jimmyf
(regular)
Fri Feb 15 2008 09:38 AM
Re: help with father-in-laws hijack this log please

hi joe,
thats all that was saved under combofix.txt,however this has been saved as cflog


C:\>prompt $

title .

color 17

set "cfldr=327882R2FWJFW"

set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt"

if defined param_ set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt"

if defined param_ set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt"

cd /d "C:\"

if not exist "327882R2FWJFW" goto Abort

if exist "C:\DOCUME~1\DAVIDD~1\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" del "C:\DOCUME~1\DAVIDD~1\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" 2>nul

"327882R2FWJFW\Nircmd.com" win close ititle "ComboFix"

copy /y/b/v C:\WINDOWS\system32\cmd.exe "327882R2FWJFW\kmd.exe" 1>nul 2>&1

For /F "tokens=*" %g in ("C:\Downloads\ComboFix.exe") do @(
set "FileName=%~ng"
set "FilePath=%~dpg"
)

If /I "C:\Downloads\" NEQ "C:\" If exist "C:\Downloads\kmd.exe" del "C:\Downloads\kmd.exe" 2>nul

If not defined FileName goto END

DIR /AD/B | C:\WINDOWS\System32\FindStr.exe -IVX ComboFix 1>dirname00

C:\WINDOWS\System32\FindStr.exe -LIXC:"ComboFix" dirname00 1>nul 2>&1 && call :NameChk

del /Q dirname0? 2>nul

If exist "ComboFix" DIR /AD "ComboFix" 1>nul 2>&1 && (
rd /s/q "ComboFix" 2>nul
If exist "ComboFix" (
pushd "327882R2FWJFW"
call pid.bat
popd
rd /s/q "ComboFix" 2>nul
)
If exist "ComboFix" (
"327882R2FWJFW\handle.cfexe" "C:\ComboFix" | "327882R2FWJFW\SED.cfexe" -r "/pid:/!d; s/.*: (.*): .*/\1/" 1>temp00
for /F "tokens=1,2" %g in (temp00) do @echo.y | "327882R2FWJFW\Handle.cfexe" -p %g -c %h 1>nul
del /q temp00 2>nul
rd /s/q "ComboFix" 2>nul
)
)

If exist "ComboFix" rd /s/q "ComboFix" 2>nul

If not exist "ComboFix" Ren "327882R2FWJFW" "ComboFix" 1>nul 2>&1

If exist "327882R2FWJFW" goto AbortB

set cfldr=

Start "." /d"C:\ComboFix" "C:\ComboFix\kmd.exe" /c " "C:\ComboFix\c.bat" "C:\Documents and Settings\david douglas\Desktop\CFScript.txt" "

"ComboFix\nircmd.com" execmd del Start_.cmd

del Start_.cmd

hope thats what you require.
cheers
jim


Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved