Removing the cmd auto shutdown virus

Posted by Techie Kid on November 9th, 2008 and filed under Virus

A few moments ago, I fixed my friend’s computer’s problem. She was having problems accessing the command prompt (DOS) from her Windows XP operating system. Every time she attempts to execute “cmd” on her Run dialog box, her computer automatically shuts down. Here is my analysis on how the virus prevents her from using the command prompt and how to remove the virus from the system.
Problem

A virus is preventing the user from using the command prompt. When “cmd” is used, the system automatically shuts off.

Analysis

After giving attempting the “cmd” on her system, the command prompt executes a file called “pc-off.bat“. If my assumptions are correct, this file causes the system to shut down. The file injects itself before the “cmd” command starts.

The only way that this can be done is to inject a command in the Command Processor registry entry. To solve the problem, we have to trace and remove the command that was injected by the virus.

Solution

We must first gain access to our registry editor (regedit on your run prompt). In some cases, the virus disables user (admin) access to the registry. Since the virus injects itself in our command prompt, using DOS to access the registry is not possible. What I can suggest is you download and install an alternate registry editor which you can use to browse your registry editors.

One you gain access to the system registry, browse on the [HKEY_CURRENT_USERSoftwareMicrosoftCommand Processor] and remove the “autorun“= “c:Windowspc-off.bat” entry.


Remove or delete the highlighted entry.

After removing the autorun entry, download and run this batch file.

In some reported cases, the pc-off.bat virus have other variations like bar311.exe, password_viewer.exe, and photos.zip.exe. The fix file above should remove these files as well.

After fixing the problem, update your anti-virus or buy an updated anti-virus to prevent further infection.

Like my post? Please share:
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • BlinkList
  • blogmarks
  • DZone
  • Live
  • Reddit
  • Slashdot
  • Socialogs
  • SphereIt
  • StumbleUpon
  • Technorati
  • Ratimarks
  • blogtercimlap
  • eKudos
  • email
  • Fark
  • Gwar
  • LinkaGoGo
  • LinkArena
  • LinkedIn
  • Linkter
  • MySpace
  • Netvibes
  • Ping.fm
  • Tumblr
  • Webride
  • Wikio
  • Wists
  • Wykop
  • Yahoo! Buzz

Related articles

About the Author

Techie Kid is a multi-niche blogger, photography enthusiast, WordCamp 2008 organizer, Philippine Blog Awards 2009 organizer, and Philippine Blog Awards 2008 Bloggers’ Choice Awardee.

28 Responses to “Removing the cmd auto shutdown virus”

  1. Jehzeel Laurente Says:

    wow! thanks for this post! It helped me solve my shutdown prob :D

    Reply



  2. engr vicencio Says:

    it is the best solution i ever found! i tried a lot but this is the most accurate. thanks!

    Reply



  3. tiara Says:

    ah. had the same problem a few months ago… pero ang ginamit ko noob killer. :)

    Reply



  4. andi Says:

    not working

    Reply



  5. specialist Says:

    Great… my friend problem was solve.. thanks br0 :)

    Reply



  6. BellaCullen Says:

    Hi there! Thanks very much for this. I was able to get rid of this extremely annoying virus and can now use “CMD” anytime. Thanks again!

    -BC

    Reply



  7. abby Says:

    ei thanks…it really works…;)

    Reply



  8. keepU Says:

    Im having trouble with my PC coz every 2:30 min in using it, my internet connection is gone…how to solve this please help me..tnx

    Reply



  9. anthony Says:

    hi
    got into registry editor but auto run is not there ??

    Reply



  10. T J B Says:

    WOW IT IS A GOOD WAY BUT MAK IT EASY FOR THOSE WHO DONT KNOW COMPUTER BY USEDING THE COAD ONLY BESIDE THIS PC AutoOff Fix

    Reply



  11. car floor jacks Says:

    This is the first time I commented here and I should say that you give genuine, and quality information for other bloggers! Great job.
    p.s. You have a very good template . Where have you got it from?

    Reply



  12. yen Says:

    it’s not working for me. i followed all instructions (deleted the registry value and ran the batchfile editor) but still it went autoshut down..when i checked it again, the value was still there.. Please help me. ae there other alternatives for my problem? PLEASE MAIL ME. dhey_scarlet16@yahoo.com your tip will be highly appreciated! thanks and God bless!

    Reply



  13. yen Says:

    i want to thank the owner of this blog for being generous in posting some solutions regarding malwares.. :) may God bless you more :)
    (unfortunately it didn’t work for me, but it worked for others though.. :P )

    i’ve surfed the net for alternative solutions..i found something that works for my pc. so if the solution above doesn’t work on your pc,it may have other problems that should be fixed first.
    you may try this:

    http://www.testmy.net/forum/index.php?topic=22968.msg266502

    just click the link :)

    Thanks people.:) God Bless!

    Reply



  14. talens126 Says:

    It works!!! Thanks….

    Reply



  15. Cyrus Says:

    Hello guys,

    Thanks for the solution but you are lacking one important thing!
    Pls do this first before following the instructions above:

    First, stop the virus application running at the Windows background (processes)
    Press CTRL-ALT-DEL and select Task Manager.
    Go to the Processes tab and stop the application: (bar311.exe, password_viewer.exe, and photos.zip.exe).

    Then you can proceed with the other remaining steps..

    Thanks!

    Reply



  16. ramaq Says:

    Thank bro!..

    it’s really work..

    Reply



  17. kevlocky Says:

    WOWOWOWOWOWOW!!!!!!! WHAT A GENIUS!!!!!!!!!! 100 STARS FOR YOU BRO!!!!!! YOU’VE SOLVE MY PROBLEM IN A FEW SECONDS!!!!

    Reply



  18. rifai Says:

    how to make a shutdown virus??????????

    Reply



  19. mr. winner Says:

    thank you very much…
    since i cannot go to “regedit,” i just search for the “.bat” file and alas! the “pc-off.bat” appeared…i just deleted this file and the problem with “cmd autshutoff” is corrected…

    Reply



  20. Natzz Reyes Says:

    its not working for me…when i restart my computer, it appears again.. my avast anti-virus detects the pc-off.bat virus.. what should i do?? pls email me..thanx!

    Reply



  21. Natzz Reyes Says:

    natzz1569@yahoo.com.. pls email me here..thanx!

    Reply



  22. sinomee Says:

    Ah.. Paano download and run batch file?
    you mean that i will run autoshutdown?

    Reply



  23. daniboyu Says:

    after i flug in my mp3 player on my computer i saw a folder named “bi mat” i tried to delete it but it returns continoustly.
    so when i open the folder my computer started to shutdown again and again…
    i think there is some kind of virus enter my computer…
    can anyone help me plzzz.
    i cant open any files because the pc shutz in the first 5 sec. of its open… plz plz plz ty so much

    Reply



  24. James Says:

    I would like to thank the one who has saved my computer !!
    thank you very much dude, now I can run CMD.
    Thank god people like you are around.

    Reply

    Winston Reply:

    hi james. It’s my pleasure to help. :)

    Reply



  25. Joena Marie Says:

    You saved my laptop! haha! Thank you soooooo much!

    Reply



  26. Wafukz Says:

    Did the alternate registry edit & deleted pc-off.bat.
    Delete successful then downloaded PC AutoOff Fix bat file
    I executed it but then same shutdown scenario..

    I was able to see password_viewer.exe and photos.zip.exe from the cmd window while it shutdown

    Please help.. i discovered that I’m infected when I’m tried to remove shoppingreport.dll.

    Thank you for the post. By the time i read the initial paragraphs of this post, I know i should stick with your posts ^_^.

    Reply



  27. Bea Says:

    cant download pc off fix..=(pls help..

    Reply



Leave a Reply