Let me know if this cures it
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=66807&st=home&tid=6724&ver=6.5&ts=1405807200000.000007&tguid=66807-6724-1405817452867-82D09486E258F31AA117F56AA2825C97
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.certified-toolbar.com?si=66807&st=bs&tid=6724&ver=6.5&ts=1405807200000.000007&tguid=66807-6724-1405817452867-82D09486E258F31AA117F56AA2825C97&q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.certified-toolbar.com?si=66807&st=bs&tid=6724&ver=6.5&ts=1405807200000.000007&tguid=66807-6724-1405817452867-82D09486E258F31AA117F56AA2825C97&q={searchTerms}
BHO: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> No File
BHO: No Name -> {59724C01-39DF-8279-B8D9-963903150A54} -> No File
BHO: No Name -> {6B65453E-CF87-FB64-1D8A-C390D4E398A0} -> No File
BHO-x32: Adblocker -> {59724C01-39DF-8279-B8D9-963903150A54} -> C:\Program Files (x86)\Adblocker\YrvOF42kbX.dll No File
BHO-x32: pruicechop -> {6B65453E-CF87-FB64-1D8A-C390D4E398A0} -> C:\Program Files (x86)\pruicechop\7sH5f1FDDi.dll No File
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.autoconfig_url", "");
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.ftp", "");
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.ftp_port", 0);
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.http", "");
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.http_port", 0);
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.no_proxies_on", "localhost, 127.0.0.1");
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.share_proxy_settings", false);
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.ssl", "");
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.ssl_port", 0);
FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.type", 5);
FF NetworkProxy: "type", 4
FF user.js: detected! => C:\Users\Ahmed Rashed\AppData\Roaming\Mozilla\Firefox\Profiles\pydousxz.default\user.js
FF SearchPlugin: C:\Users\Ahmed Rashed\AppData\Roaming\Mozilla\Firefox\Profiles\pydousxz.default\searchplugins\Web Search.xml
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Jenes\AppData\Local\Torch
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Jenes\AppData\Local\Comodo
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Jenes\AppData\Local\Chromatic Browser
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Ahmed Rashed\AppData\Local\Torch
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Ahmed Rashed\AppData\Local\Comodo
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Ahmed Rashed\AppData\Local\Chromatic Browser
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-07-18 17:40 - 2014-07-18 17:40 - 00001056 _____ () C:\Users\Ahmed Rashed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
2014-07-18 17:35 - 2014-07-18 17:40 - 00000000 ____D () C:\Users\Ahmed Rashed\AppData\Local\iLivid
2014-07-10 16:24 - 2014-07-10 16:24 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Jenes\AppData\Local\Torch
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Jenes\AppData\Local\Comodo
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Jenes\AppData\Local\Chromatic Browser
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Guest
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Ahmed Rashed\AppData\Local\Torch
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Ahmed Rashed\AppData\Local\Comodo
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Ahmed Rashed\AppData\Local\Chromatic Browser
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-07-20 00:19 - 2014-07-20 00:19 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS
CMD: bitsadmin /reset /allusers
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
REBOOT:
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.