Start
CustomCLSID: HKU\S-1-5-21-2842711328-3727693777-432756069-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
Task: {E5A28F36-C64C-43F9-9CA5-FF05331AD3C1} - \AutoKMS No Task File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
HKU\S-1-5-21-2842711328-3727693777-432756069-1000\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2842711328-3727693777-432756069-1000\...\MountPoints2: {3263cfbc-8142-11e1-9226-c0f8dac6c39d} - "F:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-2842711328-3727693777-432756069-1000\...\MountPoints2: {8fc3ecda-d319-11e0-9c1c-806e6f6e6963} - H:\Autorun.exe
HKU\S-1-5-21-2842711328-3727693777-432756069-1000\...\MountPoints2: {cf6ee64e-1489-11e1-b0d5-c0f8dac6c39d} - F:\LaunchU3.exe -a
HKU\S-1-5-21-2842711328-3727693777-432756069-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {31090377-0740-419E-BEFC-A56E50500D5B} URL = http://search.conduit.com/Results.aspx?gd=&ctid=CT3319597&octid=EB_ORIGINAL_CTID&ISID=MFFECE766-0618-4440-A419-FF8DE7DE9CB4&SearchSource=58&CUI=&UM=5&UP=SP56D57CCF-67F4-4A4C-894C-C628ECF9A40E&q={searchTerms}&SSPV=
BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
Toolbar: HKLM-x32 - Expat Shield Toolbar - {a060276a-53be-45ec-8ebe-b94b1e803179} - C:\Program Files (x86)\Expat_Shield\prxtbExpa.dll (Conduit Ltd.)
FF SearchEngineOrder.1: Search the web (Babylon)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Extension: safe save - C:\Users\Alskki\AppData\Roaming\Mozilla\Firefox\Profiles\ekgtcvio.default\Extensions\aiyifwfsv@iecxhwbbdf.net [2013-07-21]
CHR StartupUrls: Default -> "hxxp://speedial.com/?f=7&a=spd_ir_14_25_ch&cd=2XzuyEtN2Y1L1Qzu0FtD0B0FzyyByCyCyB0E0A0EtA0AtAyCtN0D0Tzu0SzytDtDtN1L2XzutBtFtBtCtFyBtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEtC0EzzzyyEtGyBzy0BtAtGzz0C0CtBtGyBzy0E0FtGtC0CyCyEtByC0D0AyBzy0AtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyCtCtB0BtCyDzytGtCtCtAyBtGzy0B0BzytGtDyC0EzytGyE0AtDtAyD0F0C0EyDtA0EyB2Q&cr=599121295&ir=", "hxxp://search.conduit.com/?gd=&ctid=CT3319597&octid=EB_ORIGINAL_CTID&ISID=MFFECE766-0618-4440-A419-FF8DE7DE9CB4&SearchSource=55&CUI=&UM=5&UP=SP56D57CCF-67F4-4A4C-894C-C628ECF9A40E&SSPV="
CHR DefaultSearchKeyword: Default -> speedial.com
CHR DefaultSearchURL: Default -> http://speedial.com/results.php?f=4&q={searchTerms}&a=spd_ir_14_25_ch&cd=2XzuyEtN2Y1L1Qzu0FtD0B0FzyyByCyCyB0E0A0EtA0AtAyCtN0D0Tzu0SzytDtDtN1L2XzutBtFtBtCtFyBtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEtC0EzzzyyEtGyBzy0BtAtGzz0C0CtBtGyBzy0E0FtGtC0CyCyEtByC0D0AyBzy0AtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyCtCtB0BtCyDzytGtCtCtAyBtGzy0B0BzytGtDyC0EzytGyE0AtDtAyD0F0C0EyDtA0EyB2Q&cr=599121295&ir=
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
C:\Program Files (x86)\Pando Networks
S1 azxebmud; \??\C:\Windows\system32\drivers\azxebmud.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
C:\ProgramData\@system3.att
C:\Users\Alskki\AppData\Roaming\FrameworkUpdate7
C:\ProgramData\@system.temp
C:\Users\Alskki\AppData\Roaming\麽鎒駓覜
C:\Users\Alskki\AppData\Roaming\61e27ac.exe
C:\61e27ac
C:\ProgramData\Windows Genuine Advantage
C:\Users\Alskki\AppData\Roaming\INSTALL_TOR.URL
C:\Users\Alskki\AppData\INSTALL_TOR.URL
C:\Users\Alskki\AppData\Local\INSTALL_TOR.URL
C:\ProgramData\INSTALL_TOR.URL
EmptyTemp:
End