Let me know if this stops it
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKU\S-1-5-21-3308813543-1294093709-1522524983-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:53391;https=127.0.0.1:53391
ProxyEnable: [S-1-5-21-3308813543-1294093709-1522524983-1000] => Internet Explorer proxy is enabled.
HKU\S-1-5-21-3308813543-1294093709-1522524983-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.protectedio.com/?u=8c2ecf7011b253c0538b2661a807d7dd&c=p1&src=hp&inst=1439421142
SearchScopes: HKLM-x32 -> DefaultScope {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL = hxxps://search.protectedio.com/search.php/?q={searchTerms}&u=8c2ecf7011b253c0538b2661a807d7dd&c=p1&src=srch&inst=1439421142
SearchScopes: HKLM-x32 -> {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL = hxxps://search.protectedio.com/search.php/?q={searchTerms}&u=8c2ecf7011b253c0538b2661a807d7dd&c=p1&src=srch&inst=1439421142
SearchScopes: HKU\S-1-5-21-3308813543-1294093709-1522524983-1000 -> DefaultScope {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL = hxxps://search.protectedio.com/search.php/?q={searchTerms}&u=8c2ecf7011b253c0538b2661a807d7dd&c=p1&src=srch&inst=1439421142
SearchScopes: HKU\S-1-5-21-3308813543-1294093709-1522524983-1000 -> {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL = hxxps://search.protectedio.com/search.php/?q={searchTerms}&u=8c2ecf7011b253c0538b2661a807d7dd&c=p1&src=srch&inst=1439421142
BHO-x32: SecureWebBHO Class -> {D3C24E2B-C820-4492-9B69-11BF7163F998} -> C:\Program Files (x86)\Safesoft Protector\swie.dll [2015-08-11] (SecureSoft)
Toolbar: HKU\S-1-5-21-3308813543-1294093709-1522524983-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
2015-08-11 10:28 - 2015-08-11 10:28 - 00000000 ____D C:\Program Files (x86)\Safesoft Protector
2015-08-07 20:31 - 2015-08-07 20:31 - 00000000 ____D C:\Users\steve-pc\AppData\Local\{8D7C69EC-E33B-4FB9-B075-F651D101D059}
2015-08-03 20:15 - 2015-08-03 20:15 - 00000000 ____D C:\Users\steve-pc\AppData\Local\{30E8B32E-C93C-48F2-95CD-9D54D6FD8BAA}
C:\Users\steve-pc\locStrings.js
Task: {0BE6F4E8-7B16-4309-92D3-F58D5B49D915} - System32\Tasks\Maintenance Security Service => C:\Program Files (x86)\Maintenance Security\MaintenanceSecurity.exe [2015-05-26] (Secure Updater)
Task: {178B5B09-3EA0-4E73-8CEB-620D977727E1} - \SMupdate1 -> No File <==== ATTENTION
Task: {4E31FC2F-E271-4E6D-83AC-2D25A5FBAC5A} - \FFMPEGUpd -> No File <==== ATTENTION
Task: {6E868F03-7ABD-4A43-8CFD-5EB644026DB7} - \YTDownloaderUpd -> No File <==== ATTENTION
Task: {796A7FE7-BC80-4167-B762-B244C77B9616} - \SpeedUpMyPC Maintenance -> No File <==== ATTENTION
Task: {D85723B7-FE81-41CA-9D68-BE1C1B4D7655} - \SpeedUpMyPC Startup -> No File <==== ATTENTION
Task: {E4D2A7A1-8B0D-42CA-A024-74DF85618558} - \Buenosearch -> No File <==== ATTENTION
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.