Sorry i've just read your post
About MS desktop slideshow seems it's just registered COM object (dll) the right click tab with activeX server dll, installed files are bgswitch.dll and exe that runs in the background as separate process and so on etc. To know where's the registry located, you can just check the registry snapshot using some utilities like
this (Note: after reinstalling probably not complete or some of them are not related/obsolete key anyhow you can record it more accurately after the clean install of the software):
Windows Registry Editor Version 5.00
; 5/7/2009 1:27:43 AM - 5/7/2009 1:30:46 AM
; ADD section
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ACD361C7-AEC5-4A31-9478-A447402B6B62}\InprocServer32]
"(Default)"="C:\\WINDOWS\\system32\\bgswitch.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed"=hex(03):af,5b,ab,93,c4,05,51,42,7d,7b,cd,87,a7,b3,34,4a,0f,62,3a,5e,\
f9,89,32,57,42,ee,6d,39,3f,91,6e,a7,5d,d0,33,e7,fb,1c,57,87,09,5f,83,3b,e8,76,\
97,e4,d9,aa,d4,66,e7,78,07,d4,0f,f5,60,14,f0,58,e2,91,be,51,73,05,4b,b1,84,\
08,79,61,7d,ae,fc,88,4b,99
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Controls Folder\Desk\shellex\PropertySheetHandlers\BgSwitch]
@="{ACD361C7-AEC5-4a31-9478-A447402B6B62}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Controls Folder\Desk\shellex\PropertySheetHandlers\PlusPack CPL Extension]
@="{41E300E0-78B6-11ce-849B-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]
@="??"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\medctrro]
"ServicesToRestart"="??"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackgroundSwitcher"="C:\\WINDOWS\\system32\\bgswitch.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
"C:\\WINDOWS\\system32\\bgswitch.dll"=dword:00000001
"C:\\WINDOWS\\system32\\bgswitch.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Desktop Slide Show]
"DisplayIcon"="C:\\Documents and Settings\\All Users\\Application Data\\Windows Slide Show\\Uninstall.exe"
"DisplayName"="Windows Desktop Slide Show"
"NoModify"=dword:00000001
"NoRepair"=dword:00000001
"UninstallString"="C:\\Documents and Settings\\All Users\\Application Data\\Windows Slide Show\\Uninstall.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex]
"NotificationLogCheckPoint"=hex(03):1a,aa,01,00,00,00,00,00
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\Control Panel\Desktop]
"ConvertedWallpaper"="C:\\WINDOWS\\Web\\Wallpaper\\Moon flower.jpg"
"ConvertedWallpaper Last WriteTime"=hex(03):00,60,db,8f,d1,7e,c4,01
"Wallpaper"="C:\\Documents and Settings\\AMIRZ\\Local Settings\\Application Data\\Microsoft\\Wallpaper1.bmp"
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\SessionInformation]
"ProgramCount"=dword:00000004
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\Software\Microsoft\Internet Explorer\Desktop\Components]
"GeneralFlags"=dword:00000000
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\Software\Microsoft\Internet Explorer\Desktop\General]
"WallpaperFileTime"=hex(03):5e,66,7d,35,ee,ce,c9,01
"WallpaperLocalFileTime"=hex(03):5e,8e,1e,89,b3,ce,c9,01
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\BackgroundManager]
"Directory"="C:\\WINDOWS\\web\\wallpaper"
"Disabled"=dword:00000000
"Force Stretch"=dword:00000000
"Last Set Time"=hex(03):10,dd,90,89,b3,ce,c9,01
"OldConvertedWallpaper"="C:\\WINDOWS\\Web\\Wallpaper\\Moon flower.jpg"
"OldWallpaper"="C:\\Documents and Settings\\AMIRZ\\Local Settings\\Application Data\\Microsoft\\Wallpaper1.bmp"
"Random"=dword:00000001
"Refresh Frequency"=dword:00000001
"Refresh Unit"=dword:00000005
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\ShellNew]
"~reserved~"=hex(03):18,00,00,00,01,00,01,00,d9,07,05,00,04,00,07,00,01,00,\
1d,00,33,00,c8,03
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]
"HRZR_EHACNGU"=hex(03):10,00,00,00,bc,01,00,00,a0,d2,06,cc,ed,ce,c9,01
"HRZR_EHACNGU:Q:\\Qrfxgbc Phfgbzvmngvba\\Jvaqbjf 7 Qrfxgbc Fyvqrfubj sbe Kc\\KcFyvqrFubjFrghc.rkr"=hex(03):10,\
00,00,00,08,00,00,00,a0,d2,06,cc,ed,ce,c9,01
"HRZR_EHAPCY"=hex(03):10,00,00,00,10,00,00,00,d0,b6,bf,08,ee,ce,c9,01
"HRZR_EHAPCY:qrfx.pcy"=hex(03):10,00,00,00,07,00,00,00,d0,27,c2,08,ee,ce,c9,01
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\Software\Microsoft\Windows\ShellNoRoam\BagMRU]
"MRUListEx"=hex(03):00,00,00,00,07,00,00,00,01,00,00,00,0c,00,00,00,02,00,00,\
00,04,00,00,00,0b,00,00,00,0a,00,00,00,09,00,00,00,03,00,00,00,08,00,00,00,\
06,00,00,00,05,00,00,00,ff,ff,ff,ff
[HKEY_USERS\S-1-5-21-1492870128-1046174861-2901844884-1005\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@%windir%\\ehome\\ehres.dll,-2003"="Energy Blue"
"@C:\\WINDOWS\\System32\\cryptext.dll,-6112"="Microsoft Serialized Certificate Store"
"@C:\\WINDOWS\\System32\\cryptext.dll,-6113"="PKCS #7 Signature"
"@c:\\WINDOWS\\system32\\icardres.dll.mui,-4146"="Windows CardSpace backup file"
"@c:\\WINDOWS\\system32\\icardres.dll.mui,-4162"="Managed Information Card file"
"@C:\\WINDOWS\\System32\\pdh.dll,-10023"="Performance Monitor File"
"@themeui.dll,-2015"="More themes online..."
"@themeui.dll,-2016"="Windows Classic"
"@themeui.dll,-2017"="Windows XP"
"@themeui.dll,-2037"="{Tahoma, 8 pt}"
"@themeui.dll,-2038"="{Tahoma, 8 pt}"
"@themeui.dll,-2039"="{Tahoma, 8 pt}"
"@themeui.dll,-2040"="{Tahoma, 8 pt}"
"@themeui.dll,-2041"="{Tahoma, 8 pt}"
"@themeui.dll,-2042"="{Tahoma, 8 pt}"
"C:\\WINDOWS\\system32\\bgswitch.exe"="bgswitch"
"C:\\WINDOWS\\system32\\taskmgr.exe"="Windows TaskManager"
@Pratosh lol why u spammed here Bro (or posted on wrong thread either maybe?) btw nice avatar i really wanna f**k her hehe

lol cya
Edited by AMIRZ, 29 July 2009 - 07:48 PM.