"Silent Runners.vbs", revision 40,
http://www.silentrunners.org/Operating System: Windows 2000
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\
"sto32_" = "C:\WINNT\system32\sto32_.exe" [file not found]
"aaaaks" = "C:\WINNT\system32\aaaaks.exe" [file not found]
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"PopUpStopperFreeEdition" = ""C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"" ["Panicware, Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Synchronization Manager" = "mobsync.exe /logon" [MS]
"JobHisInit" = "C:\Program Files\RMClient\JobHisInit.exe" [empty string]
"MplSetUp" = "C:\Program Files\RMClient\MplSetUp.exe" ["RICOH CO.,LTD."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\System32\hticons.dll" ["Hilgraeve, Inc."]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{94D8F8FB-8742-4792-AD02-C35CBE60C2CD}" = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\system32\dhfolder.dll" [file not found]
"{DF631DFB-9AF3-4D68-B3AE-28B6C87DE83C}" = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\system32\tnaffic.dll" [null data]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{CAB81DA3-8DBF-42B4-957F-B33C320DF176}" = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\system32\guard.tmp" [null data]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: <Firmenname>"]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
gxtqnfxt\(Default) = "{332266dd-9a7d-429f-bf85-1b2378e3504b}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\system32\daobn.dll" [null data]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop is enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\Documents and Settings\Default User\My Documents\My Pictures\Im000745.jpg"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\1\
"SCRNSAVE.EXE" = "C:\WINNT\system32\ssmarque.scr" [MS]
Startup items in "office" & "All Users" startup folders:
--------------------------------------------------------
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
Enabled Scheduled Tasks:
------------------------
"IMG_1211" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1211.JPG" [file not found]
"IMG_1219" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1219.JPG" [file not found]
"IMG_1227" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1227.JPG" [file not found]
"IMG_1232" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1232.JPG" [file not found]
"IMG_1246" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1246.JPG" [file not found]
"IMG_1248" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1248.JPG" [file not found]
"IMG_1253" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1253.JPG" [file not found]
"IMG_1258" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1258.JPG" [file not found]
"IMG_1261" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1261.JPG" [file not found]
"IMG_1262" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1262.JPG" [file not found]
"IMG_1263" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1263.JPG" [file not found]
"IMG_1264" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1264.JPG" [file not found]
"IMG_1266" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1266.JPG" [file not found]
"IMG_1268" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1268.JPG" [file not found]
"IMG_1271" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1271.JPG" [file not found]
"IMG_1272" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1272.JPG" [file not found]
"IMG_1273" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1273.JPG" [file not found]
"IMG_1274" -> launches: "C:\Documents and Settings\Mandy\Desktop\Pictures\IMG_1274.JPG" [file not found]
"RUTASK" -> launches: "C:\WINNT\ru.exe" [file not found]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\msafd.dll [MS], 01 - 03, 06 - 13
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Explorer Bars
Dormant Explorer Bars in "View, Explorer Bar" menu
HKLM\Software\Classes\CLSID\{79406F24-8E95-4AF8-9FEF-2EA2B504E707}\ = "BottomFrame Class"
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = "C:\WINNT\eltt.dll" [empty string]
HKLM\Software\Classes\CLSID\{8F7D96AA-489A-4194-AB34-21EF42507932}\ = "LeftFrame Class"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\WINNT\eltt.dll" [empty string]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"]
----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 28 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 10 seconds.
---------- (total run time: 72 seconds)
Edited by ikoncenter, 20 August 2005 - 04:58 PM.