Blacklight:
09/24/05 21:58:31 [Info]: BlackLight Engine 1.0.23 initialized
09/24/05 21:58:31 [Info]: OS: 5.1 build 3590 (Service Pack 1)
09/24/05 21:58:31 [Note]: 4019 0
09/24/05 21:58:31 [Note]: 4019 1
09/24/05 21:58:31 [Note]: 4019 2
09/24/05 21:58:32 [Note]: 4019 3
09/24/05 21:58:32 [Note]: 4019 4
09/24/05 21:58:32 [Note]: 4005 0
09/24/05 21:58:44 [Note]: 4006 0
09/24/05 21:58:44 [Note]: 4019 5
09/24/05 21:58:44 [Note]: 4019 6
09/24/05 21:58:44 [Note]: 4019 7
09/24/05 21:58:44 [Note]: 4019 8
09/24/05 21:58:45 [Note]: 4019 9
09/24/05 21:58:45 [Note]: 4019 10
09/24/05 21:58:45 [Note]: 4019 11
09/24/05 21:58:45 [Note]: 4019 12
09/24/05 21:58:45 [Note]: 4019 13
09/24/05 21:58:47 [Note]: 4018 1052
09/24/05 21:58:47 [Info]: Hidden process: C:\WINDOWS\Explorer.EXE
09/24/05 21:58:47 [Note]: FSRAW library version 1.7.1011
09/24/05 21:59:44 [Info]: Hidden file: C:\WINDOWS\system32\p3.ini
09/24/05 21:59:44 [Note]: 10002 1
09/24/05 21:59:46 [Info]: Hidden file: C:\WINDOWS\system32\klogini.dll
09/24/05 21:59:46 [Note]: 10002 1
09/24/05 21:59:47 [Info]: Hidden file: C:\WINDOWS\system32\avpu32.dll
09/24/05 21:59:47 [Note]: 10002 1
09/24/05 21:59:47 [Info]: Hidden file: C:\WINDOWS\system32\avpu32.sys
09/24/05 21:59:47 [Note]: 10002 1
09/24/05 21:59:47 [Info]: Hidden file: C:\WINDOWS\system32\avpu64.sys
09/24/05 21:59:47 [Note]: 10002 1
09/24/05 21:59:54 [Info]: Hidden file: C:\WINDOWS\system32\qy.sys
09/24/05 21:59:54 [Note]: 10002 1
09/24/05 21:59:55 [Info]: Hidden file: C:\WINDOWS\system32\qz.dll
09/24/05 21:59:55 [Note]: 10002 1
09/24/05 21:59:55 [Info]: Hidden file: C:\WINDOWS\system32\qz.sys
09/24/05 21:59:55 [Note]: 10002 1
09/24/05 22:02:23 [Note]: 4007 0
Find-T: Eksisterer ikke
"Silent Runners.vbs", revision 40.1,
http://www.silentrunners.org/Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ArGoSoftMailServer" = "C:\Program Files\ArGo Software Design\Mail Server\mlsrv.exe" ["ArGo Software Design"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{4648F940-EFE3-4BAB-9211-3BE45CD5029D}" = "VSSShellExt"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\vssui.dll" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: <Firmenname>"]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! avpu32\DLLName = "avpu32.dll" [** WMI GetObject error **]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 11
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
ArGoSoft Mail Server, msServerForm, "C:\Program Files\ArGo Software Design\Mail Server\mlsrvnt.exe" ["ArGo Software Design"]
ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"]
ewido security suite guard, ewido security suite guard, "C:\Program Files\ewido\security suite\ewidoguard.exe" ["ewido networks"]
License Logging, LicenseService, "C:\WINDOWS\System32\llssrv.exe" [MS]
SSL for World Wide Web Publishing, W3SSL, "C:\WINDOWS\System32\lsass.exe" [MS]
VNC Server Version 4, WinVNC4, ""C:\Program Files\RealVNC\VNC4\winvnc4.exe" -service" ["RealVNC Ltd."]
WebTool, WebTool, "C:\PROGRA~1\MICROS~2\webtool.exe" [MS]
World Wide Web Publishing, W3SVC, "C:\WINDOWS\System32\svchost.exe -k iissvcs" {"C:\WINDOWS\System32\inetsrv\iisw3adm.dll" [MS]}
----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
use the -supp parameter or answer "No" at the first message box.
---------- (total run time: 150 seconds, including 18 seconds for message boxes)
Option^explicit: Eksisterer ikke