Norton Corporate Edition All File Scan - removed all infections except one.
Adaware - twice
AVG - once removed everything
Panda Activescan - created report (see below)
Have windows SP2
Ran Hijack This - Created Report (See Below)
Here are the reports:
Logfile of HijackThis v1.99.1
Scan saved at 12:45:31 PM, on 10/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\WINNT\system32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Farmer21\Local Settings\Temporary Internet Files\Content.IE5\IVCNQX2P\HijackThis[1].exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {42DCD648-CE30-1242-FF24-08F8E4F787D5} - C:\WINNT\system32\pnmqkdf.dll
O2 - BHO: (no name) - {5CCE4F0A-3647-17BE-5149-0438ED5E83FA} - C:\WINNT\system32\zrvjgi.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [tvxabcd.dll] C:\WINNT\system32\rundll32.exe C:\WINNT\system32\tvxabcd.dll,wiysgne
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Poker - http://download2.gam...nts/y/pt3_x.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1153715061406
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...5/installer.exe
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:52:20 AM 10/20/2006
+ Scan result:
C:\Program Files\BraveSentry -> Adware.Bravesentry : Cleaned with backup (quarantined).
C:\Program Files\BraveSentry\BraveSentry.lic -> Adware.Bravesentry : Cleaned with backup (quarantined).
C:\Program Files\BraveSentry\Uninstall.exe -> Adware.Bravesentry : Cleaned with backup (quarantined).
C:\Downloads\MLBcomShuffleSetup-dm[1].exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temp\1.dlb -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINNT\system32\dlh9jkdq1.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temp\vx2.game -> Downloader.Small.cib : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temp\5.dlb -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\WINNT\system32\dlh9jkdq5.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\WINNT\system32\kernels1118.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temp\vxt2.game -> Downloader.Small.dwx : Cleaned with backup (quarantined).
C:\WINNT\system32\kernels8.exe -> Downloader.Tibs.if : Cleaned with backup (quarantined).
C:\lo731225535.exe -> Downloader.Tibs.if : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temp\ctaijydv.exe -> Hijacker.Small.cc : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temporary Internet Files\Content.IE5\Y01LF7ZR\runfile[1].exe -> Hijacker.Small.cc : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temp\vx1.game -> Proxy.Xorpix.ar : Cleaned with backup (quarantined).
C:\WINNT\system32\vxgame1.exe -> Proxy.Xorpix.ar : Cleaned with backup (quarantined).
[232] C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll -> Proxy.Xorpix.ar : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Farmer21\Cookies\farmer21@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Farmer21\Cookies\farmer21@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\Farmer21\Cookies\farmer21@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Farmer21\Cookies\farmer21@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Farmer21\Local Settings\Temp\maxdd1.game -> Trojan.Dialer.ay : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temp\temp.fr7684 -> Trojan.Dialer.ay : Cleaned with backup (quarantined).
C:\Documents and Settings\Farmer21\Local Settings\Temp\vx3.game -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINNT\9129837.exe -> Trojan.Small.bs : Cleaned with backup (quarantined).
C:\WINNT\system32\adir.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
::Report end
UNINSTAL LIST___________________________
Ad-Aware SE Personal
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.8
ArcSoft Multimedia Email
ArcSoft PhotoImpression 5
AVG Anti-Spyware 7.5
Battlefield 2
Creative WebCam Center
Creative WebCam Instant Driver (1.01.02.0729)
Creative WebCam Instant User's Guide (English)
Diego`s Wolf Pup Rescue (remove only)
EA SPORTS online 2004
Get Yahoo! Messenger
Google Toolbar for Internet Explorer
HijackThis 1.99.1
Intel® PRO Network Connections
LiveUpdate 1.80 (Symantec Corporation)
Microsoft Office 2000 SR-1 Professional
MSN Music Assistant
NBA LIVE 2004
NVIDIA Drivers
Panda ActiveScan
Paradise Poker
Shockwave
Skype 2.5
SoundMAX
Symantec AntiVirus Client
Tiger Woods PGA TOUR 2004
Windows Media Format Runtime
Windows Media Player 10
------------------------------------------
Activescan-
Incident Status Location
Adware:adware/adsmart Not disinfected c:\winnt\system32\dlh9jkdq2.exe
Adware:adware/bravesentry Not disinfected Windows Registry
Please help. Any ideas on where to start?
Joshermon