Hi the malware has changed, you appear to have the latest version so I need to locate the trigger. If this does not stop it could you screenshot the next Avast popup and post that… As it will have more data
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "about:newtab" <======= ATTENTION
ShellExecuteHooks: Hook per l'esecuzione degli URL - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [8492032 2012-06-08] (Microsoft Corporation)
S2 aartz; C:\WINDOWS\system32\jzrkrww.dll [X]
S4 bpmgkgdbe; C:\WINDOWS\system32\jzrkrww.dll [X]
Task: C:\WINDOWS\Tasks\SymInstallStub.job => C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\SymInstallStub.exe <==== ATTENTION
C:\WINDOWS\system32\jzrkrww.dll
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that