HKLM-x32\...\Run: [] => [X] HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => No File GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ProxyServer: [HKLM] => http=proxy-url:port;https=proxy-url:port;ftp=proxy-url:port;socks=proxy-url:port; ProxyServer: [S-1-5-21-1560975029-805369101-429338555-1000] => http=proxy-url:port;https=proxy-url:port;ftp=proxy-url:port;socks=proxy-url:port; HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\S-1-5-21-1560975029-805369101-429338555-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION SearchScopes: HKLM-x32 -> DefaultScope value is missing SearchScopes: HKU\S-1-5-21-1560975029-805369101-429338555-1000 -> {74FA884D-52A0-49EC-BBD9-135181ED12E6} URL = BHO-x32: No Name -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> No File U3 idsvc; no ImagePath U3 wpcsvc; no ImagePath 2016-06-02 09:52 - 2016-06-02 09:52 - 00631524 _____ C:\Users\wayne\Desktop\service Report.pdf 2016-06-02 09:52 - 2016-06-02 09:52 - 00000219 _____ C:\Users\wayne\Desktop\Client care experts.url 2016-06-02 09:44 - 2016-06-02 09:46 - 00000000 ____D C:\Program Files\Client Care Experts 2016-06-02 09:34 - 2016-06-02 09:35 - 00000000 ____D C:\Users\wayne\AppData\Local\LogMeIn Rescue Calling Card 2016-06-02 09:34 - 2016-06-02 09:34 - 00002425 _____ C:\Users\Public\Desktop\Client Care Experts.lnk 2016-06-02 09:34 - 2016-06-02 09:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Client Care Experts 2016-06-02 09:34 - 2016-06-02 09:34 - 00000000 ____D C:\Program Files (x86)\LogMeIn Rescue Calling Card 2016-06-02 09:33 - 2016-06-02 09:33 - 00000094 _____ C:\Users\wayne\Desktop\Joe - Client Care Experts.txt 2016-06-02 08:50 - 2016-06-02 08:50 - 00002332 _____ C:\Users\wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Client Care Experts.lnk C:\Users\wayne\AppData\Local\Temp\libeay32.dll C:\Users\wayne\AppData\Local\Temp\msvcr120.dll C:\Users\wayne\AppData\Local\Temp\sqlite3.dll Task: {03D5BFFC-658B-42BC-BC7F-1D68D188170E} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {128D5A7C-3D8D-438A-9FD9-B46B6B65BB60} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {17A458F6-2402-421A-9CD2-DCD3FB15E328} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {2A39399D-64EB-452D-A597-D80BCAB30EBE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {36105029-1B89-4407-852C-8A5251CC3515} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {609FD45C-548F-4A20-AB90-DF2DEDE59870} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION Task: {82EEF70D-7C57-40B1-B0CC-4A869687F116} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {B16D100F-73B7-4404-8037-1CBF83F06FE7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {C16C07EB-5862-45EB-8122-30A6CF9AA143} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {C6292F3E-904B-4408-B6D8-A90218798DD6} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {DE7161EA-56DF-4402-B3AF-B6911F1B0C6B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {F394FD5C-D88A-4584-9609-2411A90C388D} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION FirewallRules: [{FF9947BE-2BFB-42A5-BA74-3E42D5237512}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{EEC981A7-BE9E-4449-8133-696580DD10FD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{5AE12218-4B23-41BD-AD1C-3CDD22AE655A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{7CEB2A49-560D-4B3A-A12B-C6FB008BE188}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{A6E01B17-93B4-42F6-BAC5-C2BA903288ED}] => (Allow) C:\Program Files (x86)\Bench\Proxy\pwdg.exe FirewallRules: [{7C14A584-B405-45A7-83DA-3AB88242CA7D}] => (Allow) C:\Program Files (x86)\Bench\Proxy\proc.exe FirewallRules: [{471C31D5-B192-4A14-961D-3704738FEA89}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{559BE440-F751-4A4F-AF53-F606A8E02135}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{EE0F6251-56B3-47EC-B2E6-02BC38774237}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{BD8B0C52-E36F-4CDD-BE67-D90195682DE0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{9C7F58D1-6D91-4EB9-9AFF-BCE40C89B4D9}] => (Allow) C:\Program Files\Client Care Experts\EST\EST.EXE FirewallRules: [{E673184D-C004-44FA-8712-4C16EDF0D0A3}] => (Allow) C:\Program Files\Client Care Experts\EST\EST.EXE C:\Program Files (x86)\Bench CMD: ipconfig /flushdns RemoveProxy: EmptyTemp: Hosts: