After removing a registry threat and rebooting, the same threat reappears (see below for detail). I have noticed that just as SAS prompts me with the success and reboot message, I also get a message from Avira indicating that it has blocked my registry. I'm inclined to think that Avira is actually preventing SAS from completely removing the offending registry entry. Do you have any suggestions? Thank you.
Malware.Trace (x86) HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL