A real mess

Show your magic malware removers and create a good fixlist for this system :wink:

What problems are you seeing Eddy ?

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: ProxyServer: [S-1-5-21-2929451337-3149322565-4265649252-1000] => localhost:21320 SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://jamenize.com/results.php?f=4&q={searchTerms}&a=jmz_forstw01_15_06&cd=2XzuyEtN2Y1L1Qzu0DyEzzyDyCyE0AyB0EtB0C0CyCzy0F0AtN0D0Tzu0StCtCtAyEtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StC0F0CtDtAzy0BzztG0AyEzyzztGyEtCzyyBtGzzyE0BtBtGtDzz0D0AyCzz0FyCzyyEtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtAyDyDzztA0BtGtByDtAyBtGyE0F0A0AtGzz0C0AyEtG0FzztC0Dzz0A0B0D0A0DyEyC2QtN1B1L1H1Ezu1O2U1M1B&cr=2040056470&ir= SearchScopes: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://jamenize.com/results.php?f=4&q={searchTerms}&a=jmz_forstw01_15_06&cd=2XzuyEtN2Y1L1Qzu0DyEzzyDyCyE0AyB0EtB0C0CyCzy0F0AtN0D0Tzu0StCtCtAyEtN1L2XzutAtFyBtFyBtFtBtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2StC0F0CtDtAzy0BzztG0AyEzyzztGyEtCzyyBtGzzyE0BtBtGtDzz0D0AyCzz0FyCzyyEtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtBtAyDyDzztA0BtGtByDtAyBtGyE0F0A0AtGzz0C0AyEtG0FzztC0Dzz0A0B0D0A0DyEyC2QtN1B1L1H1Ezu1O2U1M1B&cr=2040056470&ir= SearchScopes: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchTerms}&l=dis&o=HPDTDF BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> No File Toolbar: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000 -> No Name - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - No File Toolbar: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File FF Keyword.URL: hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=926458&p= FF NetworkProxy: "http", "idontknowwhatimdoing,co" FF NetworkProxy: "http_port", 20 FF NetworkProxy: "type", 4 FF user.js: detected! => C:\Users\Jonathon\AppData\Roaming\Mozilla\Firefox\Profiles\036zf84n.default\user.js [2014-02-19] 2015-11-17 16:32 - 2015-08-16 16:25 - 00000000 ____D C:\Users\Jonathon\AppData\Local\{3057060B-14FF-6AB3-7967-4F5B5D0FB3C3} 2012-01-05 22:44 - 2012-01-05 22:46 - 0010272 ___SH () C:\Users\Jonathon\AppData\Local\35cwhv16y463rn5yy4btt24w0h1f66415fkk7731p7am74 2013-06-18 12:17 - 2013-06-18 12:17 - 0000037 ___SH () C:\Users\Jonathon\AppData\Local\70149b02515b3bb20dd492.47983420 2012-01-05 22:44 - 2012-01-05 22:46 - 0010272 ___SH () C:\ProgramData\35cwhv16y463rn5yy4btt24w0h1f66415fkk7731p7am74 CustomCLSID: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-2929451337-3149322565-4265649252-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> no filepath Task: {0058C3F4-AD97-4C00-B450-98BBF319A502} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {0265AA73-B5DE-429C-8A24-D7C276D578CF} - System32\Tasks\SpeedUpMyPC Startup => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ATTENTION Task: {424CE11A-4944-403F-AF9D-359DE3047C5F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {61F5B1B6-4FD6-462E-8CCE-2A61BD97866A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {8CC6AD14-1D49-41E1-9280-7BBF7FCE0901} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION Task: {EB8504D9-323C-4074-94AC-B764A3B9990E} - System32\Tasks\HQvpn client autorun => C:\Program Files (x86)\HqVpn\HQvpn.net Client\HqVpnClient.exe <==== ATTENTION HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\win8gfore => ""="Driver" Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: ipconfig /flushdns CMD: netsh winsock reset catalog CMD: netsh int ip reset c:\resetlog.txt CMD: ipconfig /release CMD: ipconfig /renew CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on β€œClean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.