CloseProcesses:
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3266
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3317
AlternateDataStreams: C:\Windows\SysWOW64\MSIHANDLE:3418
C:\Users\Gerry\AppData\LocalLow\EmieSiteList\Otclmgmy\Xuwjkyrjjxjn
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-425655839-3175279930-4035450205-1000\...\Run: [Zdylhklb] => regsvr32.exe /s "C:\Users\Gerry\AppData\Local\Microsoft\Zdylhklb.dll" <===== ATTENTION
C:\Users\Gerry\AppData\Local\Microsoft\Zdylhklb.dll
EmptyTemp: