CustomCLSID: HKU\S-1-5-21-2222387085-2878984009-3964471230-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
Task: {6A0C387D-46C3-4B06-85CB-3449A843DC08} - System32\Tasks\0 => Iexplore.exe <==== ATTENTION
C:\Users\Brandon\AppData\LocalLow\Sun\bfajjvhle\oimkehy
HKU\S-1-5-21-364233733-4225134241-1576640876-1001\...\Run: [DYMO] => rundll32.exe "C:\Users\Brandon\AppData\Local\Temp\",CreateInstance <===== ATTENTION
HKU\S-1-5-21-364233733-4225134241-1576640876-1001\...\Run: [qcujejlwce] => regsvr32.exe /s "C:\Users\Brandon\AppData\Local\{0A013DC8-BAE8-4654-A06A-F92317D97CFF}\qcujejlwce.dll" <===== ATTENTION
C:\Users\Brandon\AppData\Local\{0A013DC8-BAE8-4654-A06A-F92317D97CFF}
HKU\S-1-5-21-364233733-4225134241-1576640876-1001\...0c966feabec1\InprocServer32: [Default-shell32] C:\Users\Brandon\AppData\Local\{8c2f3244-0c4b-220e-9a2c-125d24fb1178}\n. ATTENTION! ====> ZeroAccess/Alureon?
C:\Users\Brandon\AppData\Local\{8c2f3244-0c4b-220e-9a2c-125d24fb1178}
SearchScopes: HKCU - DefaultScope {2348AF2A-4E4C-48B8-8AFB-44B8D11DDB23} URL = https://duckduckgo.com/?q={searchTerms}
SearchScopes: HKCU - {2348AF2A-4E4C-48B8-8AFB-44B8D11DDB23} URL = https://duckduckgo.com/?q={searchTerms}
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
C:\Users\Brandon\AppData\Local\{8c2f3244-0c4b-220e-9a2c-125d24fb1178}
C:\Users\Brandon\AppData\Local\{8c2f3244-0c4b-220e-9a2c-125d24fb1178}\@
C:\Users\Brandon\ADM-1.dat
C:\Users\Brandon\CL.dat
EmptyTemp: