Could you let me know if this stops the alerts
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
DisableService: xepqli
CreateRestorePoint:
Unlock: C:\WINDOWS\System32\drivers\axykug.sys
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\Policies\Explorer: []
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: F - "F:\setup.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {18ab9cd4-b00e-11e3-8309-d850e6022b7b} - "F:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {4953098b-6ac8-11e3-8258-240a6491519c} - "G:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {56d8e6a1-fd1a-11e3-8407-001e101f513f} - "F:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {6774a710-497a-11e4-84b7-d850e6022b7b} - "G:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {6774a86d-497a-11e4-84b7-d850e6022b7b} - "G:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {6774a8a0-497a-11e4-84b7-d850e6022b7b} - "G:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {6774a92c-497a-11e4-84b7-d850e6022b7b} - "G:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {6774a96c-497a-11e4-84b7-d850e6022b7b} - "G:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {6dfbc1cf-6a8b-11e3-8257-240a6491519c} - "E:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {6dfbc20f-6a8b-11e3-8257-240a6491519c} - "F:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {8d02b6c2-aa7e-11e3-82fd-001e101fa4d3} - "F:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {94493164-970c-11e4-84cc-240a6491519c} - "F:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {b44152bb-21ba-11e4-844c-d850e6022b7b} - "F:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1001\...\MountPoints2: {f86638f8-d231-11e4-84ce-240a6491519c} - "F:\AutoRun.exe"
HKU\S-1-5-21-853127156-1723808810-3907299186-1002\...\MountPoints2: {d6f2c863-6a03-11e3-824b-806e6f6e6963} - "D:\AsInsWiz.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.8.150\SSScheduler.exe (No File)
ShortcutTarget: ygopro-1033.4-percy-update-fixed.lnk -> C:\ProgramData\{04c7ade8-26f2-f015-04c7-7ade826fb7a0}\ygopro-1033.4-percy-update-fixed.exe ()
BHO: SalePPlus -> {157c613f-8cfd-4ccf-b68c-f4916f9584a3} -> C:\Program Files (x86)\SalePPlus\VnMJ9w5pCUelk2.x64.dll ()
FF Extension: SalePPlus - C:\Users\Raph\AppData\Roaming\Mozilla\Firefox\Profiles\hqu7y68u.default\Extensions\0A@9r3f.net [2015-04-05]
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Raph\AppData\Roaming\Mozilla\Firefox\Profiles\hqu7y68u.default\Extensions\artur.dubovoy@gmail.com [2015-04-05]
FF Extension: youtubeadblocker - C:\Users\Raph\AppData\Roaming\Mozilla\Firefox\Profiles\hqu7y68u.default\Extensions\O@z0OW1WkgNN.com [2015-04-05]
CHR Extension: (SalePPlus) - C:\ProgramData\lgegkpknbmmkbkdambihlghdlhmiabpb\ [2014-09-24]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.8.150\McCHSvc.exe" [X]
2015-04-05 11:59 - 2015-04-05 11:59 - 00000000 ____D () C:\ProgramData\1531493997323098430
2015-04-05 11:59 - 2015-04-05 11:59 - 00000000 ____D () C:\Program Files (x86)\Close Tabs
2015-04-05 11:58 - 2015-04-05 11:59 - 00000000 ____D () C:\Program Files (x86)\SalePPlus
2015-04-05 11:58 - 2015-04-05 11:58 - 00000000 ____D () C:\ProgramData\lgegkpknbmmkbkdambihlghdlhmiabpb
2015-04-05 11:57 - 2015-04-05 14:30 - 00000000 ____D () C:\ProgramData\{04c7ade8-26f2-f015-04c7-7ade826fb7a0}
2015-04-05 11:57 - 2015-04-05 11:57 - 00001097 _____ () C:\Users\Raph\Desktop\ygopro-1033.4-percy-update-fixed.lnk
2015-04-05 14:30 - 2015-04-05 11:57 - 00000000 ____D () C:\ProgramData\{04c7ade8-26f2-f015-04c7-7ade826fb7a0}
C:\ProgramData\{04c7ade8-26f2-f015-04c7-7ade826fb7a0}
C:\WINDOWS\System32\drivers\axykug.sys
C:\Program Files (x86)\SalePPlus
C:\Program Files (x86)\McAfee Security Scan
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.