TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: All
from: Geo.
date: 2006-09-08 10:57:16
subject: silent runners script

From: "Geo." 

Hello,

Silent Runners R48 adds a woefully documented launch point:
HKLM\System\CurrentControlSet\Control\SecurityProviders\SecurityProviders
... that is the target of a current infection.

I have confirmed that the comma-separated DLLs listed in this value are
launched during startup.

This value appears in _all_ Windows versions.

I am unaware of *any* anti-spyware program or launch point analyzer that
detects malware launching from this location. I am unaware of
*any* documentation of this registry location as a launch point.

It is recommended that you download Silent Runners R48 and delete earlier versions.

I thank my customer Paul H. for his patience during the disinfection
process. I also thank Phaedrus of Short-Media.com for having identified the
elusive malware critter responsible for the infection:
http://www.short-media.com/forum/showthread.php?t=49709

The updated script (R48) can be found here:
http://www.silentrunners.org/Silent%20Runners.vbs

A zipped version can be found here: http://www.silentrunners.org/Silent%20Runners.zip

Thanks again to those users who have provided feedback for improve- ments.
If you ever have any problem with the script, please let me know. (Please
note the expanded FAQ: http://www.silentrunners.org/sr_faq.html ) To be
removed from this distribution list, please request it via a reply to this
e-mail or use the Contact form on the web site.

regards, Andy

--- BBBS/NT v4.01 Flag-5
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)
SEEN-BY: 633/267 270 5030/786
@PATH: 379/45 1 106/2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.