start::
CreateRestorePoint:
CloseProcesses:
Hosts:
RemoveProxy:
EmptyTemp:
Task: {52590B11-01ED-4E9D-BAA2-FDEA96726251} - System32\Tasks\ByteFence => C:\Program Files\ByteFence\ByteFence.exe [2017-07-05] (Byte Technologies LLC) <==== ATTENTION
C:\Program Files\ByteFence
Task: C:\WINDOWS\Tasks\Secured Yahoo Powered malet.job =>
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
ManualProxies: 0hxxp://thewebaccess.info/wpad.dat?68713c3b4781fd0164562b1cd1dc6f7537564539
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ilnidodcffjfecahcfiihlhiohnaobic] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2840041228-705292809-2180885002-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ilnidodcffjfecahcfiihlhiohnaobic] - hxxps://clients2.google.com/service/update2/crx
cmd: ipconfig /flushdns
end::