Avast UI/Shields/Anti-mal/Anything else Is Completely Nonexistent

I am familiar with avast and how its processes are generally isolated in them selves. recently I installed avast on a computer that i obtained from a trusted friend o clean up the maliscious junk that she somehow never notices. it installs fine, when finished it says it will run a quick scan, i was going to anyway, no dice. So i try and run the ui to start it myself, a common fix for installers not starting things, no dice. I check to see if the process is running, nope. i try and start it from the real file location, no dice. i check, because windows 7+ is nice enough to let the task manager to tell me what services are running, to see if avast has a service. yes it does. its stopped. i rightclick and start, imedetly i get a, what i found out to be later a 1053, error saying it didnt respond in a timely fashion. i try and reinstall twice, no, try and run the miniapplications, none, except for browser cleanup, dunno why, but thats not much of a help. actually the maliscious/otherwise nasty stuff intrudes and interrupts when i browse the web. the funny thing is is that the only thing that runs from avast is the browser cleanup, again didn’t help because it clears out only apps and extensions, not the actual plugins that cause consistent redirects, and the avast anti tracking and web reputation thing, cool but no help. i try and see if windows will find anything wrong with it and it just comes up with an incompatable software. no help and no tips. but, as i can see that others around here are using avast on windows 7, is quite the intruging lie. i am worried that some form of maliscious shtff already present has hacked and locked down avast from running. this poses quite the security risk if it actually is. i was forced to remove many, many different mal shkit myself. this allowed for me to browse the web fairley ok on chrome. don’t get me started on IE, i think i made it worse somehow. (not that i use it anyway) however a few of my fav sites, not meaning i clicked the fave button, just that i like them, thats an ancient IE thing to do lol, have been redirecting CONSTANTLY o various other sites, ranging from to online games that are way too desperate for players, fake shopping sites and “deals”, to, and this is creepy, The “New York Times”, I checked on this and it was the real site, not the regualr page but it was official. the only way i can get passed this is to type a location different than the main page or the simple www.blahwhatever.com (dont click that, i just wrote an example, if its real thanc its probably a bad site) however with no non-windows security system running am surley at risk as anyone would know, but running a copmputer with a broken one is extremely dangerous. nrton is out of the question and i am worried i’ll have to resort to AVG!!! hopefully you could fix this so that i dont have to do something that crazy.

I couldn’t even tell you what version of avast i’m using! All i know is that the installer version is; 10.0.2206.692

according to the amazing dxdiag my windoes specs are;

System Information

Time of this report: 11/12/2014, 16:36:39
Machine name: BAKURARYOU
Operating System: Windows 7 Home Premium 64-bit (6.1, Build 7601) Service Pack 1 (7601.win7sp1_gdr.140706-1506)
Language: English (Regional Setting: English)
System Manufacturer: Acer
System Model: AO722
BIOS: InsydeH2O Version V1.08
Processor: AMD C-60 APU with Radeon™ HD Graphics (2 CPUs), ~1.0GHz
Memory: 4096MB RAM
Available OS Memory: 3818MB RAM
Page File: 2446MB used, 5189MB available
Windows Dir: C:\Windows
DirectX Version: DirectX 11
DX Setup Parameters: Not found
User DPI Setting: Using System DPI
System DPI Setting: 96 DPI (100 percent)
DWM DPI Scaling: Disabled
DxDiag Version: 6.01.7601.17514 32bit Unicode

I hope that comes out right

I’d sure like to know why this is happening or, if i am, what i’m doing wrong.

and please, i did search, nothing of interest came up, and even so every problem, if not on a wide scale, is personally affected. so if you think to say to search for this fix, don’t. :slight_smile:

Also if you happen to reply copy what you may or not say into a quick email for me please, and send it here; billington,jesse@gmail.com

any other security programs installed?

see instructions here https://forum.avast.com/index.php?topic=53253.0
attach Malwarebytes and Farbar Recovery Scan Tool logs

a malware/log expert will have a look when online tomorrow…

I think that accidental tripling was because the server quick changed it’s datestamp and fizzed my incoming post. didn’t mean to sorry.

i have just the standard windows shtuff, neither malwarebytes nor the other thing. all i got now is windows firewall, defender (kinda sorta), and microsoft security essentials. and i don’t know how to get those logs, if they log things.

but why not? i’ll attach them to here.

[b]and i don't know how to get those logs[/b], if they log things.
click the link i posted and follow instructions .....

heh i meant defender and msse logs, sry. but i’m gonna warn you, whatever is stopping avast is stopping malwarebytes too. that log is out of the question.

oh and this may take a while. If i don’t attach them before tomorrow lemme know and i’ll try and get them up in the afternoon.

Hi there you have a veritable menagerie onboard, this may take a few runs to clear

Download the attached fixlist.txt to the same location as FRST
Run FRST and press fix
On completion reboot, this may take a while to reboot if there are a lot of temporary files to remove
A fix log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

NEXT

Please download Junkware Removal Tool to your desktop.

[]Right-mouse click JRT.exe and select “Run as Administrator” the tool will open and start scanning your system
[
]please be patient as this can take a while to complete depending on your system’s specifications
[]On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
[
]post the contents of JRT.txt into your next message.

FINALLY

Run a fresh FRST scan please

Ok, in progress. Do you think I should re-install Malwarebytes and go for the free premium trial to get it running with it’s premium chameleon driver that I question reliability after these finish? Or should I bother?

Should FRST be taking a long while?

Ok fixlog finished. Here it is. Starting asw now.

This is why it took a while EmptyTemp: => Removed 5.6 GB temporary data.

The normal free MBAM should be sufficient

Heh, expectable.

Ok, thx.

The adw cleaner is here;

AdwCleaner v4.101 - Report created 13/11/2014 at 16:08:39

Updated 09/11/2014 by Xplode

Database : 2014-11-13.1 [Live]

Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

Username : gohanlover - BAKURARYOU

Running from : C:\Users\gohanlover\Desktop\AdwCleaner.exe

Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\House Of Soft
Folder Deleted : C:\ProgramData\BestSauveFForYoauu
Folder Deleted : C:\ProgramData\CCoupEextenSion
Folder Deleted : C:\ProgramData\DisoceoauntExtennsaio
Folder Deleted : C:\ProgramData\ExstraCouupon
Folder Deleted : C:\ProgramData\FuNDeAls
Folder Deleted : C:\ProgramData\greaTSAAver
Folder Deleted : C:\ProgramData\greaTsaveor
Folder Deleted : C:\ProgramData\Red AdBlocker
Folder Deleted : C:\ProgramData\RobOaSavuer
Folder Deleted : C:\ProgramData\Websave
Folder Deleted : C:\Program Files\Level Quality Watcher
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\gohanlover\AppData\Local\genienext
Folder Deleted : C:\Users\gohanlover\AppData\LocalLow\DataMngr
Folder Deleted : C:\Users\gohanlover\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\YamiDawn\AppData\LocalLow\DataMngr
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkdcaakcmajdekncgejbjeoolngchbkc
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkdcaakcmajdekncgejbjeoolngchbkc
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkdcaakcmajdekncgejbjeoolngchbkc
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkljkgdcmkgdejmabjjfbeoinngpmchd
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkljkgdcmkgdejmabjjfbeoinngpmchd
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkljkgdcmkgdejmabjjfbeoinngpmchd
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgofoggialbadlkfedfcdhfimgipelaa
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgofoggialbadlkfedfcdhfimgipelaa
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgofoggialbadlkfedfcdhfimgipelaa
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngnglchlhphfdglkmnlnjfdipkmokefg
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngnglchlhphfdglkmnlnjfdipkmokefg
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngnglchlhphfdglkmnlnjfdipkmokefg
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nklpeollhnoecngnoeecahhhbnghcnlh
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\nklpeollhnoecngnoeecahhhbnghcnlh
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\nklpeollhnoecngnoeecahhhbnghcnlh
File Deleted : C:\END
File Deleted : C:\Windows\Reimage.ini
File Deleted : C:\Users\gohanlover\AppData\Roaming\LiveSupport.exe_log.txt
File Deleted : C:\Users\gohanlover\AppData\Roaming\regsvr32.exe_log.txt
File Deleted : C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage

***** [ Scheduled Tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\AppID\AdpeakProxy.exe
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\iMesh_V11_en_Setup.exe
Key Deleted : HKLM\SOFTWARE\Classes\Applications\iMeshV11.exe
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKCU\Software\AppDataLow{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\AVG SafeGuard toolbar
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\Reimage
Key Deleted : HKCU\Software\AppDataLow{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKCU\Software\AppDataLow\Software\Re_Markit
Key Deleted : HKCU\Software\AppDataLow\Software\Scorpion Saver
Key Deleted : HKLM\SOFTWARE{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\Adpeak, Inc.
Key Deleted : HKLM\SOFTWARE\AVG SafeGuard toolbar
Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{CA41BB14-E67B-1653-C57B-5CA99418A866}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{90120000-00B2-0409-0000-0000000FF1CE}
Key Deleted : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Key Deleted : [x64] HKLM\SOFTWARE\Scorpion Saver
Key Deleted : [x64] HKLM\SOFTWARE\Reimage
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7

***** [ Browsers ] *****

-\ Internet Explorer v11.0.9600.17420

-\ Google Chrome v38.0.2125.122

[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&ISID=M2FE25B46-6B33-49C8-82F8-9F6A3D31D7C8&SearchSource=58&CUI=&UM=6&UP=SP43DDD08A-5DA7-44FD-9E25-71AADAF718D0&q={searchTerms}&SSPV=
[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&ISID=M2FE25B46-6B33-49C8-82F8-9F6A3D31D7C8&SearchSource=58&CUI=&UM=6&UP=SP43DDD08A-5DA7-44FD-9E25-71AADAF718D0&q={searchTerms}&SSPV=
[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : flpcjncodpafbgdpnkljologafpionhb
[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://www.trovi.com/?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&ISID=M2FE25B46-6B33-49C8-82F8-9F6A3D31D7C8&SearchSource=55&CUI=&UM=6&UP=SP43DDD08A-5DA7-44FD-9E25-71AADAF718D0&SSPV=
[C:\Users\gohanlover\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://www.trovi.com/?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&ISID=M2FE25B46-6B33-49C8-82F8-9F6A3D31D7C8&SearchSource=55&CUI=&UM=6&UP=SP43DDD08A-5DA7-44FD-9E25-71AADAF718D0&SSPV=


AdwCleaner[R0].txt - [17590 octets] - [09/02/2014 12:17:39]
AdwCleaner[R1].txt - [315 octets] - [13/11/2014 16:01:03]
AdwCleaner[R2].txt - [13904 octets] - [13/11/2014 16:03:31]
AdwCleaner[S0].txt - [16486 octets] - [09/02/2014 12:20:59]
AdwCleaner[S1].txt - [13630 octets] - [13/11/2014 16:08:39]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [13691 octets] ##########

Did you want the last FRST log?

I’ll post it when finished in case.

Ok. The command prompty thing log is here;

Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.7 (11.08.2014:1)
OS: Windows 7 Home Premium x64
Ran by gohanlover on Thu 11/13/2014 at 16:18:54.94



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SMessaging [Strongvault]
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\Seaorch-NewTAb
Successfully deleted: [Folder] "C:\ProgramData\strongvault online backup"
Successfully deleted: [Folder] "C:\Users\gohanlover\appdata\local\stronghold_llc"
Successfully deleted: [Folder] "C:\Users\gohanlover\appdata\local\strongvault online backup"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ Event Viewer Logs were cleared





Scan was completed on Thu 11/13/2014 at 16:32:33.07
End of JRT log

And the final FRST.txt and Additions.txt.

OK there is still something active so I will need to use a stronger tool

Do not reboot after the FRST fix please

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

IFEO\ashAvast.exe: [Debugger] svchost.exe IFEO\ashBug.exe: [Debugger] svchost.exe IFEO\ashChest.exe: [Debugger] svchost.exe IFEO\ashCnsnt.exe: [Debugger] svchost.exe IFEO\ashDisp.exe: [Debugger] svchost.exe IFEO\ashLogV.exe: [Debugger] svchost.exe IFEO\ashMaiSv.exe: [Debugger] svchost.exe IFEO\ashPopWz.exe: [Debugger] svchost.exe IFEO\ashQuick.exe: [Debugger] svchost.exe IFEO\ashServ.exe: [Debugger] svchost.exe IFEO\ashSimp2.exe: [Debugger] svchost.exe IFEO\ashSimpl.exe: [Debugger] svchost.exe IFEO\ashSkPcc.exe: [Debugger] svchost.exe IFEO\ashSkPck.exe: [Debugger] svchost.exe IFEO\ashUpd.exe: [Debugger] svchost.exe IFEO\ashWebSv.exe: [Debugger] svchost.exe IFEO\aswChLic.exe: [Debugger] svchost.exe IFEO\aswRegSvr.exe: [Debugger] svchost.exe IFEO\aswRunDll.exe: [Debugger] svchost.exe IFEO\aswUpdSv.exe: [Debugger] svchost.exe IFEO\avastSvc.exe: [Debugger] svchost.exe IFEO\avastUI.exe: [Debugger] svchost.exe IFEO\tapinstall.exe: [Debugger] svchost.exe IFEO\VisthAux.exe: [Debugger] svchost.exe CHR StartupUrls: Default -> "", "hxxp://www.symbaloo.com/", "hxxp://google.com/", "hxxp://www.trovi.com/?gd=&ctid=CT3331172&octid=EB_ORIGINAL_CTID&ISID=M2FE25B46-6B33-49C8-82F8-9F6A3D31D7C8&SearchSource=55&CUI=&UM=6&UP=SP43DDD08A-5DA7-44FD-9E25-71AADAF718D0&SSPV=" CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now