ClassicLady
New member
17
127.0.0.1 www.freepcsecure.com
127.0.0.1 popupnukerpro.com
127.0.0.1 www.popupnukerpro.com
127.0.0.1 windefender.com
127.0.0.1 www.windefender.com
127.0.0.1 dmqfirm.com
127.0.0.1 www.dmqfirm.com
127.0.0.1 ebwmanufacture.com
127.0.0.1 www.ebwmanufacture.com
127.0.0.1 ezycontract.com
127.0.0.1 www.ezycontract.com
127.0.0.1 ads1.revenue.net
127.0.0.1 ads.kw.revenue.net
127.0.0.1 safetydownload.com
127.0.0.1 bsa.safetydownload.com
127.0.0.1 www.safetydownload.com
127.0.0.1 diskretter.com
127.0.0.1 www.diskretter.com
127.0.0.1 secretz.diskretter.com
127.0.0.1 popadprovider.com
127.0.0.1 www.popadprovider.com
127.0.0.1 blackcodec.net
127.0.0.1 www.blackcodec.net
127.0.0.1 cleancodec.com
127.0.0.1 www.cleancodec.com
127.0.0.1 democodec.com
127.0.0.1 www.democodec.com
127.0.0.1 endcodec.com
127.0.0.1 www.endcodec.com
127.0.0.1 ictprivate.com
127.0.0.1 www.ictprivate.com
127.0.0.1 jetcodec.com
127.0.0.1 www.jetcodec.com
127.0.0.1 lightcodec.net
127.0.0.1 www.lightcodec.net
127.0.0.1 megcodec.com
127.0.0.1 www.megcodec.com
127.0.0.1 mmcodecs.com
127.0.0.1 www.mmcodecs.com
127.0.0.1 mooncodec.com
127.0.0.1 www.mooncodec.com
127.0.0.1 mpgcodec.net
127.0.0.1 www.mpgcodec.net
127.0.0.1 nicecodec.com
127.0.0.1 www.nicecodec.com
127.0.0.1 popcodec.net
127.0.0.1 www.popcodec.net
127.0.0.1 procodec.net
127.0.0.1 www.procodec.net
127.0.0.1 qazcodec.com
127.0.0.1 www.qazcodec.com
127.0.0.1 redcodec.net
127.0.0.1 www.redcodec.net
127.0.0.1 sigmacode.biz
127.0.0.1 www.sigmacode.biz
127.0.0.1 stormcodec.net
127.0.0.1 www.stormcodec.net
127.0.0.1 thisfreemovies.com
127.0.0.1 www.thisfreemovies.com
127.0.0.1 todaysfreeclips.com
127.0.0.1 www.todaysfreeclips.com
127.0.0.1 turbocodec.net
127.0.0.1 www.turbocodec.net
127.0.0.1 uincodec.com
127.0.0.1 www.uincodec.com
127.0.0.1 ultracodec.com
127.0.0.1 www.ultracodec.com
127.0.0.1 videowebsoft.com
127.0.0.1 www.videowebsoft.com
127.0.0.1 whitecodec.com
127.0.0.1 www.whitecodec.com
127.0.0.1 xerocodec.com
127.0.0.1 www.xerocodec.com
127.0.0.1 ydaproject.com
127.0.0.1 www.ydaproject.com
127.0.0.1 youlikehere.com
127.0.0.1 www.youlikehere.com
127.0.0.1 destruktor.to.pl
127.0.0.1 www.destruktor.to.pl
127.0.0.1 xhcodec.com
127.0.0.1 www.xhcodec.com
127.0.0.1 vivacodec.net
127.0.0.1 www.vivacodec.net
127.0.0.1 vaulimited.com
127.0.0.1 www.vaulimited.com
127.0.0.1 mojtechnology.com
127.0.0.1 www.mojtechnology.com
127.0.0.1 ocnservice.com
127.0.0.1 www.ocnservice.com
127.0.0.1 zsvcompany.com
127.0.0.1 www.zsvcompany.com
127.0.0.1 bcnproduction.com
127.0.0.1 www.bcnproduction.com
127.0.0.1 adioserrores.com
127.0.0.1 www.adioserrores.com
127.0.0.1 allertaminacce.com
127.0.0.1 www.allertaminacce.com
127.0.0.1 alltiettantivirus.com
127.0.0.1 www.alltiettantivirus.com
127.0.0.1 antivirusaskeladd.com
127.0.0.1 www.antivirusaskeladd.com
127.0.0.1 antiviruspcsuite.com
127.0.0.1 www.antiviruspcsuite.com
127.0.0.1 antivirusscherm.com
127.0.0.1 www.antivirusscherm.com
127.0.0.1 avsystemcare.com
127.0.0.1 www.avsystemcare.com
127.0.0.1 errclean.com
127.0.0.1 www.errclean.com
127.0.0.1 errorfri.com
127.0.0.1 www.errorfri.com
127.0.0.1 errorout.com
127.0.0.1 www.errorout.com
127.0.0.1 errorskydd.com
127.0.0.1 www.errorskydd.com
127.0.0.1 errorsoshi.com
127.0.0.1 www.errorsoshi.com
127.0.0.1 nowayvirus.com
127.0.0.1 www.nowayvirus.com
127.0.0.1 pcvirusless.com
127.0.0.1 www.pcvirusless.com
127.0.0.1 sysdepannage.com
127.0.0.1 www.sysdepannage.com
127.0.0.1 syslibero.com
127.0.0.1 www.syslibero.com
127.0.0.1 systemordnare.com
127.0.0.1 www.systemordnare.com
127.0.0.1 virusdifesa.com
127.0.0.1 www.virusdifesa.com
127.0.0.1 virusforsvar.com
127.0.0.1 www.virusforsvar.com
127.0.0.1 virusgarde.com
127.0.0.1 www.virusgarde.com
127.0.0.1 virusschlacht.com
127.0.0.1 www.virusschlacht.com
127.0.0.1 virusvakt.com
127.0.0.1 www.virusvakt.com
127.0.0.1 dailykeys.com
127.0.0.1 www.dailykeys.com
127.0.0.1 videosoftonline.com
127.0.0.1 www.videosoftonline.com
127.0.0.1 xerocodec.net
127.0.0.1 www.xerocodec.net
127.0.0.1 newoutserv.com
127.0.0.1 www.newoutserv.com
127.0.0.1 mzdsoftware.com
127.0.0.1 www.mzdsoftware.com
127.0.0.1 pkbsolution.com
127.0.0.1 www.pkbsolution.com
127.0.0.1 ndcperformance.com
127.0.0.1 www.ndcperformance.com
127.0.0.1 xvsenterprise.com
127.0.0.1 www.xvsenterprise.com
127.0.0.1 gneprogram.com
127.0.0.1 www.gneprogram.com
127.0.0.1 zerocodec.com
127.0.0.1 www.zerocodec.com
127.0.0.1 4mpg.com
127.0.0.1 www.4mpg.com
127.0.0.1 adult-mpg.net
127.0.0.1 www.adult-mpg.net
127.0.0.1 allsearch.us
127.0.0.1 www.allsearch.us
127.0.0.1 bestadults.com
127.0.0.1 www.bestadults.com
127.0.0.1 cnomy.com
127.0.0.1 www.cnomy.com
127.0.0.1 megashopes.com
127.0.0.1 www.megashopes.com
127.0.0.1 rape--sex.com
127.0.0.1 www.rape--sex.com
127.0.0.1 searchs.com
127.0.0.1 www.searchs.com
127.0.0.1 teensexfans.com
127.0.0.1 www.teensexfans.com
127.0.0.1 thesearchs.com
127.0.0.1 www.thesearchs.com
127.0.0.1 zangcodec.net
127.0.0.1 www.zangcodec.net
127.0.0.1 newbieadguide.com
127.0.0.1 www.newbieadguide.com
127.0.0.1 iedefender.com
127.0.0.1 www.iedefender.com
127.0.0.1 playcodec.net
127.0.0.1 www.playcodec.net
127.0.0.1 startguard.net
127.0.0.1 www.startguard.net
127.0.0.1 malware-scanner.com
127.0.0.1 www.malware-scanner.com
127.0.0.1 bsplaycodec.com
127.0.0.1 www.bsplaycodec.com
127.0.0.1 stvfirm.com
127.0.0.1 www.stvfirm.com
127.0.0.1 ictmanufacture.com
127.0.0.1 www.ictmanufacture.com
127.0.0.1 dltsolution.com
127.0.0.1 www.dltsolution.com
127.0.0.1 elseif.biz
127.0.0.1 www.elseif.biz
127.0.0.1 ultrahqcodec.com
127.0.0.1 www.ultrahqcodec.com
127.0.0.1 antispywaresuite.com
127.0.0.1 www.antispywaresuite.com
127.0.0.1 antiworm2008.com
127.0.0.1 www.antiworm2008.com
127.0.0.1 goldenantispy.com
127.0.0.1 www.goldenantispy.com
127.0.0.1 menacerescue.com
127.0.0.1 www.menacerescue.com
127.0.0.1 trojansfilter.com
127.0.0.1 www.trojansfilter.com
127.0.0.1 3xclipsonline.com
127.0.0.1 www.3xclipsonline.com
127.0.0.1 3xcurves.com
127.0.0.1 www.3xcurves.com
127.0.0.1 3xfestival.com
127.0.0.1 www.3xfestival.com
127.0.0.1 3x-festival.com
127.0.0.1 www.3x-festival.com
127.0.0.1 3x-galls.com
127.0.0.1 www.3x-galls.com
127.0.0.1 3xmiracle.com
127.0.0.1 www.3xmiracle.com
127.0.0.1 3xmoviesblog.com
127.0.0.1 www.3xmoviesblog.com
127.0.0.1 best3xclips.com
127.0.0.1 www.best3xclips.com
127.0.0.1 bvdtechinque.com
127.0.0.1 www.bvdtechinque.com
127.0.0.1 chilly3xvids.com
127.0.0.1 www.chilly3xvids.com
127.0.0.1 chillymovs.com
127.0.0.1 www.chillymovs.com
127.0.0.1 clipsfestival.com
127.0.0.1 www.clipsfestival.com
127.0.0.1 clipsreality.com
127.0.0.1 www.clipsreality.com
127.0.0.1 codechq.net
127.0.0.1 www.codechq.net
127.0.0.1 codecvip.com
127.0.0.1 www.codecvip.com
127.0.0.1 daily3xlinks.com
127.0.0.1 www.daily3xlinks.com
127.0.0.1 dailybestclips.com
127.0.0.1 www.dailybestclips.com
127.0.0.1 dailyhugemovs.com
127.0.0.1 www.dailyhugemovs.com
127.0.0.1 dailyxvids.com
127.0.0.1 www.dailyxvids.com
127.0.0.1 download3xpics.com
127.0.0.1 www.download3xpics.com
127.0.0.1 entirexxx.com
127.0.0.1 www.entirexxx.com
127.0.0.1 free3xclips.com
127.0.0.1 www.free3xclips.com
127.0.0.1 freerealityvidz.com
127.0.0.1 www.freerealityvidz.com
127.0.0.1 freexxxmpegz.com
127.0.0.1 www.freexxxmpegz.com
127.0.0.1 galleriesforporn.com
127.0.0.1 www.galleriesforporn.com
127.0.0.1 gallsforporn.com
127.0.0.1 www.gallsforporn.com
127.0.0.1 getxxxphotos.com
127.0.0.1 www.getxxxphotos.com
127.0.0.1 hotnchilly.com
127.0.0.1 www.hotnchilly.com
127.0.0.1 picturesheap.com
127.0.0.1 www.picturesheap.com
127.0.0.1 pornxxxvideoz.com
127.0.0.1 www.pornxxxvideoz.com
127.0.0.1 realmovieszone.com
127.0.0.1 www.realmovieszone.com
127.0.0.1 streampornvideos.com
127.0.0.1 www.streampornvideos.com
127.0.0.1 temptationclips.com
127.0.0.1 www.temptationclips.com
127.0.0.1 themymoviessite.com
127.0.0.1 www.themymoviessite.com
127.0.0.1 todays3xmovies.com
127.0.0.1 www.todays3xmovies.com
127.0.0.1 topmovzonline.com
127.0.0.1 www.topmovzonline.com
127.0.0.1 topsoftwarefeed.com
127.0.0.1 www.topsoftwarefeed.com
127.0.0.1 topxxxvidz.com
127.0.0.1 www.topxxxvidz.com
127.0.0.1 vidsfest.com
127.0.0.1 www.vidsfest.com
127.0.0.1 vplprocedure.com
127.0.0.1 www.vplprocedure.com
127.0.0.1 x-pornmovz.com
127.0.0.1 www.x-pornmovz.com
127.0.0.1 x-prnmoviez.com
127.0.0.1 www.x-prnmoviez.com
127.0.0.1 yourchillyvids.com
127.0.0.1 www.yourchillyvids.com
127.0.0.1 piramisu.biz
127.0.0.1 www.piramisu.biz
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\jokvip.exe Deleted
C:\WINDOWS\nopzet.dll Deleted
Deleting [HKEY_CLASSES_ROOT\CLSID\{6F43449B-87F7-46CC-B048-8096DA2692D2}]
Deleting [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6F43449B-87F7-46CC-B048-8096DA2692D2}]
C:\DOCUME~1\PAULHU~1\Desktop\Spyware?Malware Protection.url Deleted
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{EFFED6C1-2D6F-4BFA-B20C-D33999BC70C2}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{EFFED6C1-2D6F-4BFA-B20C-D33999BC70C2}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{EFFED6C1-2D6F-4BFA-B20C-D33999BC70C2}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
AVG Anti-Spyware Log:
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 12:22:14 AM 12/15/2007
+ Scan result:
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup (quarantined).
::Report end
A new HijackThis log
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:54:25 AM, on 12/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\Program Files\McAfee\MSC\mcshell.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\downloads\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/learnmore/learnmore.asp?close=true&lcode=en-us
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O3 - Toolbar: The retnsrp - {9EF873D0-0259-4D2A-AA60-F61FA5B28FE8} - C:\WINDOWS\retnsrp.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
127.0.0.1 www.freepcsecure.com
127.0.0.1 popupnukerpro.com
127.0.0.1 www.popupnukerpro.com
127.0.0.1 windefender.com
127.0.0.1 www.windefender.com
127.0.0.1 dmqfirm.com
127.0.0.1 www.dmqfirm.com
127.0.0.1 ebwmanufacture.com
127.0.0.1 www.ebwmanufacture.com
127.0.0.1 ezycontract.com
127.0.0.1 www.ezycontract.com
127.0.0.1 ads1.revenue.net
127.0.0.1 ads.kw.revenue.net
127.0.0.1 safetydownload.com
127.0.0.1 bsa.safetydownload.com
127.0.0.1 www.safetydownload.com
127.0.0.1 diskretter.com
127.0.0.1 www.diskretter.com
127.0.0.1 secretz.diskretter.com
127.0.0.1 popadprovider.com
127.0.0.1 www.popadprovider.com
127.0.0.1 blackcodec.net
127.0.0.1 www.blackcodec.net
127.0.0.1 cleancodec.com
127.0.0.1 www.cleancodec.com
127.0.0.1 democodec.com
127.0.0.1 www.democodec.com
127.0.0.1 endcodec.com
127.0.0.1 www.endcodec.com
127.0.0.1 ictprivate.com
127.0.0.1 www.ictprivate.com
127.0.0.1 jetcodec.com
127.0.0.1 www.jetcodec.com
127.0.0.1 lightcodec.net
127.0.0.1 www.lightcodec.net
127.0.0.1 megcodec.com
127.0.0.1 www.megcodec.com
127.0.0.1 mmcodecs.com
127.0.0.1 www.mmcodecs.com
127.0.0.1 mooncodec.com
127.0.0.1 www.mooncodec.com
127.0.0.1 mpgcodec.net
127.0.0.1 www.mpgcodec.net
127.0.0.1 nicecodec.com
127.0.0.1 www.nicecodec.com
127.0.0.1 popcodec.net
127.0.0.1 www.popcodec.net
127.0.0.1 procodec.net
127.0.0.1 www.procodec.net
127.0.0.1 qazcodec.com
127.0.0.1 www.qazcodec.com
127.0.0.1 redcodec.net
127.0.0.1 www.redcodec.net
127.0.0.1 sigmacode.biz
127.0.0.1 www.sigmacode.biz
127.0.0.1 stormcodec.net
127.0.0.1 www.stormcodec.net
127.0.0.1 thisfreemovies.com
127.0.0.1 www.thisfreemovies.com
127.0.0.1 todaysfreeclips.com
127.0.0.1 www.todaysfreeclips.com
127.0.0.1 turbocodec.net
127.0.0.1 www.turbocodec.net
127.0.0.1 uincodec.com
127.0.0.1 www.uincodec.com
127.0.0.1 ultracodec.com
127.0.0.1 www.ultracodec.com
127.0.0.1 videowebsoft.com
127.0.0.1 www.videowebsoft.com
127.0.0.1 whitecodec.com
127.0.0.1 www.whitecodec.com
127.0.0.1 xerocodec.com
127.0.0.1 www.xerocodec.com
127.0.0.1 ydaproject.com
127.0.0.1 www.ydaproject.com
127.0.0.1 youlikehere.com
127.0.0.1 www.youlikehere.com
127.0.0.1 destruktor.to.pl
127.0.0.1 www.destruktor.to.pl
127.0.0.1 xhcodec.com
127.0.0.1 www.xhcodec.com
127.0.0.1 vivacodec.net
127.0.0.1 www.vivacodec.net
127.0.0.1 vaulimited.com
127.0.0.1 www.vaulimited.com
127.0.0.1 mojtechnology.com
127.0.0.1 www.mojtechnology.com
127.0.0.1 ocnservice.com
127.0.0.1 www.ocnservice.com
127.0.0.1 zsvcompany.com
127.0.0.1 www.zsvcompany.com
127.0.0.1 bcnproduction.com
127.0.0.1 www.bcnproduction.com
127.0.0.1 adioserrores.com
127.0.0.1 www.adioserrores.com
127.0.0.1 allertaminacce.com
127.0.0.1 www.allertaminacce.com
127.0.0.1 alltiettantivirus.com
127.0.0.1 www.alltiettantivirus.com
127.0.0.1 antivirusaskeladd.com
127.0.0.1 www.antivirusaskeladd.com
127.0.0.1 antiviruspcsuite.com
127.0.0.1 www.antiviruspcsuite.com
127.0.0.1 antivirusscherm.com
127.0.0.1 www.antivirusscherm.com
127.0.0.1 avsystemcare.com
127.0.0.1 www.avsystemcare.com
127.0.0.1 errclean.com
127.0.0.1 www.errclean.com
127.0.0.1 errorfri.com
127.0.0.1 www.errorfri.com
127.0.0.1 errorout.com
127.0.0.1 www.errorout.com
127.0.0.1 errorskydd.com
127.0.0.1 www.errorskydd.com
127.0.0.1 errorsoshi.com
127.0.0.1 www.errorsoshi.com
127.0.0.1 nowayvirus.com
127.0.0.1 www.nowayvirus.com
127.0.0.1 pcvirusless.com
127.0.0.1 www.pcvirusless.com
127.0.0.1 sysdepannage.com
127.0.0.1 www.sysdepannage.com
127.0.0.1 syslibero.com
127.0.0.1 www.syslibero.com
127.0.0.1 systemordnare.com
127.0.0.1 www.systemordnare.com
127.0.0.1 virusdifesa.com
127.0.0.1 www.virusdifesa.com
127.0.0.1 virusforsvar.com
127.0.0.1 www.virusforsvar.com
127.0.0.1 virusgarde.com
127.0.0.1 www.virusgarde.com
127.0.0.1 virusschlacht.com
127.0.0.1 www.virusschlacht.com
127.0.0.1 virusvakt.com
127.0.0.1 www.virusvakt.com
127.0.0.1 dailykeys.com
127.0.0.1 www.dailykeys.com
127.0.0.1 videosoftonline.com
127.0.0.1 www.videosoftonline.com
127.0.0.1 xerocodec.net
127.0.0.1 www.xerocodec.net
127.0.0.1 newoutserv.com
127.0.0.1 www.newoutserv.com
127.0.0.1 mzdsoftware.com
127.0.0.1 www.mzdsoftware.com
127.0.0.1 pkbsolution.com
127.0.0.1 www.pkbsolution.com
127.0.0.1 ndcperformance.com
127.0.0.1 www.ndcperformance.com
127.0.0.1 xvsenterprise.com
127.0.0.1 www.xvsenterprise.com
127.0.0.1 gneprogram.com
127.0.0.1 www.gneprogram.com
127.0.0.1 zerocodec.com
127.0.0.1 www.zerocodec.com
127.0.0.1 4mpg.com
127.0.0.1 www.4mpg.com
127.0.0.1 adult-mpg.net
127.0.0.1 www.adult-mpg.net
127.0.0.1 allsearch.us
127.0.0.1 www.allsearch.us
127.0.0.1 bestadults.com
127.0.0.1 www.bestadults.com
127.0.0.1 cnomy.com
127.0.0.1 www.cnomy.com
127.0.0.1 megashopes.com
127.0.0.1 www.megashopes.com
127.0.0.1 rape--sex.com
127.0.0.1 www.rape--sex.com
127.0.0.1 searchs.com
127.0.0.1 www.searchs.com
127.0.0.1 teensexfans.com
127.0.0.1 www.teensexfans.com
127.0.0.1 thesearchs.com
127.0.0.1 www.thesearchs.com
127.0.0.1 zangcodec.net
127.0.0.1 www.zangcodec.net
127.0.0.1 newbieadguide.com
127.0.0.1 www.newbieadguide.com
127.0.0.1 iedefender.com
127.0.0.1 www.iedefender.com
127.0.0.1 playcodec.net
127.0.0.1 www.playcodec.net
127.0.0.1 startguard.net
127.0.0.1 www.startguard.net
127.0.0.1 malware-scanner.com
127.0.0.1 www.malware-scanner.com
127.0.0.1 bsplaycodec.com
127.0.0.1 www.bsplaycodec.com
127.0.0.1 stvfirm.com
127.0.0.1 www.stvfirm.com
127.0.0.1 ictmanufacture.com
127.0.0.1 www.ictmanufacture.com
127.0.0.1 dltsolution.com
127.0.0.1 www.dltsolution.com
127.0.0.1 elseif.biz
127.0.0.1 www.elseif.biz
127.0.0.1 ultrahqcodec.com
127.0.0.1 www.ultrahqcodec.com
127.0.0.1 antispywaresuite.com
127.0.0.1 www.antispywaresuite.com
127.0.0.1 antiworm2008.com
127.0.0.1 www.antiworm2008.com
127.0.0.1 goldenantispy.com
127.0.0.1 www.goldenantispy.com
127.0.0.1 menacerescue.com
127.0.0.1 www.menacerescue.com
127.0.0.1 trojansfilter.com
127.0.0.1 www.trojansfilter.com
127.0.0.1 3xclipsonline.com
127.0.0.1 www.3xclipsonline.com
127.0.0.1 3xcurves.com
127.0.0.1 www.3xcurves.com
127.0.0.1 3xfestival.com
127.0.0.1 www.3xfestival.com
127.0.0.1 3x-festival.com
127.0.0.1 www.3x-festival.com
127.0.0.1 3x-galls.com
127.0.0.1 www.3x-galls.com
127.0.0.1 3xmiracle.com
127.0.0.1 www.3xmiracle.com
127.0.0.1 3xmoviesblog.com
127.0.0.1 www.3xmoviesblog.com
127.0.0.1 best3xclips.com
127.0.0.1 www.best3xclips.com
127.0.0.1 bvdtechinque.com
127.0.0.1 www.bvdtechinque.com
127.0.0.1 chilly3xvids.com
127.0.0.1 www.chilly3xvids.com
127.0.0.1 chillymovs.com
127.0.0.1 www.chillymovs.com
127.0.0.1 clipsfestival.com
127.0.0.1 www.clipsfestival.com
127.0.0.1 clipsreality.com
127.0.0.1 www.clipsreality.com
127.0.0.1 codechq.net
127.0.0.1 www.codechq.net
127.0.0.1 codecvip.com
127.0.0.1 www.codecvip.com
127.0.0.1 daily3xlinks.com
127.0.0.1 www.daily3xlinks.com
127.0.0.1 dailybestclips.com
127.0.0.1 www.dailybestclips.com
127.0.0.1 dailyhugemovs.com
127.0.0.1 www.dailyhugemovs.com
127.0.0.1 dailyxvids.com
127.0.0.1 www.dailyxvids.com
127.0.0.1 download3xpics.com
127.0.0.1 www.download3xpics.com
127.0.0.1 entirexxx.com
127.0.0.1 www.entirexxx.com
127.0.0.1 free3xclips.com
127.0.0.1 www.free3xclips.com
127.0.0.1 freerealityvidz.com
127.0.0.1 www.freerealityvidz.com
127.0.0.1 freexxxmpegz.com
127.0.0.1 www.freexxxmpegz.com
127.0.0.1 galleriesforporn.com
127.0.0.1 www.galleriesforporn.com
127.0.0.1 gallsforporn.com
127.0.0.1 www.gallsforporn.com
127.0.0.1 getxxxphotos.com
127.0.0.1 www.getxxxphotos.com
127.0.0.1 hotnchilly.com
127.0.0.1 www.hotnchilly.com
127.0.0.1 picturesheap.com
127.0.0.1 www.picturesheap.com
127.0.0.1 pornxxxvideoz.com
127.0.0.1 www.pornxxxvideoz.com
127.0.0.1 realmovieszone.com
127.0.0.1 www.realmovieszone.com
127.0.0.1 streampornvideos.com
127.0.0.1 www.streampornvideos.com
127.0.0.1 temptationclips.com
127.0.0.1 www.temptationclips.com
127.0.0.1 themymoviessite.com
127.0.0.1 www.themymoviessite.com
127.0.0.1 todays3xmovies.com
127.0.0.1 www.todays3xmovies.com
127.0.0.1 topmovzonline.com
127.0.0.1 www.topmovzonline.com
127.0.0.1 topsoftwarefeed.com
127.0.0.1 www.topsoftwarefeed.com
127.0.0.1 topxxxvidz.com
127.0.0.1 www.topxxxvidz.com
127.0.0.1 vidsfest.com
127.0.0.1 www.vidsfest.com
127.0.0.1 vplprocedure.com
127.0.0.1 www.vplprocedure.com
127.0.0.1 x-pornmovz.com
127.0.0.1 www.x-pornmovz.com
127.0.0.1 x-prnmoviez.com
127.0.0.1 www.x-prnmoviez.com
127.0.0.1 yourchillyvids.com
127.0.0.1 www.yourchillyvids.com
127.0.0.1 piramisu.biz
127.0.0.1 www.piramisu.biz
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\jokvip.exe Deleted
C:\WINDOWS\nopzet.dll Deleted
Deleting [HKEY_CLASSES_ROOT\CLSID\{6F43449B-87F7-46CC-B048-8096DA2692D2}]
Deleting [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6F43449B-87F7-46CC-B048-8096DA2692D2}]
C:\DOCUME~1\PAULHU~1\Desktop\Spyware?Malware Protection.url Deleted
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{EFFED6C1-2D6F-4BFA-B20C-D33999BC70C2}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{EFFED6C1-2D6F-4BFA-B20C-D33999BC70C2}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{EFFED6C1-2D6F-4BFA-B20C-D33999BC70C2}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
AVG Anti-Spyware Log:
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 12:22:14 AM 12/15/2007
+ Scan result:
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup (quarantined).
::Report end
A new HijackThis log
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:54:25 AM, on 12/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\Program Files\McAfee\MSC\mcshell.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\downloads\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/learnmore/learnmore.asp?close=true&lcode=en-us
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O3 - Toolbar: The retnsrp - {9EF873D0-0259-4D2A-AA60-F61FA5B28FE8} - C:\WINDOWS\retnsrp.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe