I did find one suspicious file, it was
under "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curre
ntVersion\Run" , it is named "NvCplDaemon" & its DATA
is "RUNDLL32.EXE NvQTwk,NvCplDaemon initialize" all of
the other names have data that are file paths from C:\