This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Extremely suspicious script

1 min read

This thread's last reply is from November 28, 2017, 6:28 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Today was really scary. When I came home I noticed my laptop having booted up from sleep. My CPU was active, and what it was running is exteremly suspicious.
On startup it was running "cmd.exe /c C:\SysWOW64\del.bat" in the background .. this file was created from the Administrator account. It's content is the following script:
@Echo Off
cd /d C:\Windows\SysWOW64\
:Start
del svchost.exe
If Exist svchost.exe Goto Start
del %0


It seemed it never reached the last line, in which the script would delete itself. I'm supposing this is a failed attempt to hijack the system svchost. I could not find *anything* on Google.

Scary!
Any ideas on how to investigate this further?
System svchost.exe is reported clean by virustotal online check.
Also virus/malware scanners don't find anything, obviously.
Bumping or Replying to Your Own Topic

May I draw your attention to the topic: ALL USERS OF THIS FORUM MUST READ THIS FIRST, which you should have read before posting for help.

The section here explains why you should not reply to or try to bump your topic.

If you still need help, please start a new thread an include your FRST logs:
  • FRST.txt.
  • Addition.txt.
  • Details of the problems you're experiencing.


If for any reason you can't run FRST, please let us know in your post.

This topic is now closed.