CloseProcesses: CreateRestorePoint: HKLM-x32\...\Run: [] => [X] CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\S-1-5-21-4159210540-2217699198-1934608907-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION SearchScopes: HKLM -> DefaultScope value is missing SearchScopes: HKLM -> URL hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQgMB10SEFdFbVsPVFxcFQVFcRRZV1tHDAQbc1wMWVgVFVFAch9aFQQTSEcFME0FCFwEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope value is missing SearchScopes: HKLM-x32 -> {5918FE3F-A4C4-49B7-94B4-305976513CFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-4159210540-2217699198-1934608907-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-21-4159210540-2217699198-1934608907-1000 -> {5918FE3F-A4C4-49B7-94B4-305976513CFE} URL = SearchScopes: HKU\S-1-5-21-4159210540-2217699198-1934608907-1003 -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=843&query={searchTerms}&invocationType=tb50-ie-dlink-chromesbox-en-us SearchScopes: HKU\S-1-5-21-4159210540-2217699198-1934608907-1003 -> {5918FE3F-A4C4-49B7-94B4-305976513CFE} URL = BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File CHR RestoreOnStartup: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggSdF9cAggTRxhBdwxdTA1BRwQOIQ9aVxRAGQZGdAFZBQ0VQgcFIk0FA1oDB0VXfV5bFElXTwhwJVhKAlE8TkdGC1dXFg==" CHR StartupUrls: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggSdF9cAggTRxhBdwxdTA1BRwQOIQ9aVxRAGQZGdAFZBQ0VQgcFIk0FA1oDB0VXfV5bFElXTwhwJVhKAlE8TkdGC1dXFg==" CHR DefaultSearchURL: Default -> hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQgMB10SEFdFbVsPVFxcFQVFcRRZV1tHDAQbc1wMWVgVFVFAch9aFQQTQkcFME0FBloEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms} CHR DefaultSearchKeyword: Default -> searchinterneat-a.akamaihd.net CHR DefaultNewTabURL: Default -> hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHAQXJl1bUFsXDFcUdVwVVQkXEBhCdlsOTAhJElAXeFhcVV0SExNBNARaAktXUUEeJ1pNER8fHGZGIUtbCXQeU1BoLlZP U3 idsvc; no ImagePath S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X] U3 wpcsvc; no ImagePath Task: {C94C04B6-E4C1-4931-BCF7-D531B2F8C641} - \Google Software Updater -> No File <==== ATTENTION AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 CMD: bitsadmin /reset /allusers CMD: netsh winsock reset catalog CMD: ipconfig /flushdns RemoveProxy: hosts: Emptytemp: