"Silent Runners.vbs", revision 64,
http://www.silentrunners.org/
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (32-bit)
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe [MS]
MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background [MS]
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [Safer Networking Limited]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
LaunchApp = Alaunch [Acer Inc.]
SoundMan = SOUNDMAN.EXE [Realtek Semiconductor Corp.]
ntiMUI = c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe [null data]
(Default) = (empty string) [file not found]
RemoteControl = "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [Cyberlink Corp.]
IMJPMIG8.1 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 [MS]
MSPY2002 = C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC [null data]
PHIME2002ASync = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC [MS]
PHIME2002A = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName [MS]
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [MS]
nwiz = nwiz.exe /install [NVIDIA Corporation]
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [MS]
eRecoveryService = C:\Acer\Empowering Technology\eRecovery\Monitor.exe [acer Inc.]
WinVNC = "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper [RealVNC Ltd.]
pdfFactory Dispatcher v1 = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis1.exe [FinePrint Software, LLC]
WinampAgent = C:\Program Files\Winamp\winampa.exe [null data]
OrderReminder = C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [Hewlett-Packard]
SunJavaUpdateSched = "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [Sun Microsystems, Inc.]
ApnUpdater = "C:\Program Files\Ask.com\Updater\Updater.exe" [Ask]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM…CLSID} = AcroIEHlprObj Class
\InProcServer32\(Default) = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe Systems Incorporated]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = C:\PROGRA~1\SPYBOT~1\SDHelper.dll [Safer Networking Limited]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
-> {HKLM…CLSID} = Java(tm) Plug-In SSV Helper
\InProcServer32\(Default) = C:\Program Files\Java\jre6\bin\ssv.dll [Sun Microsystems, Inc.]
{D4027C7F-154A-4066-A1AD-4243D8127440}\(Default) = Ask Toolbar BHO
-> {HKLM…CLSID} = Ask Toolbar
\InProcServer32\(Default) = C:\Program Files\Ask.com\GenericAskToolbar.dll [Ask]
{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
-> {HKLM…CLSID} = Java(tm) Plug-In 2 SSV Helper
\InProcServer32\(Default) = C:\Program Files\Java\jre6\bin\jp2ssv.dll [Sun Microsystems, Inc.]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\(Default) = JQSIEStartDetectorImpl
-> {HKLM…CLSID} = JQSIEStartDetectorImpl Class
\InProcServer32\(Default) = C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [Sun Microsystems, Inc.]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
{42071714-76d4-11d1-8b24-00a0c9068ff3} = Rozšíření panelu Zobrazení pro panoramatické zobrazení
-> {HKLM…CLSID} = Rozšíření panelu Zobrazení pro panoramatické zobrazení
\InProcServer32\(Default) = deskpan.dll [file not found]
{88895560-9AA2-1069-930E-00AA0030EBC8} = Rozšíření ikony programu HyperTerminal
-> {HKLM…CLSID} = HyperTerminal Icon Ext
\InProcServer32\(Default) = C:\WINDOWS\system32\hticons.dll [Hilgraeve, Inc.]
{5E6AB780-7743-11CF-A12B-00AA004AE837} = Panel nástrojů Microsoft pro síť Internet
-> {HKLM…CLSID} = Panel nástrojů Microsoft pro síť Internet
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{22BF0C20-6DA7-11D0-B373-00A0C9034938} = Stav stahování
-> {HKLM…CLSID} = Stav stahování
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{91EA3F8B-C99B-11d0-9815-00C04FD91972} = Rozšířená složka prostředí
-> {HKLM…CLSID} = Rozšířená složka prostředí
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{6413BA2C-B461-11d1-A18A-080036B11A03} = Augmented Shell Folder 2
-> {HKLM…CLSID} = Augmented Shell Folder 2
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{F61FFEC1-754F-11d0-80CA-00AA005B4383} = BandProxy
-> {HKLM…CLSID} = BandProxy
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{7BA4C742-9E81-11CF-99D3-00AA004AE837} = Microsoft BrowserBand
-> {HKLM…CLSID} = Microsoft BrowserBand
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{169A0691-8DF9-11d1-A1C4-00C04FD75D13} = Vyhledávat v podokně
-> {HKLM…CLSID} = Vyhledávat v podokně
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{07798131-AF23-11d1-9111-00A0C98BA67D} = Hledání na webu
-> {HKLM…CLSID} = Hledání na webu
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{AF4F6510-F982-11d0-8595-00AA004CD6D8} = Nástroj možností registrového stromu
-> {HKLM…CLSID} = Nástroj možností registrového stromu
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{01E04581-4EEE-11d0-BFE9-00AA005B4383} = &Adresa
-> {HKLM…CLSID} = &Adresa
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{A08C11D2-A228-11d0-825B-00AA005B4383} = Textové pole adresy
-> {HKLM…CLSID} = Textové pole adresy
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{00BB2763-6A77-11D0-A535-00C04FD7D062} = Automatické dokončování Microsoft
-> {HKLM…CLSID} = Automatické dokončování Microsoft
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{7376D660-C583-11d0-A3A5-00C04FD706EC} = TridentImageExtractor
-> {HKLM…CLSID} = TridentImageExtractor
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{6756A641-DE71-11d0-831B-00AA005B4383} = Automaticky dokončovaný seznam MRU
-> {HKLM…CLSID} = Automaticky dokončovaný seznam MRU
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} = Custom MRU AutoCompleted List
-> {HKLM…CLSID} = Custom MRU AutoCompleted List
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{7e653215-fa25-46bd-a339-34a2790f3cb7} = Přístupný
-> {HKLM…CLSID} = Přístupný
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{acf35015-526e-4230-9596-becbe19f0ac9} = Track Popup Bar
-> {HKLM…CLSID} = Track Popup Bar
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{00BB2764-6A77-11D0-A535-00C04FD7D062} = Automaticky dokončovaný seznam historie
-> {HKLM…CLSID} = Automaticky dokončovaný seznam historie
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{03C036F1-A186-11D0-824A-00AA005B4383} = Automaticky se doplňující seznam složky prostředí společnosti Microsoft
-> {HKLM…CLSID} = Automaticky se doplňující seznam složky prostředí společnosti Microsoft
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{00BB2765-6A77-11D0-A535-00C04FD7D062} = Kontejner automatického dokončování více seznamů
-> {HKLM…CLSID} = Kontejner automatického dokončování více seznamů
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{ECD4FC4E-521C-11D0-B792-00A0C90312E1} = Nabídka serveru pruhu prostředí
-> {HKLM…CLSID} = Nabídka serveru pruhu prostředí
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} = Panel plochy aplikací prostředí
-> {HKLM…CLSID} = Panel plochy aplikací prostředí
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{ECD4FC4C-521C-11D0-B792-00A0C90312E1} = Panel plochy prostředí
-> {HKLM…CLSID} = Panel plochy prostředí
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{ECD4FC4D-521C-11D0-B792-00A0C90312E1} = Shell Rebar BandSite
-> {HKLM…CLSID} = Shell Rebar BandSite
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{DD313E04-FEFF-11d1-8ECD-0000F87A470C} = Asistence uživatele
-> {HKLM…CLSID} = Asistence uživatele
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} = Globální nastavení složek
-> {HKLM…CLSID} = Globální nastavení složek
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{A70C977A-BF00-412C-90B7-034C51DA2439} = NvCpl DesktopContext Class
-> {HKLM…CLSID} = DesktopContext Class
\InProcServer32\(Default) = C:\WINDOWS\system32\nvcpl.dll [NVIDIA Corporation]
{FFB699E0-306A-11d3-8BD1-00104B6F7516} = Play on my TV helper
-> {HKLM…CLSID} = NVIDIA CPL Extension
\InProcServer32\(Default) = C:\WINDOWS\system32\nvcpl.dll [NVIDIA Corporation]
{1CDB2949-8F65-4355-8456-263E7C208A5D} = Desktop Explorer
-> {HKLM…CLSID} = Desktop Explorer
\InProcServer32\(Default) = C:\WINDOWS\system32\nvshell.dll [NVIDIA Corporation]
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} = Desktop Explorer Menu
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = C:\WINDOWS\system32\nvshell.dll [NVIDIA Corporation]
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} = nView Desktop Context Menu
-> {HKLM…CLSID} = nView Desktop Context Menu
\InProcServer32\(Default) = C:\WINDOWS\system32\nvshell.dll [NVIDIA Corporation]
{21569614-B795-46b1-85F4-E737A8DC09AD} = Shell Search Band
-> {HKLM…CLSID} = Shell Search Band
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = WinRAR shell extension
-> {HKLM…CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [null data]
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} = OpenOffice.org Column Handler
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" [Sun Microsystems, Inc.]
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} = OpenOffice.org Infotip Handler
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" [Sun Microsystems, Inc.]
{63542C48-9552-494A-84F7-73AA6A7C99C1} = OpenOffice.org Property Sheet Handler
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" [Sun Microsystems, Inc.]
{3B092F0C-7696-40E3-A80F-68D74DA84210} = OpenOffice.org Thumbnail Viewer
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" [Sun Microsystems, Inc.]
{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} = Microsoft Office OneNote Namespace Extension for Windows Desktop Search
-> {HKLM…CLSID} = Microsoft Office OneNote Namespace Extension for Windows Desktop Search
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL [MS]
{42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office12\msohevi.dll [MS]
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler
-> {HKLM…CLSID} = Microsoft Office Metadata Handler
\InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll [MS]
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Office Thumbnail Handler
-> {HKLM…CLSID} = Microsoft Office Thumbnail Handler
\InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
<<!>> {438755C2-A8BA-11D1-B96B-00A0C90312E1} = Browseui preloader
-> {HKLM…CLSID} = Browseui preloader
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
<<!>> {8C7461EF-2B13-11d2-BE35-3078302C2030} = Proces mezipaměti kategorií součástí
-> {HKLM…CLSID} = Proces mezipaměti kategorií součástí
\InProcServer32\(Default) = C:\WINDOWS\system32\browseui.dll [Společnost Microsoft]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
WPDShServiceObj = {AAA288BA-9A4C-45B0-95D7-94D524869DB5}
-> {HKLM…CLSID} = WPDShServiceObj Class
\InProcServer32\(Default) = C:\WINDOWS\system32\WPDShServiceObj.dll [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = {807563E5-5146-11D5-A672-00B0D022E945}
-> {HKLM…CLSID} = Microsoft Office InfoPath XML Mime Filter
\InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\
<<!>> ms-help\CLSID = {314111c7-a502-11d2-bbca-00c04f8ec294}
-> {HKLM…CLSID} = HxProtocol Class
\InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll [MS]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
-> {HKLM…CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [null data]
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
-> {HKLM…CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [null data]
HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\
WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
-> {HKLM…CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [null data]
HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\
00nView\(Default) = {1E9B04FB-F9E5-4718-997B-B8DA88302A48}
-> {HKLM…CLSID} = nView Desktop Context Menu
\InProcServer32\(Default) = C:\WINDOWS\system32\nvshell.dll [NVIDIA Corporation]
NvCplDesktopContext\(Default) = {A70C977A-BF00-412C-90B7-034C51DA2439}
-> {HKLM…CLSID} = DesktopContext Class
\InProcServer32\(Default) = C:\WINDOWS\system32\nvcpl.dll [NVIDIA Corporation]
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = OpenOffice.org Column Handler
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\OpenOffice.org 2.0\program\shlxthdl.dll" [Sun Microsystems, Inc.]
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = PDF Column Info
-> {HKLM…CLSID} = PDF Shell Extension
\InProcServer32\(Default) = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll [Adobe Systems, Inc.]
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
-> {HKLM…CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [null data]
HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
-> {HKLM…CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [null data]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
Wallpaper = F:\obrázky táta\2009-07-06 dovolená 2009\dovolená 2009 184.JPG
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
Wallpaper = C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
Windows Portable Device AutoPlay Handlers
-----------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
MSWPDShellNamespaceHandler\
Provider = @%SystemRoot%\System32\WPDShextRes.dll,-501
CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24}
InitCmdLine =
-> {HKLM…CLSID} = WPDShextAutoplay
\LocalServer32\(Default) = C:\WINDOWS\system32\WPDShextAutoplay.exe [MS]
NTIBurner\
Provider = NTI CD-Maker
InvokeProgID = NTIBurnerOpen
InvokeVerb = open
HKLM\SOFTWARE\Classes\NTIBurnerOpen\shell\open\command\(Default) = "c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\Cdmkr32.exe" [NewTech Infosystems, Inc.]
PDVDPlayCDAudioOnArrival\
Provider = PowerDVD
InvokeProgID = AudioCD
InvokeVerb = PlayWithPowerDVD
HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPowerDVD\Command\(Default) = "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%L" [CyberLink Corp.]
PDVDPlayDVDMovieOnArrival\
Provider = PowerDVD
InvokeProgID = DVD
InvokeVerb = PlayWithPowerDVD
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerDVD\Command\(Default) = "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%l" [CyberLink Corp.]
PDVDPlayVCDMovieOnArrival\
Provider = PowerDVD
InvokeProgID = VCD
InvokeVerb = PlayWithPowerDVD
HKLM\SOFTWARE\Classes\VCD\shell\PlayWithPowerDVD\Command\(Default) = "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%l" [CyberLink Corp.]
Startup items in "uzivatel" & "All Users" startup folders:
----------------------------------------------------------
C:\Documents and Settings\uzivatel\Nabídka Start\Programy\Po spuštění
OpenOffice.org 2.0 -> shortcut to: C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [null data]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch -> shortcut to: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [Adobe Systems Incorporated]
Wireless Utility -> shortcut to: C:\Program Files\EDIMAX\Common\RaUI.exe -s [Edimax Technology Co.]
Enabled Scheduled Tasks:
------------------------
Scheduled Update for Ask Toolbar -> launches: C:\Program Files\Ask.com\UpdateTask.exe [null data]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]
000000000002\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS]
000000000003\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]
Transport Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 04, 07 - 14
%SystemRoot%\system32\rsvpsp.dll [MS], 05 - 06
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
{D4027C7F-154A-4066-A1AD-4243D8127440}
-> {HKLM…CLSID} = Ask Toolbar
\InProcServer32\(Default) = C:\Program Files\Ask.com\GenericAskToolbar.dll [Ask]
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
{D4027C7F-154A-4066-A1AD-4243D8127440} = (no title provided)
-> {HKLM…CLSID} = Ask Toolbar
\InProcServer32\(Default) = C:\Program Files\Ask.com\GenericAskToolbar.dll [Ask]
Explorer Bars
HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = &Zdroje informací
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{2670000A-7350-4F3C-8081-5663EE0C6C49}\
ButtonText = Odeslat do aplikace OneNote
MenuText = Od&eslat do aplikace OneNote
CLSIDExtension = {48E73304-E1D6-4330-914C-F5F514E3486C}
-> {HKLM…CLSID} = Send to OneNote from Internet Explorer button
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll [MS]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
ButtonText = Research
{E2E2DD38-D088-4134-82B7-F2BA38496583}\
MenuText = @xpsp3res.dll,-20001
Exec = %windir%\Network Diagnostic\xpnetdiag.exe [MS]
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
ButtonText = Messenger
MenuText = Windows Messenger
Exec = C:\Program Files\Messenger\msmsgs.exe [MS]
Miscellaneous IE Hijack Points
------------------------------
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
<<H>> {00000000-6E41-4FD3-8538-502F5495E5FC} = ∀`ƈ`?ţ
-> {HKLM…CLSID} = UrlSearchHook Class
\InProcServer32\(Default) = C:\Program Files\Ask.com\GenericAskToolbar.dll [Ask]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
Adaptér výkonu služby WMI, WmiApSrv, C:\WINDOWS\system32\wbem\wmiapsrv.exe [MS]
Java Quick Starter, JavaQuickStarterService, "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" [Sun Microsystems, Inc.]
NVIDIA Display Driver Service, NVSvc, C:\WINDOWS\system32\nvsvc32.exe [NVIDIA Corporation]
Ralink Registry Writer, RalinkRegistryWriter, C:\Program Files\EDIMAX\Common\RalinkRegistryWriter.exe [Ralink Technology, Corp.]
TeamViewer 7, TeamViewer7, C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe [TeamViewer GmbH]
VNC Server, winvnc, "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -service [RealVNC Ltd.]
Safe Mode Drivers & Services (subkey name, subkey default value):
-----------------------------------------------------------------
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\
<<!>> {1a3e09be-1e45-494b-9174-d7385b45bbf5},
Print Monitors:
---------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
FPP1:\Driver = fppmon1.dll [FinePrint Software, LLC]
HPLJ1018LM\Driver = ZLhp1018.DLL [Zenographics, Inc.]
Microsoft Shared Fax Monitor\Driver = FXSMON.DLL [MS]
Send To Microsoft OneNote Monitor\Driver = msonpmon.dll [MS]
---------- (launch time: 2012-05-04 21:22:39)
<<!>>: Suspicious data at a malware launch point.
<<H>>: Suspicious data at a browser hijack point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 46 seconds, including 18 seconds for message boxes)