[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20938f52-5abf-11dc-b965-00038a000015}]
1\Command - F:\.\rundll.exe
2\Command - F:\.\Rundll.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28cee192-5f82-11dc-b974-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{434ed7b0-5d39-11dc-b96d-00038a000015}]
1\Command - .\rundll.exe
2\Command - .\Rundll.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{610b8202-4a1b-11dc-b949-000e3547d722}]
AutoRun\command - RavMon.exe
explore\Command - RavMon.exe -e
open\Command - RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61220610-5de5-11dc-b970-00038a000015}]
1\Command - .\rundll.exe
2\Command - .\Rundll.exe
AutoRun\command - .\rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76c74d98-6120-11dc-b978-00038a000015}]
AutoRun\command - E:\cintia.ico
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8aa2a6f4-2e96-11dc-b913-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ac9d021-4725-11dc-b941-00038a000015}]
1\Command - .\rundll.exe
2\Command - .\Rundll.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c6ca4f2-12d0-11dc-b8bc-00038a000015}]
Auto\command - infrom.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL infrom.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e548a23-3420-11dc-b91e-00038a000015}]
1\Command - E:\.\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a84d4118-5145-11dc-b955-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c993dad2-1be0-11dc-b8e3-00038a000015}]
AutoRun\command - E:\ntde1ect.com
explore\Command - E:\ntde1ect.com
open\Command - E:\ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cfa528d2-5b77-11dc-b967-00038a000015}]
AutoRun\command - E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da1c95f2-12e8-11dc-b8be-000e7bdd5315}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df5d2af0-4235-11dc-b932-00038a000015}]
1\Command - F:\.\rundll.exe
2\Command - F:\.\Rundll.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Rundll.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e224be72-117a-11dc-b8ac-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed575110-6bf5-11dc-b9a5-00038a000015}]
AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f66fc120-2515-11dc-b8f6-00038a000015}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fdafefad-1ccf-11dc-b8eb-00038a000015}]
1\Command - .\recycled\info.exe
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe0ddfe2-4fcb-11dc-b953-00038a000015}]
AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe0ddfe3-4fcb-11dc-b953-00038a000015}]
AutoRun\command - G:\ntde1ect.com
explore\Command - G:\ntde1ect.com
open\Command - G:\ntde1ect.com
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-11 15:48:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-10-11 15:49:33
.
--- E O F ---