Seite 2

Seite 1 - Avenger zurück - Seite 1 - Avenger




Beispiel:

Logfile of The Avenger version 1, by Swandog46
Beginning to process script file:

File C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00001.dll deleted successfully.
File C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\ibm00001.exe deleted successfully.

Completed script processing.


Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs

Registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | egdiag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|cppcs

registry keys to delete:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmfu32
HKLM\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{98663E21-9CCE-4CF6-863C-911A9523A66F}

Folders to delete:
C:\Programme\IntCodec

Drivers to disable:
lzx32
vaxjutbm

Drivers to delete:
lzx32
vaxjutbm

Files to delete:
C:\WINDOWS\csrss.exe
C:\WINDOWS\system32\o8luli3918.dll
C:\windows\system32\ lzx32 sys
C:\WINDOWS\system32\drivers\kndhhjek.sys

%Windir%\System32\askearth17.exe
%ProgramFiles%\data19
%Windir%\pi1.exe
%UserProfile%\Local Settings\Temp\ei.exe
%UserProfile%\Desktop\askearth17.exe

Programs to launch on reboot:
C:\Fixit.reg


Registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|isa.exe

Registry Keys to delete:
HKLM\software\microsoft\shared tools\msconfig\startupreg\ AntiVermins

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows| AppInit_DLLs

Files to delete:
C:\WINDOWS\TEMP\fkcc1.exe
C:\Programmi\Windows NT\com4.exe
C:\Programmi\Windows NT\lpt8.exe

Folders to delete:
C:\Programme\AntiVermins

Programs to launch on reboot:
C:\HJT\HijackThis.exe



Program C:\HJT\HijackThis.exe successfully set up to run once on reboot.




http://swandog46.geekstogo.com/avenger2/cmd1.html
# Comment:
# Files to delete:
# Files to replace with dummy:
# Files to move:
# Folders to delete:
# Registry keys to delete:
# Registry keys to replace with dummy:
# Registry values to delete:
# Registry values to replace with dummy:
# Programs to launch on reboot:
# Drivers to delete:
# Drivers to disable


Beispiel: Driver
S0 vaxjutbm;vaxjutbm;C:\WINDOWS\system32\ drivers\kndhhjek.sys []

The Service name is also the name of the subkey under
HKLM\System\CurrentControlSet\Services.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VAXJUTBM

http://swandog46.geekstogo.com/avenger2/tutorial.html
http://swandog46.geekstogo.com/avengernotes.htm

avenger scripts Suchbegriff eingeben:
Benutzerdefinierte Suche











Files to delete:
c:\windows\system32\badfile.dll
%windir%\system32\badfile2.dll
%systemdrive%\somefile.ext

Files to replace with dummy:
D:\somefile.ext

FILES TO MOVE:
C:\SOMESOURCEFILE | c:\somedestinationfile
"C:\SOMESOURCEFILE" | "c:\somedestinationfile"

Folders to Delete:
C:\somefolder

registry keys to delete:
hklm\software\badkey
hkey_local_machine\system\currentcontrolset\key

registry keys to replace with dummy:
hku\.default\somebadkey
hklm\software\some long key name

registry values to delete:
HKEY_USERS\.default\badkey | somebadvalue

Registry values to replace with dummy:
HKLM\SomeKeyPath\Blah\Blah|somevalue

programs to launch on reboot:
%systemdrive%\mybatch.bat

Drivers to disable:
vaxjutbm

Drivers to delete:
vaxjutbm





Avenger | Avenger2 | Valid HTML 4.01 Ranking-Hits