CloseProcesses: CreateRestorePoint: C:\ProgramData\Lenovo-10516.vbs C:\ProgramData\Lenovo-10562.vbs GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => No File ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => No File ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => No File ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoViewOnDrive] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKLM\...\Policies\Explorer: [NoViewContextMenu] 0 HKLM\...\Policies\Explorer: [NoShellSearchButton] 0 HKLM\...\Policies\Explorer: [NoFind] 0 HKLM\...\Policies\Explorer: [NoFile] 0 HKLM\...\Policies\Explorer: [HideClock] 0 HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0 HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKLM\...\Policies\Explorer: [NoSetFolders] 0 HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKLM\...\Policies\Explorer: [NoSetTaskbar] 0 HKLM\...\Policies\Explorer: [NoDeletePrinter] 0 HKLM\...\Policies\Explorer: [NoDFSTab] 0 HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0 HKLM\...\Policies\Explorer: [NoLogoff] 0 HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0 HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0 HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKLM\...\Policies\Explorer: [NoResolveSearch] 0 HKLM\...\Policies\Explorer: [NoSaveSettings] 0 HKLM\...\Policies\Explorer: [NoHardwareTab] 0 HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKLM\...\Policies\Explorer: [NoDesktop] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1403304 2015-10-29] (Garmin Ltd. or its subsidiaries) HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoDrives] 33554432 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-21-2186271191-3458891878-1518541264-1001\...\Policies\Explorer: [NoStartMenuSubFolders] 0 SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKLM-x32 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2186271191-3458891878-1518541264-1001 -> {5D0E24A2-78F5-4645-B9D9-9472D9AE6CB7} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20131042,19890,0,25,0 SearchScopes: HKU\S-1-5-21-2186271191-3458891878-1518541264-1001 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-2186271191-3458891878-1518541264-1001 -> {D4929332-219D-4437-8AAA-4F95180CB5A3} URL = Toolbar: HKU\S-1-5-21-2186271191-3458891878-1518541264-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found CMD: bitsadmin /reset /allusers CMD: netsh winsock reset catalog CMD: ipconfig /flushdns RemoveProxy: hosts: Emptytemp: