I had a system to fix in person this afternoon (NZDT) No Internet System restore just as a test failed, Some Windows Services failed to start causing problems, Hard Drive and CPU running a million miles an hour without the user doing anything, Browser (IE) and Exporer crashing or having problems.
Took me 2 1/2 hours approx. First of all I swapped the registry hives over to an earlier date, just under one month ago, I did not touch and Files on the system at all just the registry, using FRST.
I then used adwcleaner, which found a huge amount of PUP's (see attached). well that was a lesson what can happen with a large amount of PUP's.
Yet Adwcleaner even though it stated deleted could NOT remove all. I used another tool and it could not delete all found either.
I had to script with Combofix and OTL to force the removal of obhects that would not shift.
Another lesson for users who just state run tools like Adwcleaner, without asking for logs or checking that it did actually delete what was logged as deleted, when in fact it was not. The reality is the entries in this case were stubborn to remove for tools.
On top of that I had to remove the installed AV and clean install as the final step.
I have attached the 3 easy to read logs for users.
Quads