Let me know how the system is after this
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
AutoConfigURL: [S-1-5-21-670089946-2092166598-2698418892-1001] => http://127.0.0.1:895/proxy.js
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=eXQ&utm_content=ds&from=wpc&uid=FUJITSUXMHZ2320BHXG2_K618T913CF81&ts=1381220013&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-670089946-2092166598-2698418892-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=eXQ&utm_content=ds&from=wpc&uid=FUJITSUXMHZ2320BHXG2_K618T913CF81&ts=1381220013&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-670089946-2092166598-2698418892-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=eXQ&utm_content=ds&from=wpc&uid=FUJITSUXMHZ2320BHXG2_K618T913CF81&ts=1381220013&type=default&q={searchTerms}
FF Extension: Easy Youtube Video Downloader Express - C:\Users\Hanny\AppData\Roaming\Mozilla\Firefox\Profiles\erhxgecn.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2013-10-10]
CHR HomePage: Default -> hxxp://www.qvo6.com/?utm_source=b&utm_medium=wpc&utm_campaign=eXQ&utm_content=hp&from=wpc&uid=FUJITSUXMHZ2320BHXG2_K618T913CF81&ts=1381220012
CHR Plugin: (Native Client) - C:\Users\Hanny\AppData\Local\Google\Chrome\Application\47.0.2516.0\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Hanny\AppData\Local\Google\Chrome\Application\47.0.2516.0\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Hanny\AppData\Local\Google\Chrome\Application\47.0.2516.0\gcswf32.dll => No File
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Hanny\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0\plugin/npABPlugin.dll => No File
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Hanny\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0\plugin/online_banking_npapi.dll => No File
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Hanny\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0\plugin/content_blocker_npapi.dll => No File
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Hanny\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4190_0\plugin/npVKPlugin.dll => No File
CHR Plugin: (Kaspersky Anti-Virus) - C:\Users\Hanny\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0\plugin/npUrlAdvisor.dll => No File
2015-09-18 19:48 - 2015-09-18 14:59 - 00000000 ____D C:\Users\Hanny\Downloads\h
2015-09-18 19:47 - 2015-09-18 19:26 - 00850203 _____ C:\Users\Hanny\Downloads\h.rar
2015-09-12 20:32 - 2014-10-14 05:20 - 00000000 ____D C:\Users\Hanny\AppData\Roaming\MiniLyrics
2012-07-26 09:06 - 2012-07-26 10:20 - 82249600 ___SH () C:\ProgramData\msxcwbe.exe
Task: {D0B56DA9-031A-4E88-8C95-1D08209C9127} - System32\Tasks\{96D0DE65-D882-4830-9671-5D3776E8631B} => pcalua.exe -a "D:\Program Files\CS\SETUP.exe" -d "D:\Program Files\CS"
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.