Moderatori: m.paolo, kadosh, Luke57
[L’estensione txt è stata disattivata e non puó essere visualizzata.]
[L’estensione txt è stata disattivata e non puó essere visualizzata.]
files to delete:
C:\WINDOWS\system32\xivvr.dll
registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERaccess\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\ERaccess\Parameters
2009-03-19 16:56 . 2009-03-20 10:02 2,516 --ahs---- c:\documents and settings\All Users\Dati applicazioni\KGyGaAvL.sys
2009-03-19 16:56 . 2009-03-19 16:56 8 -r-hs---- c:\documents and settings\All Users\Dati applicazioni\CF7CB33637.sys
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\uvrkobhv
*******************
Script file located at: \??\C:\nbwpmocl.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\xivvr.dll deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERaccess\Parameters deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\ERaccess\Parameters deleted successfully.
Program C:\Documents and Settings\Administrator\Desktop\suspectfile\sys86203.exe successfully set up to run once on reboot.
Completed script processing.
*******************
Finished! Terminate.
[L’estensione txt è stata disattivata e non puó essere visualizzata.]
files to delete:
C:\WINDOWS\system32\astvw.dll
registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xmipiq
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xmipiq
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\xmipiq
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\enum\root\legacy_xmipiq
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\enum\root\legacy_xmipiq
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\enum\root\legacy_xmipiq
Visitano il forum: Nessuno e 13 ospiti