Here is the result
Windows Registry Editor Version 5.00
; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.5.0
; Results at 2/13/2008 2:20:37 AM for strings:
; ‘catchme.sys’
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\catchme]
; Contents of value:
; ??\C:\DOCUME~1\Carrie\LOCALS~1\Temp\catchme.sys
“ImagePath”=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,44,00,4f,00,43,00,
55,00,4d,00,45,00,7e,00,31,00,5c,00,43,00,61,00,72,00,72,00,69,00,65,00,5c,
00,4c,00,4f,00,43,00,41,00,4c,00,53,00,7e,00,31,00,5c,00,54,00,65,00,6d,00,
70,00,5c,00,63,00,61,00,74,00,63,00,68,00,6d,00,65,00,2e,00,73,00,79,00,73,
00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\catchme]
; Contents of value:
; ??\C:\DOCUME~1\Carrie\LOCALS~1\Temp\catchme.sys
“ImagePath”=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,44,00,4f,00,43,00,
55,00,4d,00,45,00,7e,00,31,00,5c,00,43,00,61,00,72,00,72,00,69,00,65,00,5c,
00,4c,00,4f,00,43,00,41,00,4c,00,53,00,7e,00,31,00,5c,00,54,00,65,00,6d,00,
70,00,5c,00,63,00,61,00,74,00,63,00,68,00,6d,00,65,00,2e,00,73,00,79,00,73,
00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme]
; Contents of value:
; ??\C:\DOCUME~1\Carrie\LOCALS~1\Temp\catchme.sys
“ImagePath”=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,44,00,4f,00,43,00,
55,00,4d,00,45,00,7e,00,31,00,5c,00,43,00,61,00,72,00,72,00,69,00,65,00,5c,
00,4c,00,4f,00,43,00,41,00,4c,00,53,00,7e,00,31,00,5c,00,54,00,65,00,6d,00,
70,00,5c,00,63,00,61,00,74,00,63,00,68,00,6d,00,65,00,2e,00,73,00,79,00,73,
00,00,00
; End Of The Log…