trade ad exchange pop-up is killing me

i do run avast but suddenly all browsers acts weird. i can see that some tradeadexchange.com pop up is causing this. and found instructions here.

i enclosed logs in this message, hope you can help me.

frst.log

aswMBR.txt

malwarebytes log you have attached is not the scan log …

we also need FRST additional.txt log

here. let me know if you need more. thanx

Let me know what problems remain after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-12-31] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe (McAfee, Inc.) BHO: No Name -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> No File 2016-02-03 13:55 - 2016-02-03 13:56 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\Ville\Downloads\SpyHunter-Installer.exe 2016-01-23 17:43 - 2016-01-23 17:43 - 02545171 _____ C:\Users\Ville\AppData\Roaming\sb812.dat 2016-01-23 17:43 - 2016-01-23 17:43 - 00000000 ____D C:\Users\Ville\AppData\Local\Setup829569703 2016-01-23 17:43 - 2016-01-23 17:43 - 00000000 ____D C:\Users\Ville\AppData\Local\lifi 2016-01-14 11:07 - 2016-01-14 11:07 - 00000000 ____D C:\Users\Ville\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium 2016-01-14 11:07 - 2016-01-14 11:07 - 00000000 ____D C:\Users\Ville\AppData\Local\Chromium 2016-01-14 11:04 - 2016-01-14 12:05 - 00000000 ____D C:\Users\Ville\AppData\Local\{FEF4C8A8-DA5C-A410-B7C4-81F893AC7D60} 2016-01-29 10:04 - 2015-10-15 20:27 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee 2016-01-29 10:03 - 2015-08-22 00:27 - 00000000 ____D C:\ProgramData\McAfee ShortcutWithArgument: C:\Users\Ville\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\-5423931230.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -contentTile -formatVersion 0x00000002 -pinnedTimeLow 0x7eaec2ed -pinnedTimeHigh 0x01ce9864 -securityFlags 0x00000000 -url 0x00000042 hxxp://windows.microsoft.com/fi-fi/windows-8/rearrange-tiles-start ShortcutWithArgument: C:\Users\Ville\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium\Chromium.lnk -> C:\Users\Ville\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) -> "hxxp://safesurfs.com/?ssid=1454006588&a=1004373&src=sh&uuid=4bc963eb-994a-412e-bc37-216a45a96bba" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?1232d8c331d660b376506d2ccba1e7675175980 ShortcutWithArgument: C:\Users\Ville\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://safesurfs.com/?ssid=1454006588&a=1004373&src=sh&uuid=4bc963eb-994a-412e-bc37-216a45a96bba" ShortcutWithArgument: C:\Users\Ville\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Chromium.lnk -> C:\Users\Ville\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) -> "hxxp://safesurfs.com/?ssid=1454006588&a=1004373&src=sh&uuid=4bc963eb-994a-412e-bc37-216a45a96bba" --proxy-pac-url=hxxp://unblockservice.com/wpad.dat?1232d8c331d660b376506d2ccba1e7675175980 ShortcutWithArgument: C:\Users\Ville\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://safesurfs.com/?ssid=1454006588&a=1004373&src=sh&uuid=4bc963eb-994a-412e-bc37-216a45a96bba" ShortcutWithArgument: C:\Users\Ville\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://safesurfs.com/?ssid=1454006588&a=1004373&src=sh&uuid=4bc963eb-994a-412e-bc37-216a45a96bba" Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: ipconfig /flushdns CMD: netsh winsock reset catalog CMD: netsh int ip reset c:\resetlog.txt CMD: ipconfig /release CMD: ipconfig /renew CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.

done, i’m checking now iw issue exists still. logs enclosed.

i’m so überthankful!

ville

Ads now gone ?