Hello crypton1te and welcome to avast!. I will be working on your Malware issues.

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the ‘all clear’ even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper


Malwarebytes has target the PUP program known as YUC as well as some other know to him adware entries. With FixList we will tell FRST to target the remains and preform some junk & temp file cleaning.

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Start
CreateRestorePoint:
File: C:\Program Files (x86)\Tor\tor.exe
Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f
CMD: bitsadmin /reset /allusers

CloseProcesses:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
URLSearchHook: HKLM-x32 - Default Value = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D}
SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKU\S-1-5-21-1807851072-2028520930-2935123870-1000 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
FF DefaultSearchEngine: V9 
FF DefaultSearchUrl: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}
FF SearchEngineOrder.1: appbario8 Customized Web Search
FF SelectedSearchEngine: V9 
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-31] () [File not signed] <==== ATTENTION

Hosts:
C:\Program Files (x86)\Tor

RemoveProxy:
Task: {0553E049-C8B2-4DF3-9829-8CBDD3F68B60} - \RocketTab Update Task No Task File <==== ATTENTION
Task: {2A12797F-DF8A-412C-AB4C-D4FDA9C8C80E} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
Task: {59A150F0-B1E7-4A40-B134-96D0AA6BEDC0} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION
Task: {5B7CF35D-A401-4950-A7A4-03A0E93FFDB1} - \BitGuard No Task File <==== ATTENTION
Task: {6EC5EEF7-5F5C-46D0-B187-EFDE7583FBFA} - \RocketTab No Task File <==== ATTENTION

AlternateDataStreams: C:\ProgramData\TEMP:D282699C

EmptyTemp:
End

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.