You have a TDL3 infection as well - the files will be stored in the RKQuarantine folder as well as C:_OTS\Moved files folder
Run roguekiller again selecting option 2
THEN
Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.
[Unregister Dlls]
[Processes - Safe List]
YY -> 14147364.exe -> C:\Documents and Settings\All Users\Application Data\14147364.exe
YY -> nhwlatouajw.exe -> C:\Documents and Settings\All Users\Application Data\NHWLAtOuAjw.exe
[Registry - Safe List]
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > ->
YN -> HKEY_USERS\S-1-5-18\: SearchURL\\"provider" -> gogl
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-2934302069-2821556552-4076869261-1009\] > ->
YN -> HKEY_USERS\S-1-5-21-2934302069-2821556552-4076869261-1009\: SearchURL\\"provider" -> gogl
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Dawn\Application Data\Mozilla\FireFox\Profiles\e9ijy1u0.default\prefs.js
YN -> extensions.enabledItems -> {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {299AF565-D2CB-4ED8-921F-59430FF2ED36} [HKLM] -> [Reg Error: Value error.]
YN -> {460CCA35-CD82-4696-BED8-DFB6A2552717} [HKLM] -> [Reg Error: Value error.]
YN -> {90C0B680-E001-460E-BDFA-2C2ECA7C77DC} [HKLM] -> [Reg Error: Value error.]
YN -> {A03B8D6C-89AD-49E8-B004-542A3CC5F7D2} [HKLM] -> [Reg Error: Value error.]
YN -> {F1858500-31E9-3664-BFAA-106405DC18C1} [HKLM] -> [Reg Error: Value error.]
YN -> {F84949D8-8247-4E06-A8E8-ADFD51F09346} [HKLM] -> [Reg Error: Value error.]
YN -> {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{DE9C389F-3316-41A7-809B-AA305ED9D922}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{DE9C389F-3316-41A7-809B-AA305ED9D922}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-2934302069-2821556552-4076869261-1009\] > -> HKEY_USERS\S-1-5-21-2934302069-2821556552-4076869261-1009\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{DE9C389F-3316-41A7-809B-AA305ED9D922}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Run [HKEY_USERS\S-1-5-21-2934302069-2821556552-4076869261-1009\] > -> HKEY_USERS\S-1-5-21-2934302069-2821556552-4076869261-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "NHWLAtOuAjw" -> C:\Documents and Settings\All Users\Application Data\NHWLAtOuAjw.exe [C:\Documents and Settings\All Users\Application Data\NHWLAtOuAjw.exe]
[Files/Folders - Created Within 30 Days]
NY -> Windows XP Recovery -> C:\Documents and Settings\Dawn\Start Menu\Programs\Windows XP Recovery
NY -> 14147364.exe -> C:\Documents and Settings\All Users\Application Data\14147364.exe
NY -> NHWLAtOuAjw.exe -> C:\Documents and Settings\All Users\Application Data\NHWLAtOuAjw.exe
[Files/Folders - Modified Within 30 Days]
NY -> ~14147364 -> C:\Documents and Settings\All Users\Application Data\~14147364
NY -> Windows XP Recovery.lnk -> C:\Documents and Settings\Dawn\Desktop\Windows XP Recovery.lnk
NY -> 14147364.exe -> C:\Documents and Settings\All Users\Application Data\14147364.exe
NY -> NHWLAtOuAjw.exe -> C:\Documents and Settings\All Users\Application Data\NHWLAtOuAjw.exe
[Files - No Company Name]
NY -> ~14147364 -> C:\Documents and Settings\All Users\Application Data\~14147364
NY -> ~14147364r -> C:\Documents and Settings\All Users\Application Data\~14147364r
NY -> Windows XP Recovery.lnk -> C:\Documents and Settings\Dawn\Desktop\Windows XP Recovery.lnk
NY -> 14147364 -> C:\Documents and Settings\All Users\Application Data\14147364
NY -> nefrltj.exe -> C:\WINDOWS\System32\nefrltj.exe
[Custom Items]
:Files
ipconfig /flushdns /c
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here
I will review the information when it comes back in.
Depending on what the fix contains, this process may take some time and your desktop icons might disappear or other uncommon behavior may occur.
This is no sign of malfunction, do not panic!
FINALLY
Please read carefully and follow these steps.
[*]Download TDSSKiller and save it to your Desktop.
[*]Extract its contents to your desktop.
[*]Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillermain.png
[*]If an infected file is detected, the default action will be Cure, click on Continue.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerMal-1.png
[*]If a suspicious file is detected, the default action will be Skip, click on Continue.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerSuspicious.png
[*]It may ask you to reboot the computer to complete the process. Click on Reboot Now.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerCompleted.png
[*]If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
[*]If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of “TDSSKiller.[Version][Date][Time]_log.txt”. Please copy and paste the contents of that file here.