|
|
|||||||
|
hi joe, thats all that was saved under combofix.txt,however this has been saved as cflog C:\>prompt $ title . color 17 set "cfldr=327882R2FWJFW" set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt" if defined param_ set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt" if defined param_ set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt" cd /d "C:\" if not exist "327882R2FWJFW" goto Abort if exist "C:\DOCUME~1\DAVIDD~1\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" del "C:\DOCUME~1\DAVIDD~1\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" 2>nul "327882R2FWJFW\Nircmd.com" win close ititle "ComboFix" copy /y/b/v C:\WINDOWS\system32\cmd.exe "327882R2FWJFW\kmd.exe" 1>nul 2>&1 For /F "tokens=*" %g in ("C:\Downloads\ComboFix.exe") do @( set "FileName=%~ng" set "FilePath=%~dpg" ) If /I "C:\Downloads\" NEQ "C:\" If exist "C:\Downloads\kmd.exe" del "C:\Downloads\kmd.exe" 2>nul If not defined FileName goto END DIR /AD/B | C:\WINDOWS\System32\FindStr.exe -IVX ComboFix 1>dirname00 C:\WINDOWS\System32\FindStr.exe -LIXC:"ComboFix" dirname00 1>nul 2>&1 && call :NameChk del /Q dirname0? 2>nul If exist "ComboFix" DIR /AD "ComboFix" 1>nul 2>&1 && ( rd /s/q "ComboFix" 2>nul If exist "ComboFix" ( pushd "327882R2FWJFW" call pid.bat popd rd /s/q "ComboFix" 2>nul ) If exist "ComboFix" ( "327882R2FWJFW\handle.cfexe" "C:\ComboFix" | "327882R2FWJFW\SED.cfexe" -r "/pid:/!d; s/.*: (.*): .*/\1/" 1>temp00 for /F "tokens=1,2" %g in (temp00) do @echo.y | "327882R2FWJFW\Handle.cfexe" -p %g -c %h 1>nul del /q temp00 2>nul rd /s/q "ComboFix" 2>nul ) ) If exist "ComboFix" rd /s/q "ComboFix" 2>nul If not exist "ComboFix" Ren "327882R2FWJFW" "ComboFix" 1>nul 2>&1 If exist "327882R2FWJFW" goto AbortB set cfldr= Start "." /d"C:\ComboFix" "C:\ComboFix\kmd.exe" /c " "C:\ComboFix\c.bat" "C:\Documents and Settings\david douglas\Desktop\CFScript.txt" " "ComboFix\nircmd.com" execmd del Start_.cmd del Start_.cmd hope thats what you require. cheers jim |