OK lets see if this cures it
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer Open
notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKLM\...\Run: [mobilegeni daemon] => C:\Program Files\Mobogenie\DaemonProcess.exe
HKLM\...\Run: [] => [X]
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
URLSearchHook: HKU\S-1-5-21-3759608627-2314836405-2523883543-1000 - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
SearchScopes: HKLM -> {A2C5B795-58B7-4B38-B9AD-4B836F458E06} URL = hxxp://www.ask.com/web?q={searchTerms}&l=dis&o=uscqd
SearchScopes: HKU\S-1-5-21-3759608627-2314836405-2523883543-1000 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://www.search.ask.com/web?tpid=ORJ&o=100000031&pf=V5&p2=%5ETV%5EYYYYYY%5EYY%5EUS&gct=sb&itbv=12.10.3.24&apn_uid=45FD28A7-E52B-459A-B350-3795ACC7F25E&apn_ptnrs=%5ETV&apn_dtid=%5EYYYYYY%5EYY%5EUS&apn_dbr=cr_26.0.1410.43&doi=2014-02-02&trgb=ALL&q={searchTerms}&psv=
SearchScopes: HKU\S-1-5-21-3759608627-2314836405-2523883543-1000 -> {A2C5B795-58B7-4B38-B9AD-4B836F458E06} URL = hxxp://www.ask.com/web?q={searchTerms}&l=dis&o=uscqd
SearchScopes: HKU\S-1-5-21-3759608627-2314836405-2523883543-1000 -> ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ ´Ñ;áa´[¦†8 º~RÙxœòÜ8'£-)xä URL =
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
Toolbar: HKLM - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKU\S-1-5-21-3759608627-2314836405-2523883543-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-3759608627-2314836405-2523883543-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.7.0\ViProtocol.dll [2015-07-15] (AVG Secure Search)
FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.7.0\\npsitesafety.dll [No File]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2013-02-24]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\safeguard-secure-search.xml [2013-06-27]
CHR HomePage: Default -> search.ask.com/?gct=hp
CHR Session Restore: Default -> is enabled.
2016-01-21 20:05 - 2016-01-21 20:05 - 00000000 ____D C:\Users\Main\AppData\Local\Avg
2016-01-18 12:04 - 2016-01-18 12:12 - 00000000 ____D C:\ProgramData\AVAST Software(12)
2016-01-19 16:11 - 2013-02-24 15:44 - 00000000 ____D C:\Program Files\Delta
2016-01-18 15:29 - 2015-04-21 20:36 - 00000000 ____D C:\ProgramData\AVAST Software(1026)
2016-01-18 15:29 - 2014-04-29 12:22 - 00000000 ____D C:\ProgramData\AVG Secure Search
2016-01-18 15:29 - 2014-01-05 18:33 - 00000000 ____D C:\Users\Main\AppData\Local\SwvUpdater
2016-01-18 15:29 - 2013-08-07 12:24 - 00000000 ____D C:\Users\Main\AppData\LocalLow\Toolbar4
2016-01-18 15:28 - 2014-01-14 10:22 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
Task: {A354B859-5600-4A76-A5F6-99FB7D26C1BE} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: {AC4CA156-A40D-4339-B5A9-D4E8B7F475C5} - \SaveSense -> No File <==== ATTENTION
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
C:\Program Files\Mobogenie
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as
fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THENPlease download
AdwCleaner by Xplode onto your desktop.
- Close all open programs and internet browsers.
- Double click on AdwCleaner.exe to run the tool.
- Click on Scan.
- After the scan is complete click on "Clean"
- Confirm each time with Ok.
- Your computer will be rebooted automatically. A text file will open after the restart.
- Please post the content of that logfile with your next answer.
- You can find the logfile at C:\AdwCleaner[S0].txt as well.
FINALLYDownload
Avast Uninstall Utility to your
Desktop.
Download the correct version of Avast
Avast FreeAvast ProAvast Internet SecurityAvast PremierDisconnect from the net
Uninstall Avast via control panel
- Run the uninstall tool and accept the reboot to safe mode
- Once complete reboot your system
- Reinstall Avast
----------