Hello crypton1te and welcome to avast!. I will be working on your Malware issues.
Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.
Please stay with me until given the ‘all clear’ even if symptoms seemingly abate.
Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper
Malwarebytes has target the PUP program known as YUC as well as some other know to him adware entries. With FixList we will tell FRST to target the remains and preform some junk & temp file cleaning.
1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Start
CreateRestorePoint:
File: C:\Program Files (x86)\Tor\tor.exe
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
CMD: bitsadmin /reset /allusers
CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
URLSearchHook: HKLM-x32 - Default Value = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D}
SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
SearchScopes: HKLM-x32 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
SearchScopes: HKU\S-1-5-21-1807851072-2028520930-2935123870-1000 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
FF DefaultSearchEngine: V9
FF DefaultSearchUrl: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}
FF SearchEngineOrder.1: appbario8 Customized Web Search
FF SelectedSearchEngine: V9
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-31] () [File not signed] <==== ATTENTION
Hosts:
C:\Program Files (x86)\Tor
RemoveProxy:
Task: {0553E049-C8B2-4DF3-9829-8CBDD3F68B60} - \RocketTab Update Task No Task File <==== ATTENTION
Task: {2A12797F-DF8A-412C-AB4C-D4FDA9C8C80E} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
Task: {59A150F0-B1E7-4A40-B134-96D0AA6BEDC0} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION
Task: {5B7CF35D-A401-4950-A7A4-03A0E93FFDB1} - \BitGuard No Task File <==== ATTENTION
Task: {6EC5EEF7-5F5C-46D0-B187-EFDE7583FBFA} - \RocketTab No Task File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:D282699C
EmptyTemp:
End
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.