“Silent Runners.vbs”, revision 43, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} “Mozilla Quick Launch” = ““C:\Program Files\mozilla.org\Mozilla\Mozilla.exe” -turbo” [“Mozilla, Netscape”] “ctfmon.exe” = “C:\WINDOWS\system32\ctfmon.exe” [MS] “Active Desktop Calendar” = “C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe” [“XemiComputers ltd.”] “Skype” = ““C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized” [“Skype Technologies S.A.”] “MsnMsgr” = ““C:\Program Files\MSN Messenger\MsnMsgr.Exe” /background” [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} “Apoint” = “C:\Program Files\Apoint\Apoint.exe” [“Alps Electric Co., Ltd.”] “ATIModeChange” = “Ati2mdxx.exe” [“ATI Technologies, Inc.”] “BluetoothAuthenticationAgent” = “rundll32.exe bthprops.cpl,BluetoothAuthenticationAgent” [MS] “ATIPTA” = “C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [“ATI Technologies, Inc.”] “HPDJ Taskbar Utility” = “C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe” [“HP”] “HP Component Manager” = ““C:\Program Files\HP\hpcoretech\hpcmpmgr.exe”” [“Hewlett-Packard Company”] “HP Software Update” = ““C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe”” [“Hewlett-Packard Company”] “ezShieldProtector for Px” = “C:\WINDOWS\System32\ezSP_Px.exe” [“Easy Systems Japan Ltd.”] “Switcher.exe” = “C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe” [“Sony Corporation”] “Mouse Suite 98 Daemon” = “ICO.EXE” [“Primax Electronics Ltd.”] “HKSERV.EXE” = “C:\Program Files\Sony\HotKey Utility\HKserv.exe” [“Sony Corporation”] “Windows Defender” = ““C:\Program Files\Windows Defender\MSASCui.exe” -hide” [MS] “WinampAgent” = “C:\Program Files\Winamp\winampa.exe” [null data] “ShStatEXE” = ““C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE” /STANDALONE” [“Network Associates, Inc.”] “McAfeeUpdaterUI” = ““C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe” /StartedFromRunKey” [“Network Associates, Inc.”] “Look ‘n’ Stop” = ““C:\Program Files\Soft4Ever\looknstop\looknstop.exe” -auto” [“Soft4Ever”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = “AcroIEHlprObj Class” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {9394EDE7-C8B5-483E-8773-474BF36AF6E4}(Default) = “ST” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll” [MS] {AE7CD045-E861-484f-8273-0445EE161910}(Default) = “AcroIEToolbarHelper Class” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll” [null data] {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}(Default) = “MSNToolBandBHO” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll” [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Display Panning CPL Extension” -> {CLSID}\InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “HyperTerminal Icon Ext” -> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\System32\hticons.dll” [“Hilgraeve, Inc.”] “{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}” = “Shell Extensions for RealOne Player” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Real\RealOne Player\rpshell.dll” [“RealNetworks, Inc.”] “{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Microsoft Office\OFFICE11\msohev.dll” [MS] “{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}” = “Adobe.Acrobat.ContextMenu” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll” [“Adobe Systems Inc.”] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] “{640167b4-59b0-47a6-b335-a6b3c0695aea}” = “Portable Media Devices” -> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\Audiodev.dll” [MS] “{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu” -> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\Audiodev.dll” [MS] “{21569614-B795-46b1-85F4-E737A8DC09AD}” = “Shell Search Band” -> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\browseui.dll” [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ INFECTION WARNING! “{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}” = “Microsoft AntiMalware ShellExecuteHook” -> {CLSID}\InProcServer32(Default) = “C:\PROGRA~1\WINDOW~4\MpShHook.dll” [MS] INFECTION WARNING! “{54D9498B-CF93-414F-8984-8CE7FDE0D391}” = “ewido shell guard” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\ewido anti-malware\shellhook.dll” ["TODO: "] HKLM\Software\Classes\PROTOCOLS\Filter\ INFECTION WARNING! text/xml\CLSID = “{807553E5-5146-11D5-A672-00B0D022E945}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL” [MS] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ Adobe.Acrobat.ContextMenu(Default) = “{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll” [“Adobe Systems Inc.”] ewido(Default) = “{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\ewido anti-malware\context.dll” [“ewido networks”] VirusScan(Default) = “{cda2863e-2497-4c49-9b89-06840e070a87}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Network Associates\VirusScan\shext.dll” [“Network Associates, Inc.”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ ewido(Default) = “{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\ewido anti-malware\context.dll” [“ewido networks”] VirusScan(Default) = “{cda2863e-2497-4c49-9b89-06840e070a87}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Network Associates\VirusScan\shext.dll” [“Network Associates, Inc.”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ VirusScan(Default) = “{cda2863e-2497-4c49-9b89-06840e070a87}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Network Associates\VirusScan\shext.dll” [“Network Associates, Inc.”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] Active Desktop and Wallpaper: ----------------------------- Active Desktop is disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKCU\Control Panel\Desktop\ “Wallpaper” = “C:\DOCUME~1\User\LOCALS~1\APPLIC~1\XEMICO~1\ACTIVE~1\Active Desktop Calendar.bmp” Startup items in “User” & “All Users” startup folders: ------------------------------------------------------ C:\Documents and Settings\User\Start Menu\Programs\Startup “BlueSpace NE” -> shortcut to: “C:\Program Files\Sony\BlueSpace\BlueSpaceNE.exe /hide” [“Sony Corporation”] C:\Documents and Settings\All Users\Start Menu\Programs\Startup “Acrobat Assistant” -> shortcut to: “C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe” [“Adobe Systems Inc.”] “Adobe Gamma Loader” -> shortcut to: “C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe” [“Adobe Systems, Inc.”] “PowerPanel” -> shortcut to: “C:\Program Files\PowerPanel\Program\PcfMgr.exe /launch” [“Phoenix Technologies Ltd.”] “QuickTV” -> shortcut to: “C:\Program Files\AVerTV\QuickTV.exe” [“AVerMedia Technologies, Inc.”] “VPN Client” -> shortcut to: “C:\WINDOWS\Installer{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico -user_logon” [null data] Enabled Scheduled Tasks: ------------------------ “MP Scheduled Scan” -> launches: “C:\Program Files\Windows Defender\MpCmdRun.exe Scan -ScanType config -Privileges restricted” [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000004\LibraryPath = “%SystemRoot%\System32\nwprovau.dll” [MS] 000000000005\LibraryPath = “%SystemRoot%\system32\wshbth.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 35 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\ “{47833539-D0C5-4125-9FA8-0819E2EAAC93}” = “Adobe PDF” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll” [null data] HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ “{47833539-D0C5-4125-9FA8-0819E2EAAC93}” = “Adobe PDF” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll” [null data] “{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}” = “MSN” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll” [MS] HKLM\Software\Microsoft\Internet Explorer\Toolbar\ “{47833539-D0C5-4125-9FA8-0819E2EAAC93}” = “Adobe PDF” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll” [null data] “{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}” = “0” -> {CLSID}\InProcServer32(Default) = “C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll” [MS] Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ {182EC0BE-5110-49C8-A062-BEB1D02A220B}\ = “Adobe PDF” [from CLSID] -> {CLSID}\InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll” [null data] Dormant Explorer Bars in “View, Explorer Bar” menu HKLM\Software\Classes\CLSID{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\ = “&Research” Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL” [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ “ButtonText” = “Research” {FB5F1910-F110-11D2-BB9E-00C04F795683}\ “ButtonText” = “Messenger” “MenuText” = “Windows Messenger” “Exec” = “C:\Program Files\Messenger\msmsgs.exe” [MS] Miscellaneous IE Hijack Points ------------------------------ C:\WINDOWS\INF\IERESET.INF (used to “Reset Web Settings”) Added lines (compared with English-language version): [strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Missing lines (compared with English-language version): [strings]: 1 line Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Ati HotKey Poller, Ati HotKey Poller, “C:\WINDOWS\System32\Ati2evxx.exe” [“ATI Technologies Inc.”] Bluetooth Support Service, BthServ, “C:\WINDOWS\system32\svchost.exe -k bthsvcs” {“C:\WINDOWS\System32\bthserv.dll” [MS]} Cisco Systems, Inc. VPN Service, CVPND, “C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe” [“Cisco Systems, Inc.”] ewido security suite control, ewido security suite control, “C:\Program Files\ewido anti-malware\ewidoctrl.exe” [“ewido networks”] ewido security suite guard, ewido security suite guard, “C:\Program Files\ewido anti-malware\ewidoguard.exe” [“ewido networks”] McAfee Framework Service, McAfeeFramework, “C:\Program Files\Network Associates\Common Framework\FrameworkService.exe /ServiceStart” [“Network Associates, Inc.”] Network Associates McShield, McShield, ““C:\Program Files\Network Associates\VirusScan\mcshield.exe”” [“Network Associates, Inc.”] Network Associates Task Manager, McTaskManager, ““C:\Program Files\Network Associates\VirusScan\vstskmgr.exe”” [“Network Associates, Inc.”] Windows Defender Service, WinDefend, ““C:\Program Files\Windows Defender\MsMpEng.exe”” [MS] Windows User Mode Driver Framework, UMWdf, “C:\WINDOWS\system32\wdfmgr.exe” [MS] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ Adobe PDF Port\Driver = “C:\WINDOWS\System32\AdobePDF.dll” [“Adobe Systems Incorporated.”] CNY SELPHY CP LM1\Driver = “CNYMLM01.DLL” [“CANON INC.”] hpzsnt10\Driver = “hpzsnt10.dll” [“HP”] Microsoft Document Imaging Writer Monitor\Driver = “mdimon.dll” [MS] ---------- + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 117 seconds. + The search for all Registry CLSIDs containing dormant Explorer Bars took 17 seconds. ---------- (total run time: 168 seconds)