I have scanned my computer
with both and here is what they turned up with -
------------------------WinPFind------------------------»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
UPX! 12/6/2004 4:29:22 PM 636368828 C:\movie2.2_again.avi
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
PECompact2 7/21/2005 10:16:24 AM 15400675 C:\WINDOWS\lpt$vpn.741
qoologic 7/21/2005 10:16:24 AM 15400675 C:\WINDOWS\lpt$vpn.741
SAHAgent 7/21/2005 10:16:24 AM 15400675 C:\WINDOWS\lpt$vpn.741
UPX! 5/3/2005 11:44:44 AM 25157 C:\WINDOWS\RMAgentOutput.dll
UPX! 11/17/2004 10:23:48 PM 18432 C:\WINDOWS\ss3unstl.exe
UPX! 1/10/2005 4:17:24 PM 170053 C:\WINDOWS\tsc.exe
PECompact2 7/21/2005 10:16:24 AM 15400675 C:\WINDOWS\VPTNFILE.741
qoologic 7/21/2005 10:16:24 AM 15400675 C:\WINDOWS\VPTNFILE.741
SAHAgent 7/21/2005 10:16:24 AM 15400675 C:\WINDOWS\VPTNFILE.741
UPX! 2/18/2005 6:40:14 PM 1044560 C:\WINDOWS\vsapi32.dll
aspack 2/18/2005 6:40:14 PM 1044560 C:\WINDOWS\vsapi32.dll
Checking %System% folder...
aspack 8/12/2004 9:28:46 PM 214016 C:\WINDOWS\SYSTEM32\Air Comand.SCR
aspack 3/18/2005 5:19:58 PM 2337488 C:\WINDOWS\SYSTEM32\d3dx9_25.dll
PEC2 8/23/2001 7:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
aspack 3/27/2003 6:37:34 AM 208896 C:\WINDOWS\SYSTEM32\HDBHO.dll
aspack 7/24/2004 3:02:32 PM 129536 C:\WINDOWS\SYSTEM32\IJL15.dll
aspack 7/24/2004 3:02:32 PM 804864 C:\WINDOWS\SYSTEM32\ImgX5.dll
aspack 8/12/2004 9:28:46 PM 214016 C:\WINDOWS\SYSTEM32\jets.SCR
UPX! 7/9/2002 11:30:06 PM 71680 C:\WINDOWS\SYSTEM32\macdll.dll
UPX! 12/3/2004 2:10:56 AM 401927 C:\WINDOWS\SYSTEM32\mioengine.exe
UPX! 5/23/2003 5:08:52 AM 20992 C:\WINDOWS\SYSTEM32\ogg.dll
Umonitor 8/28/2002 10:41:10 PM 631808 C:\WINDOWS\SYSTEM32\rasdlg.dll
UPX! 3/30/2004 2:15:02 AM 23040 C:\WINDOWS\SYSTEM32\ThriXXX010104Z.dll
UPX! 3/30/2004 2:15:02 AM 51200 C:\WINDOWS\SYSTEM32\ThriXXX010205PNG.dll
UPX! 3/30/2004 2:15:02 AM 56832 C:\WINDOWS\SYSTEM32\ThriXXX015003JP2.dll
UPX! 5/23/2003 5:08:52 AM 107008 C:\WINDOWS\SYSTEM32\vorbis.dll
winsync 8/23/2001 7:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
aspack 7/24/2004 3:02:32 PM 424960 C:\WINDOWS\SYSTEM32\_ISource21.dll
Checking %System%\Drivers folder and sub-folders...
Checking the Windows folder for system and hidden files within the last 60 days...
6/30/2005 6:09:32 AM 0 C:\WINDOWS\inf\oem10.inf
5/28/2005 5:57:28 PM 0 C:\WINDOWS\LastGood\INF\ceres.PNF
6/29/2005 2:49:46 PM 0 C:\WINDOWS\LastGood\INF\d3dx9_24_x86.inf
6/29/2005 2:49:46 PM 0 C:\WINDOWS\LastGood\INF\d3dx9_24_x86.PNF
6/29/2005 2:49:46 PM 0 C:\WINDOWS\LastGood\INF\d3dx9_25_x86.inf
6/29/2005 2:49:46 PM 0 C:\WINDOWS\LastGood\INF\d3dx9_25_x86.PNF
7/20/2005 8:35:30 PM 0 C:\WINDOWS\LastGood\INF\oem11.inf
7/20/2005 8:35:30 PM 0 C:\WINDOWS\LastGood\INF\oem11.PNF
7/20/2005 12:57:28 PM 0 C:\WINDOWS\LastGood\INF\q903235.inf
7/20/2005 12:57:28 PM 0 C:\WINDOWS\LastGood\INF\q903235.PNF
11/13/2009 4:33:10 PM 2049 C:\WINDOWS\page files\maxmeg.sys
7/23/2005 4:25:28 AM 1024 C:\WINDOWS\system32\config\default.LOG
7/23/2005 4:25:14 AM 1024 C:\WINDOWS\system32\config\SAM.LOG
7/23/2005 4:25:28 AM 1024 C:\WINDOWS\system32\config\SECURITY.LOG
7/23/2005 4:25:50 AM 53248 C:\WINDOWS\system32\config\software.LOG
7/23/2005 4:25:36 AM 8192 C:\WINDOWS\system32\config\system.LOG
7/20/2005 12:59:04 PM 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini
7/20/2005 6:00:04 PM 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\0JCC64AM\desktop.ini
7/20/2005 6:00:04 PM 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\85JB84JF\desktop.ini
7/20/2005 6:00:04 PM 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OBS5OFKL\desktop.ini
7/20/2005 6:00:04 PM 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\PE53ZVVT\desktop.ini
6/29/2005 5:43:54 PM 824 C:\WINDOWS\system32\Logs\Net\20050629.log
6/30/2005 3:31:16 PM 242 C:\WINDOWS\system32\Logs\Net\20050630.log
7/1/2005 11:54:50 AM 292 C:\WINDOWS\system32\Logs\Net\20050701.log
7/4/2005 11:57:34 PM 170 C:\WINDOWS\system32\Logs\Net\20050704.log
7/5/2005 3:27:08 PM 242 C:\WINDOWS\system32\Logs\Net\20050705.log
7/6/2005 12:49:14 AM 121 C:\WINDOWS\system32\Logs\Net\20050706.log
7/19/2005 11:54:10 PM 752 C:\WINDOWS\system32\Logs\Net\20050719.log
7/20/2005 6:54:38 PM 929 C:\WINDOWS\system32\Logs\Net\20050720.log
7/21/2005 10:03:12 AM 354 C:\WINDOWS\system32\Logs\Net\20050721.log
7/22/2005 11:59:56 PM 70919 C:\WINDOWS\system32\Logs\Net\20050722.log
7/23/2005 4:22:38 AM 57677 C:\WINDOWS\system32\Logs\Net\20050723.log
5/25/2005 1:09:08 PM 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\781f14b2-4a96-4d96-8c78-d53870e68519
5/25/2005 1:09:08 PM 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
7/23/2005 4:22:48 AM 6 C:\WINDOWS\Tasks\SA.DAT
»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
Checking files in %ALLUSERSPROFILE%\Startup folder...
Checking files in %ALLUSERSPROFILE%\Application Data folder...
Checking files in %USERPROFILE%\Startup folder...
Checking files in %USERPROFILE%\Application Data folder...
3/13/2005 11:59:34 PM 45128 C:\Documents and Settings\Matthew\Application Data\GDIPFONTCACHEV1.DAT
»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\ESB{3A7B0035-6A18-4D94-B5A7-831C99410C88}
ESB{3A7B0035-6A18-4D94-B5A7-831C99410C88} =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\ESB{DD3B2EBF-A493-403A-B9C5-9C7A00442158}
ESB{DD3B2EBF-A493-403A-B9C5-9C7A00442158} =
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{CFC7205E-2792-4378-9591-3879CC6C9022}
= c:\progra~1\mcafee.com\vso\mcvsshl.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\{CFC7205E-2792-4378-9591-3879CC6C9022}
= c:\progra~1\mcafee.com\vso\mcvsshl.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{FED7043D-346A-414D-ACD7-550D052499A7}
= C:\Program Files\Illustrate\dBpowerAMP\dBShell.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
CTStartup C:\Program Files\Creative\SBAudigy\Program\CTEaxSpl.EXE /run
MCUpdateExe C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
MCAgentExe c:\PROGRA~1\mcafee.com\agent\mcagent.exe
VSOCheckTask "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
VirusScan Online "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
hgdedll C:\WINDOWS\hgdedll.EXE
lqxrenc C:\WINDOWS\lqxrenc.EXE
regsync C:\WINDOWS\System32\regsync.exe
FtkCPY "C:\Program Files\Common Files\Java\ftkcpy.exe"
richup C:\WINDOWS\System32\richup.exe
TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
WhenUSave "C:\Program Files\Save\Save.exe"
C2K C:\WINDOWS\Cyb2k.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
IMAIL
MAPI
MSFS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe C:\WINDOWS\System32\ctfmon.exe
MsnMsgr "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\{BDEADF00-C265-11D0-BCED-00A0C90AB50F}
= C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
=
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\{0DF44EAA-FF21-4412-828E-260A8728E7F1}
=
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun _
NoControlPanel 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network
NoNetSetup 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
DisableRegistryTools 0
DisableTaskMgr 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WinOldApp
Disabled 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
UserInit C:\WINDOWS\system32\userinit.exe,
Shell Explorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\0aMCPClient
{F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\PostBootReminder
{7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\CDBurn
{fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\WebCheck
{E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SysTray
{35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.2.2 - Log file written to "WinPFind.Txt" in the WinPFind folder.
------------------------Track Qoo------------------------REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTStartup"="C:\\Program Files\\Creative\\SBAudigy\\Program\\CTEaxSpl.EXE /run"
"MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"VSOCheckTask"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask"
"VirusScan Online"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe\""
"hgdedll"="C:\\WINDOWS\\hgdedll.EXE"
"lqxrenc"="C:\\WINDOWS\\lqxrenc.EXE"
"regsync"="C:\\WINDOWS\\System32\\regsync.exe"
"FtkCPY"="\"C:\\Program Files\\Common Files\\Java\\ftkcpy.exe\""
"richup"="C:\\WINDOWS\\System32\\richup.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"WhenUSave"="\"C:\\Program Files\\Save\\Save.exe\""
"C2K"="C:\\WINDOWS\\Cyb2k.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
-----------------
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
Subkey --- Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03}
C:\WINDOWS\System32\cscui.dll
Subkey --- Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936}
C:\WINDOWS\system32\SHELL32.dll
Subkey --- Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46}
C:\WINDOWS\system32\SHELL32.dll
Subkey --- WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA}
C:\Program Files\WinRAR\rarext.dll
Subkey --- WinZip
{E0D79304-84BE-11CE-9641-444553540000}
C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
Subkey --- {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin
C:\WINDOWS\system32\SHELL32.dll
Subkey --- {CFC7205E-2792-4378-9591-3879CC6C9022}
c:\progra~1\mcafee.com\vso\mcvsshl.dll
=====================
HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers
Subkey --- {0D2E74C4-3C34-11d2-A27E-00C04FC30871}
C:\WINDOWS\system32\SHELL32.dll
Subkey --- {24F14F01-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\system32\SHELL32.dll
Subkey --- {24F14F02-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\system32\SHELL32.dll
Subkey --- {66742402-F9B9-11D1-A202-0000F81FEDEE}
C:\WINDOWS\system32\SHELL32.dll
Subkey --- {FED7043D-346A-414D-ACD7-550D052499A7}
C:\Program Files\Illustrate\dBpowerAMP\dBShell.dll
==============================
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
desktop.ini
==============================
C:\Documents and Settings\Matthew\Start Menu\Programs\Startup
desktop.ini
desktop.ini
==============================
C:\WINDOWS\system32 cpl files
access.cpl Microsoft Corporation
appwiz.cpl Microsoft Corporation
AudioHQU.cpl Creative Technology Ltd.
CTDetect.cpl Creative Technology Ltd.
dapanel.cpl Ken Foster
desk.cpl Microsoft Corporation
hdwwiz.cpl Microsoft Corporation
inetcpl.cpl Microsoft Corporation
intl.cpl Microsoft Corporation
joy.cpl Microsoft Corporation
jpicpl32.cpl Sun Microsystems, Inc.
main.cpl Microsoft Corporation
mmsys.cpl Microsoft Corporation
ncpa.cpl Microsoft Corporation
nusrmgr.cpl Microsoft Corporation
nwc.cpl Microsoft Corporation
odbccp32.cpl Microsoft Corporation
powercfg.cpl Microsoft Corporation
QuickTime.cpl Apple Computer, Inc.
sysdm.cpl Microsoft Corporation
telephon.cpl Microsoft Corporation
timedate.cpl Microsoft Corporation
wuaucpl.cpl Microsoft Corporation[/B]