Hi again!
Yes I reset the password you need to log into the router as well.
I unistalled the programs you said..
I got this log from defogger:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 13:35 on 03/07/2010 (Anders)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
HKCU
AEMON Tools Lite -> Removed
Checking for services/drivers...
Unable to read sptd.sys
SPTD -> Disabled (Service running -> reboot required)
-=E.O.F=-
I saved the registry and ran the OTL fix..
The computer seems ok.. it is already a bit faster.
Here are the OTL log:
All processes killed
========== OTL ==========
Error: No service named LiveUpdate Notice Ex was found to stop!
Service\Driver key LiveUpdate Notice Ex not found.
File File not found not found.
Error: No service named LiveUpdate was found to stop!
Service\Driver key LiveUpdate not found.
File C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HWSetup not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NDSTray.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Symantec PIF AlertEng not found.
File C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe not found.
Registry value HKEY_USERS\S-1-5-21-2002946825-3677852132-797418189-1001\Software\Microsoft\Windows\CurrentVersion\Run\\TOSCDSPD not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{76577871-04EC-495E-A12B-91F7C3600AFA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76577871-04EC-495E-A12B-91F7C3600AFA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8A918C1D-E123-4E36-B562-5C1519E434CE}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A918C1D-E123-4E36-B562-5C1519E434CE}\ not found.
Starting removal of ActiveX control {3B36B017-7E49-426B-95B0-B5CECD83C2E2}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3B36B017-7E49-426B-95B0-B5CECD83C2E2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B36B017-7E49-426B-95B0-B5CECD83C2E2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3B36B017-7E49-426B-95B0-B5CECD83C2E2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B36B017-7E49-426B-95B0-B5CECD83C2E2}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84f7d4ee-306b-11df-97b8-001b383fab7f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84f7d4ee-306b-11df-97b8-001b383fab7f}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84f7d4fd-306b-11df-97b8-001b383fab7f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84f7d4fd-306b-11df-97b8-001b383fab7f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84f7d4fd-306b-11df-97b8-001b383fab7f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84f7d4fd-306b-11df-97b8-001b383fab7f}\ not found.
File G:\AutoRun.exe not found.
Folder C:\ProgramData\Norton\ not found.
Folder C:\ProgramData\NortonInstaller\ not found.
Folder C:\Program Files\NortonInstaller\ not found.
Folder C:\ProgramData\Spybot - Search & Destroy\ not found.
Folder C:\Program Files\Spybot - Search & Destroy\ not found.
Folder C:\ProgramData\BanzaiInteractive\ not found.
File C:\Windows\unvise32.exe not found.
File C:\Windows\tasks\Norton Security Scan for Anders.job not found.
File C:\Users\Public\Desktop\Norton Security Scan.lnk not found.
Unable to delete ADS C:\ProgramData\TEMP:949483BD .
========== FILES ==========
File\Folder C:\Program Files\DAEMON Tools Lite not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Anders
->Temp folder emptied: 152557 bytes
->Temporary Internet Files folder emptied: 4813749 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Gabriel
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 283094218 bytes
->Java cache emptied: 37606889 bytes
->Flash cache emptied: 62814 bytes
User: Public
User: Ulrika
->Temp folder emptied: 1773391166 bytes
->Temporary Internet Files folder emptied: 1315520988 bytes
->Java cache emptied: 50872974 bytes
->Flash cache emptied: 58228 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 66106 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 3*305,00 mb
Error: Unable to interpret <[Reboot]Return to OTL, right-click in the Custom Scans/Fixes window (under the > in the current context!
OTL by OldTimer - Version 3.2.7.0 log created on 07032010_140049
Files\Folders moved on Reboot...
C:\Users\Anders\AppData\Local\Temp\Low\Google Toolbar\GoogleToolbarWelcome.log moved successfully.
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF221D.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF222C.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF228B.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF229A.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF22D9.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF22E8.tmp not found!
C:\Users\Anders\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BD2JGTFM\showthread[1].htm moved successfully.
C:\Users\Anders\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...
and the gmer log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-03 14:48:02
Windows 6.0.6002 Service Pack 2
Running: kbw31mtj.exe; Driver: C:\Users\Anders\AppData\Local\Temp\pwtdqpog.sys
---- Kernel code sections - GMER 1.0.15 ----
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x88159000, 0x4036D, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x881A2000, 0x510, 0x40000040]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe[3004] ntdll.dll!DbgBreakPoint 770A8B2E 1 Byte [90]
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!CreateWindowExW 76091305 5 Bytes JMP 6AE2DB1C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!DialogBoxParamW 760B10B0 5 Bytes JMP 6AD554C5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!DialogBoxIndirectParamW 760B2EF5 5 Bytes JMP 6AF2480F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!DialogBoxParamA 760C8152 5 Bytes JMP 6AF247AC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!DialogBoxIndirectParamA 760C847D 5 Bytes JMP 6AF24872 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!MessageBoxIndirectA 760DD4D9 5 Bytes JMP 6AF24741 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!MessageBoxIndirectW 760DD5D3 5 Bytes JMP 6AF246D6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!MessageBoxExA 760DD639 5 Bytes JMP 6AF24674 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!MessageBoxExW 760DD65D 5 Bytes JMP 6AF24612 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateDialogParamW 760872A2 5 Bytes JMP 6AE2DEA8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!GetAsyncKeyState 7608863C 5 Bytes JMP 6AD48EFF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!SetWindowsHookExW 760887AD 5 Bytes JMP 6AE29AC9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CallNextHookEx 76088E3B 5 Bytes JMP 6AE1D0ED C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!UnhookWindowsHookEx 760898DB 5 Bytes JMP 6AD9467C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!EnableWindow 7608CD8B 5 Bytes JMP 6AE2DD35 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateWindowExW 76091305 5 Bytes JMP 6AE2DB1C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!GetKeyState 76098CB1 5 Bytes JMP 6AE2D2E3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!IsDialogMessageW 760A0745 5 Bytes JMP 6AD559D7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateDialogParamA 760A17AA 5 Bytes JMP 6AF2547B C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!IsDialogMessage 760A1847 5 Bytes JMP 6AF24D17 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateDialogIndirectParamA 760A26F1 5 Bytes JMP 6AF254B2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateDialogIndirectParamW 760A9A62 5 Bytes JMP 6AF254E9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!SetKeyboardState 760B0987 5 Bytes JMP 6AF25086 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!DialogBoxParamW 760B10B0 5 Bytes JMP 6AD554C5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!DialogBoxIndirectParamW 760B2EF5 5 Bytes JMP 6AF2480F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!SendInput 760B2F75 5 Bytes JMP 6AF25C43 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!EndDialog 760B326E 5 Bytes JMP 6AD57E7E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!SetCursorPos 760C6FB2 5 Bytes JMP 6AF25C97 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!DialogBoxParamA 760C8152 5 Bytes JMP 6AF247AC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!DialogBoxIndirectParamA 760C847D 5 Bytes JMP 6AF24872 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!MessageBoxIndirectA 760DD4D9 5 Bytes JMP 6AF24741 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!MessageBoxIndirectW 760DD5D3 5 Bytes JMP 6AF246D6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!MessageBoxExA 760DD639 5 Bytes JMP 6AF24674 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!MessageBoxExW 760DD65D 5 Bytes JMP 6AF24612 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!keybd_event 760DD972 5 Bytes JMP 6AF25FC7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] SHELL32.dll!SHRestricted + D95 761A8988 4 Bytes [4D, 30, 6A, 63] {DEC EBP; XOR [EDX+0x63], CH}
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] SHELL32.dll!SHRestricted + D9D 761A8990 8 Bytes [57, 2F, 6A, 63, 9C, 5B, 69, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] ole32.dll!OleLoadFromStream 759D1E12 5 Bytes JMP 6AF24B77 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] ole32.dll!CoCreateInstance 75A09EA6 5 Bytes JMP 6AE2DB78 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x89 0x0C 0xE5 0xA6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDE 0x47 0x58 0xB4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x68 0xD6 0x98 0x44 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x89 0x0C 0xE5 0xA6 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDE 0x47 0x58 0xB4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x68 0xD6 0x98 0x44 ...
---- EOF - GMER 1.0.15 ----
Ok..
Have a nice day..
Best Regards DerArne
Yes I reset the password you need to log into the router as well.
I unistalled the programs you said..
I got this log from defogger:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 13:35 on 03/07/2010 (Anders)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
HKCU

Checking for services/drivers...
Unable to read sptd.sys
SPTD -> Disabled (Service running -> reboot required)
-=E.O.F=-
I saved the registry and ran the OTL fix..
The computer seems ok.. it is already a bit faster.
Here are the OTL log:
All processes killed
========== OTL ==========
Error: No service named LiveUpdate Notice Ex was found to stop!
Service\Driver key LiveUpdate Notice Ex not found.
File File not found not found.
Error: No service named LiveUpdate was found to stop!
Service\Driver key LiveUpdate not found.
File C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HWSetup not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NDSTray.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Symantec PIF AlertEng not found.
File C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe not found.
Registry value HKEY_USERS\S-1-5-21-2002946825-3677852132-797418189-1001\Software\Microsoft\Windows\CurrentVersion\Run\\TOSCDSPD not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{76577871-04EC-495E-A12B-91F7C3600AFA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76577871-04EC-495E-A12B-91F7C3600AFA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8A918C1D-E123-4E36-B562-5C1519E434CE}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A918C1D-E123-4E36-B562-5C1519E434CE}\ not found.
Starting removal of ActiveX control {3B36B017-7E49-426B-95B0-B5CECD83C2E2}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3B36B017-7E49-426B-95B0-B5CECD83C2E2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B36B017-7E49-426B-95B0-B5CECD83C2E2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{3B36B017-7E49-426B-95B0-B5CECD83C2E2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B36B017-7E49-426B-95B0-B5CECD83C2E2}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84f7d4ee-306b-11df-97b8-001b383fab7f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84f7d4ee-306b-11df-97b8-001b383fab7f}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84f7d4fd-306b-11df-97b8-001b383fab7f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84f7d4fd-306b-11df-97b8-001b383fab7f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84f7d4fd-306b-11df-97b8-001b383fab7f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84f7d4fd-306b-11df-97b8-001b383fab7f}\ not found.
File G:\AutoRun.exe not found.
Folder C:\ProgramData\Norton\ not found.
Folder C:\ProgramData\NortonInstaller\ not found.
Folder C:\Program Files\NortonInstaller\ not found.
Folder C:\ProgramData\Spybot - Search & Destroy\ not found.
Folder C:\Program Files\Spybot - Search & Destroy\ not found.
Folder C:\ProgramData\BanzaiInteractive\ not found.
File C:\Windows\unvise32.exe not found.
File C:\Windows\tasks\Norton Security Scan for Anders.job not found.
File C:\Users\Public\Desktop\Norton Security Scan.lnk not found.
Unable to delete ADS C:\ProgramData\TEMP:949483BD .
========== FILES ==========
File\Folder C:\Program Files\DAEMON Tools Lite not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Anders
->Temp folder emptied: 152557 bytes
->Temporary Internet Files folder emptied: 4813749 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Gabriel
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 283094218 bytes
->Java cache emptied: 37606889 bytes
->Flash cache emptied: 62814 bytes
User: Public
User: Ulrika
->Temp folder emptied: 1773391166 bytes
->Temporary Internet Files folder emptied: 1315520988 bytes
->Java cache emptied: 50872974 bytes
->Flash cache emptied: 58228 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 66106 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 3*305,00 mb
Error: Unable to interpret <[Reboot]Return to OTL, right-click in the Custom Scans/Fixes window (under the > in the current context!
OTL by OldTimer - Version 3.2.7.0 log created on 07032010_140049
Files\Folders moved on Reboot...
C:\Users\Anders\AppData\Local\Temp\Low\Google Toolbar\GoogleToolbarWelcome.log moved successfully.
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF221D.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF222C.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF228B.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF229A.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF22D9.tmp not found!
File\Folder C:\Users\Anders\AppData\Local\Temp\~DF22E8.tmp not found!
C:\Users\Anders\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BD2JGTFM\showthread[1].htm moved successfully.
C:\Users\Anders\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...
and the gmer log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-03 14:48:02
Windows 6.0.6002 Service Pack 2
Running: kbw31mtj.exe; Driver: C:\Users\Anders\AppData\Local\Temp\pwtdqpog.sys
---- Kernel code sections - GMER 1.0.15 ----
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x88159000, 0x4036D, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x881A2000, 0x510, 0x40000040]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe[3004] ntdll.dll!DbgBreakPoint 770A8B2E 1 Byte [90]
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!CreateWindowExW 76091305 5 Bytes JMP 6AE2DB1C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!DialogBoxParamW 760B10B0 5 Bytes JMP 6AD554C5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!DialogBoxIndirectParamW 760B2EF5 5 Bytes JMP 6AF2480F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!DialogBoxParamA 760C8152 5 Bytes JMP 6AF247AC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!DialogBoxIndirectParamA 760C847D 5 Bytes JMP 6AF24872 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!MessageBoxIndirectA 760DD4D9 5 Bytes JMP 6AF24741 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!MessageBoxIndirectW 760DD5D3 5 Bytes JMP 6AF246D6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!MessageBoxExA 760DD639 5 Bytes JMP 6AF24674 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4300] USER32.dll!MessageBoxExW 760DD65D 5 Bytes JMP 6AF24612 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateDialogParamW 760872A2 5 Bytes JMP 6AE2DEA8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!GetAsyncKeyState 7608863C 5 Bytes JMP 6AD48EFF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!SetWindowsHookExW 760887AD 5 Bytes JMP 6AE29AC9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CallNextHookEx 76088E3B 5 Bytes JMP 6AE1D0ED C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!UnhookWindowsHookEx 760898DB 5 Bytes JMP 6AD9467C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!EnableWindow 7608CD8B 5 Bytes JMP 6AE2DD35 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateWindowExW 76091305 5 Bytes JMP 6AE2DB1C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!GetKeyState 76098CB1 5 Bytes JMP 6AE2D2E3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!IsDialogMessageW 760A0745 5 Bytes JMP 6AD559D7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateDialogParamA 760A17AA 5 Bytes JMP 6AF2547B C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!IsDialogMessage 760A1847 5 Bytes JMP 6AF24D17 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateDialogIndirectParamA 760A26F1 5 Bytes JMP 6AF254B2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!CreateDialogIndirectParamW 760A9A62 5 Bytes JMP 6AF254E9 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!SetKeyboardState 760B0987 5 Bytes JMP 6AF25086 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!DialogBoxParamW 760B10B0 5 Bytes JMP 6AD554C5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!DialogBoxIndirectParamW 760B2EF5 5 Bytes JMP 6AF2480F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!SendInput 760B2F75 5 Bytes JMP 6AF25C43 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!EndDialog 760B326E 5 Bytes JMP 6AD57E7E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!SetCursorPos 760C6FB2 5 Bytes JMP 6AF25C97 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!DialogBoxParamA 760C8152 5 Bytes JMP 6AF247AC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!DialogBoxIndirectParamA 760C847D 5 Bytes JMP 6AF24872 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!MessageBoxIndirectA 760DD4D9 5 Bytes JMP 6AF24741 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!MessageBoxIndirectW 760DD5D3 5 Bytes JMP 6AF246D6 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!MessageBoxExA 760DD639 5 Bytes JMP 6AF24674 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!MessageBoxExW 760DD65D 5 Bytes JMP 6AF24612 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] USER32.dll!keybd_event 760DD972 5 Bytes JMP 6AF25FC7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] SHELL32.dll!SHRestricted + D95 761A8988 4 Bytes [4D, 30, 6A, 63] {DEC EBP; XOR [EDX+0x63], CH}
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] SHELL32.dll!SHRestricted + D9D 761A8990 8 Bytes [57, 2F, 6A, 63, 9C, 5B, 69, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] ole32.dll!OleLoadFromStream 759D1E12 5 Bytes JMP 6AF24B77 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4400] ole32.dll!CoCreateInstance 75A09EA6 5 Bytes JMP 6AE2DB78 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x89 0x0C 0xE5 0xA6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDE 0x47 0x58 0xB4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x68 0xD6 0x98 0x44 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x89 0x0C 0xE5 0xA6 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDE 0x47 0x58 0xB4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x68 0xD6 0x98 0x44 ...
---- EOF - GMER 1.0.15 ----
Ok..
Have a nice day..
Best Regards DerArne