I will initially disable the IE plugins for Baidu and QQ as they are readily hijacked

Let me know if there is any change after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: BHO: QQDownload IE Left Helper -> {00000000-12C9-4305-82F9-43058F20E8D2} -> C:\Program Files (x86)\Tencent\QQDownload\QQIEHelper64.dll [2013-07-31] (Tencent Technology (Shenzhen) Company Limited) BHO-x32: QQDownload IE Left Helper -> {00000000-12C9-4305-82F9-43058F20E8D2} -> C:\Program Files (x86)\Tencent\QQDownload\QQIEHelper02.dll [2013-07-31] (Tencent Technology (Shenzhen) Company Limited) BHO-x32: NavigateBHO Class -> {CD79381A-F551-4E4E-9FE5-68105416C550} -> C:\Users\user\AppData\Roaming\baidu\BaiduPlayerBrowser\2.6.1.57_1\ProtectBHO.dll No File DPF: HKLM-x32 {8AFB38D0-67A4-49D3-8822-401755FC6573} http://hk.beanfun.com/beanfun_block/embeds/BFService.cab FF Plugin-x32: @baidu.com/npxbdsetup -> C:\Windows\Downloaded Program Files\1468078\npxbdsetup.dll [2012-12-26] () FF Plugin-x32: @qq.com/QQDownloadPlugin -> C:\Program Files (x86)\Tencent\QQDownload\Browser\751\npXFPlugin.dll [2013-07-31] (Tencent Technology (Shenzhen) Company Limited) FF Plugin-x32: @qq.com/TXSSO -> C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.1.94\Bin\npSSOAxCtrlForPTLogin.dll [2013-01-25] (Tencent) Task: {9E7EE08F-E915-4FAE-8F2F-4DD16FC08933} - System32\Tasks\{8876E257-B921-40C2-8130-705213219B03} => pcalua.exe -a "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W336JY9O\install_flashplayer11x32ax_gtbp_chra_aih[1].exe" -d C:\Users\user\Desktop Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: ipconfig /flushdns CMD: netsh winsock reset catalog CMD: netsh int ip reset c:\resetlog.txt CMD: ipconfig /release CMD: ipconfig /renew CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.