Start::
CreateRestorePoint:
closeProcesses:
C:\ProgramData\QuickTime
C:\Windows\System32\Config\systemprofile\AppData\Local\Avg
C:\Windows\System32\Config\systemprofile\AppData\Local\AvgSetupLog
C:\Windows\System32\Config\systemprofile\AppData\Roaming\AVG
C:\ProgramData\Avg
DeleteKey: HKLM\SOFTWARE\AVG
DeleteKey: HKLM\SOFTWARE\AVG Persistent
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Avg
DeleteKey: HKLM\SOFTWARE\WOW6432Node\AVG Web TuneUp
DeleteKey: HKCU\SOFTWARE\AVG SafePrice
DeleteKey: HKCU\SOFTWARE\Avg Secure Update
DeleteKey: HKCU\SOFTWARE\AVG Web TuneUp
DeleteKey: HKU\.DEFAULT\SOFTWARE\AVG SafeGuard toolbar
DeleteKey: HKU\.DEFAULT\SOFTWARE\Avg Secure Update
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
C:\Users\Aer\AppData\Local\Avg
C:\Users\Aer\AppData\Local\AvgSetupLog
C:\Program Files (x86)\AVG
C:\Users\Aer\AppData\Roaming\AVG
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Avira
C:\Users\Aer\AppData\Local\Avira
DeleteKey: HKU\S-1-5-21-837392175-3066641175-3098296772-1001\SOFTWARE\Avira
C:\ProgramData\Avira
DeleteKey: HKU\.DEFAULT\SOFTWARE\Avira
DeleteKey: HKCU\SOFTWARE\Avira
C:\Users\Aer\AppData\Local\Avira Operations Gmbh & Co. KG
C:\Users\Aer\AppData\Local\Avira_Operations_Gmbh_&_C
C:\Windows\System32\drivers\phantomtap.sys
C:\Windows\System32\drivers\mfeapfk.sys
C:\Windows\System32\drivers\mfeavfk.sys
C:\Windows\System32\drivers\mfeelamk.sys
C:\Windows\System32\drivers\mfefirek.sys
C:\Windows\System32\drivers\mfehidk.sys
C:\Windows\System32\drivers\mfewfpk.sys
C:\Windows\System32\drivers\cfwids.sys
C:\Windows\System32\Config\systemprofile\AppData\Local\MFAData
C:\Program Files (x86)\Common Files\mcafee
C:\ProgramData\McAfee
C:\ProgramData\MFAData
DeleteKey: HKU\.DEFAULT\SOFTWARE\McAfee
DeleteKey: HKLM\SOFTWARE\WOW6432Node\McAfee
DeleteKey: HKU\S-1-5-21-837392175-3066641175-3098296772-1001\...\MountPoints2: {846a96f8-8586-11e6-82c2-201a06b997ab} - "E:\DigiGoSetup.exe"
DeleteKey: HKU\S-1-5-21-837392175-3066641175-3098296772-1001\...\MountPoints2: {bda71dbb-0d1f-11e4-825c-201a06b997ab} - "E:\LaunchU3.exe" -a
DeleteKey: HKU\S-1-5-21-837392175-3066641175-3098296772-1001\...\MountPoints2: {ce2defae-a21d-11e7-82d7-201a06b997ab} - "E:\SETUP.EXE"
cmd: ipconfig /flushdns
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state on
cmd: netsh winsock reset
EmptyTemp:
End::