[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{20938f52-5abf-11dc-b965-00038a000015}]
1\Command - F:.\rundll.exe
2\Command - F:.\Rundll.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{28cee192-5f82-11dc-b974-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{434ed7b0-5d39-11dc-b96d-00038a000015}]
1\Command - .\rundll.exe
2\Command - .\Rundll.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{610b8202-4a1b-11dc-b949-000e3547d722}]
AutoRun\command - RavMon.exe
explore\Command - RavMon.exe -e
open\Command - RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{61220610-5de5-11dc-b970-00038a000015}]
1\Command - .\rundll.exe
2\Command - .\Rundll.exe
AutoRun\command - .\rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{76c74d98-6120-11dc-b978-00038a000015}]
AutoRun\command - E:\cintia.ico
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{8aa2a6f4-2e96-11dc-b913-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{8ac9d021-4725-11dc-b941-00038a000015}]
1\Command - .\rundll.exe
2\Command - .\Rundll.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{8c6ca4f2-12d0-11dc-b8bc-00038a000015}]
Auto\command - infrom.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL infrom.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{8e548a23-3420-11dc-b91e-00038a000015}]
1\Command - E:.\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{a84d4118-5145-11dc-b955-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{c993dad2-1be0-11dc-b8e3-00038a000015}]
AutoRun\command - E:\ntde1ect.com
explore\Command - E:\ntde1ect.com
open\Command - E:\ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{cfa528d2-5b77-11dc-b967-00038a000015}]
AutoRun\command - E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{da1c95f2-12e8-11dc-b8be-000e7bdd5315}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{df5d2af0-4235-11dc-b932-00038a000015}]
1\Command - F:.\rundll.exe
2\Command - F:.\Rundll.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{e224be72-117a-11dc-b8ac-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{ed575110-6bf5-11dc-b9a5-00038a000015}]
AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{f66fc120-2515-11dc-b8f6-00038a000015}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{fdafefad-1ccf-11dc-b8eb-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{fe0ddfe2-4fcb-11dc-b953-00038a000015}]
AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{fe0ddfe3-4fcb-11dc-b953-00038a000015}]
AutoRun\command - G:\ntde1ect.com
explore\Command - G:\ntde1ect.com
open\Command - G:\ntde1ect.com
Newly Created Service - CATCHME
.
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-11 15:48:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
.
Completion time: 2007-10-11 15:49:33
.
— E O F —