CloseProcesses: CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION CHR HKU\S-1-5-21-207249110-600702845-166796750-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-207249110-600702845-166796750-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll => No File BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL => No File BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL => No File BHO-x32: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File Toolbar: HKU\S-1-5-21-207249110-600702845-166796750-1000 -> No Name - {093F479D-712E-46CD-9E06-62E734A05F68} - No File Handler: osf - No CLSID Value Handler: WSAllMyTubechrome - {0A0C95CF-A116-4C74 - No File 2013-01-28 18:20 - 2013-01-28 18:20 - 000248008 _____ (Ask.com) C:\Users\Webb\AppData\Local\Temp\AskSLib.dll 2013-10-28 21:26 - 2013-03-07 10:57 - 000098304 _____ () C:\Users\Webb\AppData\Local\Temp\cabex.dll 2016-05-02 09:40 - 2016-05-02 09:40 - 014185258 _____ (HOW Inc. ) C:\Users\Webb\AppData\Local\Temp\FYDSetup.exe 2013-09-02 17:45 - 2015-08-20 14:16 - 000163104 _____ (RealNetworks, Inc.) C:\Users\Webb\AppData\Local\Temp\lowproc.exe 2017-05-30 21:21 - 2017-05-30 21:21 - 000243240 _____ (McAfee, Inc.) C:\Users\Webb\AppData\Local\Temp\McCSPInstall.dll 2017-04-02 00:11 - 2008-09-12 13:39 - 000217088 _____ (MAGIX AG) C:\Users\Webb\AppData\Local\Temp\MgxVistaTools.dll 2014-01-25 19:31 - 2013-07-17 00:14 - 000798904 _____ (Microsoft Corporation) C:\Users\Webb\AppData\Local\Temp\OfficeSetup.exe 2013-10-28 21:26 - 2013-03-07 10:57 - 000172720 _____ () C:\Users\Webb\AppData\Local\Temp\PVARemove.exe 2013-09-02 17:45 - 2014-10-16 02:01 - 000090624 _____ (RealNetworks, Inc.) C:\Users\Webb\AppData\Local\Temp\stubhelper.dll 2016-10-27 20:31 - 2017-04-01 20:40 - 000153056 _____ (MAGIX AG) C:\Users\Webb\AppData\Local\Temp\unwise.exe 2015-05-15 09:26 - 2015-05-15 09:26 - 028849904 _____ () C:\Users\Webb\AppData\Local\Temp\vlc-2.2.1-win32.exe 2016-07-05 16:57 - 2016-07-05 16:57 - 030533688 _____ () C:\Users\Webb\AppData\Local\Temp\vlc-2.2.4-win32.exe 2017-10-18 16:15 - 2017-10-18 16:15 - 000123697 _____ () C:\Users\Webb\AppData\Local\Temp\{0776AC08-42A7-4437-B11F-0610BF38DA56}-62.0.3202.62_chrome_installer.exe ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL -> No File ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL -> No File ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL -> No File FirewallRules: [{D08A7FCD-5BF1-4090-B2DD-4BDE1D3422D2}] => (Allow) C:\Users\Webb\AppData\Local\Temp\7zS49BC.tmp\SymNRT.exe FirewallRules: [{5ED4E65B-54CD-46F2-85B9-07F3569087C6}] => (Allow) C:\Users\Webb\AppData\Local\Temp\7zS49BC.tmp\SymNRT.exe CMD: ipconfig /flushdns Hosts: EmptyTemp: