Let me know if this stops it
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
FF Extension: No Name - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\Extensions\mypoints@500friends.com [2015-04-12]
FF Extension: No Name - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\Extensions\weidunewtab@gmail.com [2015-04-12]
FF Extension: No Name - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\Extensions\openlinkintab@piro.sakura.ne.jp.xpi [2015-04-12]
FF Extension: No Name - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2015-04-12]
FF Extension: No Name - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\Extensions\{e23e1101-6cde-4b94-b415-508a7cde8628}.xpi [2015-04-12]
2015-03-27 09:32 - 2015-03-27 09:32 - 00003102 _____ () C:\Windows\System32\Tasks\{9CB8CE4C-EEE9-41A5-AE28-35F28FB5C0B0}
2015-03-27 09:29 - 2015-03-27 09:29 - 00003172 _____ () C:\Windows\System32\Tasks\{B214421E-8CC1-4064-B197-63724FE6477B}
2015-03-27 01:49 - 2015-03-27 01:49 - 00000000 ____D () C:\ProgramData\d0ffa7d60000669d
2015-03-27 00:43 - 2015-03-27 01:59 - 00000000 ____D () C:\ProgramData\{69eb3576-45e9-1db2-69eb-b357645ed5d9}
2015-03-27 00:43 - 2015-03-27 00:43 - 00000000 ____D () C:\ProgramData\10864421869464621889
2015-03-26 23:56 - 2015-04-17 12:56 - 00000288 _____ () C:\Windows\Tasks\UpdaterEX.job
2015-03-26 23:56 - 2015-03-27 01:00 - 00000000 ____D () C:\Users\Home\AppData\Roaming\UpdaterEX
2015-03-26 23:56 - 2015-03-26 23:56 - 00003224 _____ () C:\Windows\System32\Tasks\UpdaterEX
Task: {6FF11187-91C7-4148-97F8-AEF03ECACC47} - System32\Tasks\UpdaterEX => C:\Users\Home\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\Home\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.