"Silent Runners.vbs", revision 61,
http://www.silentrunners.org/
Operating System: Windows XP SP3
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = ""C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"" ["Nero AG"]
"DAEMON Tools Lite" = ""C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun" ["DT Soft Ltd"]
"Google Update" = ""C:\Documents and Settings\Marek\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c" ["Google Inc."]
"LDM" = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" ["Logitech"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"CnxDslTaskBar" = ""C:\Program Files\Microcom\ADSL DeskPorte USB\CnxDslTb.exe" "Microcom\ADSL DeskPorte USB"" ["Conexant Systems, Inc."]
"Kernel and Hardware Abstraction Layer" = "KHALMNPR.EXE" ["Logitech, Inc."]
"Adobe Reader Speed Launcher" = ""C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"" ["Adobe Systems Incorporated"]
"Adobe ARM" = ""C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"" ["Adobe Systems Incorporated"]
"StartCCC" = ""C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"" [null data]
"avgnt" = ""C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min" ["Avira GmbH"]
"SunJavaUpdateSched" = ""C:\Program Files\Common Files\Java\Java Update\jusched.exe"" ["Sun Microsystems, Inc."]
"NokiaMServer" = "C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup" ["Nokia"]
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\
>{26923b43-4d38-484f-9b9e-de460746276c}\(Default) = "Internet Explorer"
\StubPath = "C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig" [MS]
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"
\StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Easy Photo Print"
\InProcServer32\(Default) = "C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll" ["SEIKO EPSON CORPORATION / CyCom Technology Corp."]
{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Java(tm) Plug-In 2 SSV Helper"
\InProcServer32\(Default) = "C:\Program Files\Java\jre6\bin\jp2ssv.dll" ["Sun Microsystems, Inc."]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\(Default) = "JQSIEStartDetectorImpl"
-> {HKLM...CLSID} = "JQSIEStartDetectorImpl Class"
\InProcServer32\(Default) = "C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll" ["Sun Microsystems, Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM...CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{EFA24E62-B078-11d0-89E4-00C04FC9E26E}" = "History Band"
-> {HKLM...CLSID} = "History Band"
\InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
"{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
-> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]
"{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
-> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL" [MS]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {HKLM...CLSID} = "Microsoft Office Outlook"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]
"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"
-> {HKLM...CLSID} = "Microsoft Office Metadata Handler"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"
-> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
"{A5110426-177D-4e08-AB3F-785F10B4439C}" = "Sony Ericsson File Manager"
-> {HKLM...CLSID} = "Sony Ericsson File Manager"
\InProcServer32\(Default) = "C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrgui.dll" ["Sony Ericsson Mobile Communications AB"]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
-> {HKLM...CLSID} = "iTunes"
\InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]
"{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"
-> {HKLM...CLSID} = "SimpleShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll" [null data]
"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
\InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir Desktop\shlext.dll" ["Avira GmbH"]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\wpdshserviceobj.dll" [MS]
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\
<<!>> "BootExecute" = "autocheck autochk *"|"lsdelete" [null data]
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\
<<!>> bw+0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw+0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw-0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw-0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw00\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw00s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw10\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw10s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw20\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw20s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw30\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw30s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw40\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw40s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw50\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw50s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw60\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw60s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw70\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw70s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw80\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw80s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw90\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bw90s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwa0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwa0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwb0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwb0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwc0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwc0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwd0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwd0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwe0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwe0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwf0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwf0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwfile-8876480\CLSID = "{9462A756-7B47-47BC-8C80-C34B9B80B32B}"
-> {HKLM...CLSID} = "BackWeb GA Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwg0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwg0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwh0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwh0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwi0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwi0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwj0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwj0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwk0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwk0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwl0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwl0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwm0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwm0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwn0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwn0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwo0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwo0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwp0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwp0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwq0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwq0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwr0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwr0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bws0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bws0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwt0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwt0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwu0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwu0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwv0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwv0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bww0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bww0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwx0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwx0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwy0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwy0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwz0\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> bwz0s\CLSID = "{cd7e0184-bd4a-4e3a-9713-7764acbe7b00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> ms-help\CLSID = "{314111c7-a502-11d2-bbca-00c04f8ec294}"
-> {HKLM...CLSID} = "HxProtocol Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll" [MS]
<<!>> offline-8876480\CLSID = "{CD7E0184-BD4A-4E3A-9713-7764ACBE7B00}"
-> {HKLM...CLSID} = "BackWeb Proactive Portal Pluggable Protocol"
\InProcServer32\(Default) = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll" ["BackWeb Technologies Inc. "]
<<!>> skype4com\CLSID = "{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D}"
-> {HKLM...CLSID} = "IEProtocolHandler Class"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL" ["Skype Technologies"]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
EPP\(Default) = "{3F3B81BE-529B-40b9-8189-6666B241ADFA}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Epson Software\Easy Photo Print\EPPShell.dll" ["SEIKO EPSON CORPORATION"]
LavasoftShellExt\(Default) = "{DCE027F7-16A4-4BEE-9BE7-74F80EE3738F}"
-> {HKLM...CLSID} = "Lavasoft Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll" [null data]
Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
\InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir Desktop\shlext.dll" ["Avira GmbH"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}\(Default) = (no title provided)
-> {HKLM...CLSID} = "NBShellHook Class"
\InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll" ["Nero AG"]
HKLM\SOFTWARE\Classes\*\shellex\DragDropHandlers\
NBShellHook\(Default) = "{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}"
-> {HKLM...CLSID} = "NBShellHook Class"
\InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll" ["Nero AG"]
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\
A5110426-177D-4e08-AB3F-785F10B4439C\(Default) = "{A5110426-177D-4e08-AB3F-785F10B4439C}"
-> {HKLM...CLSID} = "Sony Ericsson File Manager"
\InProcServer32\(Default) = "C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrgui.dll" ["Sony Ericsson Mobile Communications AB"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\
ACE\(Default) = "{5E2121EE-0300-11D4-8D3B-444553540000}"
-> {HKLM...CLSID} = "SimpleShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll" [null data]
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"
-> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast5\ashShell.dll" ["AVAST Software"]
LavasoftShellExt\(Default) = "{DCE027F7-16A4-4BEE-9BE7-74F80EE3738F}"
-> {HKLM...CLSID} = "Lavasoft Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll" [null data]
Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
\InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir Desktop\shlext.dll" ["Avira GmbH"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}\(Default) = (no title provided)
-> {HKLM...CLSID} = "NBShellHook Class"
\InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll" ["Nero AG"]
HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
A5110426-177D-4e08-AB3F-785F10B4439C\(Default) = "{A5110426-177D-4e08-AB3F-785F10B4439C}"
-> {HKLM...CLSID} = "Sony Ericsson File Manager"
\InProcServer32\(Default) = "C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrgui.dll" ["Sony Ericsson Mobile Communications AB"]
NBShellHook\(Default) = "{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}"
-> {HKLM...CLSID} = "NBShellHook Class"
\InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll" ["Nero AG"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
Default executables:
--------------------
<<!>> HKLM\SOFTWARE\Classes\.com\(Default) = "ComFile"
Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------
Note: detected settings may not have any effect.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"NoDrives" = (REG_DWORD) dword:0x00000000
{unrecognized setting}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"NoDrives" = (REG_DWORD) dword:0x00000000
{unrecognized setting}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
"DisableRegistryTools" = (REG_DWORD) dword:0x00000000
{unrecognized setting}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Marek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\system32\scrnsave.scr" [MS]
Windows Portable Device AutoPlay Handlers
-----------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
iTunesBurnCDOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.BurnCD"
"InvokeVerb" = "burn"
HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayBurn "%L"" ["Apple Inc."]
iTunesImportSongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.ImportSongsOnCD"
"InvokeVerb" = "import"
HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayImportSongs "%L"" ["Apple Inc."]
iTunesPlaySongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.PlaySongsOnCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /playCD "%L"" ["Apple Inc."]
iTunesShowSongsOnArrival\
"Provider" = "iTunes"
"InvokeProgID" = "iTunes.ShowSongsOnCD"
"InvokeVerb" = "showsongs"
HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayShowSongs "%L"" ["Apple Inc."]
MSWPDShellNamespaceHandler\
"Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = " "
-> {HKLM...CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]
NeroAutoPlay7AudioToNeroDigital\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "AudioToNeroDigital_PlayCDAudioOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\AudioToNeroDigital_PlayCDAudioOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Core\nero.exe /Dialog:SaveTracks %L" ["Nero AG"]
NeroAutoPlay7CDAudio\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "CDAudio_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\CDAudio_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Core\nero.exe -w /New:AudioCD" ["Nero AG"]
NeroAutoPlay7CopyCD\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "CopyCD_PlayMusicFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\CopyCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Core\nero.exe /Dialog:DiscCopy %L" ["Nero AG"]
NeroAutoPlay7DataDisc\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "DataDisc_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\DataDisc_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Core\nero.exe -w /New:ISODisc" ["Nero AG"]
NeroAutoPlay7LaunchNeroStartSmart\
"Provider" = "Nero StartSmart"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "LaunchNeroStartSmart_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\LaunchNeroStartSmart_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe /AutoPlay" ["Nero AG"]
NeroAutoPlay7PlayAudioCD\
"Provider" = "Nero ShowTime"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "PlayAudioCD_PlayMusicFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\PlayAudioCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe /Play %L" ["Nero AG"]
NeroAutoPlay7PlayDVD\
"Provider" = "Nero ShowTime"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "PlayDVD_PlayVideoFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\PlayDVD_PlayVideoFilesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe /Play %L" ["Nero AG"]
NeroAutoPlay7RipCD\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "RipCD_PlayCDAudioOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\RipCD_PlayCDAudioOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Core\nero.exe /Dialog:SaveTracks %L" ["Nero AG"]
NeroAutoPlay7TranscodeVideo\
"Provider" = "Nero Recode"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "TranscodeVideo_PlayDVDMovieOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\TranscodeVideo_PlayDVDMovieOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Nero Recode\Recode.exe /New:CopyDVDVideo" ["Nero AG"]
NeroAutoPlay7VideoCapture\
"Provider" = "Nero Vision"
"ProgID" = "Shell.HWEventHandlerShellExecute"
"InitCmdLine" = ""C:\Program Files\Nero\Nero 7\Nero Vision\NeroVision.exe" /New:VideoCapture"
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
-> {HKLM...CLSID} = "ShellExecute HW Event Handler"
\LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]
NeroAutoPlay7ViewPhotos\
"Provider" = "Nero PhotoSnap Viewer"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "ViewPhotos_ShowPicturesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\ViewPhotos_ShowPicturesOnArrival\command\(Default) = "C:\Program Files\Nero\Nero 7\Nero PhotoSnap\PhotoSnapViewer.exe /" ["Nero AG"]
NokiaMusicBurnCD\
"Provider" = "Nokia Music"
"InvokeProgID" = "NokiaMusic.Autoplay"
"InvokeVerb" = "BurnCD"
HKLM\SOFTWARE\Classes\NokiaMusic.Autoplay\shell\BurnCD\command\(Default) = ""C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:burn %L /device:cd %L" [null data]
NokiaMusicPlayCD\
"Provider" = "Nokia Music"
"InvokeProgID" = "NokiaMusic.Autoplay"
"InvokeVerb" = "PlayCD"
HKLM\SOFTWARE\Classes\NokiaMusic.Autoplay\shell\PlayCD\command\(Default) = ""C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:playcd %L /device:cd %L" [null data]
NokiaMusicRipCD\
"Provider" = "Nokia Music"
"InvokeProgID" = "NokiaMusic.Autoplay"
"InvokeVerb" = "RipCD"
HKLM\SOFTWARE\Classes\NokiaMusic.Autoplay\shell\RipCD\command\(Default) = ""C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:rip %L /device:cd %L" [null data]
NokiaMusicViewCD\
"Provider" = "Nokia Music"
"InvokeProgID" = "NokiaMusic.Autoplay"
"InvokeVerb" = "ViewCD"
HKLM\SOFTWARE\Classes\NokiaMusic.Autoplay\shell\ViewCD\command\(Default) = ""C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /device:cd %L" [null data]
NokiaMusicViewDevice\
"Provider" = "Nokia Music"
"ProgID" = "NokiaMusic.Autoplay"
HKLM\SOFTWARE\Classes\NokiaMusic.Autoplay\CLSID\(Default) = "{546811A4-510D-4E15-9679-DD6A27C5CCB3}"
-> {HKLM...CLSID} = "Nokia Music"
\LocalServer32\(Default) = "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" [null data]
NPAutoPlayHandler\
"Provider" = "Nokia Photos"
"InvokeProgID" = "NPAutoPlay"
"InvokeVerb" = "import"
HKLM\SOFTWARE\Classes\NPAutoPlay\shell\import\command\(Default) = "C:\Program Files\Nokia\Nokia Photos\NokiaPhotos2.exe -import %1" [null data]
TVPPlayDVDMovieOnArrival\
"Provider" = "Total Video Player"
"InvokeProgID" = "totalplayer.dvd"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\totalplayer.dvd\shell\open\command\(Default) = "C:\Program Files\Total Video Converter\tvp.exe -dvd %1" [file not found]
VLCPlayCDAudioOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.CDAudio"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\play\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file cdda://%1" ["the VideoLAN Team"]
VLCPlayDVDMovieOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.DVDMovie"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\play\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file dvd://%1" ["the VideoLAN Team"]
Startup items in "Marek" & "All Users" startup folders:
-------------------------------------------------------
C:\Documents and Settings\Marek\Start Menu\Programs\Startup
"Arctosa" -> shortcut to: "C:\Program Files\Razer\Arctosa\razerhid.exe" ["Razer USA Ltd."]
"AvastUI" -> shortcut to: "C:\Program Files\Alwil Software\Avast5\AvastUI.exe" ["AVAST Software"]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Logitech Desktop Messenger" -> shortcut to: "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe /start" ["Logitech"]
"SetPointII" -> shortcut to: "C:\Program Files\Logitech\SetPoint II\SetpointII.exe" ["Logitech Inc."]
Enabled Scheduled Tasks:
------------------------
"GoogleUpdateTaskMachineCore" -> launches: "C:\Program Files\Google\Update\GoogleUpdate.exe /c" ["Google Inc."]
"GoogleUpdateTaskMachineUA" -> launches: "C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler" ["Google Inc."]
"GoogleUpdateTaskUserS-1-5-21-790525478-746137067-1606980848-1003Core" -> launches: "C:\Documents and Settings\Marek\Local Settings\Application Data\Google\Update\GoogleUpdate.exe /c" ["Google Inc."]
"GoogleUpdateTaskUserS-1-5-21-790525478-746137067-1606980848-1003UA" -> launches: "C:\Documents and Settings\Marek\Local Settings\Application Data\Google\Update\GoogleUpdate.exe /ua /installsource scheduler" ["Google Inc."]
"OGALogon" -> launches: "C:\WINDOWS\system32\OGAEXEC.exe /batch" [MS]
"RegCure Program Check" -> launches: "C:\Program Files\RegCure\RegCure.exe ShowReminders" [null data]
"RegCure" -> launches: "C:\Program Files\RegCure\RegCure.exe -t" [null data]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Inc."]
Transport Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05