Results 1 to 13 of 13

Thread: strange reset.bat file

  1. #1
    dubstylee's Avatar

    CEO, Zeropaid Inc.

    Join Date
    Apr 2002
    Location
    SD CA
    Posts
    600

    strange reset.bat file

    Was working on a friend's computer when I came across this strange file, located in C:\windows\repair. Its contents were:

    @echo off
    Rem: Brought to you by: By the best, The only
    Rem: people that did it.
    Rem: AngelDeath, Epyx, Slanchoca, DopeWeasel, Meph.
    Rem: The now Famous 5.

    batch.cmd
    inuse.exe security %systemroot%\system32\config\security /y >nul

    I did some googling and found inuse.exe is a windows utility that allows you to replace files in system memory. Is this some new spyware exploit? Has anyone seen this before?
    "Those who make peaceful revolution impossible will make violent revolution inevitable."
    - John F. Kennedy

    knofun

  2. #2
    Krell's Avatar

    worthless dirtball

    Join Date
    Sep 2002
    Posts
    9,759
    *overstating the obvious*

    For one, it comes from the Resource Kit, so it doesnt just "show up"

    Secondly, the bat credits as having been created by crackers.

    I wouldnt leave that OS on for 5 more minutes.

    I am attaching the readme files that come from the actually installation under C:\Program Files\Resource Kit.


    What kind of symptoms lead you to examine the system to begin with? What were you attempting to do? Did you examine the list of all installed programs to see if this could be slipped in with a "warez" somewhere?

    .

  3. #3
    The Hunter's Avatar

    Janitor

    Join Date
    Apr 2002
    Location
    Copperhead Road
    Posts
    11,611
    It is actually an exploit used to reset a trial period for xp back to "000" so the trial period never expires. That is as good as i can do. lol
    Grow old along with me, the best is yet to be.

  4. #4
    Krell's Avatar

    worthless dirtball

    Join Date
    Sep 2002
    Posts
    9,759
    I read your links in PM Hunter

    Yah thats what I was hinting at, especially with it in the \repair folder. If its only for resetting product activation, thats one thing, but when you dont know what processes get altered, or how your system GOT a hack, can you trust it?

    Its the game you play, mess with warez, risk getting burned.

    Good research Hunter

    .

  5. #5
    The Hunter's Avatar

    Janitor

    Join Date
    Apr 2002
    Location
    Copperhead Road
    Posts
    11,611
    thats why i wouldnt post how i can to that conclusion here, i didnt want to risk anyone trying those links.
    Grow old along with me, the best is yet to be.

  6. #6
    Krell's Avatar

    worthless dirtball

    Join Date
    Sep 2002
    Posts
    9,759
    Quote Originally Posted by The Hunter
    thats why i wouldnt post how i can to that conclusion here, i didnt want to risk anyone trying those links.
    warez site are seldom friendly, these werent either . . . heheeh im too locked down




    .

  7. #7
    The Hunter's Avatar

    Janitor

    Join Date
    Apr 2002
    Location
    Copperhead Road
    Posts
    11,611
    The first clue is when the site automaticly tries to send you the file without you asking for it.
    Grow old along with me, the best is yet to be.

  8. #8
    The Hunter's Avatar

    Janitor

    Join Date
    Apr 2002
    Location
    Copperhead Road
    Posts
    11,611
    When dub sees this, if he requests i will send him those links, but make sure your pc is really locked down before using them.
    Grow old along with me, the best is yet to be.

  9. #9
    dubstylee's Avatar

    CEO, Zeropaid Inc.

    Join Date
    Apr 2002
    Location
    SD CA
    Posts
    600
    His comp was riddled with spyware and pretty much unusable.. I ended up just reinstalling, and it did turn out he had a warez copy of xp... thanks for the replies.
    "Those who make peaceful revolution impossible will make violent revolution inevitable."
    - John F. Kennedy

    knofun

  10. #10

    Zeropaid Noob

    Join Date
    Jan 2003
    Location
    p2pconsortium.com i live
    Posts
    6,446
    u can close this thread now

  11. #11
    The Hunter's Avatar

    Janitor

    Join Date
    Apr 2002
    Location
    Copperhead Road
    Posts
    11,611
    As long as it all worked out, and i hope you told him he better start coming here and listening to all the warnings we post about spyware, and addware.
    Grow old along with me, the best is yet to be.

  12. #12

    Zeropaid Noob

    Join Date
    Jan 2003
    Location
    p2pconsortium.com i live
    Posts
    6,446
    spyware is evil
    but malware is worse
    with spyware it can be removed
    butwith malware it messes up your puter

  13. #13
    The Hunter's Avatar

    Janitor

    Join Date
    Apr 2002
    Location
    Copperhead Road
    Posts
    11,611
    Oh how true CJ, and that is why i didnt close this thread. It may still prove usefull to someone.
    Grow old along with me, the best is yet to be.

Similar Threads

  1. NTFS and FAT32: Need Feedback
    By MauerPower in forum Windows
    Replies: 36
    Last Post: April 17th, 2006, 11:49 AM
  2. Replies: 45
    Last Post: May 25th, 2005, 04:20 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •