Could you let me know if this stops it
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
Startup: C:\Users\HP PAVILION\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\d.lnk [2015-08-02]
ShortcutTarget: d.lnk -> C:\Users\HP PAVILION\AppData\Roaming\obnfjnudck.exe (ConocoPhillips)
Startup: C:\Users\HP PAVILION\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\q.lnk [2015-08-15]
ShortcutTarget: q.lnk -> C:\Users\HP PAVILION\AppData\Roaming\obiezsaocd.exe ()
Startup: C:\Users\HP PAVILION\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\s.lnk [2015-08-13]
ShortcutTarget: s.lnk -> C:\Users\HP PAVILION\AppData\Roaming\obqelddcqz.exe (No File)
S1 gphpwpmy; \??\C:\Windows\system32\drivers\gphpwpmy.sys [X]
2015-08-03 19:43 - 2015-08-03 19:43 - 00000000 ____D C:\Users\HP PAVILION\AppData\Roaming\AVG
2015-08-03 19:42 - 2015-08-03 19:44 - 00000000 ____D C:\ProgramData\AVG
2015-08-03 19:42 - 2015-08-03 19:42 - 00000000 ____D C:\Users\HP PAVILION\AppData\Local\Avg
2015-08-15 15:58 - 2015-08-15 15:58 - 89191552 __RSH () C:\Users\HP PAVILION\AppData\Roaming\obiezsaocd.exe
2015-08-02 13:52 - 2015-08-02 13:52 - 100905344 __RSH (ConocoPhillips) C:\Users\HP PAVILION\AppData\Roaming\obnfjnudck.exe
C:\Windows\system32\drivers\gphpwpmy.sys
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.