Solved Infected with Sirefef Please help!

I ran OTL starting at about 5PM yesterday. It has not finished yet. Is this normal or did it freeze up? Just seems like a long time.
I am logged on a different computer and have not disturbed it.
 
All processes killed
========== OTL ==========
Error: No service named kwdyypod was found to stop!
Service\Driver key kwdyypod not found.
File C:\DOCUME~1\Kelly\LOCALS~1\Temp\kwdyypod.sys not found.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
C:\WINDOWS\system32\49964A2587.sys moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Administrator.DELL-E510
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Documents and Settings

User: Keith
->Temp folder emptied: 4592011518 bytes
->Temporary Internet Files folder emptied: 45525705 bytes
->Java cache emptied: 54940343 bytes
->FireFox cache emptied: 671885582 bytes
->Google Chrome cache emptied: 6644455 bytes
->Flash cache emptied: 473306883 bytes

User: Kelly
->Temp folder emptied: 2122 bytes
->Temporary Internet Files folder emptied: 1776139 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 58966562 bytes
->Flash cache emptied: 5691 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 9109638 bytes
->Flash cache emptied: 21177 bytes

User: NetworkService
->Temp folder emptied: 12840 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 782 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2375405 bytes
%systemroot%\System32 .tmp files removed: 60244 bytes
%systemroot%\System32\dllcache .tmp files removed: 1948160 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 41641 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 5,645.00 mb


[EMPTYJAVA]

User: Administrator

User: Administrator.DELL-E510

User: All Users

User: Default User

User: Documents and Settings

User: Keith
->Java cache emptied: 0 bytes

User: Kelly
->Java cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Java Files Cleaned = 0.00 mb


[EMPTYFLASH]

User: Administrator

User: Administrator.DELL-E510

User: All Users

User: Default User

User: Documents and Settings

User: Keith
->Flash cache emptied: 0 bytes

User: Kelly
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.53.1 log created on 07242012_144157

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
 
Results of screen317's Security Check version 0.99.24
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date! (On Access scanning disabled!)
```````````````````````````````
Anti-malware/Other Utilities Check:

Java(TM) 6 Update 33
Adobe Flash Player 11.3.300.265
Adobe Reader X (10.1.3)
Mozilla Firefox (x86 en-US..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Malwarebytes' Anti-Malware mbamservice.exe
Malwarebytes' Anti-Malware mbamgui.exe
Microsoft Security Essentials msseces.exe
``````````End of Log````````````
 
Farbar Service Scanner Version: 22-07-2012
Ran by Kelly (administrator) on 24-07-2012 at 14:54:54
Running from "C:\Documents and Settings\Kelly\My Documents\Downloads"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
ATTENTION!=====> Unable to retrieve HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\\EnableFirewall value. The value does not exist.


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
0x0700000005000000010000000200000003000000040000000600000007000000
IpSec Tag value is correct.

**** End of log ****
 
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\Documents and Settings\Documents and Settings\Keith\Local Settings\Temporary Internet Files\Content.IE5\JYO8DVOP\in[1].htm HTML/TrojanDownloader.IFrame trojan cleaned by deleting - quarantined
C:\Documents and Settings\Keith\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@lplay.com\components\lptlf.dll a variant of Win32/Adware.Gamevance.BH application cleaned by deleting - quarantined
C:\Documents and Settings\Keith\Application Data\OpenCandy\registrybooster(6).exe a variant of Win32/RegistryBooster application cleaned by deleting - quarantined
C:\Documents and Settings\Keith\My Documents\Downloads\PageRageSetupAff(1).exe probably a variant of Win32/Adware.KKLWKLK application cleaned by deleting - quarantined
C:\Documents and Settings\Keith\My Documents\Downloads\PageRageSetupAff.exe probably a variant of Win32/Adware.KKLWKLK application cleaned by deleting - quarantined
C:\Documents and Settings\Kelly\Local Settings\Application Data\dealcabby\ie\dealcabby.dll Win32/Adware.DealCabby application cleaned by deleting - quarantined
C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll a variant of Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe probably a variant of Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\514d62a9-2c3f-4445-bf77-fec145f5db79.dat.vir a variant of Win32/Kryptik.MWP trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Program Files\LivingPlay\lpLAytl.dll.vir a variant of Win32/Adware.Gamevance.BE application cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Program Files\Search Toolbar\SearchToolbar.dll.vir Win32/Toolbar.Zugo application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1008\A0108569.exe Win32/Adware.1ClickDownload application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1009\A0108696.exe Win32/AutoRun.Spy.Banker.M worm cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1012\A0108834.exe a variant of Win32/InstallCore.W application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1020\A0114841.exe a variant of Win32/InstallCore.A application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1020\A0114843.exe a variant of Win32/InstallCore.F application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1021\A0114935.dll a variant of Win32/Toolbar.MyWebSearch.A application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1021\A0114940.dll probably a variant of Win32/Toolbar.MyWebSearch.F application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1021\A0114941.dll probably a variant of Win32/Toolbar.MyWebSearch.B application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1021\A0114944.dll probably a variant of Win32/Toolbar.MyWebSearch.P application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1021\A0114949.dll a variant of Win32/Toolbar.MyWebSearch application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1021\A0114954.dll a variant of Win32/Toolbar.MyWebSearch.P application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1026\A0116199.dll a variant of Win32/Adware.Gamevance.BE application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1026\A0116200.dll Win32/Toolbar.Zugo application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1028\A0119490.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1028\A0119491.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1028\A0119492.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1028\A0119493.dll a variant of Win32/Adware.Gamevance.BH application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1028\A0119494.exe a variant of Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{C04450D9-4133-4905-BF7B-1C74554B3F12}\RP1028\A0119495.dll Win32/Adware.DealCabby application cleaned by deleting - quarantined
 
Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[emptyjava]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post resulting log.

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure, Windows Updates are current.

4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC) weekly.

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. (Windows XP only) Run defrag at your convenience.

11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

13. Please, let me know, how your computer is doing.
 
All processes killed
========== OTL ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Administrator.DELL-E510
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Documents and Settings

User: Keith
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Kelly
->Temp folder emptied: 2793 bytes
->Temporary Internet Files folder emptied: 587299 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 74277867 bytes
->Flash cache emptied: 1556 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 8832 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 15121 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 72.00 mb


[EMPTYFLASH]

User: Administrator

User: Administrator.DELL-E510

User: All Users

User: Default User

User: Documents and Settings

User: Keith
->Flash cache emptied: 0 bytes

User: Kelly
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: Administrator

User: Administrator.DELL-E510

User: All Users

User: Default User

User: Documents and Settings

User: Keith
->Java cache emptied: 0 bytes

User: Kelly
->Java cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Java Files Cleaned = 0.00 mb

Unable to start System Restore Service. Error code 10

OTL by OldTimer - Version 3.2.53.1 log created on 07242012_180840

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
 
Thanks so much for all of your help and your patience. My husband has been having computer withdrawal because I wouldn't let him touch it while you've been helping me. I'll get a full report from him in the morning and let you know how it went. So far, I haven't had any trouble opening or running any programs. I haven't had anything freeze or crash on me. Thanks a bunch. I sent you a donation. It's not much, but I wanted you to know I appreciate everything. Take Care, Kelly
 
My husband has been having computer withdrawal because I wouldn't let him touch it while you've been helping me
Hahaha....

Way to go!!
Good luck and stay safe :)

...and thank you :)
 
Just wanted to let you know that the computer is running way faster than before! No freezing or crashing programs either. The pop up adds have stopped too. You've made my husband a very happy man! I'm pretty happy too. Thanks a bunch. Keep saving the world one computer at a time. :)
 
Back