USBNoRisk 2.2 09 May 2009 by bobby
Started at 5/13/2009 7:42:01 PM
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
C: {338c2242-eacd-11dd-ad8f-806d6172696f}
E: {e6022a64-373f-11de-8598-806d6172696f}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
autorun.inf found on C:
----------------------------------------
File C:\autorun.inf renamed successfully
Content of C:\autorun.inf.blocked
----------------------------------------
[autorun]
;uuhvrtfslemvoqywodavowwgqbiahlacbyumftddqbfzdbpkeuikyucpqgmdzkgpbvmyecopngigjsqfdeemqcxwpgnzuj
shellexecute="RECYCLER\S-4-4-62-100010653-100014943-100028325-4071.com c:\"
;rdephxhcrdmovusvdugnlsqloaemkknpojlyrqfvnoidrcehdrhnpmoyghxuhwwdkflaulduaqh
shell\Open\command="RECYCLER\S-4-4-62-100010653-100014943-100028325-4071.com c:\"
;ayhrhqixpgbqqatvqmxvbtbrabismpqxtxadlsvtqdkzeufmrtkyhhombwqytetnqfgurrngciozokbjaxdawih
shell=Open
----------------------------------------
No mountpoint found for C:
Sanitized mountpoint for 338c2242-eacd-11dd-ad8f-806d6172696f
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on E:
autorun.inf found on E:
----------------------------------------
File E:\autorun.inf renamed successfully
Content of E:\autorun.inf.blocked
----------------------------------------
[autorun]
;mcpgefugiqwbvylpnxjmvrhswlwpgm
shellexecute="RECYCLER\S-4-4-62-100010653-100014943-100028325-4071.com e:\"
;hdfkcvockkfzdpehfgdgnppfiaobsakockmdcddwlklrobjavzis
shell\Open\command="RECYCLER\S-4-4-62-100010653-100014943-100028325-4071.com e:\"
;mdmxhrkeczuoikzvvznlkyzgjmkdkzoyaqfgghuiyhcdxkcxysqexmyexstbfyxzvqqtshytfnkqptnnnjqjehyticoghsftx
shell=Open
----------------------------------------
No mountpoint found for E:
Sanitized mountpoint for e6022a64-373f-11de-8598-806d6172696f
No Desktop.ini files found on E:
----------------------------------------
========================================
Initial scan finished!
========================================
New device connected at 5/13/2009 7:42:43 PM
Scanning for connected USB mass storage...
----------------------------------------
G: {30f89afc-4001-11de-85b4-00142239506e}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
No mountpoint found for 30f89afc-4001-11de-85b4-00142239506e
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
========================================
========================================
Removed G:
========================================
New device connected at 5/13/2009 7:43:20 PM
Scanning for connected USB mass storage...
----------------------------------------
G: {d95f1aca-3838-11de-85a5-00142239506e}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
No mountpoint found for G:
Sanitized mountpoint for d95f1aca-3838-11de-85a5-00142239506e
----------------------------------------
----------------------------------------
Desktop.ini found at G:\Recycled\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------
No mimics found on drive G:
========================================
========================================
Removed G:
========================================
New device connected at 5/13/2009 7:45:26 PM
Scanning for connected USB mass storage...
----------------------------------------
G: {d46c7028-38f1-11de-85a7-00142239506e}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
Sanitized mountpoint for d46c7028-38f1-11de-85a7-00142239506e
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
========================================
========================================
Removed G:
========================================
========================================
========================================
Started at 5/13/2009 7:42:01 PM
Searching for connected USB Mass storage...
----------------------------------------
========================================
Searching for other storage...
----------------------------------------
C: {338c2242-eacd-11dd-ad8f-806d6172696f}
E: {e6022a64-373f-11de-8598-806d6172696f}
========================================
Scanning fixed storage...
----------------------------------------
No blocked files found on C:
autorun.inf found on C:
----------------------------------------
File C:\autorun.inf renamed successfully
Content of C:\autorun.inf.blocked
----------------------------------------
[autorun]
;uuhvrtfslemvoqywodavowwgqbiahlacbyumftddqbfzdbpkeuikyucpqgmdzkgpbvmyecopngigjsqfdeemqcxwpgnzuj
shellexecute="RECYCLER\S-4-4-62-100010653-100014943-100028325-4071.com c:\"
;rdephxhcrdmovusvdugnlsqloaemkknpojlyrqfvnoidrcehdrhnpmoyghxuhwwdkflaulduaqh
shell\Open\command="RECYCLER\S-4-4-62-100010653-100014943-100028325-4071.com c:\"
;ayhrhqixpgbqqatvqmxvbtbrabismpqxtxadlsvtqdkzeufmrtkyhhombwqytetnqfgurrngciozokbjaxdawih
shell=Open
----------------------------------------
No mountpoint found for C:
Sanitized mountpoint for 338c2242-eacd-11dd-ad8f-806d6172696f
No Desktop.ini files found on C:
----------------------------------------
No blocked files found on E:
autorun.inf found on E:
----------------------------------------
File E:\autorun.inf renamed successfully
Content of E:\autorun.inf.blocked
----------------------------------------
[autorun]
;mcpgefugiqwbvylpnxjmvrhswlwpgm
shellexecute="RECYCLER\S-4-4-62-100010653-100014943-100028325-4071.com e:\"
;hdfkcvockkfzdpehfgdgnppfiaobsakockmdcddwlklrobjavzis
shell\Open\command="RECYCLER\S-4-4-62-100010653-100014943-100028325-4071.com e:\"
;mdmxhrkeczuoikzvvznlkyzgjmkdkzoyaqfgghuiyhcdxkcxysqexmyexstbfyxzvqqtshytfnkqptnnnjqjehyticoghsftx
shell=Open
----------------------------------------
No mountpoint found for E:
Sanitized mountpoint for e6022a64-373f-11de-8598-806d6172696f
No Desktop.ini files found on E:
----------------------------------------
========================================
Initial scan finished!
========================================
New device connected at 5/13/2009 7:42:43 PM
Scanning for connected USB mass storage...
----------------------------------------
G: {30f89afc-4001-11de-85b4-00142239506e}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
No mountpoint found for 30f89afc-4001-11de-85b4-00142239506e
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
========================================
========================================
Removed G:
========================================
New device connected at 5/13/2009 7:43:20 PM
Scanning for connected USB mass storage...
----------------------------------------
G: {d95f1aca-3838-11de-85a5-00142239506e}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
No mountpoint found for G:
Sanitized mountpoint for d95f1aca-3838-11de-85a5-00142239506e
----------------------------------------
----------------------------------------
Desktop.ini found at G:\Recycled\ contains interesting CLSID string
----------------------------------------
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
----------------------------------------
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip = @%SystemRoot%\system32\SHELL32.dll,-22915
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText = @%SystemRoot%\system32\SHELL32.dll,-31748
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString = @%SystemRoot%\system32\SHELL32.dll,-8964
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty = %SystemRoot%\System32\shell32.dll,31
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full = %SystemRoot%\System32\shell32.dll,32
HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ = shell32.dll
----------------------------------------
No mimics found on drive G:
========================================
========================================
Removed G:
========================================
New device connected at 5/13/2009 7:45:26 PM
Scanning for connected USB mass storage...
----------------------------------------
G: {d46c7028-38f1-11de-85a7-00142239506e}
Added G:
========================================
Scanning USB mass storage for files...
----------------------------------------
No blocked files found on G:
----------------------------------------
No Autorun.inf files found on G:
Sanitized mountpoint for d46c7028-38f1-11de-85a7-00142239506e
----------------------------------------
No Desktop.ini files found on G:
----------------------------------------
No mimics found on drive G:
========================================
========================================
Removed G:
========================================
========================================
========================================