| 
 Hallo ^^ 
Also beginnen wir Mal mit Silent Runner:     Code: 
 "Silent Runners.vbs", revision 59, http://www.silentrunners.org/Operating System: Windows XP
 Output limited to non-default values, except where indicated by "{++}"
 
 
 Startup items buried in registry:
 ---------------------------------
 
 HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
 "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
 "SpybotSD TeaTimer" = "C:\Programme\Spybot - Search & Destroy\TeaTimer.exe" ["Safer-Networking Ltd."]
 "msnmsgr" = ""C:\Programme\Windows Live\Messenger\msnmsgr.exe" /background" [MS]
 
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "igfxtray" = "C:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"]
 "igfxhkcmd" = "C:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"]
 "igfxpers" = "C:\WINDOWS\system32\igfxpers.exe" ["Intel Corporation"]
 "BluetoothAuthenticationAgent" = "rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent" [MS]
 "LaunchApp" = "Alaunch" ["Acer Inc."]
 "RTHDCPL" = "RTHDCPL.EXE" ["Realtek Semiconductor Corp."]
 "Alcmtr" = "ALCMTR.EXE" ["Realtek Semiconductor Corp."]
 "SynTPEnh" = "C:\Programme\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]
 "(Default)" = "(empty string)" [file not found]
 "ADMTray.exe" = ""C:\Acer\Empowering Technology\admtray.exe"" ["Avocent Inc."]
 "IMJPMIG8.1" = ""C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" [MS]
 "MSPY2002" = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC" [null data]
 "PHIME2002ASync" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" [MS]
 "PHIME2002A" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName" [MS]
 "ePower_DMC" = "C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" ["Acer Incorporated"]
 "Acer ePower Management" = "C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot" ["Acer Value Labs, Taiwan"]
 "LManager" = "C:\PROGRA~1\LAUNCH~1\LManager.exe" ["Dritek System Inc."]
 "eRecoveryService" = "C:\Acer\Empowering Technology\eRecovery\Monitor.exe" ["acer Inc."]
 "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" ["ALWIL Software"]
 "SmcService" = "C:\PROGRA~1\Sygate\SPF\smc.exe -startgui" ["Sygate Technologies, Inc."]
 "LXSUPMON" = "C:\WINDOWS\system32\LXSUPMON.EXE RUN" ["Lexmark International Inc."]
 "Ad-Watch" = "C:\Programme\Lavasoft\Ad-Aware\AAWTray.exe" ["Lavasoft"]
 "SunJavaUpdateSched" = ""C:\Programme\Java\jre6\bin\jusched.exe"" ["Sun Microsystems, Inc."]
 
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
 {18DF081C-E8AD-4283-A596-FA578C2EBDC3}\(Default) = "AcroIEHelperStub"
 -> {HKLM...CLSID} = "Adobe PDF Link Helper"
 \InProcServer32\(Default) = "C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll" ["Adobe Systems Incorporated"]
 {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "Spybot-S&D IE Protection"
 \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
 {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "Windows Live Anmelde-Hilfsprogramm"
 \InProcServer32\(Default) = "C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]
 {DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "Java(tm) Plug-In 2 SSV Helper"
 \InProcServer32\(Default) = "C:\Programme\Java\jre6\bin\jp2ssv.dll" ["Sun Microsystems, Inc."]
 {E7E6F031-17CE-4C07-BC86-EABFE594F69C}\(Default) = "JQSIEStartDetectorImpl"
 -> {HKLM...CLSID} = "JQSIEStartDetectorImpl Class"
 \InProcServer32\(Default) = "C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll" ["Sun Microsystems, Inc."]
 
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "CPL-Erweiterung für Anzeigeverschiebung"
 -> {HKLM...CLSID} = "CPL-Erweiterung für Anzeigeverschiebung"
 \InProcServer32\(Default) = "deskpan.dll" [file not found]
 "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Erweiterung für HyperTerminal-Icons"
 -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
 "{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Programme\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."]
 "{2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0}" = "EPM-PO Shell Extension"
 -> {HKLM...CLSID} = "EPM-PO Shell Extensions"
 \InProcServer32\(Default) = "epm-po.dll" ["Acer Labs USA"]
 "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
 -> {HKLM...CLSID} = "Outlook-Dateisymbolerweiterung"
 \InProcServer32\(Default) = "C:\Programme\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
 "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Programme\Microsoft Office\Office10\msohev.dll" [MS]
 "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
 -> {HKLM...CLSID} = "Meine freigegebenen Ordner"
 \InProcServer32\(Default) = "C:\Programme\Windows Live\Messenger\fsshext.8.5.1302.1018.dll" [MS]
 "{DC70C4A5-2044-4c59-B806-DEFB9AE0DF7C}" = "Logitech Setpoint Extension"
 -> {HKLM...CLSID} = "KbLogiExt Class"
 \InProcServer32\(Default) = "C:\Programme\Logitech\SetPoint\kbcplext.dll" ["Logitech Inc."]
 "{B9B9F083-2B04-452A-8691-83694AC1037B}" = "Logitech Setpoint Extension"
 -> {HKLM...CLSID} = "LogiExt Class"
 \InProcServer32\(Default) = "C:\Programme\Logitech\SetPoint\mcplext.dll" ["Logitech Inc."]
 "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
 -> {HKLM...CLSID} = "avast"
 \InProcServer32\(Default) = "C:\Programme\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
 "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
 -> {HKLM...CLSID} = "RealOne Player Context Menu Class"
 \InProcServer32\(Default) = "C:\Programme\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
 "{A155339D-CCCD-4714-85EB-3754B804C9DF}" = "a-squared Free Context Menu Shell Extension"
 -> {HKLM...CLSID} = "a-squared Free Context Menu"
 \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL" ["Emsi Software GmbH"]
 "{4EFE464B-3D0B-4800-A5DE-2321283A3256}" = "QCD IconHandler"
 -> {HKLM...CLSID} = "QIconHandler Class"
 \InProcServer32\(Default) = "C:\Programme\Quintessential Player\QCDIcons.dll" [empty string]
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data]
 
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
 "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
 -> {HKLM...CLSID} = "WPDShServiceObj Class"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]
 
 HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\
 <<!>> "BootExecute" = "autocheck autochk *"|"lsdelete" [null data]
 
 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
 <<!>> igfxcui\DLLName = "igfxdev.dll" ["Intel Corporation"]
 
 HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
 {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
 -> {HKLM...CLSID} = "PDF Shell Extension"
 \InProcServer32\(Default) = "C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
 
 HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
 avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
 -> {HKLM...CLSID} = "avast"
 \InProcServer32\(Default) = "C:\Programme\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
 EDSshellExt\(Default) = "{29FF7AB0-BE34-4992-A30B-53A9D86EE239}"
 -> {HKLM...CLSID} = "eDSshlExt Class"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\eDSshellExt.dll" ["HiTRUST"]
 LavasoftShellExt\(Default) = "{DCE027F7-16A4-4BEE-9BE7-74F80EE3738F}"
 -> {HKLM...CLSID} = "Lavasoft Shell Extension"
 \InProcServer32\(Default) = "C:\Programme\Lavasoft\Ad-Aware\ShellExt.dll" [null data]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data]
 
 HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
 EDSshellExt\(Default) = "{29FF7AB0-BE34-4992-A30B-53A9D86EE239}"
 -> {HKLM...CLSID} = "eDSshlExt Class"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\eDSshellExt.dll" ["HiTRUST"]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data]
 
 HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
 a2FreeContMenu\(Default) = "{A155339D-CCCD-4714-85EB-3754B804C9DF}"
 -> {HKLM...CLSID} = "a-squared Free Context Menu"
 \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL" ["Emsi Software GmbH"]
 avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
 -> {HKLM...CLSID} = "avast"
 \InProcServer32\(Default) = "C:\Programme\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
 LavasoftShellExt\(Default) = "{DCE027F7-16A4-4BEE-9BE7-74F80EE3738F}"
 -> {HKLM...CLSID} = "Lavasoft Shell Extension"
 \InProcServer32\(Default) = "C:\Programme\Lavasoft\Ad-Aware\ShellExt.dll" [null data]
 MBAMShlExt\(Default) = "{57CE581A-0CB6-4266-9CA0-19364C90A0B3}"
 -> {HKLM...CLSID} = "MBAMShlExt Class"
 \InProcServer32\(Default) = "C:\Programme\Malwarebytes' Anti-Malware\mbamext.dll" ["Malwarebytes Corporation"]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data]
 
 HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
 a2FreeContMenu\(Default) = "{A155339D-CCCD-4714-85EB-3754B804C9DF}"
 -> {HKLM...CLSID} = "a-squared Free Context Menu"
 \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL" ["Emsi Software GmbH"]
 MBAMShlExt\(Default) = "{57CE581A-0CB6-4266-9CA0-19364C90A0B3}"
 -> {HKLM...CLSID} = "MBAMShlExt Class"
 \InProcServer32\(Default) = "C:\Programme\Malwarebytes' Anti-Malware\mbamext.dll" ["Malwarebytes Corporation"]
 
 
 Group Policies {policy setting}:
 --------------------------------
 
 Note: detected settings may not have any effect.
 
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\
 
 "HonorAutoRunSetting" = (REG_DWORD) dword:0x00000001
 {unrecognized setting}
 
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
 
 "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
 {Shutdown: Allow system to be shut down without having to log on}
 
 "undockwithoutlogon" = (REG_DWORD) dword:0x00000001
 {Devices: Allow undock without having to log on}
 
 
 Active Desktop and Wallpaper:
 -----------------------------
 
 Active Desktop may be disabled at this entry:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
 
 Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
 HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
 "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp"
 
 Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
 HKCU\Control Panel\Desktop\
 "Wallpaper" = "C:\Dokumente und Einstellungen\Sandra\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp"
 
 
 Enabled Screen Saver:
 ---------------------
 
 HKCU\Control Panel\Desktop\
 "SCRNSAVE.EXE" = "C:\WINDOWS\ACER.SCR" [null data]
 
 
 Windows Portable Device AutoPlay Handlers
 -----------------------------------------
 
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
 
 DVDDecrypterPlayDVDMovieOnArrival\
 "Provider" = "DVD Decrypter"
 "InvokeProgID" = "DVDDecrypter"
 "InvokeVerb" = "PlayDVDMovieOnArrival_Decrypt"
 HKLM\SOFTWARE\Classes\DVDDecrypter\shell\PlayDVDMovieOnArrival_Decrypt\Command\(Default) = ""C:\Programme\DVD Decrypter\DVDDecrypter.exe" /MODE READ /SOURCE "%1"" ["LIGHTNING UK!"]
 
 MSWPDShellNamespaceHandler\
 "Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501"
 "CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
 "InitCmdLine" = " "
 -> {HKLM...CLSID} = "WPDShextAutoplay"
 \LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]
 
 NTIBurner\
 "Provider" = "NTI CD-Maker"
 "InvokeProgID" = "NTIBurnerOpen"
 "InvokeVerb" = "open"
 HKLM\SOFTWARE\Classes\NTIBurnerOpen\shell\open\command\(Default) = ""C:\Programme\NewTech Infosystems\NTI CD & DVD-Maker 7\Cdmkr32.exe"" ["NewTech Infosystems, Inc."]
 
 PCinemaDCameraArrival\
 "Provider" = "Acer Arcade"
 "InvokeProgID" = "Picture"
 "InvokeVerb" = "PlayWithPowerCinema"
 HKLM\SOFTWARE\Classes\Picture\shell\PlayWithPowerCinema\Command\(Default) = ""C:\Program Files\Acer\Acer Arcade\Acer Arcade.exe" AUTOPLAY DSC "%L"" ["CyberLink Corp."]
 
 PCinemaDVArrival\
 "Provider" = "Acer Arcade"
 "ProgID" = "Shell.HWEventHandlerShellExecute"
 "InitCmdLine" = ""C:\Program Files\Acer\Acer Arcade\Acer Arcade.exe" DV "%L""
 HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
 -> {HKLM...CLSID} = "ShellExecute HW Event Handler"
 \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]
 
 PCinemaMusicFilesArrival\
 "Provider" = "Acer Arcade"
 "InvokeProgID" = "MusicFiles"
 "InvokeVerb" = "PlayWithPowerCinema"
 HKLM\SOFTWARE\Classes\MusicFiles\shell\PlayWithPowerCinema\Command\(Default) = ""C:\Program Files\Acer\Acer Arcade\Acer Arcade.exe" AUTOPLAY MUSIC "%L"" ["CyberLink Corp."]
 
 PCinemaPlayCDAudioOnArrival\
 "Provider" = "Acer Arcade"
 "InvokeProgID" = "AudioCD"
 "InvokeVerb" = "PlayWithPowerCinema"
 HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPowerCinema\Command\(Default) = ""C:\Program Files\Acer\Acer Arcade\Acer Arcade.exe" AUTOPLAY CD "%L"" ["CyberLink Corp."]
 
 PCinemaPlayDVDMovieOnArrival\
 "Provider" = "Acer Arcade"
 "InvokeProgID" = "DVD"
 "InvokeVerb" = "PlayWithPowerCinema"
 HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerCinema\Command\(Default) = ""C:\Program Files\Acer\Acer Arcade\Acer Arcade.exe" AUTOPLAY MOVIE "%L"" ["CyberLink Corp."]
 
 PCinemaVideoFilesArrival\
 "Provider" = "Acer Arcade"
 "InvokeProgID" = "VideoFiles"
 "InvokeVerb" = "PlayWithPowerCinema"
 HKLM\SOFTWARE\Classes\VideoFiles\shell\PlayWithPowerCinema\Command\(Default) = ""C:\Program Files\Acer\Acer Arcade\Acer Arcade.exe" AUTOPLAY VIDEO "%L"" ["CyberLink Corp."]
 
 PPCDBurningOnArrival\
 "Provider" = "PowerProducer"
 "InvokeProgID" = "Picture"
 "InvokeVerb" = "OpenWithPowerProducer"
 HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerProducer\Command\(Default) = ""C:\Program Files\CyberLink\PowerProducer\Producer.exe"" ["CyberLink"]
 
 PPDCameraArrival\
 "Provider" = "PowerProducer"
 "InvokeProgID" = "Picture"
 "InvokeVerb" = "OpenWithPowerProducer"
 HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerProducer\Command\(Default) = ""C:\Program Files\CyberLink\PowerProducer\Producer.exe"" ["CyberLink"]
 
 PPDVArrival\
 "Provider" = "PowerProducer"
 "ProgID" = "Shell.HWEventHandlerShellExecute"
 "InitCmdLine" = ""C:\Program Files\CyberLink\PowerProducer\Producer.exe""
 HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
 -> {HKLM...CLSID} = "ShellExecute HW Event Handler"
 \LocalServer32\(Default) = "rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]
 
 PSASE30ImportPicturesOnArrival\
 "Provider" = "Adobe Photoshop Album Starter Edition"
 "InvokeProgID" = "PSASE30.autoplay"
 "InvokeVerb" = "launch"
 HKLM\SOFTWARE\Classes\PSASE30.autoplay\shell\launch\command\(Default) = ""C:\Programme\Adobe\Photoshop Album Starter Edition\3.0\Apps\psaproxy.exe"  -v  %1\" ["Adobe Systems Incorporated"]
 
 RPCDBurningOnArrival\
 "Provider" = "RealPlayer"
 "InvokeProgID" = "RealPlayer.CDBurn.6"
 "InvokeVerb" = "open"
 HKLM\SOFTWARE\Classes\RealPlayer.CDBurn.6\shell\open\command\(Default) = "C:\Programme\Real\RealPlayer\RealPlay.exe /burn "%1"" ["RealNetworks, Inc."]
 
 RPDeviceOnArrival\
 "Provider" = "RealPlayer"
 "ProgID" = "RealPlayer.HWEventHandler"
 HKLM\SOFTWARE\Classes\RealPlayer.HWEventHandler\CLSID\(Default) = "{67E76F1D-BDE2-4052-913C-2752366192D2}"
 -> {HKLM...CLSID} = "RealNetworks Scheduler"
 \LocalServer32\(Default) = ""C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -autoplay" ["RealNetworks, Inc."]
 
 RPPlayCDAudioOnArrival\
 "Provider" = "RealPlayer"
 "InvokeProgID" = "RealPlayer.AudioCD.6"
 "InvokeVerb" = "play"
 HKLM\SOFTWARE\Classes\RealPlayer.AudioCD.6\shell\play\command\(Default) = "C:\Programme\Real\RealPlayer\RealPlay.exe  /play %1 " ["RealNetworks, Inc."]
 
 RPPlayDVDMovieOnArrival\
 "Provider" = "RealPlayer"
 "InvokeProgID" = "RealPlayer.DVD.6"
 "InvokeVerb" = "play"
 HKLM\SOFTWARE\Classes\RealPlayer.DVD.6\shell\play\command\(Default) = "C:\Programme\Real\RealPlayer\RealPlay.exe  /dvd %1 " ["RealNetworks, Inc."]
 
 RPPlayMediaOnArrival\
 "Provider" = "RealPlayer"
 "InvokeProgID" = "RealPlayer.AutoPlay.6"
 "InvokeVerb" = "open"
 HKLM\SOFTWARE\Classes\RealPlayer.AutoPlay.6\shell\open\command\(Default) = "C:\Programme\Real\RealPlayer\RealPlay.exe /autoplay "%1"" ["RealNetworks, Inc."]
 
 VLCPlayCDAudioOnArrival\
 "Provider" = "VideoLAN VLC media player"
 "InvokeProgID" = "VLC.CDAudio"
 "InvokeVerb" = "play"
 HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\play\command\(Default) = "C:\Programme\VideoLAN\VLC\vlc.exe --started-from-file cdda:%1" ["VideoLAN Team"]
 
 VLCPlayDVDMovieOnArrival\
 "Provider" = "VideoLAN VLC media player"
 "InvokeProgID" = "VLC.DVDMovie"
 "InvokeVerb" = "play"
 HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\play\command\(Default) = "C:\Programme\VideoLAN\VLC\vlc.exe --started-from-file dvd:%1" ["VideoLAN Team"]
 
 
 Enabled Scheduled Tasks:
 ------------------------
 
 "Ad-Aware Update (Weekly)" -> launches: "C:\Programme\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe update all silent" ["Lavasoft"]
 
 
 Winsock2 Service Provider DLLs:
 -------------------------------
 
 Namespace Service Providers
 
 HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 000000000004\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]
 
 Transport Service Providers
 
 HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
 %SystemRoot%\system32\mswsock.dll [MS], 01 - 05, 08 - 21
 %SystemRoot%\system32\rsvpsp.dll [MS], 06 - 07
 
 
 Toolbars, Explorer Bars, Extensions:
 ------------------------------------
 
 Toolbars
 
 HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
 "{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}" = (no title provided)
 -> {HKLM...CLSID} = "Acer eDataSecurity Management"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\eDStoolbar.dll" ["HiTRUST"]
 "{0FBB9689-D3D7-4F7A-A2E2-585B10099BFC}" = "Veoh Web Player Video Finder"
 -> {HKLM...CLSID} = "Veoh Web Player Video Finder"
 \InProcServer32\(Default) = "C:\Programme\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll" ["Veoh Networks Inc"]
 
 Extensions (Tools menu items, main toolbar menu buttons)
 
 HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
 {B863453A-26C3-4E1F-A54D-A2CD196348E9}\
 "ButtonText" = "ICQ Lite"
 "MenuText" = "ICQ Lite"
 "Exec" = "C:\Programme\ICQLite\ICQLite.exe" [file not found]
 
 {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\
 "MenuText" = "Spybot - Search & Destroy Configuration"
 "CLSIDExtension" = "{53707962-6F74-2D53-2644-206D7942484F}"
 -> {HKLM...CLSID} = "Spybot-S&D IE Protection"
 \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
 
 {E2E2DD38-D088-4134-82B7-F2BA38496583}\
 "MenuText" = "@xpsp3res.dll,-20001"
 "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]
 
 {E59EB121-F339-4851-A3BA-FE49C35617C2}\
 "ButtonText" = "ICQ6"
 "MenuText" = "ICQ6"
 "Exec" = "C:\Programme\ICQ6\ICQ.exe" ["ICQ, Inc."]
 
 {FB5F1910-F110-11D2-BB9E-00C04F795683}\
 "ButtonText" = "Messenger"
 "MenuText" = "Windows Messenger"
 "Exec" = "C:\Programme\Messenger\msmsgs.exe" [MS]
 
 
 Running Services (Display Name, Service Name, Path {Service DLL}):
 ------------------------------------------------------------------
 
 a-squared Free Service, a2free, ""c:\programme\a-squared free\a2service.exe"" ["Emsi Software GmbH"]
 AdminWorks Agent X6, AWService, ""C:\Acer\Empowering Technology\admServ.exe"" ["Avocent Inc."]
 avast! Antivirus, avast! Antivirus, ""C:\Programme\Alwil Software\Avast4\ashServ.exe"" ["ALWIL Software"]
 avast! iAVS4 Control Service, aswUpdSv, ""C:\Programme\Alwil Software\Avast4\aswUpdSv.exe"" ["ALWIL Software"]
 avast! Mail Scanner, avast! Mail Scanner, ""C:\Programme\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
 avast! Web Scanner, avast! Web Scanner, ""C:\Programme\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
 Bluetooth Support Service, BthServ, "C:\WINDOWS\system32\svchost.exe -k bthsvcs" {"C:\WINDOWS\System32\bthserv.dll" [MS]}
 CyberLink Background Capture Service (CBCS), CLCapSvc, ""C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe"" [empty string]
 CyberLink Media Library Service, CyberLink Media Library Service, ""C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe"" ["Cyberlink"]
 Cyberlink RichVideo Service(CRVS), RichVideo, ""C:\Programme\CyberLink\Shared Files\RichVideo.exe"" [empty string]
 CyberLink Task Scheduler (CTS), CLSched, ""C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe"" [empty string]
 ICQ Service, ICQ Service, "C:\Programme\ICQ6Toolbar\ICQ Service.exe" [empty string]
 Intel(R) PROSet/Wireless Event Log, EvtEng, "C:\Programme\Intel\Wireless\Bin\EvtEng.exe" ["Intel Corporation"]
 Intel(R) PROSet/Wireless Registry Service, RegSrvc, "C:\Programme\Intel\Wireless\Bin\RegSrvc.exe" ["Intel Corporation"]
 Intel(R) PROSet/Wireless Service, S24EventMonitor, "C:\Programme\Intel\Wireless\Bin\S24EvMon.exe" ["Intel Corporation "]
 Java Quick Starter, JavaQuickStarterService, ""C:\Programme\Java\jre6\bin\jqs.exe" -service -config "C:\Programme\Java\jre6\lib\deploy\jqs\jqs.conf"" ["Sun Microsystems, Inc."]
 Lavasoft Ad-Aware Service, Lavasoft Ad-Aware Service, ""C:\Programme\Lavasoft\Ad-Aware\AAWService.exe"" ["Lavasoft"]
 LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]
 LightScribeService Direct Disc Labeling Service, LightScribeService, ""C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe"" ["Hewlett-Packard Company"]
 Net Driver HPZ12, Net Driver HPZ12, "C:\WINDOWS\System32\svchost.exe -k HPZ12" {"C:\WINDOWS\system32\HPZinw12.dll" ["Hewlett-Packard"]}
 Pml Driver HPZ12, Pml Driver HPZ12, "C:\WINDOWS\System32\svchost.exe -k HPZ12" {"C:\WINDOWS\system32\HPZipm12.dll" ["Hewlett-Packard"]}
 Sygate Personal Firewall, SmcService, "C:\Programme\Sygate\SPF\smc.exe" ["Sygate Technologies, Inc."]
 
 
 Print Monitors:
 ---------------
 
 HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
 BJ Language Monitor2\Driver = "CNBJMON2.DLL" [MS]
 HP Standard TCP/IP Port\Driver = "HpTcpMon.dll" ["Hewlett Packard"]
 hpz3l4sa\Driver = "hpz3l4sa.dll" ["Hewlett-Packard Company"]
 Lexmark Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]
 Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]
 PDFCreator\Driver = "pdfcmnnt.dll" [null data]
 
 
 ---------- (launch time: 2009-03-25 14:12:34)
 <<!>>: Suspicious data at a malware launch point.
 |