FIRST >>>>

Please download the MCPR tool from here. Double click on the downloaded file and follow the prompts to let it clean what is left of McAfee off your system. (These remains could be interferring with Avast.)

SECOND >>>>

1- Please double-click on FRST64 (the one you scanned your system with).
2- Press the Ctrl+y (Ctrl and y keys at the same time).
3- A fixlist.txt file opens up in notepad.exe. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy. Paste this into the open notepad.

Start:: CreateRestorePoint: CloseProcesses: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK14/1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK14/1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK14/1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK14/1 HKU\S-1-5-21-1970300532-3615421346-527185286-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK14/1 HKU\S-1-5-21-1970300532-3615421346-527185286-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK14/1 SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKU\S-1-5-21-1970300532-3615421346-527185286-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} CHR StartupUrls: Default -> "hxxp://yahoo.com/" CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?ei={inputEncoding}&fr=crmas&p={searchTerms} CHR DefaultSearchKeyword: Default -> yahoo.com CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms} CHR Extension: (Google Slides) - C:\Users\Terry Swanigan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-07-02] CHR Extension: (Google Drive) - C:\Users\Terry Swanigan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-02] CHR Extension: (Grammarly for Chrome) - C:\Users\Terry Swanigan\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2017-07-02] CHR Extension: (Chrome Web Store Payments) - C:\Users\Terry Swanigan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-02] CHR Extension: (Chrome Media Router) - C:\Users\Terry Swanigan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-02] S2 0286671499041920mcinstcleanup; C:\windows\TEMP\028667~1.EXE [834664 2013-07-12] (McAfee, Inc.) C:\windows\TEMP\028667~1.EXE R2 mcbootdelaystartsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [326856 2013-07-10] (McAfee, Inc.) S4 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [X] S2 mfevtp; "C:\windows\system32\mfevtps.exe" [X] U3 aswbdisk; no ImagePath S0 cfwids; system32\drivers\cfwids.sys [X] S0 mfeapfk; system32\drivers\mfeapfk.sys [X] R0 mfeavfk; system32\drivers\mfeavfk.sys [X] S0 mfeelamk; system32\drivers\mfeelamk.sys [X] S0 mfefirek; system32\drivers\mfefirek.sys [X] R0 mfehidk; system32\drivers\mfehidk.sys [X] R0 mfewfpk; system32\drivers\mfewfpk.sys [X] 2017-07-02 20:30 - 2017-07-02 20:30 - 00000000 __RSH C:\windows\SysWOW64\Drivers\103C_HP_cPC_21-h013w_Y53316J_0U_Q5CM41507CS_E14AM1ARA602_4A_I2B0D_SHP_VA01_B80.08_T140304_W8101-0_L409_M3987_J2_7Intel_86C3_92.60_#140408_N10EC8168;168C0032_Z_G80860402_Ohp CDDVDW SN-208FB_DHWP421A.MRK 2017-07-02 20:30 - 2017-07-02 20:30 - 00000000 __RSH C:\windows\system32\Drivers\103C_HP_cPC_21-h013w_Y53316J_0U_Q5CM41507CS_E14AM1ARA602_4A_I2B0D_SHP_VA01_B80.08_T140304_W8101-0_L409_M3987_J2_7Intel_86C3_92.60_#140408_N10EC8168;168C0032_Z_G80860402_Ohp CDDVDW SN-208FB_DHWP421A.MRK cmd: ipconfig /flushdns cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state on Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f CMD: bitsadmin /reset /allusers RemoveProxy: EmptyTemp: Reboot: End::

4- Press the Ctrl+s keys to save the file. Close the notepad / fixlist.txt file.
5- Press the Fix button just once.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

http://i1351.photobucket.com/albums/p785/dbreeze2/just%20stuff/Press%20the%20FIX%20button_zpsdd5zi3mt.png

If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop or the same directory it was run from (Fixlog.txt). Please post it to your reply.

LAST >>>>

AdwCleaner

Download AdwCleaner from here . Save the file to the desktop.

NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:

http://i1351.photobucket.com/albums/p785/dbreeze2/Scanners%20screens/AdwCleaner_v6_start_zps5nymee4e.png

- Click the [b]Scan[/b] button and wait for the scan to finish.
- After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: [b]Waiting for action. Please uncheck elements you don't want to remove.[/b]
- Click the [b]Clean[/b] button.
- [b]Everything checked[/b] will be deleted.
- When the program has finished cleaning a report appears.
- Once done it may ask to reboot, allow this

http://1.bp.blogspot.com/-vitKqfMQS4o/UEDylIQ7HJI/AAAAAAAABLc/Hx-IwqKoaxg/s1600/adwcleaner_delete_restart.jpg

  • On reboot a log will be produced; please attach that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C#].txt

Optional:

NOTE: If you see AVG Secure Search being targeted for deletion, Here’s Why and Here. You can always Reinstall it.