Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\nejdccvv
*******************
Script file located at: \??\C:\Program Files\ibegoxls.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\drivers\srosa.sys deleted successfully.
File C:\WINDOWS\system32\wintems.exe deleted successfully.
File C:\windows\system32\drivers\hldrrr.exe deleted successfully.
File C:\WINDOWS\system32\mdelk.exe deleted successfully.
File C:\avenger\backup.zip deleted successfully.
File C:\Documents and Settings\Casa\Impostazioni locali\Temporary Internet Files\Content.IE5\42WYGKYV\b64_1[1].jpg deleted successfully.
File C:\Documents and Settings\Casa\Impostazioni locali\Temporary Internet Files\Content.IE5\9JRAFTYQ\b64_31[1].jpg deleted successfully.
File C:\Documents and Settings\Casa\Impostazioni locali\Temporary Internet Files\Content.IE5\GBM176Y2\b64_2[1].jpg deleted successfully.
File C:\Documents and Settings\Casa\Impostazioni locali\Temporary Internet Files\Content.IE5\Y6BWSR27\b64_2[1].jpg deleted successfully.
File C:\Programmi\ATI Multimedia\main\atidtct.exe deleted successfully.
Folder C:\WINDOWS\system32\drivers\down deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.
Completed script processing.
*******************
Finished! Terminate.