Please help clean this Windows 7 32 Bit PC

My sister’s PC generally works but demonstrates some strange behavior including slow loading of web pages, failure to start Dropbox (because permission on users***\appdata\local\temp keeps removing the explicitly added user name who is the only user and administrator anyway), and periodic crashing of applications.
In running the requested cleaning tools to generate logs it became evident that Windows Defender was running Real Time scans along side of AVAST. Windows Defender Real Time scanning has since been disabled.
Also the ASWMBR it stopped scanning, getting stuck on small temp files. The first time is was stuck on \users*****\AppData\LocalLow\Sun\Java\jrel.7.0_67\lzma.exe which was a tiny 14k file, stopped the scan, deleted the file and started the scan again.
The second time it stopped on another temp file and the scan was stopped.
There is a the of data in the Temp folders that perhaps should be removed before proceeding but not sure how to safely do that.
Finally, also attached is s TDSSKiller log that was run with certificate scan enabled.
Any advice on how to proceed greatly appreciated.
Thank you.

forgot to add the additions.txt log…

Hi xg, :slight_smile:

My name is Valinorum and I will be the acolyte today. Before we proceed, please, acknowledge yourself the following(s):

[*]Please do not create any new threads on this while we are working on your system as it wastes another volunteer’s time. If you are being helped/have solved the issue/no longer wish to continue, notify me in your reply and I will quickly close this thread. Failing to comply will result in denial of future assistance.
[*]Please do not install any new software while we are working on this system as it may hinder our process.
[*]Malware removal is a complicated process so don’t stop following the steps even if the symptoms are not found. Keep up with me until I declare you clean.
[*]Please do not try to fix anything without being ask.
[*]Please do not attach your logs or put them inside code/quote tags. Do a Copy/Paste of the entire contents of the log file and submit it inside your post unless directed otherwise.
[*]Please print or save the instructions I give you for quick reference. We may be using Safe mode which will cut you off from internet and you will not always be able to access this thread.
[*]Back up your data. I will not knowingly suggest your any course that might damage your system but sometimes Malware infections are so severe that only option we have is to re-format and re-install the operating system.
[*]If you are confused about any instruction, stop and ask. Do not keep on going.
[*]Do not repeat the steps if you face any problems.
[*]I am not an omniscient. There are things even I cannot foresee. But what I know took years to learn and perfect the skill. This site is run by volunteers who help people in need in their own free time. I would ask you to respect their time and be patient as sometimes real life demands our time and replies to you can be delayed.
[*]Private Message(PM) if and only if I have not responded to your thread within three days or your query is offtopic and personal. Do not PM me under any other circumstances. Your thread is the only medium of communication.
[*]The fixes are for your system only. Please refrain from using these fixes on other system as it may do serious damage.


You will need to replace ***** with your user-name, otherwise the fix will fail.


[*]Step # Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
[*]Open Notepad.exe. Do not use any other text editor software;
[*]Copy and Paste the contents inside the code-box to your Notepad

Start
CreateRestorePoint:
CloseProcesses:
EmptyTemp:
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1787280010-3613696176-2199675913-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
End

[*]Click on File > Save as…
[list][*]Inside the File Name box type fixlist.txt
[*]From the Save as type drop down list, choose All Files
[*]Save the file to your Desktop;
[*]Re-run FRST.exe and click Fix;
[*]Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.[]After the completion, a log will be produced;
[
]Attach the log in your next reply.[/list]


[*]Required Log(s):
[*]FRST Fix Log

Regards,
Valinorum

Valinorum,
Thank you for your help.
I created the Fixlist.txt file and ran FRST and clicked ‘FIX’.
It stalled while clearing temporary files, stuck on a small file for 20 minutes. Killed the FRST task, rebooted, and tried again.
Hence you will see two FIXLOG files. The one with the number 1 on the end was from the initial run and the one with a 2 on the end from the second run.
The computer seems better but it still has some problems like unable to uninstall a password keeper called Dashlane (object not found when running uninstall).
Also, I ran AdwCleaner to Scan (did not remove/repair) and it found several issues with Chrome (Ask.com, AOL Toolbar, Incredimail, etc).
Please let me know how you suggest I proceed.
Thank you.

Please, make sure that you have a backup of the passwords you managed via the aforementioned software as there have been incidents where users were unable to access their desired sites due to the loss of their passwords. Report me your result and I will remove the software.

Regards,
Valinorum

Thanks for your concern about the stored passwords.
There are no passwords of concern.
I am concerned about the plugins I mentioned found by AwCleaner. I would just have AdwCleaner do its thing but waited for your direction before doing as well as how to get rid of Dashlane.
Thank you.

Apply the ‘Clean’ option of AdwCleaner and post a fresh FRST scan log.

Thank you for your assistance.
AdwCleaner run and log attached.
FRST run and log attached.
Old problem or not able to remove Dashlane password manger (no worries about loosing passwords) via the add/remove programs still exists.
New problem of Dropbox not starting after AdwCleaner occurred.
Corrected Dropbox problem via Dropbox suggestions of adding user to permission of C:\Users*****\App Data\Local\Temp but it suggests something is wrong as the user is an Administrator and the folder already has Administration set as Full Control so there should be no need to add the user explicitly as Full Control.
Thank you.

[*]Step #2 Fix with FRST
Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
[*]Open Notepad.exe. Do not use any other text editor software;
[*]Copy and Paste the contents inside the code-box to your Notepad

Start
CreateRestorePoint:
CloseProcesses:
Emptytemp:
C:\Users\*****\AppData\Roaming\Dashlane
HKU\S-1-5-21-1787280010-3613696176-2199675913-1000\...\Run: [Dashlane] => C:\Users\*****\AppData\Roaming\Dashlane\Dashlane.exe [227000 2015-01-26] ()
Reg: reg delete "HKU\S-1-5-21-1787280010-3613696176-2199675913-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dashlane" /f
End

[*]Click on File > Save as…
[list][*]Inside the File Name box type fixlist.txt
[*]From the Save as type drop down list, choose All Files
[*]Save the file to your Desktop;
[*]Re-run FRST.exe and click Fix;
[*]Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.[]After the completion, a log will be produced;
[
]Attach the log in your next reply.[/list]


[*]Required Log(s):
[*]FRST Fix Log

Regards,
Valinorum