I run Windows XP SP2. Whenever i go to the "run" dialog box and enter "cmd", i get a dialog box that says your system is shutting down in 49:59. I have to type "shutdown -a" to get rid of it, but i've got sick of it. Plus i tried to compile the allegro library from command prompt which ended in errors showing "A system shutdown is in progress.". I went to the registry and went to HKLM\Software\Microsoft\WindowsNT\currentversion\winlogon. The value of "Userinit" there was "userinit.exe iph.exe". I removed the iph.exe from there and it doesn't show up in the task manager as well. But i still have the problem and don't know what's triggering it.
Can someone suggest me something?

10 Years
Discussion Span
Last Post by gerbil
Featured Replies
  • 1

    Symantec/S32ENIL.dll .. is there any chance you typed that incorrectly, arthas? It should be the name of a dll that exists in that Symantec S32 directory under program Files. Anyway, i notice that you are running Avast from Alwill Software, so that Symantec error is a leftover from an incomplete … Read More


You might be infected with the w32.blaster.worm virus. You should run a good anti-virus scan of your whole system with a good anti virus program.


I have macafee 2008. I scanned my computer thoroughly but to find nothing. The shutdown message has not stopped haunting me. SO what should I do now, please help me.


You could go into safe mode and run a alternative anti virus program ie Trend and run the DOS appliation together with the two pattern files ie lpt and sspda (latest versions,same site).
works like a bomb


I tried that but the shutdown message problem never stops haunting my computer.
Dont I have any other way.
Sorry for the trouble but I d be glad if you helped me.


so the hutdown message happens in safe mode asswell.

I have a client that called me with the same prob so I hope its somewhat like yours so I can reference later

If you are in a rush you can backup, format and install new OS on the drive (I never instruct users to format cos im not a format techy)-
keep me up to date


I am not in hurry of any kind. So what shall i do now. I dont too do format things as well.


i too tried the removal.bat. But whenever I run it it says "Are u sure u want to add c:\windows\temp\sta.reg to the registry.
Then when I click on Yes, it says
"Cannot Import c:\windows\temp\sta.reg.
The specified file is not a registry script. You can only import binary registry files from within the registry."
What is it?


Hi see if this will help you if its on a home pc

Go to registry editor and navigate to the following registry key:

HKEY_LOCAL_MACHINE \Software\Policies \Microsoft\Windows \WindowsUpdate\AU

Change the “NoAutoRebootWithLoggedOnUsers” DWord value to the required number.

0 = False (Allow auto-reboot)
1 = True (Disallow auto-reboot)


i tried to search for it in the registry bu i couldnt find the "\WindowsUpdate\AU" in the
"HKEY_LOCAL_MACHINE \Software\Policies \Microsoft\Windows \ " section.
I am using microsoft windows XP professional to re remind.
And actually what was the purpose of changing the registry key.
Was it meant for my shutdown problem
or was it for the #9 post(two steps above of this) ?


Surprise surprise!this is one funky problem, we'll crack it though.Im sticking to the roots of what your prob is(shutdown problem)
follow these
-windows repair through Recovery Console

if all fails post a HJT log and paste it here


I run Windows XP SP2. Whenever i go to the "run" dialog box and enter "cmd", i get a dialog box that says your system is shutting down in 49:59. I have to type "shutdown -a" to get rid of it, but i've got sick of it. Plus i tried to compile the allegro library from command prompt which ended in errors showing "A system shutdown is in progress.". I went to the registry and went to HKLM\Software\Microsoft\WindowsNT\currentversion\winlogon. The value of "Userinit" there was "userinit.exe iph.exe". I removed the iph.exe from there and it doesn't show up in the task manager as well. But i still have the problem and don't know what's triggering it.
Can someone suggest me something?

It has something to do with shutdown.exe of windows. It is place at start up you can stop this one by going to run command then type shutdown -a. It will stop fro executing..


It has something to do with shutdown.exe of windows. It is place at start up you can stop this one by going to run command then type shutdown -a. It will stop fro executing..

Fair enough,but if you read the whole post youll find he needs to do that every time and that should not be a continues thing when a user starts up.


Interesting lil problem that you have. Have you already checked that when you type the full command in the run window that you get the same thing..? ie type cmd.exe instead of cmd
And have you checked that in these two keys below that cmd points to system32\cmd.exe ? This reg file will fix that for you...

Windows Registry Editor Version 5.00

@="C:\\WINDOWS\\system32\\cmd.exe \"%1\""

@="C:\\WINDOWS\\system32\\cmd.exe \"%1\""

I had installed Digsby on mu computer.
Whenever I start the mesage that used to appear when I started cmd reappears.
What is happening, I dont know.
What shall i do?


ohk I dont know if you followed gerbill's post eighter way drop a High Jact This log here so I can have a good look to see if theres any sussy behaviour.if you not firmiliar wi with Hijack This let me know


I could add that you were infected by a known piece of malware, most likely via an infected thumdrive. Try this:
==Download SDFix from here: http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
and save it to your desktop. Dclick SDFix.exe and choose Run to extract it to %systemdrive%, which commonly will be C:\

** ==Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that procedure also if you have Opera.
Close ATF. Run ATF in any other accounts.
=You must restart your computer in Safe Mode:
- press F8 several times while POST is running and before IDE detection completes.
- On the Windows Advanced Options Menu, select Safe Mode and press Enter.
- When the Boot Menu appears again, select Microsoft Windows XP and press Enter.
- Log in by using the Administrator account and password. NOTE: The password is blank by default unless you set a password.
=Open the extracted SDFix folder, C:\SDFix and double click RunThis.bat to start the script. Type Y to begin the cleanup.
You will be prompted to press any key to Reboot - the pc will then restart.
The tool will run again and complete the removal process then display Finished; press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
Restart the pc in normal mode. Post the contents of the file Report.txt here, along with the log of a fresh hijackthis scan run in normal mode.

** Instead of ATF you may wish to substitue this cleaner.. it is the one I use regularly.
==Get CCleaner from http://www.ccleaner.com/ - and install it in a new folder. You should keep this one for general use. I set the installation checkboxes only to open from the recycle bin. It's neater that way.
Now run CCleaner from the recycle bin rclick menu using its default settings [if you set up CCleaner as i suggested, rclicking the bin icon should give you the Open CCleaner option...].
If you have FireFox open the Applications tab and ensure at least that Cookies and Cache are checked.
Select the Cleaner icon, press Run Cleaner.
[For future quick temp file cleaning select the options you wish to use via the Windows and Applications tabs ..]


I had informations about replies in my inbox,
but I couldnt find those in the forum, I was amazed. Its just today that I realized that everything had gone to the Page 2. Sorry for that. Any way, I tried the "cmd.exe"
instead of cmd , but the result was same.
I searched in the registry for the mentioned keys, I it wasnt there. Inside HKEY_CLASSES_ROOT\Folder\shell, there are only "explore" , "teracopy" , and "open". What should I do. Cant I add the key there, or what is it that I should do?
This is the same for another key too. I couldnt find it( actually it wasnt there).
I also have run "chkdsk" from cmd for c:
but it had no effecct.


Arthas, I need a good slapping. Ignore my post about those two shell keys - that's something I put in my sys.
But do try post #18


I also had this problem and miraculously I cured it :D

I want to share it here - After using removal.bat, I also got the "registry can not be imported..." kind of message, I continued it and then I manually searched the registry for "iph.exe". I deleted each and every value which I found. AND viola !!! I got my problem fixed.

Hey seniors, try this and you will get the solution

Please do reply if it helps...

Harish Dobhal


I also tried gebrils post #18. But whenever I ran that runthis.bat in safe mode, it complained after sometimes that
16 bit MS-DOS Subsystem
c:/Program../Symantec/S32ENIL.dll. An installable Virtual driver failed DLL initialization.
Choose close to ternimate the app.
(It all came in a dialog box)
When I chose Ignore, it says "Cannot load VDM IPX/SPX support". I have to now quit the shell.
Now when I restart in normal mode, it says finalizing.. and again displays the same .dll problem. Here also when I chose ignore it does sth. I have got a report. How is it that I send it to you people if needed.
I also tried the removing of the iph.exe's from the regisery. But it had not done me faour. Is it that I did not know the proper sequence of removing the values. And is it due to the same that I am being tortured(I mean iph.exe).


I also tried searching the "iph.exe" int the registry, but nothing was found. I thing there nothing called iph.exe in my registry.


And here is the HJT log of my system.
Please analyse it.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:49:55, on 27/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
D:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
d:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Adobe Photoshop CS2\Photoshop.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
H:\backup Softwares\Internet tools\download manager\Internet Download Manager\IDMan.exe
H:\backup Softwares\Internet tools\download manager\Internet Download Manager\IEMonitor.exe
d:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = LRI Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = phulchoki:80
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wscript.exe C:\WINDOWS\system32\SemiAntiVirus.vbs
O1 - Hosts: paypal.com
O1 - Hosts: paypal.com
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - H:\backup Softwares\Internet tools\download manager\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - d:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [MWLExe] C:\PROGRA~1\Mcafee\MWL\MWLGuiSt.exe
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ares] "D:\Notepad++\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [IDMan] H:\backup Softwares\Internet tools\download manager\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Digsby.lnk = D:\Program Files\Digsby\digsby.exe
O4 - Startup: Yankee Clipper III.lnk = D:\Program Files\YCIII\YankClip.exe
O8 - Extra context menu item: Download all links with IDM - H:\backup Softwares\Internet tools\download manager\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - H:\backup Softwares\Internet tools\download manager\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - H:\backup Softwares\Internet tools\download manager\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{C6C79FE9-09D1-4B87-B8C6-60F43FF84CA4}: NameServer =,
O21 - SSODL: JavaView - {DA191DE0-AA86-D04E-4B87-2A3D4928BE99} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - D:\Ares\chatServer.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - McAfee, Inc. - C:\Program Files\Mcafee\MWL\MwlSvc.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - d:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe

End of file - 9761 bytes

Symantec/S32ENIL.dll .. is there any chance you typed that incorrectly, arthas? It should be the name of a dll that exists in that Symantec S32 directory under program Files. Anyway, i notice that you are running Avast from Alwill Software, so that Symantec error is a leftover from an incomplete uninstallation of Symantec. To fix that you should go to Symantec's website for the removal tool for the edition of their AV that you were using. For your immediate problem you can do this....
==Navigate to this key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers
-in the right pane rclick VDD and delete it.
-in the Edit menu point to New and then select Multi-string Value.
-type VDD in the Value Name box, press ENTER.
-exit Regedit.

The Symantec tool will clear out all ? remnants though....
[with Avast installed I am surprised you do not have this entry for VDD at that key:
C:\Program Files\Alwil Software\Avast4\aswMonVd.dll ... but anyway..]
That is an incomplete SDFix log. Try running it again.


I did what you said. I deleted VDD and re added it.
I ran the runthis.bat and it went on well.
Down is the report of it( hope this time it is complete).

[b]SDFix: Version 1.207 [/b]
Run by Ashok on 28/07/2008 at 22:00

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:

Restoring Default Security Values
Restoring Default Hosts File


[b]Checking Files [/b]: 

No Trojan Files Found

Removing Temp Files

[b]ADS Check [/b]:

                                 [b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-28 22:13:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

[b]Remaining Services [/b]:

Authorized Application Key Export:

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"D:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="D:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"D:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="D:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\SightSpeed\\SightSpeed.exe"="C:\\Program Files\\SightSpeed\\SightSpeed.exe:*:Enabled:SightSpeed"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"d:\\Program Files\\BitTorrent\\bittorrent.exe"="d:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:Torrent"
"D:\\Program Files\\CEZEO software\\LanTalk NET\\LanTalk.exe"="D:\\Program Files\\CEZEO software\\LanTalk NET\\LanTalk.exe:*:Enabled:LanTalk NET Messenger"
"D:\\Program Files\\CEZEO software\\LanTalk XP\\LanTalk.exe"="D:\\Program Files\\CEZEO software\\LanTalk XP\\LanTalk.exe:*:Enabled:LanTalk XP Messenger"
"D:\\Notepad++\\Ares\\Ares.exe"="D:\\Notepad++\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\McAfee\\MWL\\MwlSvc.exe"="C:\\Program Files\\McAfee\\MWL\\MwlSvc.exe:*:Enabled:McAfee Wireless Network Security"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[b]Remaining Files [/b]:

File Backups: - C:\SDFix\backups\backups.zip

[b]Files with Hidden Attributes [/b]:

Tue 22 Apr 2008       625,664 A.SH. --- "C:\Program Files\Internet Explorer\iexplore.exe"
Mon 21 Jul 2008        50,689 A..H. --- "C:\Documents and Settings\Ashok\Application Data\EHCalCtrl3401.dll"
Mon 21 Jul 2008        31,233 A..H. --- "C:\Documents and Settings\Ashok\Application Data\EHDateCtrl2021.dll"
Mon 21 Jul 2008        16,897 A..H. --- "C:\Documents and Settings\Ashok\Application Data\EHInterfaces3301.dll"
Mon 21 Jul 2008        24,576 A..H. --- "C:\Documents and Settings\Ashok\Application Data\EHTimeCtrl2021.DLL"
Mon 21 Jul 2008        27,649 A..H. --- "C:\Documents and Settings\Ashok\Application Data\EHWindowSplitter6121.dll"
Mon 21 Jul 2008        66,048 A..H. --- "C:\Documents and Settings\Ashok\Application Data\MBSQTMoviePlugin8260.dll"
Mon 21 Jul 2008        26,624 A..H. --- "C:\Documents and Settings\Ashok\Application Data\MBSRegistrationPlugin8257.dll"
Mon 21 Jul 2008        88,576 A..H. --- "C:\Documents and Settings\Ashok\Application Data\rbap550.dll"
Mon 21 Jul 2008        74,240 A..H. --- "C:\Documents and Settings\Ashok\Application Data\rbqt550.DLL"
Thu 26 Jun 2008        20,487 A.SHR --- "C:\Program Files\McAfee\MQC\MRU.bak"
Thu 26 Jun 2008           265 A.SHR --- "C:\Program Files\McAfee\MQC\qcconf.bak"
Mon 28 Jul 2008    11,306,977 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0c909c63b4fa217757574b9dcdd658c3\BIT2F.tmp"
Mon 28 Jul 2008   170,697,558 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\97de84be36b27af6e66a0586433cda52\BIT2C.tmp"
Mon 28 Jul 2008    15,530,519 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9ec3943a72ea4aa7fb7b808e2b7554c8\BIT2D.tmp"
Thu 17 Jul 2008             0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT1.tmp"
Thu 19 Jun 2008     7,726,360 A..H. --- "C:\Documents and Settings\All Users\Application Data\Google Updater\cache\BITA.tmp"
Mon 14 Jan 2008           444 A..HR --- "C:\Documents and Settings\Ashok\Application Data\SecuROM\UserData\securom_v7_01.bak"


I see that SDFix detected no malware. Please run this scan to see what it turns up:
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.


I ran combo fix on my system, and I think it worked. I have attached the log of it below.
I can finally run DOS commands without hesitation. Thanks a lot everyone, and especially gebril and sattis.
And would you plz tell me what combofix did to my system. It would be more interesting to know how to manually fix the problem.

ComboFix 08-07-31.01 - Ashok 2008-08-01 11:35:13.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.117 [GMT 5.75:45]
Running from: D:\My Documents\Downloads\Programs\ComboFix.exe
 * Created a new restore point
 * Resident AV is active


(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

C:\Documents and Settings\Ashok\Local Settings\Temporary Internet Files\Content.IE5\52CENGOA\cnsminex_empty[1].htm
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\avatar.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\bgfadel.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\bgfader.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\common-x.css
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\common.css
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\cornerbl.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\cornerbr.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\ext_def.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\ext_roll.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\include.js
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\index.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\loader.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\loading.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\logo.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\max_def.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\max_roll.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\min_def.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\min_roll.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\noflash.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\res_def.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\res_roll.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\spacer.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\spacer.swf
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\topgrad.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\window.ico
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]005D103
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]00B2E5D
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05B6A48
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05B7479.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05B807F.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05B8F35.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05BA9D2.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05BD7F6.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05E2AEF.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05E64BB.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05E8A16.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05EADEA.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05ECF6C.bin
C:\Program Files\MyWebSearch\bar\Cache\[u]0[/u]05EED06
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search3
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat

(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))


(((((((((((((((((((((((((   Files Created from 2008-07-01 to 2008-08-01  )))))))))))))))))))))))))))))))

2008-07-29 23:37 . 2008-08-01 01:12	18	--a------	C:\WINDOWS\IDMan.INI
2008-07-28 17:23 . 2008-07-28 17:23	0	--a------	C:\WINDOWS\WB.ini
2008-07-28 16:56 . 2008-07-28 16:56	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-27 22:35 . 2008-07-27 22:35	<DIR>	d--------	C:\Documents and Settings\Default User
2008-07-22 19:51 . 2008-07-22 19:51	17,280	-rahs----	C:\WINDOWS\system32\SemiAntiVirus.vbs
2008-07-21 21:07 . 2008-07-21 21:07	<DIR>	d--------	C:\Program Files\Microsoft.NET
2008-07-21 21:07 . 2008-07-21 21:07	<DIR>	d--------	C:\Program Files\Microsoft Works
2008-07-21 21:05 . 2008-07-29 01:16	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-21 21:04 . 2008-07-21 21:04	<DIR>	dr-h-----	C:\MSOCache
2008-07-21 19:20 . 2008-07-21 19:21	<DIR>	d--------	C:\WINDOWS\ERUNT
2008-07-21 19:18 . 2008-07-21 19:19	<DIR>	d--------	C:\Documents and Settings\Administrator
2008-07-21 17:18 . 2008-07-28 22:15	<DIR>	d--------	C:\SDFix
2008-07-19 00:15 . 2008-07-19 00:30	<DIR>	d--------	C:\Documents and Settings\Ashok\Application Data\Notepad++
2008-07-18 23:56 . 2008-07-19 00:04	189	--a------	C:\tauko.HTM
2008-07-17 22:21 . 2008-06-20 23:21	245,248	-----c---	C:\WINDOWS\system32\dllcache\mswsock.dll
2008-07-17 22:21 . 2008-06-20 15:17	225,920	-----c---	C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-07-17 22:21 . 2008-06-20 16:29	138,368	-----c---	C:\WINDOWS\system32\dllcache\afd.sys
2008-07-17 22:21 . 2006-08-16 17:53	100,352	-----c---	C:\WINDOWS\system32\dllcache\6to4svc.dll
2008-07-17 13:46 . 2008-07-17 13:46	<DIR>	d--------	C:\Documents and Settings\All Users\Application Data\GRETECH
2008-07-17 13:45 . 2008-07-17 13:45	<DIR>	d--------	C:\Documents and Settings\Ashok\Application Data\GRETECH
2008-07-17 13:41 . 2008-07-29 22:48	<DIR>	d--------	C:\Documents and Settings\Ashok\Application Data\TeraCopy
2008-07-17 13:08 . 2008-07-17 13:09	<DIR>	d--------	C:\Documents and Settings\Ashok\Application Data\Digsby
2008-07-17 13:00 . 2008-07-17 13:00	<DIR>	d--------	C:\Documents and Settings\Ashok\Application Data\MSNInstaller
2008-07-13 15:25 . 2008-07-13 15:25	<DIR>	d--------	C:\Documents and Settings\PC WORLD\Application Data\SiteAdvisor
2008-07-09 22:59 . 2008-07-09 22:59	0	--a------	C:\WINDOWS\windowfx3.ini
2008-07-09 22:58 . 2008-07-09 23:00	0	--a------	C:\WINDOWS\windowfx2.ini
2008-07-08 23:23 . 2008-07-08 23:23	552	--a------	C:\WINDOWS\system32\d3d8caps.dat
2008-07-04 14:19 . 2008-07-04 14:19	<DIR>	d--------	C:\Documents and Settings\Ashok\Application Data\Apple Computer

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-08-01 05:57	---------	d-----w	C:\Documents and Settings\Ashok\Application Data\DMCache
2008-07-31 17:44	---------	d-----w	C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-07-30 07:16	---------	d-----w	C:\Documents and Settings\Ashok\Application Data\Yahoo!
2008-07-30 07:16	---------	d-----w	C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-29 17:52	---------	d-----w	C:\Documents and Settings\Ashok\Application Data\IDM
2008-07-28 11:10	---------	d-----w	C:\Program Files\Yahoo!
2008-07-27 16:34	---------	d-----w	C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-21 10:29	88,576	---ha-w	C:\Documents and Settings\Ashok\Application Data\rbap550.dll
2008-07-21 10:29	66,048	---ha-w	C:\Documents and Settings\Ashok\Application Data\MBSQTMoviePlugin8260.dll
2008-07-21 10:29	50,689	---ha-w	C:\Documents and Settings\Ashok\Application Data\EHCalCtrl3401.dll
2008-07-21 10:29	31,233	---ha-w	C:\Documents and Settings\Ashok\Application Data\EHDateCtrl2021.dll
2008-07-21 10:29	27

ComboFix does operations that are in general terms similar to other anti-malware tools. Briefly, I would not dream of attempting to emulate it manually. Check its bat file for some of its operations.
I see the point of your infection - a USB device.

==Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that procedure also if you have Opera. Repeat in other User profiles.
Close ATF.
==Please use IE or Firefox to do an online scan at panda:- http://www.pandasecurity.com/homeusers/solutions/activescan/?
-for the free online virus scan select the link Scan your PC, then Register [otherwise there will be no disinfection, merely detection] with a valid email and follow through.
Please ATTACH to your post the log it produces.
==download hijackthis: http://www.majorgeeks.com/download5554.html
-copy it to a new FOLDER placed either alongside your program files or on your desktop and then... rename hijackthis.exe to imabunny.exe
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here.

This question has already been answered. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.