CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint: HKLM Group Policy restriction on software: C:\Program Files\AVAST Software\Avast\avastui.exe <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\AVAST Software\Avast\avastsvc.exe <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\AVAST Software\Avast\ashUpd.exe <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\AVAST Software\Avast\ashQuick.exe <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\AVAST Software\Avast\sched.exe <====== ATTENTION HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION HKU\S-1-5-21-2004839443-3334354604-3548700845-1000\...\MountPoints2: {c24b614a-fe9c-11e3-9499-001b24e8768d} - E:\AutoRun.exe TMM70 IFEO\360browser.exe: [Debugger] cmd.exe /c start "" "C:\Program Files (x86)\Internet Explorer\iexplore.exe" "" IFEO\chrome.exe: [Debugger] cmd.exe /c start "" "C:\Program Files (x86)\Internet Explorer\iexplore.exe" "" IFEO\firefox.exe: [Debugger] cmd.exe /c start "" "C:\Program Files (x86)\Internet Explorer\iexplore.exe" "" IFEO\mbam.exe: [Debugger] soivpnnwo.exe IFEO\mbamgui.exe: [Debugger] bkksosotu.exe IFEO\MRT.exe: [Debugger] pcckazkiatg.exe IFEO\mrtstub.exe: [Debugger] biikxzycyzn.exe IFEO\rstrui.exe: [Debugger] nriiz.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKU\S-1-5-21-2004839443-3334354604-3548700845-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:56139;https=127.0.0.1:56139; HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rocket-find.com/?f=1&a=rckt_dsites01_14_27_ie&cd=2XzuyEtN2Y1L1QzutDtDtC0C0B0FyD0ByE0FyDyB0B0AtD0BtN0D0Tzu0SzytCtAtN1L2XzutBtFtBtCtFzztFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0F0BtAyC0EtCtAtGyE0F0C0FtGyB0B0AyCtGyDyCtAtDtGyDyBzztAtCyEyDzyzzyD0CtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDyE0BtA0EtB0DzytGyByCzz0EtGyCyD0A0DtG0FyE0DyCtGyC0ByEyDtAzyyE0EtBtD0CyC2Q&cr=1971521438&ir= SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_dsites01_14_27_ie&cd=2XzuyEtN2Y1L1QzutDtDtC0C0B0FyD0ByE0FyDyB0B0AtD0BtN0D0Tzu0SzytCtAtN1L2XzutBtFtBtCtFzztFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0F0BtAyC0EtCtAtGyE0F0C0FtGyB0B0AyCtGyDyCtAtDtGyDyBzztAtCyEyDzyzzyD0CtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDyE0BtA0EtB0DzytGyByCzz0EtGyCyD0A0DtG0FyE0DyCtGyC0ByEyDtAzyyE0EtBtD0CyC2Q&cr=1971521438&ir= SearchScopes: HKU\S-1-5-21-2004839443-3334354604-3548700845-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_dsites01_14_27_ie&cd=2XzuyEtN2Y1L1QzutDtDtC0C0B0FyD0ByE0FyDyB0B0AtD0BtN0D0Tzu0SzytCtAtN1L2XzutBtFtBtCtFzztFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0F0BtAyC0EtCtAtGyE0F0C0FtGyB0B0AyCtGyDyCtAtDtGyDyBzztAtCyEyDzyzzyD0CtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDyE0BtA0EtB0DzytGyByCzz0EtGyCyD0A0DtG0FyE0DyCtGyC0ByEyDtAzyyE0EtBtD0CyC2Q&cr=1971521438&ir= FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found] CHR DefaultSearchKeyword: Default -> wse rocket.com CHR DefaultSearchURL: Default -> http://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_dsites01_14_27_ie&cd=2XzuyEtN2Y1L1QzutDtDtC0C0B0FyD0ByE0FyDyB0B0AtD0BtN0D0Tzu0SzytCtAtN1L2XzutBtFtBtCtFzztFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0F0BtAyC0EtCtAtGyE0F0C0FtGyB0B0AyCtGyDyCtAtDtGyDyBzztAtCyEyDzyzzyD0CtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDyE0BtA0EtB0DzytGyByCzz0EtGyCyD0A0DtG0FyE0DyCtGyC0ByEyDtAzyyE0EtBtD0CyC2Q&cr=1971521438&ir= R1 {57f143ae-1ecd-493d-9ddb-32c45a3cecd5}Gw64; C:\Windows\System32\drivers\{57f143ae-1ecd-493d-9ddb-32c45a3cecd5}Gw64.sys [61112 2014-06-27] (StdLib) 2015-01-21 20:05 - 2014-08-28 22:53 - 00000316 _____ () C:\Windows\Tasks\UpdaterEX.job 2015-01-21 20:05 - 2014-07-01 21:03 - 00000316 _____ () C:\Windows\Tasks\Rocket Updater.job 2015-01-12 22:35 - 2014-12-19 21:52 - 00000000 ____D () C:\Users\Todos os Usuários\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-01-12 22:35 - 2014-12-19 21:52 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-01-12 22:30 - 2014-12-20 18:24 - 00000000 __SHD () C:\Users\Todos os Usuários\6b407430 2015-01-12 22:30 - 2014-12-20 18:24 - 00000000 __SHD () C:\ProgramData\6b407430 Task: {00549D53-45B6-4318-8195-E70660539B63} - System32\Tasks\UpdaterEX => C:\Users\Elton Carvalho\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {3EFC935D-B8B1-44C5-B75C-5A7D30AF27E7} - System32\Tasks\Rocket Updater => C:\Users\Elton Carvalho\AppData\Roaming\RocketUpdater\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: C:\Windows\Tasks\Rocket Updater.job => C:\Users\ELTONC~1\AppData\Roaming\ROCKET~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\ELTONC~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION C:\Users\Elton Carvalho\AppData\Roaming\RocketUpdater C:\Users\ELTONC~1\AppData\Roaming\UPDATE~1 EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.