|
|
jimmyf
regular
Reg'd: Thu
Posts: 58
|
Re: help with father-in-laws hijack this log please
Fri Feb 15 2008 09:38 AM
|
|
|
hi joe, thats all that was saved under combofix.txt,however this has been saved as cflog
C:\>prompt $
title .
color 17
set "cfldr=327882R2FWJFW"
set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt"
if defined param_ set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt"
if defined param_ set param_="C:\Documents and Settings\david douglas\Desktop\CFScript.txt"
cd /d "C:\"
if not exist "327882R2FWJFW" goto Abort
if exist "C:\DOCUME~1\DAVIDD~1\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" del "C:\DOCUME~1\DAVIDD~1\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" 2>nul
"327882R2FWJFW\Nircmd.com" win close ititle "ComboFix"
copy /y/b/v C:\WINDOWS\system32\cmd.exe "327882R2FWJFW\kmd.exe" 1>nul 2>&1
For /F "tokens=*" %g in ("C:\Downloads\ComboFix.exe") do @( set "FileName=%~ng" set "FilePath=%~dpg" )
If /I "C:\Downloads\" NEQ "C:\" If exist "C:\Downloads\kmd.exe" del "C:\Downloads\kmd.exe" 2>nul
If not defined FileName goto END
DIR /AD/B | C:\WINDOWS\System32\FindStr.exe -IVX ComboFix 1>dirname00
C:\WINDOWS\System32\FindStr.exe -LIXC:"ComboFix" dirname00 1>nul 2>&1 && call :NameChk
del /Q dirname0? 2>nul
If exist "ComboFix" DIR /AD "ComboFix" 1>nul 2>&1 && ( rd /s/q "ComboFix" 2>nul If exist "ComboFix" ( pushd "327882R2FWJFW" call pid.bat popd rd /s/q "ComboFix" 2>nul ) If exist "ComboFix" ( "327882R2FWJFW\handle.cfexe" "C:\ComboFix" | "327882R2FWJFW\SED.cfexe" -r "/pid:/!d; s/.*: (.*): .*/\1/" 1>temp00 for /F "tokens=1,2" %g in (temp00) do @echo.y | "327882R2FWJFW\Handle.cfexe" -p %g -c %h 1>nul del /q temp00 2>nul rd /s/q "ComboFix" 2>nul ) )
If exist "ComboFix" rd /s/q "ComboFix" 2>nul
If not exist "ComboFix" Ren "327882R2FWJFW" "ComboFix" 1>nul 2>&1
If exist "327882R2FWJFW" goto AbortB
set cfldr=
Start "." /d"C:\ComboFix" "C:\ComboFix\kmd.exe" /c " "C:\ComboFix\c.bat" "C:\Documents and Settings\david douglas\Desktop\CFScript.txt" "
"ComboFix\nircmd.com" execmd del Start_.cmd
del Start_.cmd
hope thats what you require. cheers jim
|
|
|
|
0 registered and 11 anonymous users are browsing this forum.
Moderator: putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate
Print Thread
|
Forum Permissions
You cannot start new topics
You cannot reply to topics
HTML is disabled
Mark-up is enabled
|
Rating:
Thread views: 0
|
|
|