
- Kod: Zaznacz wszystko
- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
 "WinService" = "c:\windows\system32\explorer.exe" ["xxxx"]
 "Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]
 "Windows anti virus Layer" = "jotzminevbd.exe" [null data]
 "STYLEXP" = "C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide" [empty string]
 "road atom" = "C:\DOCUME~1\SZYMON~1.PEK\DANEAP~1\FLAPPL~1\popmathbat.exe" [null data]
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ {++}
 "isamonitor.exe" = "C:\Program Files\Video ActiveX Object\isamonitor.exe" [null data]
 "pmsngr.exe" = "C:\Program Files\Video ActiveX Object\pmsngr.exe" [null data]
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]
 "OM- Counter 2.4 Beta" = ""C:\Program Files\OMDigit\OM- Counter 2.4 Beta\OMCounterApp.exe"" ["OMDigit"]
 "SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
 "AVKTray" = ""C:\Program Files\AntiVirenKit 2006\AVKTray\AVKTray.exe"" ["G DATA Software"]
 "DAEMON Tools" = ""C:\Program Files\DAEMON Tools\daemon.exe" -lang 1045" ["DT Soft Ltd."]
 "Windows anti virus Layer" = "jotzminevbd.exe" [null data]
 "NvMediaCenter" = "RunDLL32.exe NvMCTray.dll,NvTaskbarInit" [MS]
 "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
 {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "AcroIEHlprObj Class"
 \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
 {1a1ddc19-5893-43ab-a73f-f41a0f34d115}\(Default) = (no title provided)
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Program Files\Video ActiveX Object\isaddon.dll" [null data]
 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "SSVHelper Class"
 \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll" ["Sun Microsystems, Inc."]
 {F97DA966-F09D-4cab-BF29-75A0026986EA}\(Default) = "XBTP02634"
 -> {HKLM...CLSID} = "XBTP02634 Class"
 \InProcServer32\(Default) = "C:\PROGRA~1\BEARSH~2\BEARSH~1\MediaBar.dll" ["IE Toolbar"]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
 "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
 -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
 "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
 -> {HKLM...CLSID} = "DesktopContext Class"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
 "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
 -> {HKLM...CLSID} = "Desktop Explorer"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
 -> {HKLM...CLSID} = "nView Desktop Context Menu"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
 "{8D1636FD-CA49-4B4E-90E4-0A20E03A15E8}" = "jetAudio"
 -> {HKLM...CLSID} = "JetFlExt"
 \InProcServer32\(Default) = "C:\Program Files\JetAudio\JetFlExt.dll" ["JetAudio, Inc."]
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
 -> {HKLM...CLSID} = "Portable Media Devices"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
 "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
 -> {HKLM...CLSID} = "Portable Media Devices Menu"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
 "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}" = "PowerISO"
 -> {HKLM...CLSID} = "PowerISO"
 \InProcServer32\(Default) = "C:\Program Files\PowerISO\PowerISOShell.dll" ["PowerISO Computing, Inc."]
 "{e82a2d71-5b2f-43a0-97b8-81be15854de8}" = "ShellLink for Application References"
 -> {HKLM...CLSID} = "ShellLink for Application References"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\dfshim.dll" [MS]
 "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}" = "Shell Icon Handler for Application References"
 -> {HKLM...CLSID} = "Shell Icon Handler for Application References"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\dfshim.dll" [MS]
 "{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
 -> {HKLM...CLSID} = "AlcoholShellEx"
 \InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\axshlex.dll" ["Alcohol Soft Development Team"]
 "{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
 -> {HKLM...CLSID} = "Shell Search Band"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
 "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
 -> {HKLM...CLSID} = "NVIDIA CPL Extension"
 \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
 HKLM\System\CurrentControlSet\Control\Session Manager\
 INFECTION WARNING! "BootExecute" = "PDBoot.exe autocheck autochk *" [file not found], [file not found], [MS], [file not found]
 HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
 AVK9CM\(Default) = "{CAF4C320-32F5-11D3-A222-004095200FF2}"
 -> {HKLM...CLSID} = "AVK9ContextMenue"
 \InProcServer32\(Default) = "C:\Program Files\AntiVirenKit 2006\ShellExt.dll" [empty string]
 PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
 -> {HKLM...CLSID} = "PowerISO"
 \InProcServer32\(Default) = "C:\Program Files\PowerISO\PowerISOShell.dll" ["PowerISO Computing, Inc."]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
 jetAudio\(Default) = "{8D1636FD-CA49-4B4E-90E4-0A20E03A15E8}"
 -> {HKLM...CLSID} = "JetFlExt"
 \InProcServer32\(Default) = "C:\Program Files\JetAudio\JetFlExt.dll" ["JetAudio, Inc."]
 PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
 -> {HKLM...CLSID} = "PowerISO"
 \InProcServer32\(Default) = "C:\Program Files\PowerISO\PowerISOShell.dll" ["PowerISO Computing, Inc."]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
 AVK9CM\(Default) = "{CAF4C320-32F5-11D3-A222-004095200FF2}"
 -> {HKLM...CLSID} = "AVK9ContextMenue"
 \InProcServer32\(Default) = "C:\Program Files\AntiVirenKit 2006\ShellExt.dll" [empty string]
 jetAudio\(Default) = "{8D1636FD-CA49-4B4E-90E4-0A20E03A15E8}"
 -> {HKLM...CLSID} = "JetFlExt"
 \InProcServer32\(Default) = "C:\Program Files\JetAudio\JetFlExt.dll" ["JetAudio, Inc."]
 PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
 -> {HKLM...CLSID} = "PowerISO"
 \InProcServer32\(Default) = "C:\Program Files\PowerISO\PowerISOShell.dll" ["PowerISO Computing, Inc."]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 Active Desktop and Wallpaper:
 -----------------------------
 Active Desktop is disabled at this entry:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
 HKCU\Control Panel\Desktop\
 "Wallpaper" = "C:\Documents and Settings\Szymon.PEKIN-BC5VP8MD3\Dane aplikacji\Mozilla\Firefox\Tapeta pulpitu.bmp"
 Enabled Screen Saver:
 ---------------------
 HKCU\Control Panel\Desktop\
 "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
 Enabled Scheduled Tasks:
 ------------------------
 "AFF0024293CBB5BA" -> launches: "c:\docume~1\szymon~1.pek\daneap~1\flappl~1\VIEWMOVESEEK.exe" [null data]
 Winsock2 Service Provider DLLs:
 -------------------------------
 Namespace Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 Transport Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
 %SystemRoot%\system32\mswsock.dll [MS], 01 - 04, 07 - 18
 %SystemRoot%\system32\rsvpsp.dll [MS], 05 - 06
 Toolbars, Explorer Bars, Extensions:
 ------------------------------------
 Toolbars
 HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
 "{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}"
 -> {HKLM...CLSID} = "BearShare MediaBar"
 \InProcServer32\(Default) = "C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll" ["IE Toolbar"]
 HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
 "{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}"
 -> {HKLM...CLSID} = "BearShare MediaBar"
 \InProcServer32\(Default) = "C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll" ["IE Toolbar"]
 "{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F}"
 -> {HKLM...CLSID} = "Protection Bar"
 \InProcServer32\(Default) = "C:\Program Files\Video ActiveX Object\iesplugin.dll" [null data]
 HKLM\Software\Microsoft\Internet Explorer\Toolbar\
 "{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}" = (no title provided)
 -> {HKLM...CLSID} = "BearShare MediaBar"
 \InProcServer32\(Default) = "C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll" ["IE Toolbar"]
 "{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F}" = (no title provided)
 -> {HKLM...CLSID} = "Protection Bar"
 \InProcServer32\(Default) = "C:\Program Files\Video ActiveX Object\iesplugin.dll" [null data]
 Extensions (Tools menu items, main toolbar menu buttons)
 HKLM\Software\Microsoft\Internet Explorer\Extensions\
 {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
 "MenuText" = "Sun Java Console"
 "CLSIDExtension" = "{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}"
 -> {HKCU...CLSID} = "Java Plug-in 1.5.0_08"
 \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll" ["Sun Microsystems, Inc."]
 -> {HKLM...CLSID} = "Java Plug-in 1.5.0_08"
 \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll" ["Sun Microsystems, Inc."]
 Miscellaneous IE Hijack Points
 ------------------------------
 HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
 Missing lines (compared with English-language version):
 "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = (no title provided)
 -> {HKLM...CLSID} = "Search Class"
 \InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL" [empty string]
 "{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A}" = (no title provided)
 -> {HKLM...CLSID} = "BearShare MediaBar"
 \InProcServer32\(Default) = "C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll" ["IE Toolbar"]
 Running Services (Display Name, Service Name, Path {Service DLL}):
 ------------------------------------------------------------------
 Autodata Limited License Service, Autodata Limited License Service, ""C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe"" [null data]
 AVK Service, AVKService, "C:\Program Files\AntiVirenKit 2006\AVKService.exe" [empty string]
 AVKProxy, AVKProxy, ""C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe"" ["G DATA Software AG"]
 l2, l2, "C:\WINDOWS\system32\ll2.exe -s" [null data]
 NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"]
 Pml Driver HPZ12, Pml Driver HPZ12, "C:\WINDOWS\System32\HPZipm12.exe" ["HP"]
 StarWind iSCSI Service, StarWindService, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]
 Strażnik AVK, AVKWCtl, "C:\Program Files\AntiVirenKit 2006\AVKWCtl.exe" [empty string]
 Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]
 Print Monitors:
 ---------------
 HKLM\System\CurrentControlSet\Control\Print\Monitors\
 HP Standard TCP/IP Port\Driver = "HpTcpMon.dll" ["Hewlett Packard"]
 hpzsnt12\Driver = "hpzsnt12.dll" ["HP"]
 ----------
 + This report excludes default entries except where indicated.
 + To see *everywhere* the script checks and *everything* it finds,
 launch it from a command prompt or a shortcut with the -all parameter.
 + To search all directories of local fixed drives for DESKTOP.INI
 DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
 use the -supp parameter or answer "No" at the first message box.
 ---------- (total run time: 34 seconds, including 5 seconds for message boxes)
problemy sa takie przy wlanczaniu przegladarki wyskakuja dodatkowe okienka , w Firefoksie zablokowane jest dodawanie zakładek i prosiłbym jesli to mozliwe o zmiejszenie ilosci procesow

 
	
 
	 
 
	
 
 