Could you let me know what problems there are after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\Run: [tmpEDED] => wscript.exe //B "C:\Users\Acer\AppData\Local\Temp\tmpEDED.tmp.vbe" <===== ATTENTION HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\Run: [125d3f6ae0a53efa91122391603b15de] => .. [0 2015-01-07] () HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: E - E:\LaunchU3.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: F - F:\laucher.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {22c52741-2ebd-11e4-aa44-9ff07268ff8e} - E:\Startme.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {3f318391-0f4f-11e4-bd66-df6986ed03fd} - E:\AutoRun.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {43ba7662-cf85-11e3-bd1f-02704e2b0701} - E:\AutoRun.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {4af1a086-26db-11e4-8b28-844bf559dca5} - F:\LaunchU3.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {4f79a77d-1e05-11e4-ba42-844bf559dca5} - E:\LGAutoRun.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {965e2d8c-11e9-11e4-8a8f-a3edd4bfdbd4} - E:\AutoRun.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {a187ad0d-d1c6-11e3-b50b-02509a230701} - E:\AutoRun.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {a187ad48-d1c6-11e3-b50b-02509a230701} - E:\AutoRun.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {a73d73ec-cee2-11e3-a29b-02704e280701} - E:\AutoRun.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {a73d7452-cee2-11e3-a29b-02704e280701} - E:\AutoRun.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {aa4d8658-9faa-11e2-be7e-ecbf90268189} - D:\SETUP.EXE HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {bd25373c-fc9c-11e4-a846-806e6f6e6963} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {c34be88c-db4e-11e2-8a2c-ecb73ccba681} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {cfc03ff5-0f40-11e4-ab5f-ad70573821fd} - F:\laucher.exe HKU\S-1-5-21-1201811183-624649827-1094862506-1000\...\MountPoints2: {e3b115e7-6316-11e2-8653-c28af77e69fe} - E:\unlock.exe autoplay=true ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL No File BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\progra~1\mcafee\msk\mskapbho.dll No File Toolbar: HKU\S-1-5-21-1201811183-624649827-1094862506-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File CHR Extension: (WhiteSmoke New) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\klibnahbojhkanfgaglnlalfkgpcppfi [2014-07-19] Task: {ADD9F329-4C77-49D3-95C0-E09D88D323A8} - System32\Tasks\DefaultCheck => c:\Users\All Users\dtdata\R002.exe <==== ATTENTION C:\Users\Acer\AppData\Local\Temp\nsg2974.tmp C:\Users\Acer\AppData\Local\Temp\tmpEDED.tmp.vbe Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Download Anti VBS/VBE to your desktop

[]download the appropriate version (32 bit or 64 bit) and double click the file to run it.
[
]After a couple of seconds (might also take a whole minute if the machine is heavily infected and/or slow) a report will open in Notepad.
[*]Post that report

Be aware this is a very new programme and as such is not recognised by any Antivirus or Windows, it is safe so allow it to run