Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Service s\igocmokk
*******************
Script file located at: \??\C:\nuvqntej.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\qegbdmwf.dll deleted successfully.
File C:\WINDOWS\gfetqaxsdtf.dll deleted successfully.
File C:\WINDOWS\pntqkflv.dll deleted successfully.
File C:\WINDOWS\ewgf.exe deleted successfully.
File C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\nse17.tmp\kkrip feoc.exe not found!
Deletion of file C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\nse17.tmp\kkrip feoc.exe failed!
Could not process line:
C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\nse17.tmp\kkrip feoc.exe
Status: 0xc0000034
File C:\WINDOWS\tovafrnm.exe deleted successfully.
File C:\WINDOWS\gxvpsafm.dll deleted successfully.
File C:\WINDOWS\system32\asc94.dll deleted successfully.
File C:\WINDOWS\system32\ks94.dll deleted successfully.
File C:\WINDOWS\temp\_.exe deleted successfully.
File C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\vista_sp1.exe.b at deleted successfully.
File C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\media.php.bat deleted successfully.
File C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\bindsrv2.exe.ba t deleted successfully.
File C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\atmadm2.exe.bat deleted successfully.
File C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\wxb2ifa-1t.dat deleted successfully.
File C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\desktop_backgro und.zip not found!
Deletion of file C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\desktop_backgro und.zip failed!
Could not process line:
C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\desktop_backgro und.zip
Status: 0xc0000034
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad|qegbdmwf deleted successfully.
Registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{D01A8B68-D46E-42C1-B967-9043543B6E0D} deleted successfully.
Program C:\Documents and Settings\Proprietario\Documenti\Downloads\sys7712. exe successfully set up to run once on reboot.
Completed script processing.
*******************
Finished! Terminate.