Could you also post the addition.txt after this
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKLM\...\Run: [FileOpenBroker] => C:\Program Files\FileOpen\Services\FileOpenBroker64.exe [1092528 2012-10-17] (FileOpen Systems Inc.)
HKLM-x32\...\RunOnce: [sevenzipbmsb] => "C:\Users\Peter\AppData\Local\Temp\\BI_RunOnce.exe" /initurl http://sub.reichtron.com/init/Qczv2iJD2/:uid:? /affid "-" /id "0" /name " " /uniqid Qczv2iJD2 /uuid 4C4C4544-0054-5010-8032-B5C04F303332 /b (the data entry has 71 more characters). <===== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-325312308-3041302083-219346254-1003\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
BHO: SAALesCheCker -> {52625873-E990-424E-A855-70777ADD3F2F} -> C:\Program Files (x86)\SAALesCheCker\AXPt19UmrcIIB6.x64.dll [2015-07-26] ()
BHO: RobboSaveR -> {7EEF3A5A-3B2F-439C-B7A5-E5F369639A3C} -> C:\Program Files (x86)\RobboSaveR\RXFcaLHmP6mRzt.x64.dll [2015-07-26] ()
FF Plugin HKU\S-1-5-21-325312308-3041302083-219346254-1003: @my.com/Games -> C:\Users\Peter\AppData\Local\MyComGames\NPMyComDetector.dll [2015-07-26] (My.com, Inc)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\_config.js [2011-08-24] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\Mansoft.cfg [2014-10-24] <==== ATTENTION
R2 Glorious Script; C:\Program Files (x86)\Glorious Script\Glorious Script.exe [8016307 2015-07-25] () [File not signed] <==== ATTENTION
R2 Solid Pass; C:\Program Files (x86)\Solid Pass\Solid Pass.exe [8016045 2015-07-08] () [File not signed] <==== ATTENTION
2015-07-26 16:25 - 2015-07-26 16:26 - 00000000 ____D C:\Program Files (x86)\RobboSaveR
2015-07-26 16:25 - 2015-07-26 16:25 - 00000000 ____D C:\ProgramData\chfagfnhiiobmofdikfekliogpgemffk
2015-07-26 15:11 - 2015-07-26 15:13 - 00000000 ____D C:\ProgramData\feiilkmagcjckpbncninjmehbdohahib
2015-07-26 15:11 - 2015-07-26 15:11 - 00000000 ____D C:\Program Files (x86)\SAALesCheCker
2015-07-25 10:57 - 2015-07-25 10:57 - 00000000 ____D C:\Users\Peter\AppData\Local\CEF
2015-07-25 10:56 - 2015-07-25 10:56 - 00000000 ____D C:\Program Files (x86)\Glorious Script
2015-07-10 20:42 - 2015-07-13 12:38 - 00000000 ____D C:\Program Files (x86)\PrinceCoupOn
2015-07-10 20:42 - 2015-07-10 20:42 - 00000000 ____D C:\ProgramData\{6eb84474-854c-200a-6eb8-8447485411d2}
2015-07-08 20:42 - 2015-07-08 14:42 - 00010752 _____ (UG North) C:\Windows\system32\Hibiki.dll
2015-07-08 14:42 - 2015-07-08 14:42 - 00000000 ____D C:\Program Files (x86)\Solid Pass
2015-07-07 11:23 - 2015-07-13 12:36 - 00000000 ____D C:\Program Files (x86)\Page Monitor
2015-07-07 11:22 - 2015-07-13 12:35 - 00000000 ____D C:\Program Files (x86)\deal2deaaliit
2015-07-07 11:22 - 2015-07-13 12:35 - 00000000 ____D C:\Program Files (x86)\deal2deAlit
2015-07-07 11:22 - 2015-07-10 20:43 - 00000000 ____D C:\ProgramData\4724715360864044428
2015-07-07 02:42 - 2015-07-13 12:25 - 00000000 ____D C:\Program Files (x86)\CutterGeneration
2015-07-02 16:48 - 2015-07-02 16:49 - 02969616 _____ (Nets DanID ) C:\Users\Peter\Downloads\csp.exe
2015-07-13 13:07 - 2015-06-17 20:42 - 00000000 ____D C:\ProgramData\{56d297cd-4c5a-72ba-56d2-297cd4c55f35}
2015-07-13 11:54 - 2015-06-17 20:42 - 00000362 _____ C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job
2015-07-07 02:42 - 2015-06-17 20:48 - 00000000 ____D C:\ProgramData\c22f351a000010cc
C:\Program Files (x86)\Solid Pass
C:\Program Files (x86)\Glorious Script
C:\Program Files\FileOpen
C:\Windows\system32\Hibiki.dll
C:\Users\Peter\AppData\Local\Temp\Hibiki.dll
C:\Users\Peter\AppData\Local\Temp\\BI_RunOnce.exe
C:\Program Files (x86)\SAALesCheCker
C:\Program Files (x86)\RobboSaveR
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.