I know that my kid's laptop is infected with some type of spyware/virus. I have bit defender on this laptop, but I noticed that it was disabled at startup. I don't know why. I have run ccleaner both in safe mode and normal. I have run ad-aware, spybot search and destroy and Bitdefender scans. They all come out clean. Please help. I am no expert, but I have been able to clean out spyware in the past. This one has me stumped. Here is the latest hijackthis log as well as sdfix log (this was done late last night). Thank you.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 10:10:07 AM, on 6/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\WLTRYS
VC.EXE
C:\WINDOWS\System32\bcmwlt
ry.exe
C:\WINDOWS\system32\LEXBCE
S.EXE
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\LEXPPS
.EXE
C:\Program Files\Dell\QuickSet\NICCON
FIGSVC.exe
C:\WINDOWS\Debug\svcmngr.e
xe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender1
0\vsserv.e
xe
C:\WINDOWS\system32\sguwhq
prme.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.
exe
C:\WINDOWS\system32\igfxsr
vc.exe
C:\WINDOWS\system32\igfxpe
rs.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\WINDOWS\system32\WLTRAY
.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quicks
et.exe
C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe
C:\Program Files\Java\jre1.5.0_07\bin
\jusched.e
xe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Softwin\BitDefender1
0\bdmcon.e
xe
C:\Program Files\Softwin\BitDefender1
0\bdagent.
exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\WINDOWS\system32\co.exe
C:\WINDOWS\system32\aqdzrm
.exe
C:\WINDOWS\system32\aociz.
exe
C:\Program Files\Google\GoogleToolbar
Notifier\1
.2.908.500
8\GoogleTo
olbarNotif
ier.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\Charles\Desktop\H
iJackThis_
v2.exe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://us.mcafee.com/apps/msk/en-us/redir.asp?affid=105-79&installtype=force&dtag=61w26b1&langid=1&systempopup=trueO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.5.0_09\bin
\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8
EA1C75885F
9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A
07C3DB8F77
7} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A
A305ED9D92
2} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.
exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpe
rs.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quicks
et.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
Service\is
uspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2
.bin\mwsoe
mon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin
\jusched.e
xe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MS
KDetct.exe
/uninstall
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender1
0\bdmcon.e
xe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender1
0\bdagent.
exe"
O4 - HKLM\..\Run: [command] C:\WINDOWS\SYSTEM32\comman
d.exe
O4 - HKLM\..\Run: [co] C:\WINDOWS\system32\co.exe
O4 - HKLM\..\Run: [aqdzrm] C:\WINDOWS\system32\aqdzrm
.exe
O4 - HKLM\..\Run: [aociz] C:\WINDOWS\system32\aociz.
exe
O4 - HKLM\..\Run: [ghhvusojsg] C:\WINDOWS\system32\ghhvus
ojsg.exe
O4 - HKLM\..\Run: [icxyez] C:\WINDOWS\system32\icxyez
.exe
O4 - HKLM\..\Run: [uvcamwx] C:\WINDOWS\system32\uvcamw
x.exe
O4 - HKLM\..\Run: [kozgulhsy] C:\WINDOWS\system32\kozgul
hsy.exe
O4 - HKLM\..\Run: [gacyinmuc] C:\WINDOWS\system32\gacyin
muc.exe
O4 - HKLM\..\Run: [uraj] C:\WINDOWS\system32\uraj.e
xe
O4 - HKLM\..\Run: [sezizbsoguz] C:\WINDOWS\system32\sezizb
soguz.exe
O4 - HKLM\..\Run: [ibxrsy] C:\WINDOWS\system32\ibxrsy
.exe
O4 - HKLM\..\Run: [c] C:\WINDOWS\system32\c.exe
O4 - HKLM\..\Run: [uuyriyoul] C:\WINDOWS\system32\uuyriy
oul.exe
O4 - HKLM\..\Run: [rmmsodocf] C:\WINDOWS\system32\rmmsod
ocf.exe
O4 - HKLM\..\Run: [jznzeqhwkvph] C:\WINDOWS\system32\jznzeq
hwkvph.exe
O4 - HKLM\..\Run: [rzvlf] C:\WINDOWS\system32\rzvlf.
exe
O4 - HKLM\..\Run: [tcxwk] C:\WINDOWS\system32\tcxwk.
exe
O4 - HKLM\..\Run: [unscwmp] C:\WINDOWS\system32\unscwm
p.exe
O4 - HKLM\..\Run: [qwohkcsvxwv] C:\WINDOWS\system32\qwohkc
svxwv.exe
O4 - HKLM\..\Run: [h] C:\WINDOWS\system32\h.exe
O4 - HKLM\..\Run: [sguwhqprme] C:\WINDOWS\system32\sguwhq
prme.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\1
.2.908.500
8\GoogleTo
olbarNotif
ier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_09\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_09\bin
\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B
4C75499B57
8} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~4\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\system32\Shdocv
w.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {3FE16C08-D6A7-4133-84FC-D
5BFB4F7D88
6} (WebGameLoader Class) -
http://www.miniclip.com/games/ricochet-lost-worlds/en/ReflexiveWebGameLoader.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} -
http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cabO22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-0
0A0C90312E
1} - C:\WINDOWS\system32\browse
ui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3
078302C203
0} - C:\WINDOWS\system32\browse
ui.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCE
S.EXE
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCON
FIGSVC.exe
O23 - Service: Print Spooler Service (osazoiuqosmuo) - Unknown owner - C:\WINDOWS\system32\sguwhq
prme.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Services Manager (SVC_Manager) - Unknown owner - C:\WINDOWS\Debug\svcmngr.e
xe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender1
0\vsserv.e
xe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYS
VC.EXE
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
--
End of file - 10423 bytes
--------- SDFix Log --------------------------
----------
-
SDFix: Version 1.89
Run by Administrator on Mon 07/02/2007 at 11:34 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
osazoiuqosmuo
ImagePath:
C:\WINDOWS\system32\glqtku
u.exe /service
osazoiuqosmuo - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\SYSTEM32\GLQTKU
U.EXE - Deleted
Removing Temp Files...
ADS Check:
Checking C:\WINDOWS
C:\WINDOWS
No streams found.
Checking C:\WINDOWS\system32
C:\WINDOWS\system32
No streams found.
Checking C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
No streams found.
Checking C:\WINDOWS\system32\ntoskr
nl.exe
C:\WINDOWS\system32\ntoskr
nl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system
\currentco
ntrolset\s
ervices\sh
aredaccess
\parameter
s\firewall
policy\sta
ndardprofi
le\authori
zedapplica
tions\list
]
"%windir%\\system32\\sessm
gr.exe"="%
windir%\\s
ystem32\\s
essmgr.exe
:*:enabled
:@xpsp2res
.dll,-2201
9"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.e
xe"="C:\\P
rogram Files\\Common Files\\AOL\\ACS\\AOLacsd.e
xe:*:Enabl
ed:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.e
xe"="C:\\P
rogram Files\\Common Files\\AOL\\ACS\\AOLDial.e
xe:*:Enabl
ed:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Progra
m Files\\America Online 9.0\\waol.exe:*:Enabled:Am
erica Online 9.0"
"C:\\Program Files\\iTunes\\iTunes.exe"
="C:\\Prog
ram Files\\iTunes\\iTunes.exe:
*:Enabled:
iTunes"
"C:\\WINDOWS\\system32\\LE
XPPS.EXE"=
"C:\\WINDO
WS\\system
32\\LEXPPS
.EXE:*:Ena
bled:LEXPP
S.EXE"
"C:\\Program Files\\AIM\\aim.exe"="C:\\
Program Files\\AIM\\aim.exe:*:Enab
led:AOL Instant Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
="%windir%
\\Network Diagnostic\\xpnetdiag.exe:
*:Enabled:
@xpsp3res.
dll,-20000
"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolloa
d.exe"="C:
\\Program Files\\Common Files\\AOL\\Loader\\aolloa
d.exe:*:En
abled:AOL Loader"
"C:\\Program Files\\AIM6\\aim6.exe"="C:
\\Program Files\\AIM6\\aim6.exe:*:En
abled:AIM"
"C:\\Program Files\\Infogrames\\Carnivo
res Ice Age\\IceAge.EXE"="C:\\Prog
ram Files\\Infogrames\\Carnivo
res Ice Age\\IceAge.EXE:*:Enabled:
IceAge"
"C:\\Program Files\\StarportGE\\GEClien
t.exe"="C:
\\Program Files\\StarportGE\\GEClien
t.exe:*:En
abled:GECl
ient"
[HKEY_LOCAL_MACHINE\system
\currentco
ntrolset\s
ervices\sh
aredaccess
\parameter
s\firewall
policy\dom
ainprofile
\authorize
dapplicati
ons\list]
"%windir%\\system32\\sessm
gr.exe"="%
windir%\\s
ystem32\\s
essmgr.exe
:*:enabled
:@xpsp2res
.dll,-2201
9"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.e
xe"="C:\\P
rogram Files\\Common Files\\AOL\\ACS\\AOLacsd.e
xe:*:Enabl
ed:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.e
xe"="C:\\P
rogram Files\\Common Files\\AOL\\ACS\\AOLDial.e
xe:*:Enabl
ed:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Progra
m Files\\America Online 9.0\\waol.exe:*:Enabled:Am
erica Online 9.0"
"C:\\Program Files\\AIM\\aim.exe"="C:\\
Program Files\\AIM\\aim.exe:*:Enab
led:AOL Instant Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
="%windir%
\\Network Diagnostic\\xpnetdiag.exe:
*:Enabled:
@xpsp3res.
dll,-20000
"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.z
ip
Files with Hidden Attributes:
C:\WINDOWS\Debug\svcmngr.e
xe
C:\WINDOWS\system32\5952CB
427E.sys
C:\WINDOWS\system32\KGyGaA
vL.sys
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate
\Channels\
ch5\lock.t
mp
C:\Documents and Settings\rob\Application Data\GTek\GTUpdate\AUpdate
\Channels\
ch_u1\lock
.tmp
C:\Documents and Settings\Robert\Applicatio
n Data\Gtek\GTUpdate\AUpdate
\Channels\
ch_u1\lock
.tmp
C:\Documents and Settings\Robert\Applicatio
n Data\Gtek\GTUpdate\AUpdate
\Channels\
ch_u2\lock
.tmp
Finished