I just loaded a copy of XP Pro with SP2. Never had it connected to the internet, mind you...ran a scan on it and all kinds of goodies came up.
Name:Shell
Actual File:C:\WINDOWS\Explorer.exe <telnet connection
Working Folder:C:\WINDOWS\
Name:MSConfig
Actual File:C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
Working Folder:C:\WINDOWS\PCHealth\HelpCtr\Binaries\<any msconfig entry goes to user temp file, the same with regedit, mspaint notepad and wordpad...
[Network Settings]
[Hosts File Path] :HKLM DataBasePath=%SystemRoot%\System32\drivers\etc
[Hosts File Contents] :HKLM 127.0.0.1 localhost
[Domain Name] :HKLM Domain=""
[Name Server] {E05EF56E-33C7-4071-AC34-9C00878B770D}=192.168.10.1 <not my user accounts connection<
### ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporation Microsoft® Windows® Operating System 5.1.2600.2180
[Winlogon Notification] :HKLM Schedule=wlnotify.dll
### Schedule Common DLL to receive Winlogon notifications Microsoft Corporation Microsoft® Windows® Operating System 5.1.2600.2180 <PHONE HOME<
GOTTA LOVE MICROSOFT [Winlogon Notification] :HKLM sclgntfy=sclgntfy.dll