Windows Automatic/Silent Runners – Launch & Hijack Points

Launch Points

Here are the registry keys, INI-file sections, files and folders that are checked bySilent Runners and the Operating Systems (OS’s) to which they apply:

 

Item Checked

OS

1.

HKCUControl PanelDesktopSCRNSAVE.EXE

NT4+

2.

HKCUSoftwareClassesCLSID{CLSID}Implemented Categories{00021493-0000-0000-C000-000000000046}
HKCUSoftwareClassesCLSID{CLSID}Implemented Categories{00021494-0000-0000-C000-000000000046}

W2K+

3.

HKCUSoftwareClasses.batshellsubkeycommand
HKCUSoftwareClasses.batshellsubkeyddeexec

W2K+

 

HKCUSoftwareClasses.cmdshellsubkeycommand
HKCUSoftwareClasses.cmdshellsubkeyddeexec

W2K+

 

HKCUSoftwareClasses.comshellsubkeycommand
HKCUSoftwareClasses.comshellsubkeyddeexec

W2K+

 

HKCUSoftwareClasses.exeshellsubkeycommand
HKCUSoftwareClasses.exeshellsubkeyddeexec

W2K+

 

HKCUSoftwareClasses.htashellsubkeycommand
HKCUSoftwareClasses.htashellsubkeyddeexec

W2K+

 

HKCUSoftwareClasses.pifshellsubkeycommand
HKCUSoftwareClasses.pifshellsubkeyddeexec

W2K+

 

HKCUSoftwareClasses.scrshellsubkeycommand
HKCUSoftwareClasses.scrshellsubkeyddeexec

W2K+

 
 
 

HKCUSoftwareClassesbatfileshellsubkeycommand
HKCUSoftwareClassesbatfileshellsubkeyddeexec

W2K+

 

HKCUSoftwareClassescmdfileshellsubkeycommand
HKCUSoftwareClassescmdfileshellsubkeyddeexec

W2K+

 

HKCUSoftwareClassescomfileshellsubkeycommand
HKCUSoftwareClassescomfileshellsubkeyddeexec

W2K+

 

HKCUSoftwareClassesexefileshellsubkeycommand
HKCUSoftwareClassesexefileshellsubkeyddeexec

W2K+

 

HKCUSoftwareClasseshtafileshellsubkeycommand
HKCUSoftwareClasseshtafileshellsubkeyddeexec

W2K+

 

HKCUSoftwareClassespiffileshellsubkeycommand
HKCUSoftwareClassespiffileshellsubkeyddeexec

W2K+

 

HKCUSoftwareClassesscrfileshellsubkeycommand
HKCUSoftwareClassesscrfileshellsubkeyddeexec

W2K+

4.

HKCUSoftwareClasses*shellexColumnHandlers
HKCUSoftwareClasses*shellexContextMenuHandlers
HKCUSoftwareClasses*shellexCopyHookHandlers
HKCUSoftwareClasses*shellexDragDropHandlers
HKCUSoftwareClasses*shellexPropertySheetHandlers
HKCUSoftwareClassesAllFilesystemObjectsshellexColumnHandlers
HKCUSoftwareClassesAllFilesystemObjectsshellexContextMenuHandlers
HKCUSoftwareClassesAllFilesystemObjectsshellexCopyHookHandlers
HKCUSoftwareClassesAllFilesystemObjectsshellexDragDropHandlers
HKCUSoftwareClassesAllFilesystemObjectsshellexPropertySheetHandlers
HKCUSoftwareClassesDirectoryshellexColumnHandlers
HKCUSoftwareClassesDirectoryshellexContextMenuHandlers
HKCUSoftwareClassesDirectoryshellexCopyHookHandlers
HKCUSoftwareClassesDirectoryshellexDragDropHandlers

HKCUSoftwareClassesDirectoryshellexPropertySheetHandlers
HKCUSoftwareClassesDirectoryBackgroundshellexColumnHandlers
HKCUSoftwareClassesDirectoryBackgroundshellexContextMenuHandlers
HKCUSoftwareClassesDirectoryBackgroundshellexCopyHookHandlers
HKCUSoftwareClassesDirectoryBackgroundshellexDragDropHandlers
HKCUSoftwareClassesDirectoryBackgroundshellexPropertySheetHandlers
HKCUSoftwareClassesFoldershellexColumnHandlers
HKCUSoftwareClassesFoldershellexContextMenuHandlers
HKCUSoftwareClassesFoldershellexCopyHookHandlers
HKCUSoftwareClassesFoldershellexDragDropHandlers
HKCUSoftwareClassesFoldershellexPropertySheetHandlers

W2K+

5.

HKCUSoftwareClassesPROTOCOLSFilter

W2K+

6.

HKCUSoftwareClassesPROTOCOLSHandler

W2K+

7.

HKCUSoftwareMicrosoftCommand ProcessorAutoRun

NT4+

8.

HKCUSoftwareMicrosoftInternet ExplorerExplorer Bars

All

9.

HKCUSoftwareMicrosoftInternet ExplorerExtensions

All

10.

HKCUSoftwareWow6432NodeMicrosoftInternet ExplorerExtensions

64b

11.

HKCUSoftwareMicrosoftInternet ExplorerToolbarShellBrowser

All

12.

HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser

All

13.

HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.batApplication
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.cmdApplication
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.comApplication
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.exeApplication
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.htaApplication
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.pifApplication
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.scrApplication

WMe/W2K/WXP

 

HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.batProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.cmdProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.comProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.exeProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.htaProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.pifProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.scrProgid

WXP

 

HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.batUserChoiceProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.cmdUserChoiceProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.comUserChoiceProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.exeUserChoiceProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.htaUserChoiceProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.pifUserChoiceProgid
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerFileExts.scrUserChoiceProgid

WVa+

14.

HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellIconOverlayIdentifiers

W2K+

15.

HKCUSoftwareMicrosoftWindowsCurrentVersionGroup PolicyScripts

WVa+

16.

HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRun

WMe/W2K+

17.

HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRunany subkey

WMe/W2K

18.

HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemShell

W2K+

19.

HKCUSoftwareMicrosoftWindowsCurrentVersionRun

All

20.

HKCUSoftwareMicrosoftWindowsCurrentVersionRunany subkey

W2K

21.

HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnce

All

22.

HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnceany subkey

W2K

23.

HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnceEx

All

24.

HKCUSoftwareMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad

All

25.

HKCUSoftwareMicrosoftWindows NTCurrentVersionAccessibilityConfiguration

WVa+

26.

HKCUSoftwareMicrosoftWindows NTCurrentVersionWindowsload
HKCUSoftwareMicrosoftWindows NTCurrentVersionWindowsrun

NT4/W2K/WXP/WVa

27.

HKCUSoftwareMicrosoftWindows NTCurrentVersionWinlogonShell

NT4+

28.

HKCUSoftwarePoliciesMicrosoftWindowsSystemScripts

W2K/WXP

29.

HKLMSoftwareClassesCLSID{CLSID}Implemented Categories{00021493-0000-0000-C000-000000000046}
HKLMSoftwareClassesCLSID{CLSID}Implemented Categories{00021494-0000-0000-C000-000000000046}

All

30.

HKLMSoftwareClasses.batshellsubkeycommand
HKLMSoftwareClasses.batshellsubkeyddeexec

All

 

HKLMSoftwareClasses.cmdshellsubkeycommand
HKLMSoftwareClasses.cmdshellsubkeyddeexec

NT4+

 

HKLMSoftwareClasses.comshellsubkeycommand
HKLMSoftwareClasses.comshellsubkeyddeexec

All

 

HKLMSoftwareClasses.exeshellsubkeycommand
HKLMSoftwareClasses.exeshellsubkeyddeexec

All

 

HKLMSoftwareClasses.htashellsubkeycommand
HKLMSoftwareClasses.htashellsubkeyddeexec

All

 

HKLMSoftwareClasses.pifshellsubkeycommand
HKLMSoftwareClasses.pifshellsubkeyddeexec

All

 

HKLMSoftwareClasses.scrshellsubkeycommand
HKLMSoftwareClasses.scrshellsubkeyddeexec

All

 
 
 

HKLMSoftwareClassesbatfileshellsubkeycommand
HKLMSoftwareClassesbatfileshellsubkeyddeexec

All

 

HKLMSoftwareClassescmdfileshellsubkeycommand
HKLMSoftwareClassescmdfileshellsubkeyddeexec

NT4+

 

HKLMSoftwareClassescomfileshellsubkeycommand
HKLMSoftwareClassescomfileshellsubkeyddeexec

All

 

HKLMSoftwareClassesexefileshellsubkeycommand
HKLMSoftwareClassesexefileshellsubkeyddeexec

All

 

HKLMSoftwareClasseshtafileshellsubkeycommand
HKLMSoftwareClasseshtafileshellsubkeyddeexec

All

 

HKLMSoftwareClassespiffileshellsubkeycommand
HKLMSoftwareClassespiffileshellsubkeyddeexec

All

 

HKLMSoftwareClassesscrfileshellsubkeycommand
HKLMSoftwareClassesscrfileshellsubkeyddeexec

All

31.

HKLMSoftwareClasses*shellexColumnHandlers
HKLMSoftwareClasses*shellexContextMenuHandlers
HKLMSoftwareClasses*shellexCopyHookHandlers
HKLMSoftwareClasses*shellexDragDropHandlers
HKLMSoftwareClasses*shellexPropertySheetHandlers
HKLMSoftwareClassesAllFilesystemObjectsshellexColumnHandlers
HKLMSoftwareClassesAllFilesystemObjectsshellexContextMenuHandlers
HKLMSoftwareClassesAllFilesystemObjectsshellexCopyHookHandlers
HKLMSoftwareClassesAllFilesystemObjectsshellexDragDropHandlers
HKLMSoftwareClassesAllFilesystemObjectsshellexPropertySheetHandlers
HKLMSoftwareClassesDirectoryshellexColumnHandlers
HKLMSoftwareClassesDirectoryshellexContextMenuHandlers
HKLMSoftwareClassesDirectoryshellexCopyHookHandlers
HKLMSoftwareClassesDirectoryshellexDragDropHandlers
HKLMSoftwareClassesDirectoryshellexPropertySheetHandlers
HKLMSoftwareClassesDirectoryBackgroundshellexColumnHandlers
HKLMSoftwareClassesDirectoryBackgroundshellexContextMenuHandlers
HKLMSoftwareClassesDirectoryBackgroundshellexCopyHookHandlers
HKLMSoftwareClassesDirectoryBackgroundshellexDragDropHandlers
HKLMSoftwareClassesDirectoryBackgroundshellexPropertySheetHandlers
HKLMSoftwareClassesFoldershellexColumnHandlers
HKLMSoftwareClassesFoldershellexContextMenuHandlers
HKLMSoftwareClassesFoldershellexCopyHookHandlers
HKLMSoftwareClassesFoldershellexDragDropHandlers
HKLMSoftwareClassesFoldershellexPropertySheetHandlers

All

32.

HKLMSoftwareWow6432NodeClasses*shellexColumnHandlers
HKLMSoftwareWow6432NodeClasses*shellexContextMenuHandlers
HKLMSoftwareWow6432NodeClasses*shellexCopyHookHandlers
HKLMSoftwareWow6432NodeClasses*shellexDragDropHandlers
HKLMSoftwareWow6432NodeClasses*shellexPropertySheetHandlers
HKLMSoftwareWow6432NodeClassesAllFilesystemObjectsshellexColumnHandlers
HKLMSoftwareWow6432NodeClassesAllFilesystemObjectsshellexContextMenuHandlers
HKLMSoftwareWow6432NodeClassesAllFilesystemObjectsshellexCopyHookHandlers
HKLMSoftwareWow6432NodeClassesAllFilesystemObjectsshellexDragDropHandlers
HKLMSoftwareWow6432NodeClassesAllFilesystemObjectsshellexPropertySheetHandlers
HKLMSoftwareWow6432NodeClassesDirectoryshellexColumnHandlers
HKLMSoftwareWow6432NodeClassesDirectoryshellexContextMenuHandlers
HKLMSoftwareWow6432NodeClassesDirectoryshellexCopyHookHandlers
HKLMSoftwareWow6432NodeClassesDirectoryshellexDragDropHandlers
HKLMSoftwareWow6432NodeClassesDirectoryshellexPropertySheetHandlers
HKLMSoftwareWow6432NodeClassesDirectoryBackgroundshellexColumnHandlers
HKLMSoftwareWow6432NodeClassesDirectoryBackgroundshellexContextMenuHandlers
HKLMSoftwareWow6432NodeClassesDirectoryBackgroundshellexCopyHookHandlers
HKLMSoftwareWow6432NodeClassesDirectoryBackgroundshellexDragDropHandlers
HKLMSoftwareWow6432NodeClassesDirectoryBackgroundshellexPropertySheetHandlers
HKLMSoftwareWow6432NodeClassesFoldershellexColumnHandlers
HKLMSoftwareWow6432NodeClassesFoldershellexContextMenuHandlers
HKLMSoftwareWow6432NodeClassesFoldershellexCopyHookHandlers
HKLMSoftwareWow6432NodeClassesFoldershellexDragDropHandlers
HKLMSoftwareWow6432NodeClassesFoldershellexPropertySheetHandlers

64b

33.

HKLMSoftwareClassesPROTOCOLSFilter

All

34.

HKLMSoftwareClassesPROTOCOLSHandler

All

35.

HKLMSoftwareMicrosoftActive SetupInstalled Components

All

36.

HKLMSoftwareWow6432NodeMicrosoftActive SetupInstalled Components

64b(7)

37.

HKLMSoftwareMicrosoftCommand ProcessorAutoRun

NT4+

38.

HKLMSoftwareWow6432NodeMicrosoftCommand ProcessorAutoRun

64b

39.

HKLMSoftwareMicrosoftInternet ExplorerExplorer Bars

All

40.

HKLMSoftwareWow6432NodeMicrosoftInternet ExplorerExplorer Bars

64b

41.

HKLMSoftwareMicrosoftInternet ExplorerExtensions

All

42.

HKLMSoftwareWow6432NodeMicrosoftInternet ExplorerExtensions

64b

43.

HKLMSoftwareMicrosoftInternet ExplorerToolbar

All

44.

HKLMSoftwareWow6432NodeMicrosoftInternet ExplorerToolbar

64b

45.

HKLMSoftwareMicrosoftWindowsCurrentVersionAuthenticationCredential Provider Filters

WVa+

46.

HKLMSoftwareMicrosoftWindowsCurrentVersionAuthenticationCredential Providers

WVa+

47.

HKLMSoftwareMicrosoftWindowsCurrentVersionAuthenticationPLAP Providers

WVa+

48.

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerAutoplayHandlersHandlers

WXP+

49.

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects

All

50.

HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects

64b

51.

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerDeviceNotificationCallbacks

WVa+

52.

HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionExplorerDeviceNotificationCallbacks

64b

53.

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler

All

54.

HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler

64b

55.

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks

All

56.

HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks

64b

57.

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerShellIconOverlayIdentifiers

All

58.

HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionExplorerShellIconOverlayIdentifiers

64b

59.

HKLMSoftwareMicrosoftWindowsCurrentVersionGroup PolicyScripts

WVa+

60.

HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRun

WMe/W2K+

61.

HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerRunany subkey

WMe/W2K

62.

HKLMSoftwareMicrosoftWindowsCurrentVersionRun

All

63.

HKLMSoftwareMicrosoftWindowsCurrentVersionRunany subkey

W2K

64.

HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVe
rsionRun

64b

65.

HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnce

All

66.

HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnceany subkey

W2K

67.

HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnceSetup

All

68.

HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnceEx

All

69.

HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices

W9x

70.

HKLMSoftwareMicrosoftWindowsCurrentVersionRunServicesOnce

W9x

71.

HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved

All

72.

HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionShell ExtensionsApproved

64b

73.

HKLMSoftwareMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad

All

74.

HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad

64b

75.

HKLMSoftwareMicrosoftWindows NTCurrentVersionAccessibilityConfiguration

WVa+

76.

HKLMSoftwareMicrosoftWindows NTCurrentVersionAccessibilityUtility Manager

W2K (6)

77.

HKLMSoftwareMicrosoftWindows NTCurrentVersionAedebug

NTx

78.

HKLMSoftwareMicrosoftWindows NTCurrentVersionImage File Execution Options

NTx

79.

HKLMSoftwareWow6432NodeMicrosoftWindows NTCurrentVersionImage File Execution Options

64b

80.

HKLMSoftwareMicrosoftWindows NTCurrentVersionInitFileMapping

NT4+

81.

HKLMSoftwareMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs

NT4+

82.

HKLMSoftwareWow6432NodeMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs

64b

83.

HKLMSoftwareWow6432NodeMicrosoftWindows NTCurrentVersionWindowsIconServiceLib

WVa+

84.

HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonGinaDLL
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonShell
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonSystem
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonTaskman
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonUserinit
HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonVmApplet

NT4+

85.

HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonNotify

W2K/WXP

86.

HKLMSoftwarePoliciesMicrosoftWindowsSystemScripts

W2K/WXP

87.

HKLMSystemCurrentControlSetControlSafeBootMinimal
HKLMSystemCurrentControlSetControlSafeBootNetwork

< p>W2K+

88.

HKLMSystemCurrentControlSetControlServiceControlManagerExtension

Wn7

89.

HKLMSystemCurrentControlSetControlBootVerificationProgramImagePath

NT4+

90.

HKLMSystemCurrentControlSetControlClass{4D36E96B-E325-11CE-BFC1-08002BE10318}UpperFilters

W2K+

91.

HKLMSystemCurrentControlSetControlLsaAuthentication Packages
HKLMSystemCurrentControlSetControlLsaNotification Packages
HKLMSystemCurrentControlSetControlLsaSecurity Packages

NT4+

92.

HKLMSystemCurrentControlSetControlPrintMonitors

All

93.

HKLMSystemCurrentControlSetControlSafeBootAlternateShell
HKLMSystemCurrentControlSetControlSafeBootOptionUseAlternateShell

W2K+

94.

HKLMSystemCurrentControlSetControlSecurityProvidersSecurityProviders

All

95.

HKLMSystemCurrentControlSetControlSession ManagerBootExecute
HKLMSystemCurrentControlSetControlSession ManagerExecute
HKLMSystemCurrentControlSetControlSession ManagerSetupExecute

NT4+

96.

HKLMSystemCurrentControlSetControlWOWcmdline
HKLMSystemCurrentControlSetControlWOWwowcmdline

NTx

97.

HKLMSystemCurrentControlSetServices

NT4+

98.

HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries
HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries

All

99.

%WINDIR%WIN.INI [windows] load=, run=

W9x

100.

%WINDIR%SYSTEM.INI [boot] shell=, scrnsave.exe=

W9x

101.

%WINDIR%WINSTART.BAT

W9x (2)

102.

[Local Fixed Disk]AUTORUN.INF open=, shellexecute=

All (3)

103.

[Local Fixed Disk][Any Folder with “S” Attribute]DESKTOP.INI [.ShellClassInfo] CLSID= / UICLSID=

All (1)

104.

%WINDIR%All UsersStart MenuProgramsStartup

W9x

105.

%WINDIR%Start MenuProgramsStartup

W9x

106.

%ALLUSERSPROFILE%Start MenuProgramsStartup

NTx

107.

%USERPROFILE%Start MenuProgramsStartup

NTx

108.

%ALLUSERSPROFILE%MicrosoftWindowsStart MenuProgramsStartup

WVa+

109.

%USERPROFILE%AppDataRoamingMicrosoftWindowsStart MenuProgramsStartup

WVa+

110.

%USERPROFILE%AppDataLocalMicrosoftWindows SidebarSettings.ini

WVa+

111.

%WINDIR%Tasks

W9x/NTx

112.

%WINDIR%System32Tasks

WVa+

Hijack Points

These registry keys and files can be used to redirect the desktop, network and Internet Explorer:

 

Item Checked

O/S

1.

HKCUSoftwareMicrosoftInternet ExplorerDesktopComponents

W9x/NTx

2.

HKCUSoftwareMicrosoftInternet ExplorerMain

All (4)

3.

HKCUSoftwareMicrosoftInternet ExplorerSearchURL

All (4)

4.

HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks

All

5.

HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState

W9x/NTx

6.

HKCUSoftwareMicrosoftWindowsCurrentVersionPolicies

All

7.

HKCUSoftwarePoliciesMicrosoftInternet Explorer

All

8.

HKCUSoftwarePoliciesMicrosoftWindows

All

9.

HKCUSoftwarePoliciesMicrosoftWindowsCurrentVersionInternet Settings

W2K+

10.

HKLMSoftwareMicrosoftInternet ExplorerMain

All (4)

11.

HKLMSoftwareMicrosoftInternet ExplorerSearch

All (4)

12.

HKLMSoftwareMicrosoftInternet ExplorerAboutURLs

All

13.

HKLMSoftwareMicrosoftWindowsCurrentVersionPolicies

All

14.

HKLMSoftwareMicrosoftWindowsCurrentVersionURLDefaultPrefix

All

15.

HKLMSoftwareMicrosoftWindowsCurrentVersionURLPrefixes

All

16.

HKLMSoftwarePoliciesMicrosoftWindows NTSystemRestore

WXP+

17.

HKLMSystemCurrentControlSetServicesTcpipParametersDataBasePath

NT4+

18.

%WINDIR%HOSTS
%WINDIR%System32driversetcHOSTS

W9x
NT4+

19.

%WINDIR%INFIERESET.INF

Note 5

 

W9x:

Windows 95, Windows 98 (Standard Edition), Windows 98 SE (Second Edition), and Windows Me (Millennium Edition)

NTx:

Windows NT 4.0, Windows 2000, and Windows XP

NT4+:

Windows NT 4.0, Windows 2000
, Windows XP, Windows Vista, and Windows 7

W2K+:

Windows 2000, Windows XP, Windows Vista, and Windows 7

WXP:

Windows XP and Windows Server 2003

WXP+:

Windows XP, Windows Vista, and Windows 7

WVa+:

Windows Vista and Windows 7

Wn7:

Windows 7

64b:

Windows XP, Windows Vista and Windows 7 64-bit only

(1):

launch point checked by answering “No” at the script’s first message box and “Yes” at the message box that follows it or with the “-supp” or “-all” command line parameters

(2):

excluding Windows Me

(3):

excluding Windows Me, Windows XP SP2/SP3, Windows Vista, and Windows 7

(4):

not checked by Silent Runners – reset by IERESET.INF (except Windows Vista and Windows 7)

(5):

Internet Explorer 5.01, 5.5 & 6.0 only

(6):

only active if UtilMan service running

(7):

excluding Windows XP 64-bit

 

Source: Silent Runners – Launch & Hijack Points

Leave a Reply

Your email address will not be published. Required fields are marked *