CloseProcesses: CreateRestorePoint: GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - No Path Or update_url value CHR HKLM\...\Chrome\Extension: [dgadkdfaoaaboghcnjmbcppkalapgkmb] - No Path Or update_url value CHR HKLM\...\Chrome\Extension: [jmolcgpienlcieaajfkkdamlngancncm] - D:\idm\Internet Download Manager\IDMGCExt.crx [2013-06-20] CHR HKLM\...\Chrome\Extension: [kllhllgiijehpamgcmeciagegjecoaod] - No Path Or update_url value CHR HKU\S-1-5-21-299502267-1935655697-1417001333-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - No Path Or update_url value CHR HKU\S-1-5-21-299502267-1935655697-1417001333-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - No Path Or update_url value R3 cpuz137; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cpuz137\cpuz137_x32.sys [X] S3 GGSAFERDriver; No ImagePath S4 IntelIde; No ImagePath U1 WS2IFSL; No ImagePath U3 acqdwj3n; No ImagePath C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cpuz137 2015-04-14 14:48 - 2015-04-14 20:24 - 00000000 ____D () C:\Program Files\RichMediaViewV1 2015-04-14 14:48 - 2015-04-14 20:24 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\FoxTab 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Program Files\Conduit 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Program Files\AskPartnerNetwork 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Babylon 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AskPartnerNetwork 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\APN 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\VNT 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\Conduit 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\AskPartnerNetwork 2015-04-14 14:48 - 2015-04-14 14:48 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Babylon 2015-04-14 14:19 - 2015-04-14 14:50 - 00000000 ____D () C:\Program Files\SystemConserve 2015-04-14 14:17 - 2015-04-14 14:48 - 00000000 ____D () C:\Program Files\bestadblocker 2015-04-14 14:15 - 2015-04-14 14:15 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\cncaklookhiljnimkipmolldampgfcmf 2015-04-15 17:30 - 2014-01-30 10:30 - 00000416 _____ () C:\WINDOWS\Tasks\At2.job 2015-04-15 17:30 - 2013-11-03 22:30 - 00000416 _____ () C:\WINDOWS\Tasks\At1.job 2015-04-14 20:24 - 2014-01-30 10:30 - 00000000 ____D () C:\Documents and Settings\NetworkService\Application Data\FoxTab 2015-04-14 20:24 - 2013-09-01 08:57 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\CRE C:\Documents and Settings\Administrator\Local Settings\Temp\ASCSetup_1323593.exe C:\Documents and Settings\Administrator\Local Settings\Temp\avgnt.exe C:\Documents and Settings\Administrator\Local Settings\Temp\Quarantine.exe Task: C:\WINDOWS\Tasks\At1.job => C:\DOCUME~1\ADMINI~1\APPLIC~1\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\WINDOWS\Tasks\At2.job => C:\DOCUME~1\NETWOR~1\APPLIC~1\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION C:\DOCUME~1\ADMINI~1\APPLIC~1\FoxTab C:\DOCUME~1\NETWOR~1\APPLIC~1\FoxTab AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:BF3D62E7 HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\22944368.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\22944368.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" FF user.js: detected! => C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\a1zf5h3p.default\user.js [2015-04-14] FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found] CMD: ipconfig /flushdns hosts: Emptytemp: