HKU\S-1-5-21-855852175-3270004835-611297600-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION URLSearchHook: HKLM - (No Name) - {eef3855c-fc2d-41e6-8d91-d368f51b3055} - No File SearchScopes: HKLM -> DefaultScope {4D367D41-2111-4C13-B8A9-8FA3CFE72D27} URL = SearchScopes: HKU\S-1-5-21-855852175-3270004835-611297600-1001 -> DefaultScope {4D367D41-2111-4C13-B8A9-8FA3CFE72D27} URL = BHO: VIPRE Search Guard Helper -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> C:\Program Files\VIPRE\VSGN.dll No File Toolbar: HKLM - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - No File Handler: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - C:\Program Files\VIPRE\VSGN.dll No File FF Plugin: samsung.com/SamsungLinkPCPlugin -> C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File CHR HKLM\...\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - No Path CHR HKLM\...\Chrome\Extension: [dflinnddekagfkncpgojoppgnppfkbkj] - No Path CHR HKLM\...\Chrome\Extension: [heoldelcflnigdllmlopiefhkkobendj] - No Path CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - No Path CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\\ChromeExt\\avg.crx [Not Found] S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X] S3 catchme; \??\C:\Users\mike\AppData\Local\Temp\catchme.sys [X] S3 lmimirr; system32\DRIVERS\lmimirr.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] C:\Users\mike\AppData\Local\temp\avgnt.exe C:\Users\mike\AppData\Local\temp\i4jdel0.exe C:\Users\mike\AppData\Local\temp\oi_{3818E67A-553D-4C2A-939B-2D818A12ACBA}.exe C:\Users\mike\AppData\Local\temp\SamsungAPInstaller_1389549848551.exe C:\Users\mike\AppData\Local\temp\SamsungAPInstaller_1389979349451.exe C:\Users\mike\AppData\Local\temp\SamsungAPInstaller_1411264141087.exe C:\Users\mike\AppData\Local\temp\SetupUtil.exe C:\Users\mike\AppData\Local\temp\SkypeSetup.exe C:\Users\mike\AppData\Local\temp\UNINSTALL.EXE Task: {A06CCE9E-68E0-496A-857D-1B8FC6BDD8B6} - \BackgroundContainer Startup Task No Task File <==== ATTENTION CMD: ipconfig /flushdns EmptyTemp: