Here's the log:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-11-2014 02
Ran by Dan at 2014-11-16 09:10:27 Run:1
Running from C:\Users\Dan\Desktop
Loaded Profile: Dan (Available profiles: Dan)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe
C:\ProgramData\Search Protection
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Receiver.lnk
ShortcutTarget: Receiver.lnk -> C:\Windows\Installer\{961882FF-663F-47D2-8588-C9943C5E6A26}\pnaico.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk
ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe ()
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Receiver.lnk
C:\Windows\Installer\{961882FF-663F-47D2-8588-C9943C5E6A26}
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk
C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL =
search.ask.com/web?q={searchterms}&l=dis&o=HPNTDFSearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL =
search.ask.com/web?q={searchterms}&l=dis&o=HPNTDFSearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL =
SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL =
SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
SearchScopes: HKCU - {E1A33FAA-626E-4E1D-8776-86F083A07DDD} URL =
BHO: No Name -> {434D4756-372D-5341-5400-7A786E7484D7} -> No File
BHO: No Name -> {4F524A2D-5637-4300-76A7-7A786E7484D7} -> No File
Toolbar: HKU\S-1-5-21-1800431798-4075450857-3895629184-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
S1 qknfd; system32\drivers\qknfd.sys [X]
C:\Users\Dan\CourtTeleworkSoftware.exe
C:\Users\Dan\AppData\Local\Temp\mssinstaller.exe
C:\Users\Dan\AppData\Local\Temp\mysearchdial.exe
C:\Users\Dan\AppData\Local\Temp\ose00000.exe
C:\Users\Dan\AppData\Local\Temp\SkypeSetup.exe
AlternateDataStreams: C:\Users\Dan\Downloads\launch.ica:icasource
HKU\S-1-5-21-1800431798-4075450857-3895629184-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
CustomCLSID: HKU\S-1-5-21-1800431798-4075450857-3895629184-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
Reboot:
end
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Search Protection => value deleted successfully.
"C:\ProgramData\Search Protection" => File/Directory not found.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Receiver.lnk => Moved successfully.
C:\Windows\Installer\{961882FF-663F-47D2-8588-C9943C5E6A26}\pnaico.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk => Moved successfully.
C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe => Moved successfully.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Receiver.lnk" => File/Directory not found.
C:\Windows\Installer\{961882FF-663F-47D2-8588-C9943C5E6A26} => Moved successfully.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk" => File/Directory not found.
C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
"HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
"HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}" => Key deleted successfully.
"HKCR\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key deleted successfully.
"HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => Key deleted successfully.
"HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E1A33FAA-626E-4E1D-8776-86F083A07DDD}" => Key deleted successfully.
"HKCR\CLSID\{E1A33FAA-626E-4E1D-8776-86F083A07DDD}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{434D4756-372D-5341-5400-7A786E7484D7}" => Key deleted successfully.
"HKCR\CLSID\{434D4756-372D-5341-5400-7A786E7484D7}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5637-4300-76A7-7A786E7484D7}" => Key deleted successfully.
"HKCR\CLSID\{4F524A2D-5637-4300-76A7-7A786E7484D7}" => Key not found.
HKU\S-1-5-21-1800431798-4075450857-3895629184-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully.
"HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => Key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
qknfd => Service deleted successfully.
C:\Users\Dan\CourtTeleworkSoftware.exe => Moved successfully.
C:\Users\Dan\AppData\Local\Temp\mssinstaller.exe => Moved successfully.
C:\Users\Dan\AppData\Local\Temp\mysearchdial.exe => Moved successfully.
C:\Users\Dan\AppData\Local\Temp\ose00000.exe => Moved successfully.
C:\Users\Dan\AppData\Local\Temp\SkypeSetup.exe => Moved successfully.
C:\Users\Dan\Downloads\launch.ica => ":icasource" ADS removed successfully.
"HKU\S-1-5-21-1800431798-4075450857-3895629184-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => Key Deleted Successfully.
"HKU\S-1-5-21-1800431798-4075450857-3895629184-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key deleted successfully.
"HKU\S-1-5-21-1800431798-4075450857-3895629184-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key not found.
The system needed a reboot.
==== End of Fixlog ====