ClearJavaCache::
DDS::
mStart Page = hxxp://search.searchonme.com/
File::
c:\windows\system32\drivers\kdwijva.sys
Driver::
eltytq
ClearJavaCache::
File::
c:\windows\system32\drivers\kdwijva.sys
Folder::
c:\program files\Ask.com
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
Driver::
eltytq
ClearJavaCache::
File::
C:\Documents and Settings\Buckeye Rob\Application Data\Mozilla\Firefox\Profiles\cxcq3xmg.default\extensions\{c74d2683-d76b-40a2-a534-98330284414e}\chrome.manifest
C:\Documents and Settings\Buckeye Rob\My Documents\Driver Genius Professional Edition V9.0.0.180 (Retail) (Fully Updatable) [h33t] [blaze69]\Driver_Genius_9_Professional_US_Full.EXE
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\R3ZNQPQY\imp[4]
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RHGNSJPZ\imp[2]
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\RHGNSJPZ\imp[3]
ClearJavaCache::
File::
C:\Program Files\Uniblue\SpeedUpMyPC\Launcher.exe
C:\Program Files\Uniblue\SpeedUpMyPC\sp_move_serial.exe
C:\Program Files\Uniblue\SpeedUpMyPC\sp_track_install.exe
C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe
:Services
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.searchonme.com/?l=1&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 2B 9C 04 02 11 1D E3 4C B3 32 38 C0 9D 2B 5A D9 [binary data]
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.searchonme.com/?l=1&q={searchTerms}
FF - prefs.js..browser.search.order.1: "SearchOnMe"
[2011/06/11 18:29:32 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Documents and Settings\Buckeye Rob\Application Data\Mozilla\Firefox\Profiles\cxcq3xmg.default\extensions\{c74d2683-d76b-40a2-a534-98330284414e}
[2012/02/08 13:12:58 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]
[start explorer]
[Reboot]
:Services
:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default =
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{20D707E3-184A-40FF-970A-572AC9BBB3F1}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie8
IE - HKCU\..\SearchScopes\{2A83ED6A-969D-4EFB-A5CE-86F9951A1F8B}: "URL" = http://rover.ebay.com/rover/1/711-43047-14818-1/4?satitle={searchTerms}
IE - HKCU\..\SearchScopes\{76E33316-A026-460E-A91F-EBB95A48D756}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{794742FF-B1C3-4C08-9F7F-16093638A64B}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={46EC57AA-F3B4-4081-B60D-CC8C759BD140}&mid=5307ee3871ac47d1be38d1a90ba6db9f-8b144253687c63810fde9e6294ffe190b626129b&lang=en&ds=AVG&pr=fr&d=2012-01-15 11:29:04&v=10.0.0.7&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{D0FBA784-AAD4-45E4-9E70-E1302A6CC681}: "URL" = http://search.yahoo.com/search?p={searchTerms}&fr=chr-tyc8
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaulturl: "http://in.search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://us.mg.mail.yahoo.com/neo/launch"
FF - prefs.js..extensions.enabledItems: {c74d2683-d76b-40a2-a534-98330284414e}:1.0
FF - prefs.js..extensions.enabledItems: avg@toolbar:10.0.0.7
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B80ba599f-43f5-475d-8175-fa7c87727350%7D&mid=5307ee3871ac47d1be38d1a90ba6db9f-8b144253687c63810fde9e6294ffe190b626129b&ds=AVG&v=10.2.0.3&lang=en&pr=fr&d=2012-01-15%2011%3A29%3A04&sap=ku&q="
[2012/03/21 10:35:52 | 000,000,464 | ---- | M] () -- C:\Documents and Settings\Buckeye Rob\Application Data\Mozilla\Firefox\Profiles\cxcq3xmg.default\searchplugins\SearchOnMe.xml
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.