Let me know if this stops it
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKU\S-1-5-21-3002349881-248581018-3281444942-1000\...\CurrentVersion\Windows: [Load] C:\ProgramData\msrfcr.exe <===== ATTENTION
HKU\S-1-5-21-3002349881-248581018-3281444942-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://adpica.mediaweb.co.kr/RealMedia/ads/adstream_sx.ads/ID_start/pica_browser@x01?CCODE=C001
HKU\S-1-5-21-3002349881-248581018-3281444942-1000\Software\Microsoft\Internet Explorer\Main,SpeedStart = hxxp://adpica.mediaweb.co.kr/RealMedia/ads/adstream_sx.ads/ID_start/pica_browser@x01?CCODE=C001
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKU\S-1-5-21-3002349881-248581018-3281444942-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
CHR StartupUrls: Default -> "hxxp://id.hao123.com/?tn=spark_inner_hp_06_hao123_id&fr=ElUf3HYjQ+9i/TR7FnsbuWIIXbIJdRWoN6N5JA==","hxxp://google.com/","hxxp://start.pcfaster.com/?_bid=df99aaf8f6dff13896c52a7df6bd7ece&_t=hpsf","hxxp://www.google.com/","bdbrowser://tabpage/"
CHR Session Restore: Default -> is enabled.
S1 Bfilter; \??\C:\windows\System32\drivers\Bfilter.sys [X]
S1 Bfmon; \??\C:\windows\System32\drivers\Bfmon.sys [X]
S1 Bnbase; System32\drivers\bnbasex64.sys [X]
S1 Bndef; \??\C:\windows\System32\drivers\bndef64.sys [X]
S1 Bprotect; \??\C:\windows\System32\drivers\Bprotect.sys [X]
S3 BprotectEx; \??\C:\windows\System32\drivers\BprotectEx.sys [X]
S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X]
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]
S3 PCFApiUtil; \??\C:\Program Files (x86)\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil64.sys [X]
S3 X6va017; \??\C:\windows\SysWOW64\Drivers\X6va017 [X]
S3 X6va025; \??\C:\windows\SysWOW64\Drivers\X6va025 [X]
S4 BASSVC; C:\Program Files (x86)\Baidu Security\MoboMarket\1.3.1.3965\bassvc.exe [208928 2014-12-05] (Baidu, Inc.)
2010-11-21 10:24 - 2010-11-21 10:24 - 99992576 ___SH () C:\ProgramData\msrfcr.exe
Task: {25CCE7B9-E624-46BB-BAD2-1320205AD040} - System32\Tasks\SparkUpdater => C:\Program Files (x86)\baidu\Spark\SparkUpdate.exe [2015-10-27] (Baidu.com, Inc.)
C:\Users\kevin\AppData\Local\Unity\WebPlayer\Uninstall.exe
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Hosts:
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.