REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "gcasServ"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\"" "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\Integrity Client\\iclient.exe\"" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "winsync"="C:\\WINDOWS\\System32\\glxd4d.exe reg_run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" ----------------- HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers Subkey --- LDVPMenu {BDA77241-42F6-11d0-85E2-00AA001FE28C} C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll Subkey --- nfsqtkqt {1174ac1a-860b-4ef8-89da-a192639232ea} Subkey --- Offline Files {750fdf0e-2a26-11d1-a3ea-080036587f03} C:\WINDOWS\System32\cscui.dll Subkey --- Open With {09799AFB-AD67-11d1-ABCD-00C04FC30936} C:\WINDOWS\system32\SHELL32.dll Subkey --- Open With EncryptionMenu {A470F8CF-A1E8-4f65-8335-227475AA5C46} C:\WINDOWS\system32\SHELL32.dll Subkey --- WinRAR Subkey --- WinZip {E0D79300-84BE-11CE-9641-444553540000} C:\PROGRA~1\WinZip\wzshlext.dll Subkey --- Yahoo! Mail {5464D816-CF16-4784-B9F3-75C0DB52B499} C:\PROGRA~1\Yahoo!\Common\ymmapi.dll Subkey --- {a2a9545d-a0c2-42b4-9708-a0b2badd77c8} Start Menu Pin C:\WINDOWS\system32\SHELL32.dll ===================== HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers Subkey --- {0D2E74C4-3C34-11d2-A27E-00C04FC30871} C:\WINDOWS\system32\SHELL32.dll Subkey --- {24F14F01-7B1C-11d1-838f-0000F80461CF} C:\WINDOWS\system32\SHELL32.dll Subkey --- {24F14F02-7B1C-11d1-838f-0000F80461CF} C:\WINDOWS\system32\SHELL32.dll Subkey --- {66742402-F9B9-11D1-A202-0000F81FEDEE} C:\WINDOWS\system32\SHELL32.dll ============================== C:\Documents and Settings\All Users\Start Menu\Programs\Startup DESKTOP.INI knut.exe ============================== C:\Documents and Settings\Arvind\Start Menu\Programs\Startup DESKTOP.INI knut.exe DESKTOP.INI ============================== C:\WINDOWS\SYSTEM32 cpl files ACCESS.CPL Microsoft Corporation appwiz.cpl Microsoft Corporation desk.cpl Microsoft Corporation HDWWIZ.CPL Microsoft Corporation inetcpl.cpl Microsoft Corporation intl.cpl Microsoft Corporation joy.cpl Microsoft Corporation jpicpl32.cpl Sun Microsystems, Inc. MAIN.CPL Microsoft Corporation MMSYS.CPL Microsoft Corporation NCPA.CPL Microsoft Corporation NUSRMGR.CPL Microsoft Corporation ODBCCP32.CPL Microsoft Corporation POWERCFG.CPL Microsoft Corporation QuickTime.cpl Apple Computer, Inc. sysdm.cpl Microsoft Corporation TELEPHON.CPL Microsoft Corporation TIMEDATE.CPL Microsoft Corporation vgactl.cpl wuaucpl.cpl Microsoft Corporation