| Metallica |  26.06.2008 15:58 |         Code:  
 "Silent Runners.vbs", revision 58, http://www.silentrunners.org/ 
Operating System: Windows Vista 
Output limited to non-default values, except where indicated by "{++}"     
Startup items buried in registry: 
---------------------------------   
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} 
"MsnMsgr" = ""C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background" [MS] 
"ehTray.exe" = "C:\Windows\ehome\ehTray.exe" [MS] 
"PowerBar" = "(empty string)" [file not found] 
"Vidalia" = ""C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"" ["vidalia-project.net"] 
"WMPNSCFG" = "C:\Program Files\Windows Media Player\WMPNSCFG.exe" [MS] 
"ISUSPM Startup" = ""C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup" ["Macrovision Corporation"] 
"ICQ" = ""C:\PROGRA~1\ICQ6\ICQ.exe" silent" ["ICQ, Inc."] 
"Power2GoExpress" = "*D*D**W** (unwritable string)" [file not found] 
"SpybotSD TeaTimer" = "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" ["Safer Networking Limited"]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} 
"Windows Defender" = "C:\Program Files\Windows Defender\MSASCui.exe -hide" 
"RtHDVCpl" = "RtHDVCpl.exe" ["Realtek Semiconductor"] 
"BisonHK" = "C:\Windows\BisonCam\BisonHK.exe" [null data] 
"BsMnt" = "C:\Windows\BisonCam\BsMnt.exe" [empty string] 
"MGSysCtrl" = "C:\Program Files\System Control Manager\MGSysCtrl.exe" ["MSI"] 
"Adobe Reader Speed Launcher" = ""C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"" ["Adobe Systems Incorporated"] 
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = "C:\Program Files\Google\Gmail Notifier\gnotify.exe" ["Google Inc."] 
"RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."] 
"ISUSScheduler" = ""C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start" ["Macrovision Corporation"] 
"avgnt" = ""C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min" ["Avira GmbH"] 
"Skytel" = "Skytel.exe" ["Realtek Semiconductor Corp."] 
"NvSvc" = "RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart" [MS] 
"NvCplDaemon" = "RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" [MS] 
"NvMediaCenter" = "RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" [MS]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ {++} 
"Cleanup" = "C:\cleanup.exe" [null data]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = "Adobe PDF Reader" 
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"] 
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = "Spybot-S&D IE Protection" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"] 
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = "SSVHelper Class" 
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."] 
{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided) 
  -> {HKLM...CLSID} = "Windows Live Anmelde-Hilfsprogramm" 
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ 
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class" 
  -> {HKLM...CLSID} = "DesktopContext Class" 
                   \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"] 
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" 
  -> {HKLM...CLSID} = "WinRAR" 
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR 3.61 Multi\rarext.dll" [null data] 
"{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}" = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" 
  -> {HKLM...CLSID} = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL" [MS] 
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" 
  -> {HKLM...CLSID} = (no title provided) 
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS] 
"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler" 
  -> {HKLM...CLSID} = "Microsoft Office Metadata Handler" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS] 
"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler" 
  -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS] 
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders" 
  -> {HKLM...CLSID} = "Meine freigegebenen Ordner" 
                   \InProcServer32\(Default) = "C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll" [MS] 
"{44440D00-FF19-4AFC-B765-9A0970567D97}" = "TuneUp Theme Extension" 
  -> {HKLM...CLSID} = "TuneUp Theme Extension" 
                   \InProcServer32\(Default) = "C:\Windows\System32\uxtuneup.dll" ["TuneUp Software GmbH"] 
"{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}" = "TuneUp Shredder Shell Extension" 
  -> {HKLM...CLSID} = "TuneUp Shredder Shell Extension" 
                   \InProcServer32\(Default) = "C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll" ["TuneUp Software GmbH"] 
"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning" 
  -> {HKLM...CLSID} = "Shell Extension for Malware scanning" 
                   \InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"] 
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper" 
  -> {HKLM...CLSID} = "NVIDIA CPL Extension" 
                   \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]   
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\ 
<<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}" 
  -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]   
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ 
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info" 
  -> {HKLM...CLSID} = "PDF Shell Extension" 
                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]   
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ 
Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" 
  -> {HKLM...CLSID} = "Shell Extension for Malware scanning" 
                   \InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"] 
TuneUp Shredder Shell Extension\(Default) = "{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}" 
  -> {HKLM...CLSID} = "TuneUp Shredder Shell Extension" 
                   \InProcServer32\(Default) = "C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll" ["TuneUp Software GmbH"] 
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" 
  -> {HKLM...CLSID} = "WinRAR" 
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR 3.61 Multi\rarext.dll" [null data]   
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ 
TuneUp Shredder Shell Extension\(Default) = "{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}" 
  -> {HKLM...CLSID} = "TuneUp Shredder Shell Extension" 
                   \InProcServer32\(Default) = "C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll" ["TuneUp Software GmbH"] 
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" 
  -> {HKLM...CLSID} = "WinRAR" 
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR 3.61 Multi\rarext.dll" [null data]   
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ 
Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" 
  -> {HKLM...CLSID} = "Shell Extension for Malware scanning" 
                   \InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"] 
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" 
  -> {HKLM...CLSID} = "WinRAR" 
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR 3.61 Multi\rarext.dll" [null data]     
Group Policies {GPedit.msc branch and setting}: 
-----------------------------------------------   
Note: detected settings may not have any effect.   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\   
"ConsentPromptBehaviorAdmin" = (REG_DWORD) dword:0x00000002 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode}   
"ConsentPromptBehaviorUser" = (REG_DWORD) dword:0x00000001 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
User Account Control: Behavior Of The Elevation Prompt For Standard Users}   
"EnableInstallerDetection" = (REG_DWORD) dword:0x00000001 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
User Account Control: Detect Application Installations And Prompt For Elevation}   
"EnableLUA" = (REG_DWORD) dword:0x00000001 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
User Account Control: Run All Administrators In Admin Approval Mode}   
"EnableSecureUIAPaths" = (REG_DWORD) dword:0x00000001 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
User Account Control: Only elevate UIAccess applications that are installed in secure locations}   
"EnableVirtualization" = (REG_DWORD) dword:0x00000001 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
User Account Control: Virtualize file and registry write failures to per-user locations}   
"PromptOnSecureDesktop" = (REG_DWORD) dword:0x00000001 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
User Account Control: Switch to the secure desktop when prompting for elevation}   
"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
Shutdown: Allow system to be shut down without having to log on}   
"undockwithoutlogon" = (REG_DWORD) dword:0x00000001 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
Devices: Allow undock without having to log on}   
"FilterAdministratorToken" = (REG_DWORD) dword:0x00000000 
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 
User Account Control: Admin Approval Mode for the Built-in Administrator Account}   
"EnableUIADesktopToggle" = (REG_DWORD) dword:0x00000000 
{unrecognized setting}     
Active Desktop and Wallpaper: 
-----------------------------   
Active Desktop may be disabled at this entry: 
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState   
Displayed if Active Desktop enabled and wallpaper not set by Group Policy: 
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ 
"Wallpaper" = "C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows Photo Gallery\Hintergrundbild der Windows-Fotogalerie.jpg"   
Displayed if Active Desktop disabled and wallpaper not set by Group Policy: 
HKCU\Control Panel\Desktop\ 
"Wallpaper" = "C:\Users\Metal\AppData\Roaming\Mozilla\Firefox\Desktop Hintergrund.bmp"     
Windows Portable Device AutoPlay Handlers 
-----------------------------------------   
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\   
P2GCDBurningOnArrival\ 
"Provider" = "Power2Go" 
"InvokeProgID" = "Picture" 
"InvokeVerb" = "OpenWithPower2Go" 
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPower2Go\Command\(Default) = ""C:\Program Files\CyberLink\Power2Go\Power2Go.exe"" ["Cyberlink"]   
P2GDVDBurningOnArrival\ 
"Provider" = "Power2Go" 
"InvokeProgID" = "BlankDVD" 
"InvokeVerb" = "OpenWithPower2Go" 
HKLM\SOFTWARE\Classes\BlankDVD\shell\OpenWithPower2Go\Command\(Default) = ""C:\Program Files\CyberLink\Power2Go\Power2Go.exe"" ["Cyberlink"]   
PDirXDVArrival\ 
"Provider" = "PowerDirector Express" 
"ProgID" = "Shell.HWEventHandlerShellExecute" 
"InitCmdLine" = ""C:\Program Files\CyberLink\PowerDirector Express\PDX.exe" /DV" 
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" 
  -> {HKLM...CLSID} = "Shell Execute Hardware Event Handler" 
                   \LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]   
PDVDPlayCDAudioOnArrival\ 
"Provider" = "PowerDVD" 
"InvokeProgID" = "AudioCD" 
"InvokeVerb" = "PlayWithPowerDVD" 
HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPowerDVD\Command\(Default) = ""C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%l"" ["CyberLink Corp."]   
PDVDPlayDVDMovieOnArrival\ 
"Provider" = "PowerDVD" 
"InvokeProgID" = "DVD" 
"InvokeVerb" = "PlayWithPowerDVD" 
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerDVD\Command\(Default) = ""C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%l"" ["CyberLink Corp."]   
PDVDPlayVCDMovieOnArrival\ 
"Provider" = "PowerDVD" 
"InvokeProgID" = "VCD" 
"InvokeVerb" = "PlayWithPowerDVD" 
HKLM\SOFTWARE\Classes\VCD\shell\PlayWithPowerDVD\Command\(Default) = ""C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%l"" ["CyberLink Corp."]   
PPCDBurningOnArrival\ 
"Provider" = "PowerProducer" 
"InvokeProgID" = "Picture" 
"InvokeVerb" = "OpenWithPowerProducer" 
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerProducer\Command\(Default) = ""C:\Program Files\CyberLink\PowerProducer\Producer.exe"" ["CyberLink"]   
PPDCameraArrival\ 
"Provider" = "PowerProducer" 
"InvokeProgID" = "Picture" 
"InvokeVerb" = "OpenWithPowerProducer" 
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerProducer\Command\(Default) = ""C:\Program Files\CyberLink\PowerProducer\Producer.exe"" ["CyberLink"]   
PPDVArrival\ 
"Provider" = "PowerProducer" 
"ProgID" = "Shell.HWEventHandlerShellExecute" 
"InitCmdLine" = ""C:\Program Files\CyberLink\PowerProducer\Producer.exe"" 
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" 
  -> {HKLM...CLSID} = "Shell Execute Hardware Event Handler" 
                   \LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]   
PStarterBlankCDArrival\ 
"Provider" = "DVD Solution" 
"InvokeProgID" = "Picture" 
"InvokeVerb" = "OpenWithPowerStarter" 
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files\CyberLink\DVD Solution\PowerStarter.exe"" [empty string]   
PStarterMixedCDArrival\ 
"Provider" = "DVD Solution" 
"InvokeProgID" = "MixedContent" 
"InvokeVerb" = "OpenWithPowerStarter" 
HKLM\SOFTWARE\Classes\MixedContent\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files\CyberLink\DVD Solution\PowerStarter.exe"" [empty string]   
PStarterMusicFilesArrival\ 
"Provider" = "DVD Solution" 
"InvokeProgID" = "MusicFiles" 
"InvokeVerb" = "OpenWithPowerStarter" 
HKLM\SOFTWARE\Classes\MusicFiles\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files\CyberLink\DVD Solution\PowerStarter.exe"" [empty string]   
PStarterPicturesArrival\ 
"Provider" = "DVD Solution" 
"InvokeProgID" = "Picture" 
"InvokeVerb" = "OpenWithPowerStarter" 
HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files\CyberLink\DVD Solution\PowerStarter.exe"" [empty string]   
PStarterPlayCDAudioOnArrival\ 
"Provider" = "DVD Solution" 
"InvokeProgID" = "AudioCD" 
"InvokeVerb" = "PlayWithPowerStarter" 
HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPowerStarter\Command\(Default) = ""C:\Program Files\CyberLink\DVD Solution\PowerStarter.exe" "%L"" [empty string]   
PStarterPlayDVDMovieOnArrival\ 
"Provider" = "DVD Solution" 
"InvokeProgID" = "DVD" 
"InvokeVerb" = "PlayWithPowerStarter" 
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerStarter\Command\(Default) = ""C:\Program Files\CyberLink\DVD Solution\PowerStarter.exe" "%L"" [empty string]   
PStarterVideoFilesArrival\ 
"Provider" = "DVD Solution" 
"InvokeProgID" = "VideoFiles" 
"InvokeVerb" = "OpenWithPowerStarter" 
HKLM\SOFTWARE\Classes\VideoFiles\shell\OpenWithPowerStarter\Command\(Default) = ""C:\Program Files\CyberLink\DVD Solution\PowerStarter.exe"" [empty string]   
VLCPlayCDAudioOnArrival\ 
"Provider" = "VideoLAN VLC media player" 
"InvokeProgID" = "VLC.CDAudio" 
"InvokeVerb" = "play" 
HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\play\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file cdda:%1" ["VideoLAN Team"]   
VLCPlayDVDMovieOnArrival\ 
"Provider" = "VideoLAN VLC media player" 
"InvokeProgID" = "VLC.DVDMovie" 
"InvokeVerb" = "play" 
HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\play\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file dvd:%1" ["VideoLAN Team"]   
WinampMTPHandler\ 
"Provider" = "Winamp" 
"ProgID" = "Shell.HWEventHandlerShellExecute" 
"InitCmdLine" = "C:\Program Files\Winamp\winamp.exe" 
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" 
  -> {HKLM...CLSID} = "Shell Execute Hardware Event Handler" 
                   \LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]   
WinampPlayMediaOnArrival\ 
"Provider" = "Winamp" 
"InvokeProgID" = "Winamp.File" 
"InvokeVerb" = "Play" 
HKLM\SOFTWARE\Classes\Winamp.File\shell\Play\command\(Default) = ""C:\Program Files\Winamp\winamp.exe" "%1"" ["Nullsoft"] 
HKLM\SOFTWARE\Classes\Winamp.File\shell\Play\DropTarget\CLSID = "{46986115-84D6-459c-8F95-52DD653E532E}" 
  -> {HKLM...CLSID} = (no title provided) 
                   \LocalServer32\(Default) = ""C:\Program Files\Winamp\winamp.exe"" ["Nullsoft"]     
Startup items in "Metal" & "All Users" startup folders: 
-------------------------------------------------------   
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 
"Privoxy" -> shortcut to: "C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe" ["The Privoxy team - www.privoxy.org"]     
Winsock2 Service Provider DLLs: 
-------------------------------   
Namespace Service Providers   
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 
000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS] 
000000000002\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS] 
000000000003\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS] 
000000000004\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS] 
000000000005\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS] 
000000000006\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 
000000000007\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]   
Transport Service Providers   
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: 
%SystemRoot%\system32\mswsock.dll [MS], 01 - 29     
Toolbars, Explorer Bars, Extensions: 
------------------------------------   
Explorer Bars   
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\   
HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Recherchieren" 
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] 
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL" [MS]   
Extensions (Tools menu items, main toolbar menu buttons)   
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ 
"MenuText" = "Sun Java Konsole" 
"CLSIDExtension" = "{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}" 
  -> {HKLM...CLSID} = "Java Plug-in 1.6.0_05" 
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."]   
{2670000A-7350-4F3C-8081-5663EE0C6C49}\ 
"ButtonText" = "An OneNote senden" 
"MenuText" = "An OneNote s&enden" 
"CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}" 
  -> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll" [MS]   
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ 
"ButtonText" = "Research"   
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ 
"MenuText" = "Spybot - Search & Destroy Configuration" 
"CLSIDExtension" = "{53707962-6F74-2D53-2644-206D7942484F}" 
  -> {HKLM...CLSID} = "Spybot-S&D IE Protection" 
                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]   
{E59EB121-F339-4851-A3BA-FE49C35617C2}\ 
"ButtonText" = "ICQ6" 
"MenuText" = "ICQ6" 
"Exec" = "C:\Program Files\ICQ6\ICQ.exe" ["ICQ, Inc."]     
Running Services (Display Name, Service Name, Path {Service DLL}): 
------------------------------------------------------------------   
Agere Modem Call Progress Audio, AgereModemAudio, "C:\Windows\system32\agrsmsvc.exe" ["Agere Systems"] 
Automatische WLAN-Konfiguration, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\wlansvc.dll" [MS]} 
Avira AntiVir Personal – Free Antivirus Guard, AntiVirService, ""C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe"" ["Avira GmbH"] 
Avira AntiVir Personal – Free Antivirus Planer, AntiVirScheduler, ""C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe"" ["Avira GmbH"] 
Bluetooth-Unterstützungsdienst, BthServ, "C:\Windows\system32\svchost.exe -k bthsvcs" {"C:\Windows\System32\bthserv.dll" [MS]} 
CNG-Schlüsselisolation, KeyIso, "C:\Windows\system32\lsass.exe" [MS] 
Computerbrowser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\browser.dll" [MS]} 
Cyberlink RichVideo Service(CRVS), RichVideo, ""C:\Program Files\CyberLink\Shared Files\RichVideo.exe"" [empty string] 
Extensible Authentication-Protokoll, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\eapsvc.dll" [MS]} 
Messenger USN Journal Reader-Service für freigegebene Ordner, usnjsvc, ""C:\Program Files\Windows Live\Messenger\usnsvc.exe"" [MS] 
O2Micro Flash Memory Card Service, o2flash, ""C:\Program Files\O2Micro Oz128 Driver\o2flash.exe"" ["O2Micro International"] 
SCM Driver Daemon, NishService, "C:\Program Files\System Control Manager\edd.exe" [null data] 
SSTP-Dienst, SstpSvc, "C:\Windows\system32\svchost.exe -k LocalService" {"C:\Windows\system32\sstpsvc.dll" [MS]} 
TuneUp Designerweiterung, UxTuneUp, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\uxtuneup.dll" ["TuneUp Software GmbH"]} 
Windows Driver Foundation - Benutzermodus-Treiberframework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]} 
Windows Media Player-Netzwerkfreigabedienst, WMPNetworkSvc, ""C:\Program Files\Windows Media Player\wmpnetwk.exe"" [MS] 
Windows-Bilderfassung, stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]} 
Zugriff auf Eingabegeräte, hidserv, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\system32\hidserv.dll" [MS]}     
Print Monitors: 
---------------   
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ 
Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS] 
SUGS2 Langmon\Driver = "sugs2l3.dll" [empty string]     
---------- (launch time: 2008-06-26 16:53:58) 
<<!>>: Suspicious data at a malware launch point.   
+ This report excludes default entries except where indicated. 
+ To see *everywhere* the script checks and *everything* it finds, 
  launch it from a command prompt or a shortcut with the -all parameter. 
+ To search all directories of local fixed drives for DESKTOP.INI 
  DLL launch points, use the -supp parameter or answer "No" at the 
  first message box and "Yes" at the second message box. 
---------- (total run time: 55 seconds, including 18 seconds for message boxes)      |