Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\fslrpita
*******************
Script file located at: \??\C:\Program Files\xpbuaqvi.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Registry key HKLM\SYSTEM\CurrentControlSet\Services\SrvKdq deleted successfully.
Folder C:\documents and settings\pFpemDE deleted successfully.
File C:\WINDOWS\qjnmwqdk.exe deleted successfully.
File C:\WINDOWS\svhost.dll deleted successfully.
File C:\WINDOWS\115252174116.exe deleted successfully.
File C:\WINDOWS\winsys.exe deleted successfully.
File C:\WINDOWS\system32\svshost.exe deleted successfully.
File C:\WINDOWS\SFTVFJAH.EXE deleted successfully.
Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.
Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList|pFpemDE deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Nel process manager non c'è più in effetti, però se faccio lo scan con Hijackthis c'è ancora:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\SFTVFJAH.EXE
Inoltre adesso quando mi ha riavviato il Pc ho dovuto scegliere l'utente, come faccio a rimetterlo in automatico? (sono solo io l'utente)