Sembra che non ci sia più,almeno questo è quello che mi fa notare Kaspersky dandomi il virus come eliminato..comunque...
Questo è lo script di Avenger:
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\cscqopha
*******************
Script file located at: \??\C:\WINDOWS\wqstrjih.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\drivers\hidr.exe not found!
Deletion of file C:\WINDOWS\system32\drivers\hidr.exe failed!
Could not process line:
C:\WINDOWS\system32\drivers\hidr.exe
Status: 0xc0000034
File C:\WINDOWS\system32\drivers\srosa.sys deleted successfully.
File C:\WINDOWS\system32\wintems.exe deleted successfully.
File C:\WINDOWS\system32\hldrrr.exe not found!
Deletion of file C:\WINDOWS\system32\hldrrr.exe failed!
Could not process line:
C:\WINDOWS\system32\hldrrr.exe
Status: 0xc0000034
File C:\WINDOWS\system32\trusted.exe not found!
Deletion of file C:\WINDOWS\system32\trusted.exe failed!
Could not process line:
C:\WINDOWS\system32\trusted.exe
Status: 0xc0000034
File C:\WINDOWS\system32\drivers\pci32.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\pci32.sys failed!
Could not process line:
C:\WINDOWS\system32\drivers\pci32.sys
Status: 0xc0000034
File C:\windows\system32\drivers\hldrrr.exe deleted successfully.
File C:\WINDOWS\system32\drivers\hldrrr.ex_ not found!
Deletion of file C:\WINDOWS\system32\drivers\hldrrr.ex_ failed!
Could not process line:
C:\WINDOWS\system32\drivers\hldrrr.ex_
Status: 0xc0000034
File C:\WINDOWS\system32\mdelk.exe deleted successfully.
Error: C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\43QX65TH is a folder, not a file!
Deletion of file C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\43QX65TH failed!
Could not process line:
C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\43QX65TH
Status: 0xc00000ba
Error: C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\H7DQ1G6R is a folder, not a file!
Deletion of file C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\H7DQ1G6R failed!
Could not process line:
C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\H7DQ1G6R
Status: 0xc00000ba
Error: C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\N8KZBWPN is a folder, not a file!
Deletion of file C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\N8KZBWPN failed!
Could not process line:
C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\N8KZBWPN
Status: 0xc00000ba
Error: C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\Z3P2I9X5 is a folder, not a file!
Deletion of file C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\Z3P2I9X5 failed!
Could not process line:
C:\Documents and Settings\Melvin\Impostazioni locali\Temporary Internet Files\Content.IE5\Z3P2I9X5
Status: 0xc00000ba
File C:\Programmi\Realtek\InstallShield\AzMixerSel.exe deleted successfully.
File C:\Programmi\Acer\OrbiCam\CameraAssistant.exe deleted successfully.
Folder C:\WINDOWS\exefnd not found!
Deletion of folder C:\WINDOWS\exefnd failed!
Could not process line:
C:\WINDOWS\exefnd
Status: 0xc0000034
Folder C:\WINDOWS\exefld not found!
Deletion of folder C:\WINDOWS\exefld failed!
Could not process line:
C:\WINDOWS\exefld
Status: 0xc0000034
Folder C:\WINDOWS\system32\drivers\down deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 failed!
Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\pci32
Status: 0xc0000034
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 failed!
Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File "C:\WINDOWS\system32\ljJDVmli.dll" deleted successfully.
File "C:\WINDOWS\system32\urqNGayV.dll" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.