This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Extremely suspicious script

1 min read

✨ The volunteers who helped with this thread aren't active anymore, but you can still get a personalized answer — click Ask AI below.

This thread's last reply is from November 28, 2017, 6:28 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Chase87
Today was really scary. When I came home I noticed my laptop having booted up from sleep. My CPU was active, and what it was running is exteremly suspicious.
On startup it was running "cmd.exe /c C:\SysWOW64\del.bat" in the background .. this file was created from the Administrator account. It's content is the following script:
@Echo Off
cd /d C:\Windows\SysWOW64\
:Start
del svchost.exe
If Exist svchost.exe Goto Start
del %0


It seemed it never reached the last line, in which the script would delete itself. I'm supposing this is a failed attempt to hijack the system svchost. I could not find *anything* on Google.

Scary!
Any ideas on how to investigate this further?
Chase87
System svchost.exe is reported clean by virustotal online check.
Also virus/malware scanners don't find anything, obviously.
mAL_rEm018 Admin/Teacher
Bumping or Replying to Your Own Topic

May I draw your attention to the topic: ALL USERS OF THIS FORUM MUST READ THIS FIRST, which you should have read before posting for help.

The section here explains why you should not reply to or try to bump your topic.

If you still need help, please start a new thread an include your FRST logs:
  • FRST.txt.
  • Addition.txt.
  • Details of the problems you're experiencing.


If for any reason you can't run FRST, please let us know in your post.

This topic is now closed.

✨ Ask AI about this thread

No ads, no affiliate links — generated on request from this thread's own archived content, not written by forum staff. Never run a scan/removal tool as a self-service step if the original thread describes it being done under a helper's direct supervision, and don't include your name, email, or other personal details in a follow-up question. See our privacy page for details on how this works.