Which browser do the adverts show in ?
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKLM-x32\...\RunOnce: [360safeuninst] => C:\Users\user\AppData\Local\Temp\remove360.bat [1782 2015-07-11] () <===== ATTENTION
HKU\S-1-5-21-1328610593-2988302748-3692750778-1000\...\Run: [QQ2009] => E:\Tencent\QQ\Bin\QQ.exe [139960 2015-07-10] (Tencent)
HKU\S-1-5-21-1328610593-2988302748-3692750778-1000\...\MountPoints2: {5b25d3fa-9028-11e2-ac3b-bc5ff4687250} - F:\autorun.exe
HKU\S-1-5-21-1328610593-2988302748-3692750778-1000\...\MountPoints2: {62dd396a-8863-11e2-8180-bc5ff4687250} - H:\autorun.exe
HKU\S-1-5-21-1328610593-2988302748-3692750778-1000\...\MountPoints2: {8d43027a-8e75-11e2-9fad-bc5ff4687250} - G:\Startme.exe
HKU\S-1-5-21-1328610593-2988302748-3692750778-1000\...\MountPoints2: {8e87627f-8c47-11e2-852c-806e6f6e6963} - F:\autorun.exe
HKU\S-1-5-21-1328610593-2988302748-3692750778-1000\...\MountPoints2: {9b5dfcc2-9118-11e3-b22e-bc5ff4687250} - I:\autorun.exe
ShellIconOverlayIdentifiers-x32: [AAADesktopTips] -> {4562B511-62E9-4533-B7B2-56A8BB10B482} => No File
BHO: QQDownload IE Left Helper -> {00000000-12C9-4305-82F9-43058F20E8D2} -> E:\Tencent\QQDownload\QQIEHelper64.dll [2013-06-26] (Tencent Technology (Shenzhen) Company Limited)
BHO-x32: No Name -> {00000000-12C9-4305-82F9-43058F20E8D2} -> No File
BHO-x32: No Name -> {6A19C29D-ED45-4483-8999-9F939C8161F2} -> No File
BHO-x32: No Name -> {889D2FEB-5411-4565-8998-1DD2C5261283} -> No File
BHO-x32: QQMiniDL Helper Class -> {C9C7334B-5657-41e1-8F79-F6AACECA05F4} -> C:\Program Files (x86)\Common Files\Tencent\QQMiniDL\60\Browser\QQIEHelper01.dll [2014-07-15] (Tencent Technology (Shenzhen) Company Limited)
BHO-x32: AccountProtectBHO Class -> {DDD362CF-523B-4BC9-8FDC-58F93B6BC945} -> C:\Users\user\AppData\Roaming\Tencent\QQ\QQAntiPhishing\AccountProtect.dll [2015-06-30] (Tencent)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKU\S-1-5-21-1328610593-2988302748-3692750778-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
FF Plugin-x32: @baidu.com/npxbdsetup -> C:\Windows\Downloaded Program Files\998503072\npxbdsetup.dll [2012-12-10] ()
FF Plugin-x32: @baidu.com/YunWebDetectPlugin -> e:\Roaming\baidu\BaiduYunGuanjia\npYunWebDetect.dll [2015-05-07] (Baidu.com, Inc.)
FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\Npchrome\npactivex.dll [2015-07-10] (Tencent)
FF Plugin-x32: @qq.com/QQDownloadPlugin -> E:\Tencent\QQDownload\Browser\769\npXFPlugin.dll [2013-02-25] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @qq.com/QQMiniDLPlugin -> C:\Program Files (x86)\Common Files\Tencent\QQMiniDL\60\Browser\npXFMiniDLPlugin.dll [2014-04-25] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @qq.com/QQPhotoDrawEx -> C:\Program Files (x86)\Tencent\Qzone\npQQPhotoDrawEx.dll No File
FF Plugin-x32: @qq.com/QzoneMusic -> C:\Program Files (x86)\Tencent\QzoneMusic\npQzoneMusic.dll [2014-08-30] (Tencent)
FF Plugin-x32: @qq.com/TXSSO -> C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.30\Bin\npSSOAxCtrlForPTLogin.dll [2015-06-26] (Tencent)
FF Plugin-x32: @tencent.com/npQQMailWebKit,version=1.0.0.1 -> C:\Program Files (x86)\QQMailPlugin\npQQMailWebKit.dll [2013-04-25] (Tencent)
FF Plugin-x32: @tencent.com/nptxftnWebKit,version=1.0.0.1 -> C:\Program Files (x86)\QQMailPlugin\nptxftnWebKit.dll [2013-04-08] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @xunlei.com/npxluser -> C:\Program Files (x86)\Common Files\Thunder Network\UserAgent\npxluser2.0.2.3.dll No File
FF Plugin HKU\S-1-5-21-1328610593-2988302748-3692750778-1000: @xunlei.com/npxlgamebox -> D:\gay\XLGameBox\Program\npxlgamebox1.0.0.3.dll No File
FF Plugin HKU\S-1-5-21-1328610593-2988302748-3692750778-1000: @xunlei.com/npxluser -> C:\Program Files (x86)\Common Files\Thunder Network\UserAgent\npxluser2.0.2.3.dll No File
FF Plugin HKU\S-1-5-21-1328610593-2988302748-3692750778-1000: anvisoft.com/AdblockPlugin -> C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll No File
FF Extension: NetVideoHunter - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\f5z0uz0x.default\Extensions\netvideohunter@netvideohunter.com [2015-06-13]
S3 BaiduYunUtility; e:\Roaming\baidu\BaiduYunGuanjia\YunUtilityService.exe [90392 2015-05-07] ()
R2 QPCore; C:\Program Files (x86)\Common Files\Tencent\QQProtect\Bin\QQProtect.exe [96952 2015-06-30] (Tencent)
R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [319568 2015-05-25] (360.cn)
U3 acobvjox; No ImagePath
R4 360netmon; system32\DRIVERS\360netmon.sys [X]
R1 360reskit64; \??\C:\Windows\system32\drivers\360reskit64.sys [X]
2015-07-11 04:15 - 2015-07-11 04:15 - 00000000 ____D C:\ProgramData\360safe
2015-07-11 04:15 - 2015-07-11 04:15 - 00000000 ____D C:\ProgramData\360safe
2015-07-11 03:08 - 2015-05-25 18:41 - 00319568 _____ (360.cn) C:\Windows\system32\Drivers\360Box64.sys
2015-07-10 20:40 - 2015-07-10 20:40 - 00000000 ____D C:\Users\user\AppData\Local\Tencent
2015-07-10 20:40 - 2015-07-10 20:40 - 00000000 ____D C:\Program Files (x86)\Tencent
2015-07-10 20:38 - 2015-06-09 18:22 - 00064952 _____ (Tencent) C:\Windows\system32\Drivers\QQProtectX64.sys
2015-07-10 20:37 - 2015-07-10 23:27 - 00000000 ____D C:\ProgramData\Tencent
2015-07-11 03:29 - 2014-03-16 13:48 - 00000000 ____D C:\Program Files (x86)\360
2015-07-11 03:09 - 2013-12-25 01:53 - 00000000 ____D C:\Users\user\AppData\Roaming\360Login
2015-06-13 00:05 - 2014-11-14 08:27 - 00000000 __SHD C:\Users\user\AppData\Local\EmieBrowserModeList
2015-06-13 00:05 - 2014-04-26 00:28 - 00000000 __SHD C:\Users\user\AppData\Local\EmieUserList
2015-06-13 00:05 - 2014-04-26 00:28 - 00000000 __SHD C:\Users\user\AppData\Local\EmieSiteList
2015-06-23 00:56 - 2013-03-12 22:30 - 00000000 ____D C:\Users\user\AppData\Roaming\Youtube Downloader HD
C:\Users\user\AppData\Local\Temp\remove360.bat
Task: {EFF27C1B-F1EC-40CC-8207-237C4741EC3B} - System32\Tasks\{530DBFC7-1916-4153-9C46-F34D09261AF9} => C:\Users\user\Desktop\1\1.exe
2015-07-11 21:35 - 2014-09-04 07:43 - 00000456 _____ C:\Windows\Tasks\微软设备健康助手自动更新.job
2015-07-11 20:49 - 2015-02-19 13:13 - 00000462 _____ C:\Windows\Tasks\微软设备健康助手设备检查.job
2015-07-11 02:40 - 2014-11-20 20:52 - 00000440 _____ C:\Windows\Tasks\微软设备健康助手开机检测.job
FF Plugin HKU\S-1-5-21-1328610593-2988302748-3692750778-1000: duowan.com/Checker -> C:\Program Files (x86)\Common Files\duowan\yy\YYSSO\1.0.0.3\npChecker.dll [2013-10-09] (广州多玩信息技术有限公司)
C:\Program Files (x86)\Common Files\Tencent
E:\365
E:\yy
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that