Thanks thisisu!
@Thisisu :
You have CLSID hijack ;)
@Thisisu :
You have CLSID hijack ;)
HKEY_CLASSES_ROOT\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32
-> C:\RECYCLER\S-1-5-21-823518204-842925246-839522115-1003\$848ec4efb4fb6501ab69678738a3a5c6\n.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32
-> %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad : CDBurn
-> {fbeb8a05-beee-4442-804e-409d6c4515e9}