CloseProcesses: CreateRestorePoint: SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1814905456-3194672661-2885556747-1000 -> {F1D6D8B8-D23A-41C0-AAC8-9CA2819BBA8B} URL = 2015-07-13 09:40 - 2015-04-13 12:33 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 Task: {C4EB9297-19CD-445D-9789-AD89D6AC070C} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1814905456-3194672661-2885556747-1000 Folder: C:\ProgramData\{8AF32939-989B-460A-8726-CA2C776032A1} File: C:\ProgramData\SPL3CF0.tmp EmptyTemp: CMD: bitsadmin /reset /allusers cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state on/off Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartupApproved" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartupApproved" /F Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F