nvm:
"Silent Runners.vbs", revision 35,
http://www.silentrunners.org/Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"MSMSGS" = ""C:\Programmer\Messenger\msmsgs.exe" /background" [MS]
"WhatPulse" = "D:\Whatpulse\WhatPulse.exe" [null data]
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"HTpatch" = "C:\WINDOWS\htpatch.exe" [null data]
"NeroCheck" = "C:\WINDOWS\System32\\NeroCheck.exe" ["Ahead Software Gmbh"]
"VOBRegCheck" = "C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg" [null data]
"Zone Labs Client" = "C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe" ["Zone Labs Inc."]
"QuickTime Task" = ""C:\Programmer\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"SunJavaUpdateSched" = "C:\Programmer\Java\j2re1.4.2_06\bin\jusched.exe" [null data]
"iTunesHelper" = "C:\Programmer\iTunes\iTunesHelper.exe" ["Apple Computer, Inc."]
"KernelFaultCheck" = "C:\WINDOWS\system32\dumprep 0 -k" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7695ECA05670}\(Default) = "Yahoo! Companion BHO" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
{45AD732C-2CE2-4666-B366-B2214AD57A49}\(Default) = "Idea2 SidebarBrowserMonitor Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Desktop Sidebar\sbhelp.dll" ["Idea2"]
{9394EDE7-C8B5-483E-8773-474BF36AF6E4}\(Default) = "ST" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll" [MS]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = "Google Toolbar Helper" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\programmer\google\googletoolbar1.dll" ["Google Inc."]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = "MSNToolBandBHO" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Kontrolpanel-udvidelse til skærmpanorering"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal-ikon"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{F5D92341-0A64-11D0-9956-0000E8096023}" = "CD Copy Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Shellext\CDWshext.dll" ["VoB Computersysteme GmbH"]
"{F5D92342-0A64-11D0-9956-0000E8096023}" = "CD Wizard Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Shellext\CDWshext.dll" ["VoB Computersysteme GmbH"]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Microsoft Office\Office10\msohev.dll" [MS]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Universal Plug and Play-enheder"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\upnpui.dll" [MS]
"{FED7043D-346A-414D-ACD7-550D052499A7}" = "dBpowerAMP Music Converter 1"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Illustrate\dBpowerAMP\dBShell.dll" [empty string]
"{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5}" = "dBpowerAMP Music Converter"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Illustrate\dBpowerAMP\dMCShell.dll" [empty string]
"{661825E5-B9A4-4D3E-8B74-3B6B63C32A80}" = "Shell Extensions for The Font Creator Program"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\HIGH-L~1\FONTCR~1\FCPSHL.dll" ["High-Logic"]
"{F2185E5D-720E-4956-90D9-75F6AC141575}" = "Idea2 SidebarIconHandler Class"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Desktop Sidebar\sbhelp.dll" ["Idea2"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{21B68731-364D-4C15-A56E-24CBB6D01D52}" = "World Wide Web"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\WWWTBar.dll" [empty string]
"{330417E8-EF62-4047-82BE-D8305CEFF572}" = "AMEncShlExt extension"
-> {CLSID}\InProcServer32\(Default) = "D:\PROGRA~2\ALTWAV~1\amshellext.dll" ["4Musics, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\WinRAR\rarext.dll" [null data]
"{2F5AC606-70CF-461C-BFE1-734234536262}" = "WindowBlinds CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "D:\PROGRA~2\Stardock\OBJECT~1\WINDOW~1\wbui.dll" ["Stardock.Net, Inc"]
"{DCA04635-8950-48D5-8404-35A5ADCE3E3B}" = "Google Deskbar"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Google\deskbar-0.5.95.0\ggtaskbar.dll" ["Google"]
"{B8323370-FF27-11D2-97B6-204C4F4F5020}" = "SmartFTP Shell Extension DLL"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\SmartFTP\smarthook.dll" ["SmartFTP"]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"0aMCPClient" = "{F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Common Files\Stardock\MCPCore.dll" ["Stardock"]
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
INFECTION WARNING! "AppInit_DLLs" = "4APPINITSOFTWARE\Microsoft\Windows NT\CurrentVersion\WindowsAppInit_DLLs,wbsys.dll" [file not found]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
INFECTION WARNING! WB\DLLName = "D:\PROGRA~2\Stardock\OBJECT~1\WINDOW~1\fastload.dll" ["Stardock"]
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
Enabled Wallpaper and Active Desktop:
-------------------------------------
Active Desktop is enabled.
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\Firefox Wallpaper.bmp"
Startup items in "Christian" & "All Users" startup folders:
-----------------------------------------------------------
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start
"Monitor Apache Servers" -> shortcut to: "C:\Jelly Homepage\Apache and stuff\Apache\Apache2\bin\ApacheMonitor.exe" ["Apache Software Foundation"]
Enabled Scheduled Tasks:
------------------------
"A2232A939174D3B7" -> launches: "c:\docume~1\lisbeth\applic~1\option~1\settings safe debug.exe" [null data]
"A4D9E4FC91BE99B8" -> launches: "c:\progra~1\option~1\settings safe debug.exe" [file not found]
"AD738133918034F7" -> launches: "c:\progra~1\option~1\settings safe debug.exe" [file not found]
"AE366031918A1135" -> launches: "c:\docume~1\malene\applic~1\option~1\settings safe debug.exe" [null data]
"AF4E39DF9181AB5F" -> launches: "c:\docume~1\christ~1\applic~1\option~1\settings safe debug.exe" [null data]
"SDMsgUpdate (SmartDrawTrial)" -> launches: "C:\PROGRA~1\SMARTD~1\Messages\SDNotify.exe -PSmartDrawTrial -V7 -SSDN.ini -A -T -N -L -X" [empty string]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {CLSID}\(Default) = "&Google"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\googlenav.dll" ["Google Inc."]
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {CLSID}\(Default) = "&Google"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\googlenav.dll" ["Google Inc."]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
-> {CLSID}\(Default) = "MSN"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll" [MS]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
-> {CLSID}\(Default) = "Yahoo! Companion"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll" ["Yahoo! Inc."]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {CLSID}\(Default) = "&Google"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\googlenav.dll" ["Google Inc."]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
-> {CLSID}\(Default) = "MSN"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll" [MS]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
-> {CLSID}\(Default) = "Yahoo! Companion"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll" ["Yahoo! Inc."]
Dormant Explorer Bars in "View, Explorer Bar" menu
HKLM\Software\Classes\CLSID\{0494D0DE-F8E0-41AD-92A3-14154ECE70AC}\
(Default) = "My Search Bar Quick View"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\WINDOWS\System32\shdocvw.dll" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKCU\Software\Microsoft\Internet Explorer\Extensions\
{1BA9CB25-1DCD-4015-A2E0-F8563B58CAA0}\
"ButtonText" = "Microsoft® JavaScript® Console"
"MenuText" = "JavaScript Console"
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{09FE188B-6E85-479E-9411-51FB2220DF80}\
"ButtonText" = "Subscribe in Desktop Sidebar"
"MenuText" = "Subscribe in Desktop Sidebar"
"CLSIDExtension" = "{45AD732C-2CE2-4666-B366-B2214AD57A49}"
-> {CLSID}\InProcServer32\(Default) = "C:\Programmer\Desktop Sidebar\sbhelp.dll" ["Idea2"]
{1BA9CB25-1DCD-4015-A2E0-F8563B58CAA0}\
"ButtonText" = "Microsoft® JavaScript® Console"
"MenuText" = "JavaScript Console"
{B863453A-26C3-4E1F-A54D-A2CD196348E9}\
"ButtonText" = "ICQ Lite"
"MenuText" = "ICQ Lite"
"Exec" = "C:\Icq/\ICQLite.exe" ["ICQ Ltd."]
{DCECF0D2-6316-4D64-9405-917EDC8418AB}\
"ButtonText" = "Microsoft® JavaScript® Console"
"MenuText" = "JavaScript Console"
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Programmer\Messenger\msmsgs.exe" [MS]
HOSTS file
----------
C:\WINDOWS\system32\Drivers\Etc\HOSTS
maps: 23 domain names to IP addresses,
22 of the IP addresses are *not* localhost!
All Non-Disabled Services (Display Name, Service Name, Path {Service DLL}):
---------------------------------------------------------------------------
Alias Maya 5.0 PLE Help Server, Maya5PLEHelpServer, ""C:\Programmer\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe" -s "C:\Programmer\AliasWavefront\Maya 5.0 Personal Learning Edition\docs/Wrapper.conf"" [null data]
Apache2, Apache2, ""C:\Jelly Homepage\Apache and stuff\Apache\Apache2\bin\Apache.exe" -k runservice" ["Apache Software Foundation"]
ASP.NET State Service, aspnet_state, "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe" [MS]
Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\System32\Ati2evxx.exe" ["ATI Technologies Inc."]
ATI Smart, ATI Smart, "C:\WINDOWS\system32\ati2sgag.exe" [empty string]
Autodesk Licensing Service, Autodesk Licensing Service, ""C:\Programmer\Fælles filer\Autodesk Shared\Service\AdskScSrv.exe"" [null data]
AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe" ["GRISOFT, s.r.o."]
AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe" ["GRISOFT, s.r.o."]
ColdFusion MX 7 Application Server, ColdFusion MX 7 Application Server, ""C:\CFusionMX7\runtime\bin\jrunsvc.exe"" ["Macromedia Inc."]
ColdFusion MX 7 Search Server, ColdFusion MX 7 Search Server, ""C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe" -cfg "C:\CFusionMX7\verity\k2\common\verity.cfg" -ntstart 1" ["Verity, Inc."]
Fax, Fax, "C:\WINDOWS\system32\fxssvc.exe" [MS]
HTTP SSL, HTTPFilter, "C:\WINDOWS\System32\svchost.exe -k HTTPFilter" {"C:\WINDOWS\System32\w3ssl.dll" [MS]}
iPod Service, iPodService, "C:\Programmer\iPod\bin\iPodService.exe" ["Apple Computer, Inc."]
Logical Disk Manager Administrative Service, dmadmin, "C:\WINDOWS\System32\dmadmin.exe /com" ["Microsoft Corp., Veritas Software"]
Machine Debug Manager, MDM, ""C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe"" [MS]
Macromedia Licensing Service, Macromedia Licensing Service, ""C:\Programmer\Fælles filer\Macromedia Shared\Service\Macromedia Licensing.exe"" [null data]
MySQL, MySQL, ""C:\Programmer\MySQL\MySQL Server 4.1\bin\mysqld-nt" --defaults-file="C:\Programmer\MySQL\MySQL Server 4.1\my.ini" MySQL" [null data]
Programadministration, AppMgmt, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\appmgmts.dll" [file not found]}
Serienummertjenesten for bærbart medie, WmdmPmSN, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\mspmsnsv.dll" [MS]}
StyleXPService, StyleXPService, ""C:\Programmer\TGTSoft\StyleXP\StyleXPService.exe"" [empty string]
Tjenesten Netværksadgang, xmlprov, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\xmlprov.dll" [MS]}
Tjenesten RIP Listener, Iprip, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\iprip.dll" [MS]}
Tjenesten Simple TCP/IP Services, SimpTcp, "C:\WINDOWS\System32\tcpsvcs.exe" [MS]
TrueVector Internet Monitor, vsmon, "C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service" ["Zone Labs Inc."]
WMI-ydelseskort, WmiApSrv, "C:\WINDOWS\System32\wbem\wmiapsrv.exe" [MS]
X10 Device Network Service, x10nets, "C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe" ["X10"]
----------
This report excludes default entries except where indicated.
To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
----------