start:: closeprocesses: createrestorepoint: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#/?show_is=1&source=art HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#/?show_is=1&source=art HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#/?show_is=1&source=art HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#/?show_is=1&source=art HKU\S-1-5-21-3213657535-2202803051-3904661825-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#/?show_is=1&source=art HKU\S-1-5-21-3213657535-2202803051-3904661825-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#/?show_is=1&source=art SearchScopes: HKU\S-1-5-21-3213657535-2202803051-3904661825-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={CC39A275-4090-4576-9F0D-F59A2F95D56C}&mid=abdf26adc2a647ceb6f39d852c830bab-00cf00eda8c3ba48ca5a0933ad023e599f2cf399&lang=en&ds=px011&coid=avgtbdispx&cmpid=&pr=sa&d=2017-11-18 20:03:16&v=19.6.0.592&pid=safeguard&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-3213657535-2202803051-3904661825-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={CC39A275-4090-4576-9F0D-F59A2F95D56C}&mid=abdf26adc2a647ceb6f39d852c830bab-00cf00eda8c3ba48ca5a0933ad023e599f2cf399&lang=en&ds=px011&coid=avgtbdispx&cmpid=&pr=sa&d=2017-11-18 20:03:16&v=19.6.0.592&pid=safeguard&sg=&sap=dsp&q={searchTerms} FF Extension: (Avira Browser Safety) - C:\Users\Jonathan\AppData\Roaming\Mozilla\Firefox\Profiles\P7WEfwxl.default\Extensions\abs@avira.com [2016-12-30] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx S2 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [392480 2017-03-23] (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_lbstatic-a.akamaihd.net_0.localstorage-journal C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_funsafetab.com_0.localstorage-journal C:\Users\Jonathan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_translationbuddy.dl.tb.ask.com_0.localstorage-journal deletekey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 deletekey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} deletekey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 2017-12-29 19:08 - 2016-12-30 14:44 - 000000000 ____D C:\Program Files (x86)\Avira emptytemp: end::