1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

How to temove this bat file?

Discussion in 'Windows Security' started by Claire Bennette, May 28, 2009.

  1. Dear all Recently I noticed that My Computer creating funny bat file called
    xh319r9b.bat.
    It uses autorun.inf and when I delete those 2 files it creates again in 5
    seconds. How
    can I remove those 2 files I tried to scan those 2 files in Mcafee and
    Norton Both Its
    not recognize it.
     
  2. 1PW

    1PW Guest

    Claire Bennette wrote:<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Dear all Recently I noticed that My Computer creating funny bat file called
    > xh319r9b.bat.
    > It uses autorun.inf and when I delete those 2 files it creates again in 5
    > seconds. How
    > can I remove those 2 files I tried to scan those 2 files in Mcafee and
    > Norton Both Its
    > not recognize it.<!--colorc--><!--/colorc-->

    Hello Claire:

    This can be looked at from several directions. This might be a
    legitimate file whose name is purposefully randomized for its protection.

    or...

    This could be malware that's also protecting itself with the same
    randomized name technique.

    You could try submitting the batch file (through upload) to:

    <https://www.virustotal.com/>

    If the contents of the batch file isn't too long, you could post its
    contents here in a follow-up post for our analysis.

    Although you've called them by their manufacturer names, you haven't
    told us which exact and specific products you are scanning the batch
    file with.

    Are you also running antispyware applications? Please reveal as much
    system information as is available.

    Pete
    --
    1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t]
     
  3. Please do not ask anyone to post potentially malicious software in these
    newsgroups!

    --

    Richard Urban
    Microsoft MVP
    Windows Desktop Experience


    "1PW" <barcrnahgjuvfgy@nby.pbz> wrote in message
    news:gvnubd$61q$1@news.eternal-september.org...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Claire Bennette wrote:<!--coloro:green--><span style="color:green <!--/coloro-->
    >> Dear all Recently I noticed that My Computer creating funny bat file
    >> called xh319r9b.bat.
    >> It uses autorun.inf and when I delete those 2 files it creates again in 5
    >> seconds. How
    >> can I remove those 2 files I tried to scan those 2 files in Mcafee and
    >> Norton Both Its
    >> not recognize it.<!--colorc--><!--/colorc-->
    >
    > Hello Claire:
    >
    > This can be looked at from several directions. This might be a legitimate
    > file whose name is purposefully randomized for its protection.
    >
    > or...
    >
    > This could be malware that's also protecting itself with the same
    > randomized name technique.
    >
    > You could try submitting the batch file (through upload) to:
    >
    > <https://www.virustotal.com/>
    >
    > If the contents of the batch file isn't too long, you could post its
    > contents here in a follow-up post for our analysis.
    >
    > Although you've called them by their manufacturer names, you haven't told
    > us which exact and specific products you are scanning the batch file with.
    >
    > Are you also running antispyware applications? Please reveal as much
    > system information as is available.
    >
    > Pete
    > --
    > 1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t] <!--colorc--><!--/colorc-->
     
  4. Jordon

    Jordon Guest

    Richard Urban wrote:<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Please do not ask anyone to post potentially malicious software in these
    > newsgroups!<!--colorc--><!--/colorc-->

    He just suggested to post the contents of a batch file. Plain
    text in a news group message isn't malicious.

    --
    Jordon
     
  5. From: "Jordon" <jordon@REMOVEgrahamtrucking.com>

    | Richard Urban wrote:<!--coloro:blue--><span style="color:blue <!--/coloro--><!--coloro:green--><span style="color:green <!--/coloro-->
    >> Please do not ask anyone to post potentially malicious software in these
    >> newsgroups!<!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->

    | He just suggested to post the contents of a batch file. Plain
    | text in a news group message isn't malicious.

    | --
    | Jordon


    Yes, the contets of a .BAT or .CMD is OK. No problem with that.

    One could say; del *.* /y is malicious.

    --
    Dave

    Multi-AV -
     
  6. John Doe

    John Doe Guest

    damn it - there went my hard drive! : }

    "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
    news:%23gg$jaK4JHA.3304@TK2MSFTNGP06.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > From: "Jordon" <jordon@REMOVEgrahamtrucking.com>
    >
    > | Richard Urban wrote:<!--coloro:green--><span style="color:green <!--/coloro--><!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> Please do not ask anyone to post potentially malicious software in these
    >>> newsgroups!<!--colorc--><!--/colorc--><!--colorc--><!--/colorc-->
    >
    > | He just suggested to post the contents of a batch file. Plain
    > | text in a news group message isn't malicious.
    >
    > | --
    > | Jordon
    >
    >
    > Yes, the contets of a .BAT or .CMD is OK. No problem with that.
    >
    > One could say; del *.* /y is malicious.
    >
    > --
    > Dave
    >
    > Multi-AV -

    >
    > <!--colorc--><!--/colorc-->
     
  7. 1PW

    1PW Guest

    Richard Urban wrote:<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Please do not ask anyone to post potentially malicious software in these
    > newsgroups!<!--colorc--><!--/colorc-->

    Hello Richard:

    Your point is well taken. If it's bad stuff, surely it would
    propagate. If it's not, we might help the OP further. From my
    standpoint it's a conundrum, so Virus Total /is/ obviously the better
    step.

    Thank you,

    Pete
    --
    1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t]
     
  8. Believe it or not, someone is liable to take that text and save it with
    either a .cmd or a .bat extension and run it. (-:

    I know several who are that stupid!

    --

    Richard Urban
    Microsoft MVP
    Windows Desktop Experience


    "1PW" <barcrnahgjuvfgy@nby.pbz> wrote in message
    news:gvqgqh$4e4$1@news.eternal-september.org...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Richard Urban wrote:<!--coloro:green--><span style="color:green <!--/coloro-->
    >> Please do not ask anyone to post potentially malicious software in these
    >> newsgroups!<!--colorc--><!--/colorc-->
    >
    > Hello Richard:
    >
    > Your point is well taken. If it's bad stuff, surely it would propagate.
    > If it's not, we might help the OP further. From my standpoint it's a
    > conundrum, so Virus Total /is/ obviously the better step.
    >
    > Thank you,
    >
    > Pete
    > --
    > 1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t] <!--colorc--><!--/colorc-->
     
  9. From: "Richard Urban" <richardurbanREMOVETHIS@hotmail.com>

    | Believe it or not, someone is liable to take that text and save it with
    | either a .cmd or a .bat extension and run it. (-:

    | I know several who are that stupid!

    | --

    Chances are the .BAT will contain references to an external command that is malware that
    does NOT exist outside the infected person's environment and therefore a 3rd party who
    copies & pastes the contents of said .BAT would not be in trouble.

    --
    Dave

    Multi-AV -
     
  10. Point taken!

    --

    Richard Urban
    Microsoft MVP
    Windows Desktop Experience


    "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
    news:efmOa6R4JHA.1096@TK2MSFTNGP06.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > From: "Richard Urban" <richardurbanREMOVETHIS@hotmail.com>
    >
    > | Believe it or not, someone is liable to take that text and save it with
    > | either a .cmd or a .bat extension and run it. (-:
    >
    > | I know several who are that stupid!
    >
    > | --
    >
    > Chances are the .BAT will contain references to an external command that
    > is malware that
    > does NOT exist outside the infected person's environment and therefore a
    > 3rd party who
    > copies & pastes the contents of said .BAT would not be in trouble.
    >
    > --
    > Dave
    >
    > Multi-AV -

    >
    > <!--colorc--><!--/colorc-->
     
  11. John Doe

    John Doe Guest

    I need those as customers, talk about job security! : }

    "Richard Urban" <richardurbanREMOVETHIS@hotmail.com> wrote in message
    news:%23UcUfXP4JHA.4412@TK2MSFTNGP06.phx.gbl...<!--coloro:blue--><span style="color:blue <!--/coloro-->
    > Believe it or not, someone is liable to take that text and save it with
    > either a .cmd or a .bat extension and run it. (-:
    >
    > I know several who are that stupid!
    >
    > --
    >
    > Richard Urban
    > Microsoft MVP
    > Windows Desktop Experience
    >
    >
    > "1PW" <barcrnahgjuvfgy@nby.pbz> wrote in message
    > news:gvqgqh$4e4$1@news.eternal-september.org...<!--coloro:green--><span style="color:green <!--/coloro-->
    >> Richard Urban wrote:<!--coloro:darkred--><span style="color:darkred <!--/coloro-->
    >>> Please do not ask anyone to post potentially malicious software in these
    >>> newsgroups!<!--colorc--><!--/colorc-->
    >>
    >> Hello Richard:
    >>
    >> Your point is well taken. If it's bad stuff, surely it would propagate.
    >> If it's not, we might help the OP further. From my standpoint it's a
    >> conundrum, so Virus Total /is/ obviously the better step.
    >>
    >> Thank you,
    >>
    >> Pete
    >> --
    >> 1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t]<!--colorc--><!--/colorc-->
    > <!--colorc--><!--/colorc-->
     

Share This Page