Thanks Essexboy. Here is the file:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-05-2015
Ran by A Steel Lady at 2015-05-20 14:50:55 Run:1
Running from G:\
Loaded Profiles: A Steel Lady (Available profiles: A Steel Lady)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
CreateRestorePoint:
HKLM-x32\...\Run: [ospd_us_1050] => [X]
HKLM-x32\...\Run: [gmsd_us_532] => [X]
HKLM-x32\...\Run: [gmsd_us_558] => "C:\Program Files (x86)\gmsd_us_558\gmsd_us_558.exe"
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\...\Run: [Boxerexe] => C:\Users\A Steel Lady\AppData\Local\Boxer\BoxerApp.exe
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\...\Run: [JunkCleaner] => C:\Program Files (x86)\PandaJe Group\Junk Cleaner\JunkCleaner.exe
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\...\Run: [GoogleChromeAutoLaunch_8678E05336FE7E3302F93AC77FAB0AA5] => "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
HKU\S-1-5-18\...\Run: [SearchProtect] => C:\Windows\system32\config\systemprofile\AppData\Roaming\SearchProtect\bin\cltmng.exe
AppInit_DLLs-x32: c:\programdata\lolliscan\lolliscan32.dll => "c:\programdata\lolliscan\lolliscan32.dll" File Not Found
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
Toolbar: HKU\S-1-5-21-1885504849-1370587953-3290610847-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
S2 moleluty; C:\Users\A Steel Lady\AppData\Roaming\C01FA761-1431120270-E111-8703-CBF38146158A\jnspF71E.tmp [X]
S2 UpdateCheck; C:\Program Files (x86)\Coupoon\UpdateCheck.exe run [X]
2015-05-15 11:12 - 2015-05-15 11:16 - 06420480 _____ () C:\Program Files (x86)\GUTBC1E.tmp
2015-05-15 11:12 - 2015-05-15 11:12 - 00000000 ____D () C:\Program Files (x86)\GUMBC1D.tmp
2015-05-10 21:11 - 2015-05-10 21:11 - 00000000 __SHD () C:\Users\A Steel Lady\AppData\Local\EmieUserList
2015-05-10 21:11 - 2015-05-10 21:11 - 00000000 __SHD () C:\Users\A Steel Lady\AppData\Local\EmieSiteList
2015-05-10 21:11 - 2015-05-10 21:11 - 00000000 __SHD () C:\Users\A Steel Lady\AppData\Local\EmieBrowserModeList
2015-05-08 15:23 - 2015-05-13 17:18 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-08 15:19 - 2015-05-08 15:19 - 0000906 _____ () C:\ProgramData\JunkCleaner.lnk
Task: {1291D067-0E5B-434A-9FCC-DAFDF1D562CA} - \ZFNENS No Task File <==== ATTENTION
Task: {388DCBF1-E50D-4593-85B8-3DE0C8F912BE} - \boosterpop No Task File <==== ATTENTION
Task: {60F9A5A9-5425-4DF9-BFD6-ECA850FCA181} - \IE_ERR4WDR No Task File <==== ATTENTION
Task: {7DAB5F3C-15DF-44B6-94D4-E861F6B95762} - \AI_Updater No Task File <==== ATTENTION
Task: {AEA4A02A-ADDD-4809-91A7-D1177574134B} - \IEError No Task File <==== ATTENTION
Task: {B3B7F1A4-F66A-4884-9016-1339EB0AC8C4} - \c0976ad7-b268-4bd9-b131-7cf2ab414e25-7 No Task File <==== ATTENTION
Task: {B7A656C8-AED6-46FD-BAA5-492D5B3167D5} - \UPDTEXE4_WDR No Task File <==== ATTENTION
Shortcut: C:\ProgramData\JunkCleaner.lnk -> C:\Program Files (x86)\Pandaje Group\Junk Cleaner\JunkCleaner.exe (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\JunkCleaner.lnk -> C:\Program Files (x86)\Pandaje Group\Junk Cleaner\JunkCleaner.exe (No File)
FirewallRules: [{DB27DFBA-0469-4032-BB53-30B6AD57334E}] => (Allow) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
Shortcut: C:\Users\Public\Desktop\Search.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (No File)
C:\Program Files (x86)\gmsd_us_558
C:\Program Files (x86)\Crossbrowse
c:\programdata\lolliscan
C:\Users\A Steel Lady\AppData\Local\Boxer
C:\Windows\system32\config\systemprofile\AppData\Roaming\SearchProtect
C:\Users\A Steel Lady\AppData\Roaming\C01FA761-1431120270-E111-8703-CBF38146158A
C:\Program Files (x86)\Coupoon
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ospd_us_1050 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_us_532 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_us_558 => value deleted successfully.
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Boxerexe => value deleted successfully.
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\Software\Microsoft\Windows\CurrentVersion\Run\\JunkCleaner => value deleted successfully.
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_8678E05336FE7E3302F93AC77FAB0AA5 => value deleted successfully.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtect => value deleted successfully.
"c:\programdata\lolliscan\lolliscan32.dll" => Value Data removed successfully.
"HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.
moleluty => Service deleted successfully.
UpdateCheck => Service deleted successfully.
C:\Program Files (x86)\GUTBC1E.tmp => Moved successfully.
C:\Program Files (x86)\GUMBC1D.tmp => Moved successfully.
C:\Users\A Steel Lady\AppData\Local\EmieUserList => Moved successfully.
C:\Users\A Steel Lady\AppData\Local\EmieSiteList => Moved successfully.
C:\Users\A Steel Lady\AppData\Local\EmieBrowserModeList => Moved successfully.
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully.
C:\ProgramData\JunkCleaner.lnk => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1291D067-0E5B-434A-9FCC-DAFDF1D562CA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1291D067-0E5B-434A-9FCC-DAFDF1D562CA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ZFNENS" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{388DCBF1-E50D-4593-85B8-3DE0C8F912BE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{388DCBF1-E50D-4593-85B8-3DE0C8F912BE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\boosterpop" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{60F9A5A9-5425-4DF9-BFD6-ECA850FCA181}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60F9A5A9-5425-4DF9-BFD6-ECA850FCA181}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IE_ERR4WDR" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7DAB5F3C-15DF-44B6-94D4-E861F6B95762}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7DAB5F3C-15DF-44B6-94D4-E861F6B95762}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AI_Updater" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AEA4A02A-ADDD-4809-91A7-D1177574134B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEA4A02A-ADDD-4809-91A7-D1177574134B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IEError" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B3B7F1A4-F66A-4884-9016-1339EB0AC8C4}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3B7F1A4-F66A-4884-9016-1339EB0AC8C4}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\c0976ad7-b268-4bd9-b131-7cf2ab414e25-7" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B7A656C8-AED6-46FD-BAA5-492D5B3167D5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7A656C8-AED6-46FD-BAA5-492D5B3167D5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UPDTEXE4_WDR" => Key deleted successfully.
Shortcut: C:\ProgramData\JunkCleaner.lnk -> C:\Program Files (x86)\Pandaje Group\Junk Cleaner\JunkCleaner.exe (No File) => Error: No automatic fix found for this entry.
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\JunkCleaner.lnk -> C:\Program Files (x86)\Pandaje Group\Junk Cleaner\JunkCleaner.exe (No File) => Error: No automatic fix found for this entry.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DB27DFBA-0469-4032-BB53-30B6AD57334E} => value deleted successfully.
Shortcut: C:\Users\Public\Desktop\Search.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (No File) => Error: No automatic fix found for this entry.
"C:\Program Files (x86)\gmsd_us_558" => File/Directory not found.
"C:\Program Files (x86)\Crossbrowse" => File/Directory not found.
"c:\programdata\lolliscan" => File/Directory not found.
"C:\Users\A Steel Lady\AppData\Local\Boxer" => File/Directory not found.
"C:\Windows\system32\config\systemprofile\AppData\Roaming\SearchProtect" => File/Directory not found.
"C:\Users\A Steel Lady\AppData\Roaming\C01FA761-1431120270-E111-8703-CBF38146158A" => File/Directory not found.
"C:\Program Files (x86)\Coupoon" => File/Directory not found.
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
The operation completed successfully.
========= End of Reg: =========
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
The operation completed successfully.
========= End of Reg: =========
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\S-1-5-21-1885504849-1370587953-3290610847-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.
========= End of RemoveProxy: =========
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
Unable to cancel {E00F1D6B-08EC-4967-A9C8-9A6CEBB15952}.
Unable to cancel {A99966BF-A5BC-4653-A51B-740A692FF5B9}.
Unable to cancel {02C66B61-D975-4D2D-93BA-13192356DA7C}.
{5918994B-140A-49FA-8EEC-4B7E11EAB72C} canceled.
{44C38846-500D-479E-BF1B-FD512A24CA59} canceled.
{942917D1-DBDC-40B2-80B6-AD311FBDE034} canceled.
{3C10A23A-A809-417C-940C-4591FCFFFF1C} canceled.
{0B151DF2-304F-41DC-A11C-F65436611159} canceled.
{792B90B4-3A8F-414C-967E-A4A90FCF178A} canceled.
Unable to cancel {5CC6F266-E52C-41CA-BE79-300ECAEA7854}.
Unable to cancel {7959FAE3-80D7-4954-8A24-98264E36EBCB}.
Unable to cancel {F2850E8F-88A1-432D-81A3-1160295111E9}.
Unable to cancel {737486EF-CBEC-4CAB-BCB4-ADCEB9332368}.
Unable to cancel {A97AD247-8985-419B-AB68-F9B45F9B562F}.
Unable to cancel {5B171B7D-B5DF-4A91-BD59-94BA80CF53DC}.
Unable to cancel {8879D6E2-2DFB-4C9E-9EBD-F0B2C0A71094}.
Unable to cancel {EC931246-29BB-46E3-9577-537C25B95FD9}.
Unable to cancel {C6CFD347-F63A-4281-A469-087A3559BF1E}.
Unable to cancel {3BB19B89-DF0A-4771-B33B-C5C0F96BB37D}.
Unable to cancel {ED54DDFA-FB8B-4638-A42F-1C6E3336934D}.
Unable to cancel {589A47FB-1A04-4617-809B-A57F149AB429}.
{F15A4650-18E6-4475-BEA5-E0F00611738E} canceled.
7 out of 22 jobs canceled.
========= End of CMD: =========
EmptyTemp: => Removed 64.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog 14:57:55 ====