Solved Possibly infection, am I safe?

Discussion in 'Am I Infected?' started by endlessroads, Jul 23, 2012.


Thread Status:
Not open for further replies.
  1. endlessroads Bronze Member

    Bronze
    Message Count:
    6
    Likes Received:
    0
    My System
    Loading...
    I apologize if this has been recently posted and I missed it, but here's my problem.

    While browsing the web earlier I got a prompt that I was unsure about. The prompt was one of the common "Do you want to allow following program to make changes to this computer" asking if I would allow 'Windows Command Processor' make changes, it said the publisher was verified, and I think it said windows, but I'm not certain. I said no, and the pop up came back a second later, every time I pressed no it did this, it would not stop. I did a quick google on my phone and saw that there have been a lot of people that have gotten this prompt, and that it is in fact a virus/trojan or whatever. Most of the people posting had said yes to the prompt and were suffering problems from that, but I have no said yes. I did a restart of my computer to see if it happened again, the load up was very slow, when windows did load the normal programs that load up (steam, msn) did not and after about 60 seconds the prompt came back up, this got me pretty worried. I looked at the file that the prompt was coming from or trying to open and saw that it was in my appdata folder. I rebooted my comp in safe mode and went to the location and saw 1 or 2 files with strange names (eg xuahshzhzh, I assume randomized) I deleted these files, and then again from my recycling bin. I then went to msconfig and looked up my start up files or whatever they are, I noticed an unknown one that was enabled and had a randomized name again, I disabled it and then went to its location, found it and deleted it. I restarted my computer in normal mode, everything loaded quickly as normal and programs launched as normal and there has been no prompt since I've done that (about an hour ago). Please google 'windows command processor' if you would like to see what others are saying, but I have seen no solutions and mainly people posting large logs and being told complex ways of trying to find a fix. I really dont know much about software and this kind of stuff so what I really want to know is am I safe? Everything seems to be gone (Although when I look at msconfig>start up, I can still see the randomized file but it is disabled and when I recheck its location it is no longer there) and my computer is running as normal, should there be others precautions or something I take? Any help and opinion if very appreciated, I hate the uneasy feeling this stuff gives me.

    Ps. Virus scans come up clean

  2. Babis Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    12
    My System
    Loading...
    Try this :

    Delete Windows Command Processor files:%appdata%\npswf32.dll
    %appdata%\Inspector-[rnd].exe
    %desktopdir%\Windows Command Processor.lnk
    %commonprograms%\Windows Command Processor.lnk
    Delete Windows Command Processor registry files:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run!Inspectordiv class=”downloadbutton”
  3. endlessroads Bronze Member

    Bronze
    Message Count:
    6
    Likes Received:
    0
    My System
    Loading...
    I'm not exactly sure on what you want me to do there Babis? I'm fairly confident I don't have those files to delete, because I never allowed windows command processor to take action.

    Also, I have learned that If I had press 'yes' to the prompts, the virus would have run a fake virus detection that showed multiple critical threats and then asked me to buy a fake program to get rid of the threats. None of this is happened, so If I have prevented this, does this mean I'm safe from the virus? Because it doesn't sound all that dangerous if it only tries to make you buy something, and I've stopped it from doing that...
  4. Google Advertisement

  5. Babis Bronze Member

    Bronze
    Message Count:
    87
    Likes Received:
    12
    My System
    Loading...
    In that case, yes, you are safe As far as I know. :)
  6. endlessroads Bronze Member

    Bronze
    Message Count:
    6
    Likes Received:
    0
    My System
    Loading...
    Thanks haha, and I hope I am safe!
  7. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,758
    My System
    Loading...
    I concur :)
  8. endlessroads Bronze Member

    Bronze
    Message Count:
    6
    Likes Received:
    0
    My System
    Loading...
    Good to hear crush, thank you.
  9. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,758
    My System
    Loading...
    Solved then endlessroads?
  10. endlessroads Bronze Member

    Bronze
    Message Count:
    6
    Likes Received:
    0
    My System
    Loading...
    Sorry for the late reply, but yes solved, no problems and you guys made me confident enough not to take further action :)

Possibly infection, am I safe?

Thread Status:
Not open for further replies.