da f.punzi » lun feb 04, 2008 11:04 am
Ho fatto un paio di aggiunte allo script per neutralizzare il fallimento precedente:
C:\Avenger\backup-04.02.2008-10.33.23,79.zip
C:\Avenger\mdelk.exe
Stavolta credo sia andata (le finestre di explorer mi si aprono di nuovo velocemente). Ecco il log:
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\dactarli
*******************
Script file located at: \??\C:\obaqgqmf.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\drivers\srosa.sys deleted successfully.
File C:\WINDOWS\system32\wintems.exe deleted successfully.
File C:\windows\system32\drivers\hldrrr.exe deleted successfully.
File C:\WINDOWS\system32\mdelk.exe deleted successfully.
File C:\Avenger\backup.zip deleted successfully.
File C:\Avenger\backup-02.02.2008-14.44.44,06.zip deleted successfully.
File C:\Avenger\backup-04.02.2008-10.33.23,79.zip deleted successfully.
File C:\Avenger\mdelk.exe deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\0RQ76NI3\b64_1[1].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\0RQ76NI3\b64_1[2].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\0RQ76NI3\b64_1[3].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\0RQ76NI3\b64_2[1].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\3IYX1PHL\b64_31[2].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\3IYX1PHL\b64_31[1].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\AP8PA5M1\b64_2[1].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\AP8PA5M1\b64_2[2].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\ZACDIM4L\b64_1[1].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\ZACDIM4L\b64_31[1].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\ZACDIM4L\b64_31[2].jpg deleted successfully.
File C:\Documents and Settings\winxp\Impostazioni locali\Temporary Internet Files\Content.IE5\ZACDIM4L\b64_31[3].jpg deleted successfully.
File C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe deleted successfully.
Folder C:\WINDOWS\system32\drivers\down deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.
Completed script processing.
*******************
Finished! Terminate.