cool, i just thought of a way of extracting the script code from the executable right away, no need to wait for tomorrow then, here it is :
Cleaner.bat
echo call wscript.echo("OUTLAWS-trojan Cleaner 2007, by Red_phoenix2k@hotmail.com, NO WARRANTY on usage") > %windir%\temp\msg.vbs
%windir%\temp\msg.vbs
del /f %windir%\temp\msg.vbs
echo call wscript.echo("Plz CLOSE all background applications, press OK and then WAIT for the finished message") > %windir%\temp\msg.vbs
%windir%\temp\msg.vbs
del /f %windir%\temp\msg.vbs
taskkill /f /im notepad.exe /t
taskkill /f /im taskmger.com /t
taskkill /f /im systems.com /t
taskkill /f /im mypictures.exe /t
for %%x in ( c d e f g h i j k l m n o p q r s t u v w x y z ) do attrib -s -r -h %%x:\autorun.inf
for %%x in ( c d e f g h i j k l m n o p q r s t u v w x y z ) do del /f %%x:\autorun.inf
for %%x in ( c d e f g h i j k l m n o p q r s t u v w x y z ) do attrib -s -r -h %%x:\recycler\systems.com
for %%x in ( c d e f g h i j k l m n o p q r s t u v w x y z ) do del /f %%x:\recycler\systems.com
for %%x in ( c d e f g h i j k l m n o p q r s t u v w x y z ) do attrib -s -r -h %%x:\systems.com
for %%x in ( c d e f g h i j k l m n o p q r s t u v w x y z ) do del /f %%x:\systems.com
for %%x in ( c d e f g h i j k l m n o p q r s t u v w x y z ) do attrib -s -r -h %%x:\mypictures.exe
for %%x in ( c d e f g h i j k l m n o p q r s t u v w x y z ) do del /f %%x:\mypictures.exe
attrib -s -r -h %windir%\system32\notepad.exe
del /f %windir%\system32\notepad.exe
attrib -s -r -h %windir%\system32\taskmger.com
del /f %windir%\system32\taskmger.com
copy /y %windir%\notepad.exe %windir%\system32\notepad.exe
reg add "hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Shell" /t reg_sz /d "Explorer.exe" /f
reg add "hkcu\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableTaskmgr" /t reg_dword /d 0 /f
reg add "hkcu\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRegistryTools" /t reg_dword /d 0 /f
reg add "hkcu\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "NoFolderOptions" /t reg_dword /d 0 /f
reg delete "hklm\Software\Microsoft\Windows\CurrentVersion\Run" /v "systry" /f
reg delete "hklm\Software\Microsoft\Windows\CurrentVersion\Run" /v "userd" /f
echo call wscript.echo("Finished cleaning up, Plz RESTART ur computer now ;)") > %windir%\temp\msg.vbs
%windir%\temp\msg.vbs
del /f %windir%\temp\msg.vbs
if this looks like malware code to u guys just tell me and i'll remove the link from rapidshare hehe