Hi,
Done as instructed.
I can't believe what that has found!!!... Looks like I have been hijacked by some porn site!!
This would explain the desktop picture that appeared last week!...replacing my normal one with a couple lesbians!
Thanks for your time on this, we are obviously getting somewhere close to nailing this virus..
Regards,
Steve
Here is the Kapersky log:
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, November 27, 2005 20:40:17
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 27/11/2005
Kaspersky Anti-Virus database records: 152049
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 30541
Number of viruses found: 2
Number of infected objects: 98
Number of suspicious objects: 0
Duration of the scan process: 1716 sec
Infected Object Name - Virus Name
C:\Documents and Settings\Steve\Complete\Babe Gets Boobs Tortured By Bdsm Mistress.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Babe Gets Boobs Tortured By Bdsm Mistress.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Boobs Tortured Hardcore.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Boobs Tortured Hardcore.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets ###### Clamps & Tied Up.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets ###### Clamps & Tied Up.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets ###### Tortured At Home.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets ###### Tortured At Home.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Spanked On rear At Home.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Spanked On rear At Home.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Spanked On Tight rear.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Spanked On Tight rear.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Tied Up & Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Tied Up & Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Wax Tortured Hardcore.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Gets Wax Tortured Hardcore.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Shows Tiny Tits & Tight rear.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Shows Tiny Tits & Tight rear.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Tied Up Gets Tortured Hardcore.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Tied Up Gets Tortured Hardcore.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Tied Up Shows Shaved Cunt.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Babe Tied Up Shows Shaved Cunt.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Movies.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Movies.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Slave Blows Her Master.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Bdsm Slave Blows Her Master.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets Boobs Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets Boobs Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets ###### Clamps.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets ###### Clamps.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets ###### Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets ###### Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets Tied Up At Home.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets Tied Up At Home.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets Toes Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Busty Bdsm Babe Gets Toes Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets Boobs Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets Boobs Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets Nipples Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets Nipples Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets ###### Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets ###### Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets Spanked On Tight rear.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets Spanked On Tight rear.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets Wheel Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Gets Wheel Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Nude At Home Shows Tits.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Bdsm Babe Nude At Home Shows Tits.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Blond Bdsm Babe Gets Tits Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Cute Blond Bdsm Babe Gets Tits Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Group Of Bdsm Lovers With A Hard Outdoor Bondage.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Group Of Bdsm Lovers With A Hard Outdoor Bondage.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Hard Lesbian Bdsm.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Hard Lesbian Bdsm.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Babe Gets Nipples Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Babe Gets Nipples Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Babe Gets ###### Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Babe Gets ###### Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Babe Gets Tortured At Home.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Babe Gets Tortured At Home.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Babe Nude Gets Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Babe Nude Gets Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Teen Gets Cunt Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Teen Gets Cunt Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Teen Gets Nipples Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Teen Gets Nipples Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Teen Gets ###### Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Innocent Bdsm Teen Gets ###### Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Intense Bdsm With Cute Babe.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Intense Bdsm With Cute Babe.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Kimberly Restrained For Fun.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Kimberly Restrained For Fun.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Latina Babe Bdsm #######.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Latina Babe Bdsm #######.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Lesbian Lesson In Bdsm.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Lesbian Lesson In Bdsm.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Ouch That Really Stings Me.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Ouch That Really Stings Me.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Queen Of Bdsm.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Queen Of Bdsm.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Rough Bdsm Style #######.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Rough Bdsm Style #######.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Something Solid Goes Deep Into Vagina Of Bdsm Lover.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Something Solid Goes Deep Into Vagina Of Bdsm Lover.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Taylor Must Obey Her Master.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Taylor Must Obey Her Master.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Gets Boobs Tortured.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Gets Boobs Tortured.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Gets ###### Clamps.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Gets ###### Clamps.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Gets Tortured At Home.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Gets Tortured At Home.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Gets Tortured Hardcore.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Gets Tortured Hardcore.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Shows Bald ######.zip/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\Documents and Settings\Steve\Complete\Tied Up Bdsm Babe Shows Bald ######.zip Infected: Trojan-Dropper.Win32.WinAD.h
C:\System Volume Information\_restore{E6925715-6979-4395-B6B6-4FDBEB15B56D}\RP3\A0002297.exe Infected: Trojan-Dropper.Win32.WinAD.h
C:\WINDOWS\system32\TFTP3800 Infected: Backdoor.Win32.Rbot.ul
Scan process completed.
And now the HijackThis log...
Logfile of HijackThis v1.99.1
Scan saved at 20:44:12, on 27/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Trust\305KS\Mouse\mouse32a.exe
C:\Program Files\Trust\305KS\Keyboard\KbdAp32A.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Steve\My Documents\Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Freeserve - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\FREESE~1\FSBar\FSBar.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Trust\305KS\Keyboard\MMKEYBD.EXE
O4 - HKLM\..\Run: [FLMBROWSEMOUSE] C:\Program Files\Trust\305KS\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: Search with Freeserve - res://C:\PROGRA~1\FREESE~1\FSBar\FSBar.dll/VSearch.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1132776756515
O17 - HKLM\System\CCS\Services\Tcpip\..\{FD11D8CA-6523-4CE4-BA78-BF8F360C3A18}: NameServer = 80.225.248.178 80.225.248.186
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)