Start:: CreateRestorePoint: closeProcesses: C:\ProgramData\QuickTime C:\Windows\System32\Config\systemprofile\AppData\Local\Avg C:\Windows\System32\Config\systemprofile\AppData\Local\AvgSetupLog C:\Windows\System32\Config\systemprofile\AppData\Roaming\AVG C:\ProgramData\Avg DeleteKey: HKLM\SOFTWARE\AVG DeleteKey: HKLM\SOFTWARE\AVG Persistent DeleteKey: HKLM\SOFTWARE\WOW6432Node\Avg DeleteKey: HKLM\SOFTWARE\WOW6432Node\AVG Web TuneUp DeleteKey: HKCU\SOFTWARE\AVG SafePrice DeleteKey: HKCU\SOFTWARE\Avg Secure Update DeleteKey: HKCU\SOFTWARE\AVG Web TuneUp DeleteKey: HKU\.DEFAULT\SOFTWARE\AVG SafeGuard toolbar DeleteKey: HKU\.DEFAULT\SOFTWARE\Avg Secure Update C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen C:\Users\Aer\AppData\Local\Avg C:\Users\Aer\AppData\Local\AvgSetupLog C:\Program Files (x86)\AVG C:\Users\Aer\AppData\Roaming\AVG DeleteKey: HKLM\SOFTWARE\WOW6432Node\Avira C:\Users\Aer\AppData\Local\Avira DeleteKey: HKU\S-1-5-21-837392175-3066641175-3098296772-1001\SOFTWARE\Avira C:\ProgramData\Avira DeleteKey: HKU\.DEFAULT\SOFTWARE\Avira DeleteKey: HKCU\SOFTWARE\Avira C:\Users\Aer\AppData\Local\Avira Operations Gmbh & Co. KG C:\Users\Aer\AppData\Local\Avira_Operations_Gmbh_&_C C:\Windows\System32\drivers\phantomtap.sys C:\Windows\System32\drivers\mfeapfk.sys C:\Windows\System32\drivers\mfeavfk.sys C:\Windows\System32\drivers\mfeelamk.sys C:\Windows\System32\drivers\mfefirek.sys C:\Windows\System32\drivers\mfehidk.sys C:\Windows\System32\drivers\mfewfpk.sys C:\Windows\System32\drivers\cfwids.sys C:\Windows\System32\Config\systemprofile\AppData\Local\MFAData C:\Program Files (x86)\Common Files\mcafee C:\ProgramData\McAfee C:\ProgramData\MFAData DeleteKey: HKU\.DEFAULT\SOFTWARE\McAfee DeleteKey: HKLM\SOFTWARE\WOW6432Node\McAfee DeleteKey: HKU\S-1-5-21-837392175-3066641175-3098296772-1001\...\MountPoints2: {846a96f8-8586-11e6-82c2-201a06b997ab} - "E:\DigiGoSetup.exe" DeleteKey: HKU\S-1-5-21-837392175-3066641175-3098296772-1001\...\MountPoints2: {bda71dbb-0d1f-11e4-825c-201a06b997ab} - "E:\LaunchU3.exe" -a DeleteKey: HKU\S-1-5-21-837392175-3066641175-3098296772-1001\...\MountPoints2: {ce2defae-a21d-11e7-82d7-201a06b997ab} - "E:\SETUP.EXE" cmd: ipconfig /flushdns cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state on cmd: netsh winsock reset EmptyTemp: End::