Sorry, once in a while someone falls through the cracks! Give me a bit of time- I'll check the logs now. Please hold off on the reformat/reinstall.
Edit: for logs. Mbam and SAS are clean. We suggest that Combofix not be run unless it is on the instructions of the helper. BitTorrent shows up, so we're going to need a log showing it gone.
The steps tell you to disable Real Time Protection before the scans. For you, it would be AdWatch:
AD-AWARE AD-WATCH
- Right click on the Ad-Watch icon in the system tray.
- At the bottom of the screen there will be two checkable items called "Active" and "Automatic".
[o] Active: This will turn Ad-Watch On\Off without closing it.
[o] Automatic: Suspicious activity will be blocked automatically.
- Uncheck both of those boxes.
* (When done, you can re-enable it using the same steps but this time check both boxes.)
Please open HijackThis, and select
Do a system scan only.
Place a checkmark next to the following entries (if present):
(Re: first R0 entry: If you have a home page set to come up blank, okay to leave. If not, check for removal.)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
Then, close all other open windows, leaving only HijackThis open, and select
Fix checked.
Your Adobe Reader is out of date. Vulnerabilities can be exploited. Click here to download the latest version :
https://www.techspot.com/downloads/345-adobe-reader.html
OR
Install the FoxIt Reader: this does the same thing as Adobe, but doesn’t have the bloat:
http://www.foxitsoftware.com/pdf/rd_intro.php
Please run a full system scan with Avast, save the log and attach it with next post.
Rescan with HijackThis after you disable AdWatch, include new log.
I don't see anything obvious in these logs for a redirect, so definitely need the AV scan.