a variety of antivirus,
anti-spyware and other security software but they do not find anything.
Updating to a higher level of system software is in the moment no option
because some programs are not made for newer systems.
If anyone knows an answer please let me know.
Greetings

Posted by James Matthews on September 26, 2007, 12:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sounds like a lame attempt at trying something. Or they want you to think
it's legit!

--

http://www.goldwatches.com/mens/cufflinks.html
http://www.jewelerslounge.com/
> Since a week or two our nt4 PC's and servers are haven a problem with a
> vitus
> or trojan that uses cmd.exe . it uses nearly 100 percent of the cpu making
> the computer sluggish and it also causes problems with dhcp and dns.
> It started with a program called dirx9.exe and an entry in the registry
> that
> started this program at startup. After startup it takes awhile before the
> program starts cmd.exe . When unseen or undetected it starts even more
> instances of cmd.exe and dividing the cpu time nicely between all these
> instances. The first time i was able to stop the process dirx9.exe and
> removed the entry from the registry and after a restart the computers
> functions normally. After two days dirx9.exe shows up in the processes and
> starts cmd.exe again. This time i could not stop the process, there was no
> entry in the registry and i had to clean the computers in VGA mode. Again
> one
> or two days later cmd.exe was started and used almost 100 percent but this
> time there is no dirx9.exe as a process, there is no entry in the registry
> and the only thing i can do is rename cmd.exe to prevent it from being
> started. For the pc's this is a workable way but on the server are some
> programs that need cmd.exe so i cannot rename it.
> I scanned the computers and servers with a variety of antivirus,
> anti-spyware and other security software but they do not find anything.
> Updating to a higher level of system software is in the moment no option
> because some programs are not made for newer systems.
> If anyone knows an answer please let me know.
> Greetings
>


Similar ThreadsPosted
trojan virus June 18, 2008, 1:26 pm
Help! Trojan Horse Virus July 20, 2005, 7:22 pm
Beyond.Class Trojan virus October 27, 2005, 7:25 am
virus, trojan, malware August 20, 2008, 4:32 pm
Removal of Trojan Virus Startpage June 27, 2005, 12:25 pm
Hackern.ini file = virus/trojan ? November 15, 2006, 5:31 pm
Removal of Virus/Trojan DLLs ? November 25, 2007, 12:13 am
Re: Trojan Horse Dropper.small.28.AU virus May 20, 2006, 12:13 am
JS Downloader Agent (Virus) and Trojan Horses January 27, 2008, 2:24 pm
How to find virus/worm/trojan on network client September 21, 2005, 11:29 pm

The site map in XML format XML site map

Contact Us | Privacy Policy