View Single Post
Old 10-15-2007, 10:41 PM   #7 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,329
OS: N/A


Re: Motherload virus(es)

Open NOTEPAD.exe and copy/paste the text in the quotebox below into it:

Code:
@echo off
if exist "%temp%\log.txt" del "%temp%\log.txt"
for %%g in (
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdBreak1.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdBreak10.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdBreak7.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdBreak9.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip"
"C:\Documents and Settings\David Osburn\My Documents\Dana\AOL\BSINSTALL.exe"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\10.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\11.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\12.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\13.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\14.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\16.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\17.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\19.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\1A.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\1B.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\1C.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\1D.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\1E.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\1F.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\20.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\21.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\23.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\29.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\30.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\42.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\6C7.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\88.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\8B.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\92.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\A.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\B.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\C.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\D.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\E.tmp"
"C:\Program Files\Trend Micro\Internet Security 12\Quarantine\F.tmp"
) do ( del /a/f/q %%g >nul 2>&1
if exist %%g echo.%%~g>>"%temp%\log.txt" )
if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt" ) else echo.Deleted Successfully !!
echo.GetObject("winmgmts:" ^& "{impersonationLevel=impersonate}!\\" ^& "." ^& "\root\default").Get("SystemRestore").Disable("")>SR.vbs
echo.GetObject("winmgmts:" ^& "{impersonationLevel=impersonate}!\\" ^& "." ^& "\root\default").Get("SystemRestore").Enable("")>>SR.vbs
cscript.exe //nologo //b SR.vbs
del SR.vbs
ping 1.1.1.1 -n 1 -w 5000 >nul
del %0
Save this as fix.bat Choose to "Save type as - All Files"
It should look like this:
Double click on fix.bat & allow it to run

Post back to tell me what it says
__________________

Question - what have you done for the community today?
sUBs is offline