home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 2081
Discussions: 186,591, Posts: 2,226,900, Members: 230,216
Free Scan: Update Your PC's Outdated Drivers to Optimize Performance
Old May 30th, 2008, 07:53 PM   Digg it!   #1 (permalink)
Member
 
Join Date: Oct 2004
Posts: 32
strange .bat file shutting down win vista... not really a virus but...

So my dumb-a$$ ex-girlfriend decided she wanted to spy on her current boyfriend by "hacking" into his myspace. (yeah I know + why am I helping her now). well she found a supposed myspace password hacker through youtube & lo-and-behold screwed up her computer just like I told her she would. whatever, now the damage is done & maybe she has a lesson learned.... right.

You can view the video here if you want YouTube - Myspace Password Hacker 8.0 (NEW)
the guy says there is a link to download this "utility" in a zip file. So of course she downloaded it (it was actually just a .bat file, unless something else came with it un-seen). Upon running it, it restarted her comp, and since then after boot-up, if you try to do anything (and I mean anything) it reboots.

I downloaded the same file while running linux to minimize my risk and examined it.

So heres the commands this batch file runs. as near as I can tell there is no way for it to repeatedly run any kind of malicious operation, but... (just for safety's sake, if you're running windows don't mess with this, I don't want to be blamed)


ipconfig /release

start shutdown.exe -s -t 04 -c "You Must Restart Windows To Use Myspace Password Hacker 8.0"


The "comment" shown above appeared the first time, but not since.

The thing that gets me is that there should be no way for this thing to auto execute.

I understand what the commands and flags all do (reset ip / network connection, "shutdown" with a flag to shutdown, with a delay of 4 seconds and kill all running processes.

There were no other files downloaded with this (like I said unless something snook in), she said that she deleted the file from her desktop @ some point (not quite sure when she managed to do it) but regardless, by going in with a boot cd and browsing with a file manager, i could find no trace of it in her recycle bin, desktop or temp internet files.

She's running winVista Home Premium on a gateway W340UI laptop.

If anyone has any suggestions, I would really appreciate the input, otherwise i'll have to try to salvage all of her files and restore the computer to a factory installation and reinstall all her programs for her. I'm sure there is just something I am not seeing here. It won't stay runn9ing in safe mode either, so I can't even try to run any utilities from with-in windows itself.

Thanks!!!

renesisspeed is offline   Reply With Quote
TechIMO.com Ads - Login or register for less ads.
How many errors does your computer have?

You no longer need to guess! This free stability scan and registry cleaner download will give you a complete diagnosis of your Windows registry, identifying errors and conflicts.

FREE instant scan


Guest, Register Free! to remove this ad and get your tech support questions answered in minutes!
Old May 30th, 2008, 08:23 PM     #2 (permalink)
Banned
 
Keymaker's Avatar
 
Join Date: Jan 2005
Location: Loveland, CO
Posts: 5,493
Blog Entries: 2
Send a message via ICQ to Keymaker Send a message via Yahoo to Keymaker
She obviously didn't download the correct file. I would not have run that batch file from the begin with. Unless I'm using VMware. Of course I would also run that little haxxers program in VMware as well.

Anyway... You need to see what is auto starting. I know a few, unfortunately this requires to install the utility. Seen as how the computer won't stay on, that won't help.. I think this stand alone utility may help if you run it in a live CD like UBCD4WIN. SIW | System Information for Windows by Gabriel Topala

Does safe mode work?


Last edited by Keymaker : May 30th, 2008 at 08:25 PM.
Keymaker is offline   Reply With Quote
Old May 31st, 2008, 04:08 PM     #3 (permalink)
Member
 
Join Date: Oct 2004
Posts: 32
If I run that utility from a live cd, won't it just tell me what the start-up processes for the live cd OS are?

& no, Safe Mode does not work. I also tried going into safe mode with command prompt and it immediately began to shut down. (presumably as soon as command prompt was launched, just like when trying to manually launch anything else.)

(PS: I was born in Loveland... live in Detroit now )

renesisspeed is offline   Reply With Quote
Old June 1st, 2008, 03:57 AM     #4 (permalink)
Banned
 
Keymaker's Avatar
 
Join Date: Jan 2005
Location: Loveland, CO
Posts: 5,493
Blog Entries: 2
Send a message via ICQ to Keymaker Send a message via Yahoo to Keymaker
Quote:
Originally Posted by renesisspeed View Post
If I run that utility from a live cd, won't it just tell me what the start-up processes for the live cd OS are?
Your right, it will. forgot about that. Well UBCD4win has some tools. So you could browse the hard drive . Ahh, dang, you can't even use safe mode either. I had to use safe mode once to evoke a system restore through the command prompt.

There has to be something in the windows startup directory. If you browse the hard drive with a live CD, then I would look in the Windows folder. Especially system32.

Have you tried to use the recovery console with the Windows install disk?







Quote:
Originally Posted by renesisspeed View Post
(PS: I was born in Loveland... live in Detroit now )
Small world! Especially how small this town is. You won't believe how much it has changed now. Building all over! We have a new hospital, (Level 2 trauma I believe) Medical Center of the Rockies, and out that way near I25 there is a new shopping mall. Couple years ago when the Blue Angles came to Loveland I was listening to their coms. and heard one pilot say how he couldn't believe how much we changed. They were here before many years ago. I'm not originally from Loveland though. Moved from Riverside CA. Seems like everyone is moving from there. Now if my parents would have stayed.. they would had made a fortune on the house!

Last edited by Keymaker : June 1st, 2008 at 04:01 AM.
Keymaker is offline   Reply With Quote
Old June 1st, 2008, 03:42 PM     #5 (permalink)
Member
 
Join Date: Oct 2004
Posts: 32
Well. I haven't been able to find anything relating to the original file name anywhere on the C drive. I also tried to look for files that were created when it happened and couldn't come up with anything productive. The only thing I found (& it didn't do any good) were the prefetch files created at the time it happened (for cmd.exe, ipconfig.exe & shutdown.exe). I had hoped that by deleting them & letting them be re-created fresh I might be able to solve the problem.

So basically, im still stumped. I really don't want to have to run recovery & restore it to factory... but it looks like that may be what its coming to. Either way Keymaker, I really appreciate you're input.
renesisspeed is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
reading a .bat file ShuckyD Webmastering and Programming 4 October 8th, 2007 05:21 PM
A bat file to shutdown Vista? EXreaction Applications and Operating Systems 3 March 27th, 2007 04:29 PM
Strange message when shutting down XP 4deucer Security and Privacy Issues 4 May 3rd, 2005 02:37 PM
Win ME & autoexec.bat Jonty Applications and Operating Systems 3 September 17th, 2003 09:18 AM
Create a .bat file shotokan General Tech Discussion 10 May 28th, 2003 10:13 AM

Most Active Discussions
Is It Just Me? (494)
heatsink issue (8)
Word Association!! (1655)
SSD's, RAID, and External Backup (6)
New Mobo (16)
1 internet. 1 house. 3 computer. ho.. (11)
UPGRADING C/D DRIVE TO 250GB & .. (10)
Is This A Compatible Gaming PC? (16)
Connected to LAN but unable to use .. (5)
Recent Discussions
C++ compiler suggestions (2)
Letter Count Array (3)
Hard Core Overclock (9)
SSD's, RAID, and External Backu.. (6)
Folderchat: The Holiday thread (113)
1 internet. 1 house. 3 computer.. (11)
heatsink issue (8)
FS: New Benny Hill Megaset DVD .. (6)
Computer won't start (2)
New Mobo (16)
FS: Dell 6000 laptop, modded 36.. (2)
Apple iPod touch 16 GB $200 (4)


All times are GMT -4. The time now is 01:01 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28