Ok, so heres the logs.
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal (File)
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage (File)
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal (File)
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage (File)
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.lyricsmode.com_0.localstorage-journal (File)
Successfully deleted: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.lyricsmode.com_0.localstorage (File)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PXNBR0O (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CN66PO8X (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JO1VV7RS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SOXJ67OP (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PXNBR0O (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CN66PO8X (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JO1VV7RS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SOXJ67OP (Temporary Internet Files Folder)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
# AdwCleaner v5.112 - Logfile created 21/04/2016 at 14:46:47
# Updated 17/04/2016 by Xplode
# Database : 2016-04-19.5 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Owner - OWNER-VAIO
# Running from : C:\Users\Owner\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
Folder Found : C:\Users\Owner\WebConnect
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\PackageAware
***** [ Files ] *****
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d16fk4ms6rqz1v.cloudfront.net_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d2m2wsoho8qq12.cloudfront.net_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_d2m2wsoho8qq12.cloudfront.net_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.strtpoint.com_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.strtpoint.com_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_serviceama-a.akamaihd.net_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_serviceama-a.akamaihd.net_0.localstorage-journal
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_uk.ask.com_0.localstorage
File Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_uk.ask.com_0.localstorage-journal
***** [ DLL ] *****
***** [ Shortcuts ] *****
Shortcut Infected : C:\Users\Public\Desktop\Google Chrome.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\Desktop\Internet Explorer (64-bit).lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\I-Learn_ Student Dashboard.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\kamkam94 _ Quizlet.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
Shortcut Infected : C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ( "hxxp://trustedsurf.com/?ssid=1460825999&a=1003203&src=sh&uuid=45c74ead-4253-4aba-ab56-0680942c4607" )
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Key Found : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
Key Found : HKCU\Software\Microsoft\Tinstalls
Key Found : HKCU\Software\SrpnFiles
Key Found : HKLM\SOFTWARE\SrpnFiles
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ac225167-00fc-452d-94c5-bb93600e7d9a}
Key Found : HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\Software\Microsoft\Tinstalls
Key Found : HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\Software\SrpnFiles
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{B2B2E4A1-9B67-41D3-ABD5-5994E6A51961}]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{B7F2BFE1-81D6-4555-9D9F-9904913F8635}]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{879AC841-3BFA-462D-AC63-273580238EBB}]
Value Found : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{52B67663-FEA8-4050-85DB-9452D511695E}]
***** [ Web browsers ] *****
*************************
C:\AdwCleaner\AdwCleaner[S1].txt - [6040 bytes] - [21/04/2016 14:46:47]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [6113 bytes] ##########
Mbam
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 4/21/2016
Scan Time: 2:57 PM
Logfile: mbamlog.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.04.21.06
Rootkit Database: v2016.04.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Owner
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 391999
Time Elapsed: 36 min, 55 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 12
PUP.Optional.HijackHosts.Gen, C:\Windows\System32\bhvo\shsu\ygo.dat, Quarantined, [6b0f4f626138360079697ced53b28d73],
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (107.178.247.130 connect.facebook.net), Replaced,[502a723fb6e342f48236303fa65f5ba5]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (.facebook.net
107.178.255.88 www.go), Replaced,[bebcf3be6b2e1422d7e127487590f60a]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (107.178.248.130 static.doubleclick.net), Removal Failed,[6a10e3ce8316dc5aa811650ad3328a76]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (.facebook.net
107.178.255.88 www.goog), Replaced,[7901862bd2c772c42594afc064a145bb]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (107.178.255.88 www.google-analytics.com), Removal Failed,[d4a6664b4e4b9e9894267ff0a06558a8]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (nalytics.com
107.178.255.88 www.s), Removal Failed,[0278ac055b3edc5abefc6d023fc635cb]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (gle-analytics.com
107.178.255), Removal Failed,[fc7e149d4f4ac472dddd27480df8db25]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (.google-analytics.com
107.178.255.88 w), Replaced,[7703664ba6f3e0560ab02946ec19728e]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (nalytics.com
107.178.255.88 www.statcounte), Replaced,[3f3b159c960347ef5862501f669ff50b]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (tics.com
107.178.255.88 www.statco), Replaced,[bebcfcb5c2d769cd6951313e20e503fd]
Hijack.Host, C:\Windows\System32\drivers\etc\hosts, Good: (), Bad: (er.com
107.178.255.88 ssl.google-analy), Removal Failed,[aad08c250198072f4e6c393661a4847c]
Physical Sectors: 0
(No malicious items detected)
(end)
Everything is going good, but I'm still getting spam tabs opening up, not the same one as last time now. This time its a different service. I'll edit in the name later.
The domain for the tab was trusted surf.