Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Service s\jmgsnjbt
*******************
Script file located at: \??\C:\WINDOWS\csvxsdiy.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File c:\windows\system32\iocsiuwe.log deleted successfully.
File C:\DOCUME~1\utente\IMPOST~1\Temp\sta18B.exe deleted successfully.
File C:\DOCUME~1\utente\IMPOST~1\Temp\sta14C.exe deleted successfully.
File C:\DOCUME~1\utente\IMPOST~1\Temp\staE2.exe deleted successfully.
File C:\DOCUME~1\utente\IMPOST~1\Temp\staF9.exe deleted successfully.
File C:\DOCUME~1\utente\IMPOST~1\Temp\D653F3EC.TMP deleted successfully.
File C:\DOCUME~1\utente\IMPOST~1\Temp\IH10A.tmp deleted successfully.
File c:\windows\system32\srvjchaa.exe deleted successfully.
File C:\DOCUME~1\utente\DATIAP~1\ONEREA~1\dumb second.exe deleted successfully.
File C:\WINDOWS\tasks\pwzedz.job deleted successfully.
Folder C:\Documents and Settings\All Users\Dati applicazioni\Book Slow Axis Web deleted successfully.
Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe deleted successfully.
Registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run |srvjchaa deleted successfully.
Registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run |axis web cake second deleted successfully.
Completed script processing.
*******************
Finished! Terminate.