Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Service s\mxdnlmhk

*******************

Script file located at: \??\C:\WINDOWS\system32\iutteawt.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Could not open file C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\m_hook.sys for deletion
Deletion of file C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\m_hook.sys failed!

Could not process line:
C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\m_hook.sys
Status: 0xc000003a



Could not open file C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\rosa.sys for deletion
Deletion of file C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\rosa.sys failed!

Could not process line:
C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\rosa.sys
Status: 0xc000003a



Could not open file C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\hidr.exe for deletion
Deletion of file C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\hidr.exe failed!

Could not process line:
C:\Documents and Settings\nomeutente\Dati applicazioni\hidires\hidr.exe
Status: 0xc000003a



File c:\WINDOWS\system32\wintems.exe not found!
Deletion of file c:\WINDOWS\system32\wintems.exe failed!

Could not process line:
c:\WINDOWS\system32\wintems.exe
Status: 0xc0000034

File c:\WINDOWS\system32\hldrrr.exe deleted successfully.


Could not open folder C:\Documents and Settings\nomeutente\Dati applicazioni\hidires for deletion
Deletion of folder C:\Documents and Settings\nomeutente\Dati applicazioni\hidires failed!

Could not process line:
C:\Documents and Settings\nomeutente\Dati applicazioni\hidires
Status: 0xc000003a

Folder c:\WINDOWS\exefld deleted successfully.


Registry key HKLM\SYSTEM\CurrentControlSet\Services\m_hook not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\m_hook failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\m_hook
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_H OOK not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_H OOK failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_H OOK
Status: 0xc0000034

Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ros a deleted successfully.
Registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run |hldrrr deleted successfully.

Completed script processing.

*******************

Finished! Terminate.