CloseProcesses: CreateRestorePoint: HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-2588259368-3398593882-3987161955-1000\...\MountPoints2: {165b3c49-78e8-11e4-959f-806e6f6e6963} - E:\RunMe.exe ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = U4 Avgfwfd; system32\DRIVERS\avgfwd6a.sys [X] C:\Users\Home\AppData\Local\Temp\avguirn_081692346769.exe C:\Users\Home\AppData\Local\Temp\avguirn_081778736183.exe C:\Users\Home\AppData\Local\Temp\avguirn_082048732973.exe C:\Users\Home\AppData\Local\Temp\avguirn_082124867046.exe C:\Users\Home\AppData\Local\Temp\avguirn_08230171427.exe C:\Users\Home\AppData\Local\Temp\avguirn_08529085845.exe C:\Users\Home\AppData\Local\Temp\avguirn_08699622339.exe C:\Users\Home\AppData\Local\Temp\avguirn_08798282415.exe C:\Users\Home\AppData\Local\Temp\avguirn_08815743683.exe C:\Users\Home\AppData\Local\Temp\HPPSdr.exe C:\Users\Home\AppData\Local\Temp\Quarantine.exe AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125] CMD: bitsadmin /reset /allusers CMD: ipconfig /flushdns RemoveProxy: hosts: Emptytemp: