start CreateRestorePoint:(Pokki) C:\Users\Phoebe\AppData\Local\Pokki\Engine\HostAppService.exe (Pokki) C:\Users\Phoebe\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe (Pokki) C:\Users\Phoebe\AppData\Local\Pokki\Engine\StartMenuIndexer.exe HKLM\...\Run: [] => [X] HKU\S-1-5-21-998093710-3193632456-2710228237-1001\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchScopes: HKU\S-1-5-21-998093710-3193632456-2710228237-1001 -> {890CE8C5-062C-11E5-8261-2C600C1E4B03} URL = http://search.homepa...q={searchTerms}2015-05-28 18:29 - 2015-05-28 18:29 - 00000871 _____ () C:\Users\Phoebe\Desktop\µTorrent.lnk2015-05-28 18:29 - 2015-05-28 18:29 - 00000851 _____ () C:\Users\Phoebe\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk2015-05-28 18:28 - 2015-05-30 01:27 - 00000000 ____D () C:\Users\Phoebe\AppData\Roaming\uTorrent2015-05-28 18:28 - 2015-05-28 18:28 - 01742928 _____ (BitTorrent Inc.) C:\Users\Phoebe\Downloads\uTorrent_3-4-2-build-38913.exe 2015-05-28 14:40 - 2015-05-28 14:40 - 00000000 ____D () C:\Users\Public\Pokki 2015-05-28 14:34 - 2015-05-31 00:46 - 00000000 ____D () C:\Users\Phoebe\AppData\Local\Pokki Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON EmptyTemp: CMD: bitsadmin /reset /allusers end