my avast has warning every site for ulr:mal

hi i have a huge problem with pop ups by avast that malicious blocked and its poping up for every site i open so i just need a solution to end this so plz help me

Could you attach a screen shot of the popup please whilst I look at the logs

Let me know how it is after this run

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-19\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-20\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1454471165-2077806209-527237240-500\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKLM -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.look-for-it.info/?l=1&q={searchTerms}&pid=21152&r=2015/02/09&hid=4075019979740501923&lg=EN&cc=IN&unqvl=82 SearchScopes: HKLM -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.look-for-it.info/?l=1&q={searchTerms}&pid=21152&r=2015/02/09&hid=4075019979740501923&lg=EN&cc=IN&unqvl=82 SearchScopes: HKU\S-1-5-21-1454471165-2077806209-527237240-500 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.look-for-it.info/?l=1&q={searchTerms}&pid=21152&r=2015/02/09&hid=4075019979740501923&lg=EN&cc=IN&unqvl=82 FF DefaultSearchEngine: mystartsearch FF DefaultSearchEngine,S: WebSearch FF DefaultSearchUrl: hxxp://websearch.look-for-it.info/?pid=21152&r=2015/02/09&hid=4075019979740501923&lg=EN&cc=IN&unqvl=82&l=1&q= FF SearchEngineOrder.1: WebSearch FF SearchEngineOrder.1,S: WebSearch FF SelectedSearchEngine: mystartsearch FF SelectedSearchEngine,S: WebSearch FF Extension: unisoalees - C:\Documents and Settings\Administrator.SRI-C7D60FA0C71\Application Data\Mozilla\Firefox\Profiles\qrm0y785.default\Extensions\2UR@EdF1.org [2015-02-09] FF Extension: unisaoles - C:\Documents and Settings\Administrator.SRI-C7D60FA0C71\Application Data\Mozilla\Firefox\Profiles\qrm0y785.default\Extensions\8Hq8@g44.org [2015-02-09] FF Extension: BuitSaveur - C:\Documents and Settings\Administrator.SRI-C7D60FA0C71\Application Data\Mozilla\Firefox\Profiles\qrm0y785.default\Extensions\hog8TU@l5H.edu [2015-02-28] FF Extension: youtubeadblocker - C:\Documents and Settings\Administrator.SRI-C7D60FA0C71\Application Data\Mozilla\Firefox\Profiles\qrm0y785.default\Extensions\IJsVvBqW@ZC.org [2015-02-09] FF Extension: uniosailes - C:\Documents and Settings\Administrator.SRI-C7D60FA0C71\Application Data\Mozilla\Firefox\Profiles\qrm0y785.default\Extensions\KcUWdXINEx@o.edu [2015-02-09] FF Extension: unisaLes - C:\Documents and Settings\Administrator.SRI-C7D60FA0C71\Application Data\Mozilla\Firefox\Profiles\qrm0y785.default\Extensions\Lx8F@Y.com [2011-08-29] FF Extension: No Name - C:\Documents and Settings\Administrator.SRI-C7D60FA0C71\Application Data\Mozilla\Firefox\Profiles\qrm0y785.default\extensions\fftoolbar2014@etech.com [Not Found] 2015-02-16 00:42 - 2015-02-16 00:42 - 00000000 ____D () C:\Program Files\RandoumPrice 2015-02-16 00:41 - 2015-02-16 00:41 - 00000000 ____D () C:\Program Files\GReatSaVee4U 2015-02-16 00:41 - 2015-02-16 00:41 - 00000000 ____D () C:\Program Files\BuitSaveur 2015-02-09 16:22 - 2015-02-09 16:22 - 00000000 ____D () C:\Program Files\uniosailes 2015-02-09 16:22 - 2015-02-09 16:22 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\ohghcialcnngdakicpjeaiimbgnpgonn 2015-02-09 16:19 - 2015-02-09 16:19 - 00000000 ____D () C:\Program Files\unisaoles 2015-02-09 16:18 - 2015-02-09 16:18 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\gbanelpgmhkljmkjifoffigmicflgbkn 2015-02-09 16:17 - 2011-08-29 00:01 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\{e872a812-1bea-90a3-e872-2a8121bea048} 2015-02-09 16:00 - 2015-02-16 00:41 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\9338453446935218154 2015-02-09 16:00 - 2015-02-09 16:00 - 00000000 ____D () C:\Program Files\unisoalees 2015-02-09 16:00 - 2015-02-09 16:00 - 00000000 ____D () C:\Program Files\uniisales 2015-02-09 15:57 - 2015-02-09 15:57 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\hnlmbdkpfkkgpadfnoeojgbpafinhmil 2015-02-09 15:56 - 2015-02-20 01:11 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\{6ed25b3c-8c88-d80c-6ed2-25b3c8c86cf2} CustomCLSID: HKU\S-1-5-21-1454471165-2077806209-527237240-500_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\DOCUME~1\ADMINI~1.SRI\LOCALS~1\Temp\2Fc2\temp\Gopala-Gopala-2015-320KBPS.zip.exe No File EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.