1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
205.
206.
207.
208.
209.
210.
211.
212.
213.
214.
215.
216.
217.
218.
219.
220.
221.
222.
223.
224.
225.
226.
227.
228.
229.
230.
231.
232.
233.
234.
235.
236.
237.
238.
239.
240.
241.
242.
243.
244.
245.
246.
247.
248.
249.
250.
251.
252.
253.
254.
255.
256.
257.
258.
259.
260.
261.
262.
263.
264.
265.
266.
267.
268.
269.
270.
271.
272.
273.
274.
275.
276.
277.
278.
279.
280.
281.
282.
283.
284.
285.
286.
287.
288.
289.
290.
291.
292.
293.
294.
295.
296.
297.
298.
299.
300.
301.
302.
303.
304.
305.
306.
307.
308.
309.
310.
311.
312.
313.
314.
315.
316.
317.
318.
319.
320.
321.
322.
323.
324.
325.
326.
327.
328.
329.
330.
331.
332.
333.
334.
335.
336.
337.
338.
339.
340.
341.
342.
343.
344.
345.
346.
347.
348.
349.
350.
351.
352.
353.
354.
355.
356.
357.
358.
359.
360.
361.
362.
363.
364.
365.
366.
367.
368.
369.
370.
371.
372.
373.
374.
375.
376.
377.
378.
379.
380.
381.
382.
383.
384.
385.
386.
387.
388.
389.
390.
391.
392.
393.
394.
395.
396.
397.
398.
399.
400.
401.
402.
403.
404.
405.
406.
407.
408.
409.
410.
411.
412.
413.
414.
415. | "Silent Runners.vbs", revision 72, http://www.silentrunners.org/
Operating System: Microsoft Windows 10 Pro (64-bit), Version 1903
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
OneDrive = "C:\Users\daw\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background [MS]
WTFast Tray = "C:\Program Files (x86)\WTFast\WTFast.exe" trayonly [null data]
CCleaner Smart Cleaning = "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [Piriform Software Ltd]
ExpressVPN4 = C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPN.exe [null data]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
SecurityHealth = C:\WINDOWS\system32\SecurityHealthSystray.exe
jv16 PT (System Startup Check) = "C:\Program Files (x86)\jv16 PowerTools\jv16pt_PreWorker2.exe" /SysStartupCheck /PT:"C:\Program Files (x86)\jv16 PowerTools\" [null data]
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ {++}
IAStorIcon = C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 [Intel Corporation]
OnScreen Control = C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreenStartUpApp.exe [TODO: <Company name>]
Live Update = C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER [Micro-Star INT'L CO., LTD.]
MSIRegister = "C:\MSI\MSIRegister\MSIRegister.exe" [null data]
SunJavaUpdateSched = "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [Oracle Corporation]
Aimersoft Helper Compact.exe = C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [AimerSoft]
ExpressVPNNotificationService = "C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe" [ExpressVPN]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\(Default) = Skype for Business Click to Call BHO
-> {HKLM...CLSID} = Skype for Business Browser Helper
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office15\OCHelper.dll [MS]
-> {HKLM...Wow...CLSID} = Skype for Business Browser Helper
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [MS]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
-> {HKLM...CLSID} = Java(tm) Plug-In SSV Helper
\InProcServer32\(Default) = C:\Program Files\Java\jre1.8.0_221\bin\ssv.dll [Oracle Corporation]
{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\(Default) = (no title provided)
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Browser Helper
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
-> {HKLM...Wow...CLSID} =
\InProcServer32\(Default) = [file not found]
{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
-> {HKLM...CLSID} = Java(tm) Plug-In 2 SSV Helper
\InProcServer32\(Default) = C:\Program Files\Java\jre1.8.0_221\bin\jp2ssv.dll [Oracle Corporation]
{EC1E29BB-F56A-45D8-B023-D3EF710FA0E0}\(Default) = ScriptInjectionPluginBrowserHelperObject
-> {HKLM...CLSID} = Kaspersky Protection
\InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\IEExt\ie_plugin.dll [AO Kaspersky Lab]
-> {HKLM...Wow...CLSID} = Kaspersky Protection
\InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\IEExt\ie_plugin.dll [AO Kaspersky Lab]
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\(Default) = Lync Click to Call BHO
-> {HKLM...CLSID} = Skype for Business Browser Helper
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office15\OCHelper.dll [MS]
-> {HKLM...Wow...CLSID} = Skype for Business Browser Helper
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [MS]
{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\(Default) = (no title provided)
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Browser Helper
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
-> {HKLM...Wow...CLSID} =
\InProcServer32\(Default) = [file not found]
{EC1E29BB-F56A-45D8-B023-D3EF710FA0E0}\(Default) = ScriptInjectionPluginBrowserHelperObject
-> {HKLM...CLSID} = Kaspersky Protection
\InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\IEExt\ie_plugin.dll [AO Kaspersky Lab]
-> {HKLM...Wow...CLSID} = Kaspersky Protection
\InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\IEExt\ie_plugin.dll [AO Kaspersky Lab]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\
GoogleDriveBlacklisted\(Default) = {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}
-> {HKLM...CLSID} = Google Drive Shell extension
\InProcServer32\(Default) = C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [Google]
GoogleDriveSynced\(Default) = {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}
-> {HKLM...CLSID} = Google Drive Shell extension
\InProcServer32\(Default) = C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [Google]
GoogleDriveSyncing\(Default) = {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}
-> {HKLM...CLSID} = Google Drive Shell extension
\InProcServer32\(Default) = C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [Google]
OneDrive6\(Default) = {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
-> {HKCU...CLSID} = ReadOnlyOverlayHandler Class
\InProcServer32\(Default) = C:\Users\daw\AppData\Local\Microsoft\OneDrive\19.192.0926.0012\amd64\FileSyncShell64.dll [MS]
OneDrive7\(Default) = {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}
-> {HKCU...CLSID} = UpToDateUnpinnedOverlayHandler Class
\InProcServer32\(Default) = C:\Users\daw\AppData\Local\Microsoft\OneDrive\19.192.0926.0012\amd64\FileSyncShell64.dll [MS]
SkyDrivePro1 (ErrorConflict)\(Default) = {8BA85C75-763B-4103-94EB-9470F12FE0F7}
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict)
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
SkyDrivePro2 (SyncInProgress)\(Default) = {CD55129A-B1A1-438E-A425-CEBC7DC684EE}
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress)
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
SkyDrivePro3 (InSync)\(Default) = {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync)
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
GGDriveOverlay1\(Default) = {E68D0A50-3C40-4712-B90D-DCFA93FF2534}
-> {HKLM...CLSID} = GGDriveOverlay1 Class
\InProcServer32\(Default) = C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [GG Network S.A.]
GGDriveOverlay2\(Default) = {E68D0A51-3C40-4712-B90D-DCFA93FF2534}
-> {HKLM...CLSID} = GGDriveOverlay2 Class
\InProcServer32\(Default) = C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [GG Network S.A.]
GGDriveOverlay3\(Default) = {E68D0A52-3C40-4712-B90D-DCFA93FF2534}
-> {HKLM...CLSID} = GGDriveOverlay3 Class
\InProcServer32\(Default) = C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [GG Network S.A.]
GGDriveOverlay4\(Default) = {E68D0A53-3C40-4712-B90D-DCFA93FF2534}
-> {HKLM...CLSID} = GGDriveOverlay4 Class
\InProcServer32\(Default) = C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [GG Network S.A.]
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\
OneDrive6\(Default) = {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
-> {HKCU...Wow...CLSID} = ReadOnlyOverlayHandler Class
\InProcServer32\(Default) = C:\Users\daw\AppData\Local\Microsoft\OneDrive\19.192.0926.0012\FileSyncShell.dll [MS]
OneDrive7\(Default) = {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}
-> {HKCU...Wow...CLSID} = UpToDateUnpinnedOverlayHandler Class
\InProcServer32\(Default) = C:\Users\daw\AppData\Local\Microsoft\OneDrive\19.192.0926.0012\FileSyncShell.dll [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\
{578480AA-1B1C-4343-AABD-62C0A273DCB5}
-> {HKLM...CLSID} = Cloud Cache Invalidator SSO
\InProcServer32\(Default) = C:\Windows\System32\Windows.CloudStore.dll [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
{09A47860-11B0-4DA5-AFA5-26D86198A780} = EPP
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Program Files\Windows Defender\shellext.dll [MS]
{B41DB860-64E4-11D2-9906-E49FADC173CA} = WinRAR shell extension
-> {HKLM...CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]
{8BA85C75-763B-4103-94EB-9470F12FE0F7} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict)
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict)
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
{CD55129A-B1A1-438E-A425-CEBC7DC684EE} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress)
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress)
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
{E768CD3B-BDDC-436D-9C13-E1B39CA257B1} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync)
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync)
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} = Microsoft SkyDrive Pro Browser Helper
-> {HKLM...CLSID} = Microsoft SkyDrive Pro Browser Helper
\InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office15\GROOVEEX.DLL [MS]
{0006F045-0000-0000-C000-000000000046} = Microsoft Outlook Custom Icon Handler
-> {HKLM...CLSID} = Outlook File Icon Extension
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office15\OLKFSTUB.DLL [MS]
{E68D0A50-3C40-4712-B90D-DCFA93FF2534} = GGDriveOverlay1
-> {HKLM...CLSID} = GGDriveOverlay1 Class
\InProcServer32\(Default) = C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [GG Network S.A.]
{E68D0A51-3C40-4712-B90D-DCFA93FF2534} = GGDriveOverlay2
-> {HKLM...CLSID} = GGDriveOverlay2 Class
\InProcServer32\(Default) = C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [GG Network S.A.]
{E68D0A52-3C40-4712-B90D-DCFA93FF2534} = GGDriveOverlay3
-> {HKLM...CLSID} = GGDriveOverlay3 Class
\InProcServer32\(Default) = C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [GG Network S.A.]
{E68D0A53-3C40-4712-B90D-DCFA93FF2534} = GGDriveOverlay4
-> {HKLM...CLSID} = GGDriveOverlay4 Class
\InProcServer32\(Default) = C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll [GG Network S.A.]
{AD392E40-428C-459F-961E-9B147782D099} = UltraISO
-> {HKLM...CLSID} = UIContextMenu Class
\InProcServer32\(Default) = C:\Program Files (x86)\UltraISO\isoshl64.dll [EZB Systems, Inc.]
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler
-> {HKLM...CLSID} = Microsoft Office Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\OFFICE15\msoshext.dll [MS]
{42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office15\msohevi.dll [MS]
{B28AA736-876B-46DA-B3A8-84C5E30BA492} = Witryny sieci Web
-> {HKLM...CLSID} = Witryny sieci Web
\InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE15\WXPNSE.DLL [MS]
{755D388B-420B-4692-A974-84AAF0E577D3} = Scan with Kaspersky Anti-Virus
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\ShellEx.dll [AO Kaspersky Lab]
{0875DCB6-C686-4243-9432-ADCCF0B9F2D7} = Microsoft OneNote Namespace Extension for Windows Desktop Search
-> {HKLM...CLSID} = Microsoft OneNote Namespace Extension for Windows Desktop Search
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\Office16\ONFILTER.DLL [MS]
{E3956DCF-D1C7-4375-AAAA-22FF8191C479} = Microsoft Access Metadata Handler
-> {HKLM...CLSID} = Microsoft Access Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{33154C99-BF49-443D-A73C-303A23ABBE97} = Microsoft Excel Metadata Handler
-> {HKLM...CLSID} = Microsoft Excel Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{01BE4CFB-129A-452B-A209-F9D40B3B84A5} = Microsoft PowerPoint Metadata Handler
-> {HKLM...CLSID} = Microsoft PowerPoint Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{5383EF74-273B-4278-AB0C-CDAA9FD5369E} = Microsoft Visio Metadata Handler
-> {HKLM...CLSID} = Microsoft Visio Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{5985FC23-2588-4D9A-B38B-7E7AFFAB3155} = Microsoft Word Metadata Handler
-> {HKLM...CLSID} = Microsoft Word Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Access Thumbnail Handler
-> {HKLM...CLSID} = Microsoft Access Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{72B66649-3DBF-429F-BD6F-7774A9784B78} = Microsoft Excel Thumbnail Handler
-> {HKLM...CLSID} = Microsoft Excel Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{35C5242B-7455-4F9C-962B-369EA43ED6F3} = Microsoft PowerPoint Thumbnail Handler
-> {HKLM...CLSID} = Microsoft PowerPoint Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{AFE9E2F0-5BBA-4169-A33B-EE3727AC3482} = Microsoft Visio Thumbnail Handler
-> {HKLM...CLSID} = Microsoft Visio Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{355822FC-86F1-4BE8-B5F0-A33736789641} = Microsoft Word Thumbnail Handler
-> {HKLM...CLSID} = Microsoft Word Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\msoshext.dll [MS]
{506F4668-F13E-4AA1-BB04-B43203AB3CC0} = {506F4668-F13E-4AA1-BB04-B43203AB3CC0}
-> {HKLM...CLSID} = ImageExtractorShellExt Class
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\Office16\VISSHE.DLL [MS]
{D66DC78C-4F61-447F-942B-3FB6980118CF} = {D66DC78C-4F61-447F-942B-3FB6980118CF}
-> {HKLM...CLSID} = CInfoTipShellExt Class
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\Office16\VISSHE.DLL [MS]
{5E2121EE-0300-11D4-8D3B-444553540000} = Catalyst Context Menu extension
-> {HKLM...CLSID} = SimpleShlExt Class
\InProcServer32\(Default) = C:\Program Files\AMD\CNext\CNext\atiacm64.dll [Advanced Micro Devices, Inc.]
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
{DB19096C-5365-4164-A246-59FEFF9D8062} = Nameext
-> {HKLM...Wow...CLSID} = Projekty w przedsiębiorstwie
\InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office15\NAMEEXT.DLL [MS]
{0006F045-0000-0000-C000-000000000046} = Microsoft Outlook Custom Icon Handler
-> {HKLM...Wow...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office15\OLKFSTUB.DLL [MS]
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler
-> {HKLM...Wow...CLSID} = Microsoft Office Metadata Handler
\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\msoshext.dll [MS]
{00F33137-EE26-412F-8D71-F84E4C2C6625} = (no title provided)
-> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
\InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
{00F346CB-35A4-465B-8B8F-65A29DBAB1F6} = Windows Live Photo Gallery Viewer Drop Target Shim
-> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Shim
\InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} = Windows Live Photo Gallery Editor Drop Target Shim
-> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Editor Shim
\InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
{00F30F90-3E96-453B-AFCD-D71989ECC2C7} = Windows Live Photo Gallery Autoplay Drop Target Shim
-> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim
\InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS]
{755D388B-420B-4692-A974-84AAF0E577D3} = Scan with Kaspersky Anti-Virus
-> {HKLM...Wow...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\shellex.dll [AO Kaspersky Lab]
{E3956DCF-D1C7-4375-AAAA-22FF8191C479} = Microsoft Access Metadata Handler
-> {HKLM...Wow...CLSID} = Microsoft Access Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{33154C99-BF49-443D-A73C-303A23ABBE97} = Microsoft Excel Metadata Handler
-> {HKLM...Wow...CLSID} = Microsoft Excel Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{01BE4CFB-129A-452B-A209-F9D40B3B84A5} = Microsoft PowerPoint Metadata Handler
-> {HKLM...Wow...CLSID} = Microsoft PowerPoint Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{5383EF74-273B-4278-AB0C-CDAA9FD5369E} = Microsoft Visio Metadata Handler
-> {HKLM...Wow...CLSID} = Microsoft Visio Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{5985FC23-2588-4D9A-B38B-7E7AFFAB3155} = Microsoft Word Metadata Handler
-> {HKLM...Wow...CLSID} = Microsoft Word Metadata Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Access Thumbnail Handler
-> {HKLM...Wow...CLSID} = Microsoft Access Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{72B66649-3DBF-429F-BD6F-7774A9784B78} = Microsoft Excel Thumbnail Handler
-> {HKLM...Wow...CLSID} = Microsoft Excel Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{35C5242B-7455-4F9C-962B-369EA43ED6F3} = Microsoft PowerPoint Thumbnail Handler
-> {HKLM...Wow...CLSID} = Microsoft PowerPoint Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{AFE9E2F0-5BBA-4169-A33B-EE3727AC3482} = Microsoft Visio Thumbnail Handler
-> {HKLM...Wow...CLSID} = Microsoft Visio Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
{355822FC-86F1-4BE8-B5F0-A33736789641} = Microsoft Word Thumbnail Handler
-> {HKLM...Wow...CLSID} = Microsoft Word Thumbnail Handler
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\msoshext.dll [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\
{C5D7540A-CD51-453B-B22B-05305BA03F07}\(Default) = Cloud Experience Credential Provider
-> {HKLM...CLSID} = Cloud Experience Credential Provider
\InProcServer32\(Default) = C:\Windows\System32\cxcredprov.dll [MS]
{F8A1793B-7873-4046-B2A7-1F318747F427}\(Default) = FIDO Credential Provider
-> {HKLM...CLSID} = FIDO Credential Provider
\InProcServer32\(Default) = C:\WINDOWS\system32\fidocredprov.dll [MS]
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\
{6cfb9c5c-138e-4bb3-8a3d-d5383e910e57}\DllName = C:\WINDOWS\System32\RdpGroupPolicyExtension.dll [file not found]
{CFF649BD-601D-4361-AD3D-0FC365DB4DB7}\DllName = C:\WINDOWS\system32\domgmt.dll [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = {807583E5-5146-11D5-A672-00B0D022E945}
-> {HKLM...CLSID} = Microsoft Office InfoPath XML Mime Filter
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLMF.DLL [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\
<<!>> ms-help\CLSID = {314111c7-a502-11d2-bbca-00c04f8ec294}
-> {HKLM...CLSID} = HxProtocol Class
\InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll [MS]
<<!>> mso-minsb-roaming.16\CLSID = {83C25742-A9F7-49FB-9138-434302C88D07}
-> {HKLM...CLSID} = Min Sandbox Protocol Roaming Class
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [MS]
<<!>> mso-minsb.16\CLSID = {42089D2D-912D-4018-9087-2B87803E93FB}
-> {HKLM...CLSID} = Min Sandbox Protocol Class
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [MS]
<<!>> osf\CLSID = {D924BDC6-C83A-4BD5-90D0-095128A113D1}
-> {HKLM...CLSID} = Protocol Class
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [MS]
<<!>> osf-roaming.16\CLSID = {42089D2D-912D-4018-9087-2B87803E93FB}
-> {HKLM...CLSID} = Min Sandbox Protocol Class
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [MS]
<<!>> osf.16\CLSID = {5504BE45-A83B-4808-900A-3A5C36E7F77A}
-> {HKLM...CLSID} = Protocol Class
\InProcServer32\(Default) = C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [MS]
HKCU\Software\Classes\*\shellex\ContextMenuHandlers\
GGDriveMenu\(Default) = {E68D0A55-3C40-4712-B90D-DCFA93FF2534}
-> {HKCU...CLSID} = GGDriveMenu Class
\InProcServer32\(Default) = C:\Users\daw\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll [GG Network S.A.]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
GDContextMenu\(Default) = {BB02B294-8425-42E5-983F-41A1FA970CD6}
-> {HKLM...CLSID} = GDContextMenu Class
\InProcServer32\(Default) = C:\Program Files (x86)\Google\Drive\contextmenu64.dll [Google]
Kaspersky Anti-Virus 19.0.0\(Default) = {755D388B-420B-4692-A974-84AAF0E577D3}
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\ShellEx.dll [AO Kaspersky Lab]
-> {HKLM...Wow...CLSID} = (no title provided)
\InProcServer32\(Default) = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\shellex.dll [AO Kaspersky Lab]
WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}
-> {HKLM...CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]
WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
-> {HKLM...Wow...CLSID} = WinRAR
\InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]
HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
-> {HKLM...CLSID} = MBAMShlExt Class
\InProcServer32\(Default) = C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [Malwarebytes]
|