start Startup: C:\Users\stef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\428z7tvq.lnk ShortcutTarget: 428z7tvq.lnk -> C:\PROGRA~3\qvt7z824.cpp (No File) URLSearchHook: HKCU - (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2504091 SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File Toolbar: HKCU - No Name - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No File FF Extension: OneClickDownloader - C:\Users\stef\AppData\Roaming\Mozilla\Firefox\profiles\extensions\OneClickDownload@OneClickDownload.com [2012-10-10] FF HKLM-x32\...\Firefox\Extensions: [offerboxffx@offerbox.com] - C:\Program Files (x86)\OfferBox\offerboxffx@offerbox.com S3 Lavasoft Ad-Aware Service; "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe" [X] S2 Winmgmt; C:\PROGRA~3\428z7tvq.zvv [X] R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [69152 2009-09-23] (Lavasoft AB) Task: {B053B04F-5DB6-433F-833B-2CA46FE454AB} - System32\Tasks\0 => Iexplore.exe Task: {C1E7A828-4422-43D5-ACCD-1F053B5B0268} - System32\Tasks\4615 => Wscript.exe C:\Users\stef\AppData\Local\Temp\launchie.vbs //B HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Lavasoft Ad-Aware Service => ""="Service" 2014-03-02 03:58 - 2014-03-02 04:35 - 95027928 ____T () C:\ProgramData\428z7tvq.fee C:\Program Files (x86)\OfferBox C:\PROGRA~3\qvt7z824.cpp C:\Users\stef\AppData\Local\Temp\launchie.vbs C:\Users\stef\AppData\Local\Temp\drm_dialogs.dll C:\Users\stef\AppData\Local\Temp\drm_dyndata_7380014.dll C:\Users\stef\AppData\Local\Temp\DTLite4481-0347.exe C:\Users\stef\AppData\Local\Temp\IEHistory.exe C:\Users\stef\AppData\Local\Temp\InstalledPrograms.exe C:\Users\stef\AppData\Local\Temp\sfamcc00001.dll end