Hej, det var tidligt om morgenen og jeg troede jeg kunne nå det inden jeg skulle på job, men den gik ikke, derfor.
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\wrskiisq
*******************
Script file located at: \??\C:\Documents and Settings\hinyfrq^.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Registry key \Registry\User\S-1-5-21-4143980258-3897299837-3496439251-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{864097C5-B10C-7319-B712-7FBA75BC2BE3} not found!
Replacement with dummy of registry key HKEY_USERS\S-1-5-21-4143980258-3897299837-3496439251-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{864097C5-B10C-7319-B712-7FBA75BC2BE3} failed!
Status: 0xc0000034
Registry key \Registry\User\S-1-5-21-4143980258-3897299837-3496439251-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{864097C5-B10C-7319-B712-7FBA75BC2BE3} not found!
Replacement with dummy of registry key HKEY_USERS\S-1-5-21-4143980258-3897299837-3496439251-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{864097C5-B10C-7319-B712-7FBA75BC2BE3} failed!
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.
********************************* ROOTCHK-(17-09-07)-LOG, by ejvindh
2007-09-20 12:44:51.68
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 12:44:52
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{864097C5-B10C-7319-B712-7FBA75BC2BE3}]
“bbmfpgjganmgohofibmemnijnkmmpddjeefg”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abonbgfjlkhflnkgjgbbbopgdcfnngfnjl”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“iamfpgjganmgohofib”=hex:61,61,00,00
“haonbgfjlkhflnkg”=hex:61,61,00,00
“iaafjnjocbbnkikgik”=hex:61,61,00,00
“bbmfpgjganmgohofibmemnijnkmmeekggilf”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abonbgfjlkhflnkgjgbbbopgdccnagkkjn”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abafjkcepiamoieippfapdpenjfhdblcnf”=hex:69,61,67,65,6c,6a,66,65,6b,64,65,69,6e,65,67,70,63,68,00,e1
“malegmkanicjmkjjmigaebnhnm”=hex:68,61,6e,6b,6c,70,61,61,61,6c,62,6d,63,62,64,64,00,68
scanning hidden files ...
hidden processes: 0
hidden services: 0
hidden files: 0
********************************* ROOTCHK-(17-09-07)-LOG, by ejvindh
2007-09-20 13:06:46.73
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 13:06:48
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{864097C5-B10C-7319-B712-7FBA75BC2BE3}]
“bbmfpgjganmgohofibmemnijnkmmpddjeefg”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abonbgfjlkhflnkgjgbbbopgdcfnngfnjl”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“iamfpgjganmgohofib”=hex:61,61,00,00
“haonbgfjlkhflnkg”=hex:61,61,00,00
“iaafjnjocbbnkikgik”=hex:61,61,00,00
“bbmfpgjganmgohofibmemnijnkmmeekggilf”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abonbgfjlkhflnkgjgbbbopgdccnagkkjn”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abafjkcepiamoieippfapdpenjfhdblcnf”=hex:69,61,67,65,6c,6a,66,65,6b,64,65,69,6e,65,67,70,63,68,00,e1
“malegmkanicjmkjjmigaebnhnm”=hex:68,61,6e,6b,6c,70,61,61,61,6c,62,6d,63,62,64,64,00,68
scanning hidden files ...
hidden processes: 0
hidden services: 0
hidden files: 0
Sidste nye Rootchk herunder.
********************************* ROOTCHK-(17-09-07)-LOG, by ejvindh
2007-09-20 13:11:54.26
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 13:11:55
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{864097C5-B10C-7319-B712-7FBA75BC2BE3}]
“bbmfpgjganmgohofibmemnijnkmmpddjeefg”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abonbgfjlkhflnkgjgbbbopgdcfnngfnjl”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“iamfpgjganmgohofib”=hex:61,61,00,00
“haonbgfjlkhflnkg”=hex:61,61,00,00
“iaafjnjocbbnkikgik”=hex:61,61,00,00
“bbmfpgjganmgohofibmemnijnkmmeekggilf”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abonbgfjlkhflnkgjgbbbopgdccnagkkjn”=hex:6a,61,6e,6b,61,61,6a,70,63,66,6a,6b,68,6b,63,6c,63,6c,68,67,00,..
“abafjkcepiamoieippfapdpenjfhdblcnf”=hex:69,61,67,65,6c,6a,66,65,6b,64,65,69,6e,65,67,70,63,68,00,e1
“malegmkanicjmkjjmigaebnhnm”=hex:68,61,6e,6b,6c,70,61,61,61,6c,62,6d,63,62,64,64,00,68
scanning hidden files ...
hidden processes: 0
hidden services: 0
hidden files: 0
