Sunday, February 10, 2008

Computer Shuts Down when you Open up CMD (Command Prompt)

Computer Shuts Down when you Open up CMD (Command Prompt)

This is the symptom of a computer having bar311.exe virus A.K.A. winzip123. The virus comprises bar311.exe, password_viewer.exe, photos.zip.exe and pc-off.bat.

When you boot your Windows XP in Safe Mode the message appears: Thank You!!!
Password:Winzip123


The pc-off.bat contains the syntax like this"C:/path/shutdown -s -f -t 2 -c" which automatically shutdown your computer when you run the cmd.exe.

Manual removal is outlined below. Download bar311.exe - winzip123.exe Automatic Remover here.

Manual removal:

1. upon start up.... after os loading... go to task manager by pressing CTRL+ALT+DEL then kill password_viewer.exe or bar311.exe or photos.zip.exe...

2. EDIT the following registry entries thru regedit at start/run

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="userinit.exe,bar311.exe" ---> remove ", bar311.exe" only... leave userinit.exe because this is used by Windows when you log-in...

[HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
"HideFileExt"=dword:00000000
"ShowSuperHidden"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\Command Processor]
"autorun"="c:\Windows\pc-off.bat" --> remove "c:\Windows\pc-off.bat" or delete the autorun key.


3. go to your flash drive (USB drive), please use the folders view in the explorer and use the navigation panel on the left side when accessing the drives to avoid triggering the autorun... then delete autorun.inf and password_viewer.exe or bar311.exe


4. open notepad then type what is shown below as is...

@echo off
del /a /f c:\Windows\bar311.exe
del /a /f c:\Windows\password_viewer.exe
del /a /f c:\Windows\photos.zip.exe
del /a /f c:\Windows\pc-off.bat
pause

then save this as remove.bat then click to run.... this will remove the virus...

82 comments:

  1. Your Suggestation is very help ful thans a lot

    ReplyDelete
  2. thanks, it works

    ReplyDelete
  3. Thank you. You're the man! :)

    ReplyDelete
  4. thanks a lot..but how did u know? did u develop the virus urself?

    ReplyDelete
  5. kick @ss! killed the virus in a snap. Now, time to get an avs. Thanks!

    ReplyDelete
  6. wth, avg can't piss it off...

    ReplyDelete
  7. Thanks for sharing this solution.. was very helpful! Thanks again

    ReplyDelete
  8. nice tut man....^^
    dam avg....

    ReplyDelete
  9. Great! It really helps.
    Thank you...

    ReplyDelete
  10. Thanks for this blog, now I can use my cmd :)

    More power to you sir! :)

    ReplyDelete
  11. IT WORKS!!!!
    THANK YOU!!!!
    YIPEEE!!!

    ReplyDelete
  12. I love you for that

    ReplyDelete
  13. I'm a Believer!!!! WAHOOO!!!!! Curse the one who created that virus, and all hail to you for your solution!!!

    ReplyDelete
  14. thank you sooooo..much.... your post is superb..:)

    ReplyDelete
  15. w00t! Thanks to you problem has been resolved. It's kinda crappy that my AVG is up to date but it can't detect it. :S

    ReplyDelete
  16. wow!..thanks alot!,it really works!..:)

    ReplyDelete
  17. thanks. ang sarap mo!

    ReplyDelete
  18. The amount of replies giving me some confidence, i've been chasing this solution for almost five-six months now... let me have a try!!

    ReplyDelete
  19. Still have the "shtdown running cmd.exe " I tried all these, not a single file is present what you have specified. All seemed OK in regisry as well. What could be the issue?

    ReplyDelete
  20. thank u very much..i've been worried sick...thank u thank u thank u

    ReplyDelete
  21. your the man!!!!.....


    thank you very much for this post... I remove now the #$^&*& virus... :D

    ReplyDelete
  22. Both Task Manager and Registry Editor were disabled. What now?

    ReplyDelete
  23. WOW!!! I was about to reformat my PC when I saw this link. Thanks a lot!!!

    ReplyDelete
  24. magaling magaling magaling!!!!!! salamat ng marami!!!!!!

    ReplyDelete
  25. thanks...meron pla n2 eh!!thanks bro,try qoh 2...

    ReplyDelete
  26. Hello. I'm having the same problem, but I can't seem to find the exe files you mentioned in my processes. Pls. help. Thaks in advance! :)

    ReplyDelete
  27. Hi, my problem was solved already. This article is really helpful, but if it doesn't solve your problems, you can try http://www.troublefixers.com/command-prompt-disabled-by-virus/. This worked for me. Goodluck. :)

    ReplyDelete
  28. rak rakan na toh. . galing mo pare. . astig. . salamat. . wag na magtiwala sa anti-virus. . sayo nako magtitiwala. .\m/

    ReplyDelete
  29. DUDE!!! THANKS ALOT! WHEW! THAT WAS VERY HELPFUL, EASY STEP BY STEP TOO:)
    GREAT JOB!

    ReplyDelete
  30. hi.. thank you for posting this.. i've been having this problem for a long time now.. you're d man!

    ReplyDelete
  31. wonderful, halatang pinoy eh! haha panalo!

    ReplyDelete
  32. wow. this was very helpful. good thing this post is available online. i couldn't thank you enough. cheers mate!

    ReplyDelete
  33. my norton detect the said file as a virus and unsafe to run.

    ReplyDelete
  34. Thanks...it helps a lot...

    My computer shuts down not just when running CMD but also when installing any anti-virus program so I'm thinking that it's the same virus.

    But now it's solved. Thanks alot!!!

    Mabuhay ka! :)

    ReplyDelete
  35. i also can't open task manager, it's disabled T_T

    ReplyDelete
  36. wow! it worked!!! finally got rid of that stoopid problem. thank god i found this blog. thanks dude!! da best ka!!!

    ReplyDelete
  37. you're the man! one thing.. the automated removal of the virus - the file itself is infected.

    ReplyDelete
  38. um. di ko dn magets #3. paexplain nmn ung thumb drive mo..?

    ReplyDelete
  39. I found this very useful.
    Thanks! You make my day

    Download movies /
    videos

    ReplyDelete
  40. thanks very helpful...

    ReplyDelete
  41. I was struggling with this issue for the past 5 months and your article for manual removal helped to resolve the problem.
    Thanks alot for posting the solution.

    ReplyDelete
  42. Thank you very much, you are an angel, it worked like a charm.

    ReplyDelete
  43. It's really TRUE! i'm searching for this answer for so long! UR A BLESSING DUDE! thank u!

    ReplyDelete
  44. i remove viruses through the command prompt, and one day it refuses to work properly!! thanks to your guide i got it working again. thank you very much!!
    na-typo ka siguro sa #3.. are u pinoy? salamat!

    ReplyDelete
  45. thanks been infected since last week after backing up some pics from a friends pc

    ReplyDelete
  46. salamat po nang marami..
    ie,
    thanks a lot po...

    ReplyDelete
  47. 3. go to your thumb drive mo, please use the folders view in the explorer and use the navigation panel on the left side when accessing the drives to avoid triggering the autorun... then delete autorun.inf and password_viewer.exe or bar311.exe

    HELP IM STUCK HIR PLSS HELP ME

    ReplyDelete
  48. hi!
    i was following the step by step manual removal of the virus kaso pagdting ko sa #3 wala na..wat does he mean by thumb drive mo?

    ReplyDelete
  49. superb man thanks a lot...bravo

    ReplyDelete
  50. You're a genius!!!!

    You helped me solve my problem. Mabuhay ka, brader.

    ReplyDelete
  51. You're a genius!!!!

    You helped me solve my problem. Mabuhay ka, brader.

    ReplyDelete
  52. THANK YOU VERY VERY VERY MUCH!!!

    ReplyDelete
  53. Thanks a lot. It really helps. Godbless.

    ReplyDelete
  54. what's thumb drive mo?

    ReplyDelete
  55. Edited it a while ago. Thumb drive a.k.a. flash drive.

    ReplyDelete
  56. THANK YOU!!! shit it worked! thanks a lot!

    ReplyDelete
  57. you are damm great!!!!! it works!!

    ReplyDelete
  58. THANKS,YOUR THE MAN

    ReplyDelete
  59. good job man your very helpful

    ReplyDelete
  60. wow i downloaded the auto removal..it worked..we have two desktops and one laptop that shuts down everytime i open command prompt..tried it on my laptop and my cmd works now..will try it on the 2 other units..thanks again

    ReplyDelete
  61. this is how you make a great technical guide. very easy to follow.. thanks

    ReplyDelete
  62. wow! man u saved a a lot of time! i was thinking of reformatting the system! thanks a lot bro! ur d man!!

    ReplyDelete
  63. thanks! downloaded the file.. works!

    ReplyDelete
  64. do I have to delete the following too?:

    "Hidden"=dword:00000001
    "HideFileExt"=dword:00000000
    "ShowSuperHidden"=dword:00000001

    I did not find any bar311.exe, password_viewer.exe, and photos.zip.exe but did find the pc-off.bat on my laptop..

    will it work the same? and please do answer my question. Do I have to delete the 3 things that I have mentioned above?

    ReplyDelete
  65. whoa, this thing was posted July 2008, and is still helpful up to now. thank you so much! i enjoyed the step-by-step fix. =)

    ReplyDelete
  66. For problem of this kind I would recommend that you use the System Restore tool which can easily solve problems of these kinds.

    ReplyDelete
  67. two years on the net and still very usefull...

    btw YOUR MY HERO!!!!

    ReplyDelete
  68. after trying to find the fix for my computer for a long time, you're simple automatic remover program was absolutely brilliant!!!

    Ultimate props!!!

    ReplyDelete
  69. thank you very much!!! :)

    ReplyDelete
  70. There definitely can be the issue of virus attacking your system.

    ReplyDelete
  71. I was also facing the same problem recently, you need to get the program re installed and then get it installed again....

    ReplyDelete
  72. i had experienced this once from windows xp and did the step-by-step procedure...now that i have win7, i cant find those batch files and when running the cmd prmpt shuts my pc down.. :(

    ReplyDelete
  73. You're the best man! This helped me a month ago, but I didn't get to post... so thank you! XD

    ReplyDelete