GroupPolicyScripts: Group Policy detected <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-2517414903-4262703431-2207850217-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKU\S-1-5-21-2517414903-4262703431-2207850217-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co...ng}&rlz=1I7ACAW SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co...ng}&rlz=1I7ACAW SearchScopes: HKU\S-1-5-21-2517414903-4262703431-2207850217-1000 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co...1I7ACAW_enUS436 SearchScopes: HKU\S-1-5-21-2517414903-4262703431-2207850217-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2517414903-4262703431-2207850217-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.co...1I7ACAW_enUS436 Toolbar: HKU\S-1-5-21-2517414903-4262703431-2207850217-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File C:\Users\James\AppData\Local\temp\CABINET.DLL C:\Users\James\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsrypj2.dll C:\Users\James\AppData\Local\temp\EXPAND.EXE C:\Users\James\AppData\Local\temp\PATCHER.EXE CustomCLSID: HKU\S-1-5-21-2517414903-4262703431-2207850217-1000_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File Task: {9FFDA7D6-8C49-4400-A915-94B7DF37B1E4} - System32\Tasks\3f115fe0 => C:\Users\James\AppData\Local\Temp\\setup1058103264.exe <==== ATTENTION C:\Users\James\AppData\Local\Temp\\setup1058103264.exe HKU\S-1-5-21-2517414903-4262703431-2207850217-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION! Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: CMD: bitsadmin /reset /allusers CMD: ipconfig /flushdns EmptyTemp: