Could you confirm that you installed the GbPlugin
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-696272906-3478152169-1572563272-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={FE941A3F-6A1E-4BBF-8048-9E366A2C7A66}&mid=c940fced741047cdbc3ea138fadcf72d-06050e277f64d1ccca6d2151ed49f9cb1323dc9e&lang=pt-br&ds=ZEN&coid=avgtbdisZE&cmpid=&pr=fr&d=2015-08-13 20:31:58&v=4.1.5.143&pid=wtu&sg=&sap=hp
SearchScopes: HKU\S-1-5-21-696272906-3478152169-1572563272-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={FE941A3F-6A1E-4BBF-8048-9E366A2C7A66}&mid=c940fced741047cdbc3ea138fadcf72d-06050e277f64d1ccca6d2151ed49f9cb1323dc9e&lang=pt-br&ds=ZEN&coid=avgtbdisZE&cmpid=&pr=fr&d=2015-08-13 20:31:58&v=4.1.5.143&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-696272906-3478152169-1572563272-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={FE941A3F-6A1E-4BBF-8048-9E366A2C7A66}&mid=c940fced741047cdbc3ea138fadcf72d-06050e277f64d1ccca6d2151ed49f9cb1323dc9e&lang=pt-br&ds=ZEN&coid=avgtbdisZE&cmpid=&pr=fr&d=2015-08-13 20:31:58&v=4.1.5.143&pid=wtu&sg=&sap=dsp&q={searchTerms}
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKU\S-1-5-21-696272906-3478152169-1572563272-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Extension: No Name - C:\Users\Raquel\AppData\Roaming\Mozilla\Firefox\Profiles\2vk9p6tu.default-1370103863645\Extensions\trash [2015-05-01]
S0 ovanvq; no ImagePath
U3 a08v2di4; C:\Windows\System32\Drivers\a08v2di4.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
2015-08-13 20:20 - 2015-08-14 12:12 - 00000000 ____D C:\ProgramData\MFAData
2015-08-13 20:20 - 2015-08-13 20:20 - 00000000 ____D C:\Users\Raquel\AppData\Local\MFAData
2015-08-13 20:18 - 2015-08-14 11:31 - 00000000 ____D C:\Users\Todos os Usuários\Avg
2015-08-13 20:18 - 2015-08-14 11:31 - 00000000 ____D C:\Users\Raquel\AppData\Local\AvgSetupLog
2015-08-13 20:18 - 2015-08-14 11:31 - 00000000 ____D C:\ProgramData\Avg
2015-08-13 20:18 - 2015-08-13 20:18 - 00000000 ____D C:\Users\Raquel\AppData\Local\Avg
2015-08-13 11:48 - 2015-08-13 11:48 - 00388608 _____ (Trend Micro Inc.) C:\Users\Raquel\Downloads\HijackThis.exe
2015-08-13 09:18 - 2015-08-13 09:18 - 00000000 ____D C:\Users\Raquel\AppData\Local\{BBB85357-6AB3-42AE-9CC4-4AF6541A375F}
2015-08-06 10:03 - 2015-08-06 10:03 - 00000000 ____D C:\Users\Raquel\AppData\Local\{02A22EE4-EB2A-4B13-B60C-9E1268FB8FC6}
2015-07-31 08:58 - 2015-07-31 08:58 - 00000000 ____D C:\Users\Raquel\AppData\Local\{6FB3F8F9-DFDE-4B12-AD65-0BDB33C1940B}
2015-07-30 09:06 - 2015-07-30 09:06 - 00000000 ____D C:\Users\Raquel\AppData\Local\{B0F5F93C-25F6-4C95-9B43-8082EBEE4165}
2015-07-28 09:28 - 2015-07-28 09:28 - 00000000 ____D C:\Users\Raquel\AppData\Local\{D7C9DBF2-8336-4C03-BE0F-DC9938DAACA7}
2015-07-27 19:16 - 2015-07-27 19:17 - 00000000 ____D C:\Users\Raquel\AppData\Local\{751667F9-C914-4B49-A857-C0C14C4334E3}
2015-07-26 22:44 - 2015-07-26 22:44 - 00000000 ____D C:\Users\Raquel\AppData\Local\{103B52BC-3CE1-4323-AA4F-76EABD1ECFBF}
2015-07-26 09:26 - 2015-07-26 09:26 - 00000000 ____D C:\Users\Raquel\AppData\Local\{0792945E-1EE5-49C7-9E50-92ED8EB53312}
2015-07-25 10:10 - 2015-07-25 10:10 - 00000000 ____D C:\Users\Raquel\AppData\Local\{B2D3292E-998F-4605-8ECD-8187C13E6AED}
2015-07-23 23:20 - 2015-07-23 23:20 - 00000000 ____D C:\Users\Raquel\AppData\Local\{C577B508-9D6C-407D-BAD2-595E75AB49B2}
2015-07-23 08:25 - 2015-07-23 08:26 - 00000000 ____D C:\Users\Raquel\AppData\Local\{64E5EA89-734B-45F2-9404-3B0681312AE1}
2015-07-22 09:16 - 2015-07-22 09:16 - 00000000 ____D C:\Users\Raquel\AppData\Local\{6DDBA632-00C9-46D6-969E-472717942A54}
2015-07-21 08:10 - 2015-07-21 08:10 - 00000000 ____D C:\Users\Raquel\AppData\Local\{49C520CC-7855-4B6F-B8B0-C47A373BA2E7}
2015-07-21 07:42 - 2015-07-21 07:42 - 00000199 _____ C:\Windows\system32\2015-07-21-10-42-13.099-AvastVBoxSVC.exe-3148.log
2015-07-20 08:43 - 2015-07-20 08:43 - 00000000 ____D C:\Users\Raquel\AppData\Local\{72929CB8-66D2-4159-B4BC-E68B97218541}
2015-07-20 08:32 - 2015-07-20 08:33 - 00000199 _____ C:\Windows\system32\2015-07-20-11-32-50.070-AvastVBoxSVC.exe-3260.log
2015-07-18 12:34 - 2015-07-18 12:34 - 00000199 _____ C:\Windows\system32\2015-07-18-15-34-24.024-AvastVBoxSVC.exe-3888.log
2015-07-18 08:33 - 2015-07-18 08:33 - 00000000 ____D C:\Users\Raquel\AppData\Local\{A5B8AEB2-48EB-47F9-95DF-5B9ABF2526A5}
2015-07-18 08:16 - 2015-07-18 08:17 - 00000199 _____ C:\Windows\system32\2015-07-18-11-16-56.063-AvastVBoxSVC.exe-4692.log
2015-07-17 19:44 - 2015-07-17 19:45 - 00000000 ____D C:\Users\Raquel\AppData\Local\{031EE3B0-90C6-4B25-B2DE-9FA0A11694C4}
2015-07-17 19:38 - 2015-07-17 19:38 - 00000199 _____ C:\Windows\system32\2015-07-17-22-38-34.017-AvastVBoxSVC.exe-3648.log
2015-07-16 22:18 - 2015-07-16 22:19 - 00000000 ____D C:\Users\Raquel\AppData\Local\{BE68F5D9-DD1D-4245-A232-511E08D0C9B0}
2015-07-16 20:53 - 2015-07-16 20:53 - 00000199 _____ C:\Windows\system32\2015-07-16-23-53-28.016-AvastVBoxSVC.exe-3404.log
2015-07-16 08:17 - 2015-07-16 08:17 - 00000199 _____ C:\Windows\system32\2015-07-16-11-17-00.076-AvastVBoxSVC.exe-3068.log
2015-07-15 20:33 - 2015-07-15 20:33 - 00000000 ____D C:\Users\Raquel\AppData\Local\{2491086C-1E5E-41A5-BB47-329B998BE025}
2015-07-15 20:25 - 2015-07-15 20:25 - 00000199 _____ C:\Windows\system32\2015-07-15-23-25-00.080-AvastVBoxSVC.exe-3296.log
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that