Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Service s\gwcqncmk
*******************
Script file located at: \??\C:\Documents and Settings\embkomdg.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\mmjxydvu.ini deleted successfully.
File C:\WINDOWS\system32\ddabc.dll deleted successfully.
File C:\WINDOWS\system32\hsqqedin.dll deleted successfully.
File C:\WINDOWS\system32\syhjwsiv.dll deleted successfully.
File C:\WINDOWS\system32\ijbueckf.dll not found!
Deletion of file C:\WINDOWS\system32\ijbueckf.dll failed!
Could not process line:
C:\WINDOWS\system32\ijbueckf.dll
Status: 0xc0000034
File C:\WINDOWS\system32\fkceubji.ini deleted successfully.
File C:\WINDOWS\system32\gjilaygb.dll deleted successfully.
File C:\WINDOWS\system32\cbadd.ini2 deleted successfully.
File C:\WINDOWS\system32\cbadd.ini deleted successfully.
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX308.tmp not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX308.tmp failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX308.tmp
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\3q93E3.tmp not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\3q93E3.tmp failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\3q93E3.tmp
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX13D.tmp not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX13D.tmp failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX13D.tmp
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX3AE.tmp not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX3AE.tmp failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX3AE.tmp
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX29.tmp not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX29.tmp failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX29.tmp
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\3169644 not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\3169644 failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\3169644
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX49.tmp not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX49.tmp failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX49.tmp
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX381.tmp not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX381.tmp failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX381.tmp
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\removalfile.bat not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\removalfile.bat failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\removalfile.bat
Status: 0xc0000034
File C:\WINDOWS\system32\spoolw.exe not found!
Deletion of file C:\WINDOWS\system32\spoolw.exe failed!
Could not process line:
C:\WINDOWS\system32\spoolw.exe
Status: 0xc0000034
File C:\WINDOWS\system32\igfxsvc.exe not found!
Deletion of file C:\WINDOWS\system32\igfxsvc.exe failed!
Could not process line:
C:\WINDOWS\system32\igfxsvc.exe
Status: 0xc0000034
File C:\WINDOWS\system32\iifcawx.dll not found!
Deletion of file C:\WINDOWS\system32\iifcawx.dll failed!
Could not process line:
C:\WINDOWS\system32\iifcawx.dll
Status: 0xc0000034
File C:\WINDOWS\system32\mlljk.dll not found!
Deletion of file C:\WINDOWS\system32\mlljk.dll failed!
Could not process line:
C:\WINDOWS\system32\mlljk.dll
Status: 0xc0000034
File C:\WINDOWS\system32\hsqqedin.dll not found!
Deletion of file C:\WINDOWS\system32\hsqqedin.dll failed!
Could not process line:
C:\WINDOWS\system32\hsqqedin.dll
Status: 0xc0000034
File C:\WINDOWS\system32\gjilaygb.dll not found!
Deletion of file C:\WINDOWS\system32\gjilaygb.dll failed!
Could not process line:
C:\WINDOWS\system32\gjilaygb.dll
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\win13C.exe not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\win13C.exe failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\win13C.exe
Status: 0xc0000034
File C:\DOCUME~1\Cicco\IMPOST~1\Temp\win154.bat not found!
Deletion of file C:\DOCUME~1\Cicco\IMPOST~1\Temp\win154.bat failed!
Could not process line:
C:\DOCUME~1\Cicco\IMPOST~1\Temp\win154.bat
Status: 0xc0000034
Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.
Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks\{9AA57522-2ECD-47DF-BD38-20E7E577A464} not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks\{9AA57522-2ECD-47DF-BD38-20E7E577A464} failed!
Status: 0xc0000034
Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{38253AA1-B7CB-4562-BBDE-AB0341B440B5} not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{38253AA1-B7CB-4562-BBDE-AB0341B440B5} failed!
Status: 0xc0000034
Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{799C1013-489B-42C4-A344-86D700895700} deleted successfully.
Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A} deleted successfully.
Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{addaf5bf-de45-443a-99a8-dfb32b02cd95} not found!
Deletion of registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{addaf5bf-de45-443a-99a8-dfb32b02cd95} failed!
Status: 0xc0000034
Program C:\Documents and Settings\Cicco\Desktop\sys24275.exe successfully set up to run once on reboot.
Completed script processing.
*******************
Finished! Terminate.