CustomCLSID: HKU\S-1-5-21-986009405-2142943058-2643793774-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
HKU\S-1-5-21-986009405-2142943058-2643793774-1001\...\Policies\Explorer: [NoThumbnailCache] 1
HKU\S-1-5-21-986009405-2142943058-2643793774-1001\...\Policies\Explorer: [DisableThumbnailsOnNetworkFolders] 1
HKU\S-1-5-21-986009405-2142943058-2643793774-1001\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-986009405-2142943058-2643793774-1001\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-986009405-2142943058-2643793774-1001\...\Command Processor: "C:\Users\Jim\AppData\Roaming\Microsoft\Windows\IEUpdate\WPDShextAutoplay.exe" <===== ATTENTION!
HKU\S-1-5-21-986009405-2142943058-2643793774-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
EmptyTemp: