Help- Malware attack

My computer crashed and I had to restore to an old system restore point and now my computer seems to be overrun with malware.
Avast keeps notifying me of Threats detected that it has blocked URL:Mal and chrome keeps redirecting google to random sites.
I have tried running a boot scan of avast and Malwarebytes but neither have helped

Malware log
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.21.03

Windows Vista x86 NTFS
Internet Explorer 7.0.6000.16546
Robbie :: ROBBIE-PC [administrator]

3/21/2012 8:08:38 AM
mbam-log-2012-03-21 (08-08-38).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 217543
Time elapsed: 49 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 6
C:\ProgramData\QDlAJcvEKoYotV.exe (Trojan.FakeAlert) → Quarantined and deleted successfully.
C:\Users\Robbie\AppData\Roaming\Perfect Automation\records\111122-191730.exe (Spyware.Passwords.XGen) → Quarantined and deleted successfully.
C:\Users\Robbie\AppData\Roaming\Perfect Automation\records\111122-192433hawaiin2.exe (Spyware.Passwords.XGen) → Quarantined and deleted successfully.
C:\Users\Robbie\AppData\Local\Temp\77A0.tmp (Trojan.FakeAlert) → Quarantined and deleted successfully.
C:\Users\Robbie\AppData\Local\Temp\1CE3.tmp (Trojan.FakeAlert) → Quarantined and deleted successfully.
C:\Users\Robbie\AppData\Local\Temp\y7LBh9Dlx8eKwy.exe.tmp (Trojan.FakeAlert) → Quarantined and deleted successfully.

(end)

Nshield log
21.03.2012 19:24:53 Network Shield: blocked access to malicious site hxtp://locateboss.com/search?id=c122baf027b8d0896433ab908b2e8b1e [ C:\Windows\Explorer.EXE ( 2984 ) ]
21.03.2012 22:04:54 Network Shield: blocked access to malicious site hxtp://popsearchtips.net/search?id=99f933956ab9f5de6c9f6d738b5038f9 [ C:\Windows\Explorer.EXE ( 1816 ) ]
21.03.2012 22:30:25 Network Shield: blocked access to malicious site hxtp://yousearchtube.com/search?id=406abbe9dca4069a301500b1628ec4b4 [ C:\Windows\Explorer.EXE ( 1816 ) ]
21.03.2012 23:12:03 Network Shield: blocked access to malicious site hxtp://godadsearch.com/search?id=61d7e46999f961ff99b0f8b561a2ec7c [ C:\Windows\Explorer.EXE ( 1816 ) ]
22.03.2012 00:25:28 Network Shield: blocked access to malicious site hxtp://clipsandvids.com/search?id=3f4649708972a3a3dcbae29e96227103 [ C:\Windows\Explorer.EXE ( 1816 ) ]
22.03.2012 02:32:07 Network Shield: blocked access to malicious site hxtp://resultman.com/search?id=3828e8369508db742fc6d150389145a7 [ C:\Windows\Explorer.EXE ( 1816 ) ]
26.03.2012 08:10:49 Network Shield: blocked access to malicious site hxtp://linkfindersite.com/search?id=e29db1db609dfcc9c748e4cdbbc2f50b [ C:\Windows\Explorer.EXE ( 3336 ) ]
26.03.2012 08:27:20 Network Shield: blocked access to malicious site hxtp://topdomainnow.com/search?id=b370243b38c01eca50bd353405189bea [ C:\Windows\Explorer.EXE ( 3336 ) ]
26.03.2012 09:05:02 Network Shield: blocked access to malicious site hxtp://popsearchtips.com/search?id=5fb5e52a5b890c52d3048b01e3428ba0 [ C:\Windows\Explorer.EXE ( 3336 ) ]
26.03.2012 09:16:09 Network Shield: blocked access to malicious site hxtp://newtopdomain.com/search?id=f118af7ddb272a7b984091e357393b60 [ C:\Windows\Explorer.EXE ( 3336 ) ]
26.03.2012 18:29:08 Network Shield: blocked access to malicious site hxtp://popsearchtips.net/search?id=a146e34ac0d27ee465749e849b4319c4 [ C:\Windows\Explorer.EXE ( 3336 ) ]
26.03.2012 20:51:13 Network Shield: blocked access to malicious site hxtp://freenewslinker.com/search?id=92b7a99cab12c3af4584241b99af49e5 [ C:\Windows\Explorer.EXE ( 3336 ) ]
26.03.2012 21:33:27 Network Shield: blocked access to malicious site hxtp://smokepuma.com/search?id=b588c4b942296dab85a65797c8398b3f [ C:\Windows\Explorer.EXE ( 3336 ) ]
26.03.2012 23:03:10 Network Shield: blocked access to malicious site hxtp://bustoutvideo.com/search?id=b6622e0d2af2f68652f3cac340064680 [ C:\Windows\explorer.exe ( 7292 ) ]
26.03.2012 23:06:50 Network Shield: blocked access to malicious site hxtp://topnametech.com/search?id=70e86522cd9801198a0ee88b64e02f7c [ C:\Windows\explorer.exe ( 7292 ) ]
26.03.2012 23:34:40 Network Shield: blocked access to malicious site hxtp://godadsearch.com/search?id=05c1aaf7647ee38b5ff892626cad586f [ C:\Windows\explorer.exe ( 7292 ) ]
27.03.2012 00:54:29 Network Shield: blocked access to malicious site hxtp://searchtermpros.com/search?id=12f0417eea3f370a225ed5ad38f8c4d8 [ C:\Windows\explorer.exe ( 7292 ) ]
27.03.2012 01:28:27 Network Shield: blocked access to malicious site hxtp://smokepuma.com/search?id=ca5483a0601c2786db7cc1bb5a66fdac [ C:\Windows\explorer.exe ( 7292 ) ]
27.03.2012 01:47:13 Network Shield: blocked access to malicious site hxtp://newslinker.info/search?id=2b922d4ee1e144aeedb845ed4fac3699 [ C:\Windows\explorer.exe ( 7292 ) ]
27.03.2012 03:45:19 Network Shield: blocked access to malicious site hxtp://newtopdomain.com/search?id=116b893f7d778e3d26f8c8dbd9f280d3 [ C:\Windows\explorer.exe ( 5288 ) ]
27.03.2012 04:08:58 Network Shield: blocked access to malicious site hxtp://fastlinkers.com/search?id=6b3ae885772d577bd21c5ce648f2f6ba [ C:\Windows\explorer.exe ( 5288 ) ]
27.03.2012 04:13:06 Network Shield: blocked access to malicious site hxtp://videorejects.com/search?id=421e53f2ec050c9700db23afdb945841 [ C:\Windows\explorer.exe ( 5288 ) ]
27.03.2012 04:33:04 Network Shield: blocked access to malicious site hxtp://resultdawg.com/search?id=78feef53f017c4479fd3f357c2167527 [ C:\Windows\explorer.exe ( 5288 ) ]
27.03.2012 04:34:56 Network Shield: blocked access to malicious site hxtp://newslinkernow.com/search?id=76e9c16621592e6a65a5a176a1fcd8af [ C:\Windows\explorer.exe ( 5288 ) ]
27.03.2012 05:56:47 Network Shield: blocked access to malicious site hxtp://newslinker.info/search?id=788f6fc1e65055db5ec93158fb047cf7 [ C:\Windows\explorer.exe ( 4240 ) ]
27.03.2012 05:58:42 Network Shield: blocked access to malicious site hxtp://smokepuma.com/search?id=c38ca44214fae688a4a4a074329cb533 [ C:\Windows\explorer.exe ( 4240 ) ]
27.03.2012 06:08:07 Network Shield: blocked access to malicious site hxtp://bestdomainfranchise.com/search?id=2d83f36974ae21670f1a3e9327bd7888 [ C:\Windows\explorer.exe ( 4240 ) ]
27.03.2012 06:09:58 Network Shield: blocked access to malicious site hxtp://tubeleaker.com/search?id=3739ba7e1d40face0982a84c12632dfe [ C:\Windows\explorer.exe ( 4240 ) ]
27.03.2012 06:32:32 Network Shield: blocked access to malicious site hxtp://topnametech.com/search?id=bf03e20620ba505709848868994a46e5 [ C:\Windows\explorer.exe ( 4240 ) ]
27.03.2012 06:36:32 Network Shield: blocked access to malicious site hxtp://smokepuma.com/search?id=cfae9420bd0ef02b3292448346372229 [ C:\Windows\explorer.exe ( 4240 ) ]
27.03.2012 06:53:54 Network Shield: blocked access to malicious site hxtp://thefastfinders.com/search?id=7dc00fee76ada47c09f963aec8866fd9 [ C:\Windows\explorer.exe ( 4240 ) ]

the malwarebytes scan log you posted is from 3/21/2012…do you have one that is new?
if not, update mawarebytes, run a quick scan and post the log if anything is detected

also attach the log from aswMBR http://forum.avast.com/index.php?topic=53253.0

Monitoring :smiley:

Here is the new Malware log
I tried running the aswMBR.exe but nothing happens when I double click on it or when I run it from a command line

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.27.08

Windows Vista x86 NTFS
Internet Explorer 7.0.6000.16546
Robbie :: ROBBIE-PC [administrator]

3/27/2012 11:11:45 PM
mbam-log-2012-03-27 (23-11-45).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 216565
Time elapsed: 11 minute(s), 20 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

I also ran Rogue killer accroding to instructions of someone with a similar problem and these are the logs

Hi,

Could you run aswMBR per the instructions found >> http://forum.avast.com/index.php?topic=53253.0 I want to make sure everything seems on the up and up with this scan first.

I have tried to run aswMBR but nothing happens when I double click it.
I tried renaming it or running it from a command line but nothing either

Hi,

Could you try and run aswMBR from Safe Mode please. If it does not work do the following…

Please download TDSSKiller.zip

[*]Extract it to your desktop
[*]Double click TDSSKiller.exe
[*]when the window opens, click on Change Parameters
[*]under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
[*]click OK
[*]Press Start Scan

[*]Only if Malicious objects are found then ensure Cure is selected
[*]Then click Continue > Reboot now

[*]Copy and paste the log in your next reply

[*]A copy of the log will be saved automatically to the root of the drive (typically C:)


If aswMBR was able to run in Safe Mode please post the log that was created…if not…post the log made by TDSSKiller.