Les-

Actually I do know my keys from my values. The virus puts the subkey "drvddll.exe" under the run, the value of the subkey is actually "%System%\drvddll.exe".