can some one please help with removing tmz tmp

zs

Attach your basic logs. (MBAM, FRST and aswMBR…!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0

here are the logs

OK, now you’ve to wait a bit…

Let me know what problems remain after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

HKU\S-1-5-21-1010254731-2353233438-141588879-1001\...\Winlogon: [Shell] C:\Windows\expstart.exe [925184 2013-03-29] () <==== ATTENTION AppInit_DLLs: c:\progra~3\bitguard\271769~1.27\{16cdf~1\loader.dll => c:\progra~3\bitguard\271769~1.27\{16cdf~1\loader.dll File Not Found AppInit_DLLs-x32: c:\progra~3\bitguard\271832~1.68\{16cdf~1\bitguard.dll => "c:\progra~3\bitguard\271832~1.68\{16cdf~1\bitguard.dll" File Not Found URLSearchHook: HKU\S-1-5-21-1010254731-2353233438-141588879-1001 - (No Name) - {49c795c2-604a-4d18-aeb1-b3eba27e5ea2} - No File SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-1010254731-2353233438-141588879-1001 -> BrowserMngrDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKU\S-1-5-21-1010254731-2353233438-141588879-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = Toolbar: HKU\S-1-5-21-1010254731-2353233438-141588879-1001 -> No Name - {49C795C2-604A-4D18-AEB1-B3EBA27E5EA2} - No File DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} FF DefaultSearchEngine: Search the web (Babylon) FF SearchEngineOrder.1: Search the web (Babylon) FF SelectedSearchEngine: Search the web (Babylon) FF Extension: PricePeep - C:\Users\elijah\AppData\Roaming\Mozilla\Firefox\Profiles\1kc3b28p.default\Extensions\pricepeep@getpricepeep.com [2013-06-15] FF Extension: No Name - C:\Users\elijah\AppData\Roaming\Mozilla\Firefox\Profiles\1kc3b28p.default\extensions\ffxtlbr@babylon.com [Not Found] FF Extension: IObit Toolbar - C:\Program Files (x86)\IObit Toolbar\FF [2014-11-18] FF Extension: No Name - C:\Users\elijah\AppData\Roaming\Mozilla\Firefox\Profiles\1kc3b28p.default\extensions\plugin@yontoo.com.xpi [Not Found] FF Extension: No Name - C:\Users\elijah\AppData\Roaming\Mozilla\Firefox\Profiles\1kc3b28p.default\extensions\pricepeep@getpricepeep.com.xpi [Not Found] FF Extension: No Name - C:\Users\elijah\AppData\Roaming\Mozilla\Firefox\Profiles\1kc3b28p.default\extensions\{28387537-e3f9-4ed7-860c-11e69af4a8a0} [Not Found] FF Extension: No Name - C:\Users\elijah\AppData\Roaming\Mozilla\Firefox\Profiles\1kc3b28p.default\extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9} [Not Found] CHR StartupUrls: Profile 1 -> "hxxp://search.babylon.com/?affID=112555&tt=120912_ccp_3712_7&babsrc=HP_ss&mntrId=608a8621000000000000ac8112bf440a", "hxxp://search.conduit.com/?CUI=UN24720061541314816&ctid=CT3272718&SearchSource=48" CHR DefaultSuggestURL: Profile 1 -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} 2014-11-18 22:20 - 2014-11-29 12:27 - 00000000 ____D () C:\Program Files (x86)\Application Updater Task: {C01871B9-DF76-4C06-9724-D5E811E84B8E} - \BitGuard No Task File <==== ATTENTION C:\Users\elijah\jagex_cl_loginapplet_LIVE.dat C:\Users\elijah\jagex_cl_oldschool_LIVE.dat C:\Users\elijah\jagex_cl_runescape_LIVE.dat C:\Users\elijah\jagex_cl_runescape_LIVE1.dat C:\Users\elijah\random.dat C:\Windows\expstart.exe c:\progra~3\bitguard EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

.

Are you still getting the alerts ?

no not at all

If all is well tomorrow let me know and I will tidy up :slight_smile:

thanks a lot