Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

In desperate need of help!


  • Please log in to reply
8 replies to this topic

#1 mimi_3

mimi_3

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:48 PM

Posted 09 July 2010 - 05:51 PM

I am in desperate need of help. I tried to do this alone by downloading hijack this but realized I am way in over my head. I have avg but it doesn't do anything. I'm currently using windows XP.

Names: Trojan horse generic18.vsd, adware generic4.ains, trojan dropper, trojan backdoor... (These are the names that keep popping up on he avg search).

Symptoms: On start up I get a message about malwaredoctor and it wants me to click on it. Anytime I use msn because its somehow connected with explorer I get tons of adds. My computer is slow.

Attempts: I tried to delete it through add/Remove. It doesn't let me. I tried to heal it using Avg.

Extras: I have a another computer that shares my internet.

What can I do what can I download to relieve my computer of this mess?

Edited by mimi_3, 09 July 2010 - 06:41 PM.
Moved from Virus, Trojan, Spyware, and Malware Removal Logs ~BP


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:48 PM

Posted 09 July 2010 - 08:16 PM

Hello and welcome. first get rid iof HJT ,one it's dangerous to use unsupervised and two, we do even really use it anymore.

Now you have found a backdoor ... This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.


Next run MBAM (MalwareBytes):

Please download Malwarebytes Anti-Malware (v1.46) and save it to your desktop.
Before you save it rename it to say zztoy.exe


alternate download link 1
alternate download link 2
MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

Follow with ATF and SAS: If you cannot access Safe Mode,run in normal ,but let me know.

Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

From your regular user account..
Download Attribune's ATF Cleaner and then SUPERAntiSpyware , Free Home Version. Save both to desktop ..
DO NOT run yet.
Open SUPER from icon and install and Update it
Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining
.
Click the "Close" button to leave the control center screen and exit the program. DO NOT run yet.

Now reboot into Safe Mode: How to enter safe mode(XP)
Using the F8 Method
Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode
.

Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.

NOW Scan with SUPER
Open from the desktop icon or the program Files list
On the left, make sure you check C:\Fixed Drive.
Perform a Complete scan. After scan,Verify they are all checked.
Click OK on the summary screen to quarantine all found items.
If asked if you want to reboot, click "Yes" and reboot normally.

To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log.
A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
Click Close to exit the program.


Please ask any needed questions,post logs and Let us know how the PC is running now.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 mimi_3

mimi_3
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:48 PM

Posted 10 July 2010 - 10:32 PM

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4301

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

7/10/2010 11:12:25 PM
mbam-log-2010-07-10 (23-12-25).txt

Scan type: Quick scan
Objects scanned: 151728
Time elapsed: 30 minute(s), 35 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 35
Registry Values Infected: 7
Registry Data Items Infected: 4
Folders Infected: 7
Files Infected: 20

Memory Processes Infected:
C:\Documents and Settings\JO\Local Settings\Temp\Ash.exe (Trojan.FraudPack) -> Unloaded process successfully.

Memory Modules Infected:
C:\WINDOWS\system32\snlb.dbo (Backdoor.Bot) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\cscrptxt.cscrptxt (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9ff32ecb-3194-4b44-943c-0018bd1335dc} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff32ecb-3194-4b44-943c-0018bd1335dc} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9ff32ecb-3194-4b44-943c-0018bd1335dc} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e0ec6fba-f009-3535-95d6-b6390db27da1} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\cscrptxt.cscrptxt.1.0 (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ca0906de-afac-46f1-9c48-0929d33da165} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{ca0906de-afac-46f1-9c48-0929d33da165} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ca0906de-afac-46f1-9c48-0929d33da165} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ca0906de-afac-46f1-9c48-0929d33da165} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallWTF1012$ (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adgj.aghlp (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adgj.aghlp.1 (Adware.EZLife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adshothlpr.adshothlpr (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adshothlpr.adshothlpr.1.0 (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weather Services (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jdk5swfmzy (Trojan.FraudPack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mchk (Adware.Adshot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sdebegopepu (Trojan.Hiloti) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\070700setup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\skb (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls\wxfw.dll (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: c:\windows\system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe rundll32.exe snlb.dbo ytuoww) Good: (Explorer.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> Delete on reboot.
C:\Program Files\$NtUninstallWTF1012$ (Adware.EZLife) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Application Data\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Application Data\Sky-Banners\skb (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Application Data\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Application Data\Street-Ads\sta (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\JO\Local Settings\Temp\Ash.exe (Trojan.FraudPack) -> Delete on reboot.
C:\WINDOWS\system32\snlb.dbo (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\hzawv.exe (Adware.Adshot) -> Quarantined and deleted successfully.
C:\WINDOWS\ewowogijanilerih.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uzawv.dll (Adware.EZlife) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qzawv.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\R1884.exe (Adware.EZLife) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Local Settings\Temp\C6.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Local Settings\Temp\drebjsrc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Local Settings\Temp\erms.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Local Settings\Temp\waroemsxcn.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\15.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Delete on reboot.
C:\Program Files\$NtUninstallWTF1012$\elUninstall.exe (Adware.EZLife) -> Quarantined and deleted successfully.
C:\WINDOWS\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\JO\Application Data\520EB79ED3A26A040AE4416E1AF22D46\070700Setup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sdra64.exe (Spyware.Zbot) -> Delete on reboot.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

Thank you so much!!! So far so good. The pop up at the start disappeared. I did not get any error msgs. My other question before I download the two other cleaners is do I need to do anything after it reboots on its own. Once it restarts without issues does it mean I can go ahead with the next steps? I looked at the log and basically what I'm asking is that if it says delete on reboot that its actually deleted or do i have to go back on Malwarebytes and do another step?

Also Attribune's ATF Cleaner and then SUPERAntiSpyware, where do I get this? (sorry for the noob questions). Again thank you so much I noticed a big change already.

I answered my own question lol I just need to click the link right lol. ATF cleaner. exe by atribune.org and the other on its website.

just waiting for the A okay to continue on to the next step!

Edited by mimi_3, 10 July 2010 - 10:51 PM.


#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:48 PM

Posted 10 July 2010 - 11:01 PM

Hello yes after the reboot move on tio the ATF and SAS.. Just click on the words ATF and SAS SUPER.... in Blue it's a hyper link to the dpwnload.

Now I also need to tell you about the found Backdoor bots... One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 mimi_3

mimi_3
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:48 PM

Posted 11 July 2010 - 04:19 AM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/11/2010 at 04:38 AM

Application Version : 4.40.1002

Core Rules Database Version : 5181
Trace Rules Database Version: 2993

Scan type : Complete Scan
Total Scan Time : 03:25:33

Memory items scanned : 232
Memory threats detected : 0
Registry items scanned : 8812
Registry threats detected : 0
File items scanned : 84025
File threats detected : 406

Adware.Flash Tracking Cookie
C:\Documents and Settings\JO\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\Z8ENSRW4\VITAMINE.NETWORLDMEDIA.NET

Rogue.AntiMalwareDoctor
C:\Documents and Settings\JO\Application Data\520EB79ED3A26A040AE4416E1AF22D46

Trojan.Agent/Gen-Nullo[Short]
C:\AVENGER\SDRA64.EXE
C:\AVENGER\SNLB.DBO

Adware.Tracking Cookie
142.memecounter.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
2mdn.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
a.ads1.msn.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
acvs.mediaonenetwork.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
adbureau.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
adc2.adcentriconline.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
ads1.msn.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
bc.youporn.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
cdn.insights.gravity.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
cdn4.specificclick.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
clicksor.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
core.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
crackle.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
ds.serving-sys.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
enhance.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
fastclick.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
files.adbrite.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
googleads.g.doubleclick.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
i.adultswim.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
ia.media-imdb.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
imagec17.247realmedia.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
interclick.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
kerb.memecounter.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
m1.2mdn.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
m1.emea.2mdn.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
macromedia.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.heavy.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.jambocast.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.mtvnservices.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.nbcdfw.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.putfile.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.resulthost.org [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.scanscout.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.socialvibe.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.tattomedia.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.telus.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.thewb.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.y8.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media.ytv.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media01.kyte.tv [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media1.break.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
media1.clubpenguin.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
mediaforgews.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
mediaonenetwork.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
memecounter.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
msnbcmedia.msn.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
msntest.serving-sys.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
objects.tremormedia.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
oddcast.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
pornotube.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
secure-us.imrworldwide.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
serial-punter.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
serving-sys.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
spe.atdmt.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
stat.radioblogclub.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
stat.tvblogclub.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
static.youporn.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
track.webgains.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
udn.specificclick.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
videos.mediaite.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
vitamine.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
www.ardmediathek.de [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
www.teenmag.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
wwwstatic.megaporn.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
yo.static.presidiomedia.com [ C:\Documents and Settings\JO\Application Data\Macromedia\Flash Player\#SharedObjects\Z8ENSRW4 ]
.cgm.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.videoegg.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
server.cpmstar.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.apmebf.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adcentriconline.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.partypoker.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.media.photobucket.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.collective-media.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adlegend.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.interclick.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.msnbc.112.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adserver.adtechus.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
data.coremetrics.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.advertiseyourgame.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
rotator.adjuggler.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
rotator.adjuggler.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.chitika.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lfstmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.bellcan.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.mediaconverter.org [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adultfriendfinder.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adultfriendfinder.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.bravenet.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.yieldmanager.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.xiti.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.dmtracker.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
adv.bewebmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
adserver.sevenload.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
eas.apm.emediate.eu [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.interclick.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.popcapgames.122.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
banners.tribute.ca [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.pubads.g.doubleclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.tripod.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.tripod.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ehg-ctv.hitbox.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ehg-ctv.hitbox.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ehg-ctv.hitbox.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.112.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ehg-ctv.hitbox.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
secure.partyaccount.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.partyaccount.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.sympatico.112.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adinterax.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adinterax.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.game-advertising-online.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.msnaccountservices.112.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.socialmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.server.cpmstar.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adserver.adtechus.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.gamersmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.gamersmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.vitamine.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
vitamine.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
vitamine.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.vitamine.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ehg-ctv.hitbox.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.mediafire.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.mediafire.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.gamesbannernet.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ads.gamesbannernet.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ice.112.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.adserver.adtechus.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
media.mtvnservices.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.viacom.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.viacom.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.viacom.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.viacom.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.viacom.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.vitamine.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
rm.yieldmanager.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
rm.yieldmanager.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.tns-counter.ru [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.partypoker.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
www.partypoker.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.rambler.ru [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
us.2.cqcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ideamamaadnetwork.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ideamamaadnetwork.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.mediafire.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
verticalmediaads.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.verticalmediaads.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.gamestats.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.gamestats.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.gamestats.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.gamestats.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
www.gamestats.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.gamestats.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
www.gamestats.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.harpo.122.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
dc.tremormedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.dlmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.stats.adbrite.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
d.mediaforceads.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
www.findit-quick.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
kronos.bravenet.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.bet.122.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
citi.bridgetrack.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
adserverpremium.ca [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.tenilstats.turner.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
sitestat.mayoclinic.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ehg-ctv.hitbox.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.sixapart.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.teenmag.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.teenmag.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
www.teenmag.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.teenmag.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.hearstmagazines.112.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.teenmag.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.networldmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
metroleap.rotator.hadj7.adjuggler.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
metroleap.rotator.hadj7.adjuggler.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ad-g.doubleclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.realmedia.co.kr [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.clickaider.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.audioporncentral.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.audioporncentral.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.eb.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.mmedia.t134.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.gostats.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ad.velmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.velmedia.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.videos.mediaite.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.mediaite.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
videos.mediaite.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
wsclick.searchcanvas.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.examinercom.122.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
ad1.clickhype.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
insights.viralogy.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.thenakedscientists.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.traveldiscounters.ca [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.trvlnet.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.trvlnet.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.trvlnet.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
www.clickmanage.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
www.clickmanage.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.vimby.adbureau.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
account.live.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
adserver.adreactor.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
mediacorptv.sg [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.mediacorp.sg [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.mediacorp.112.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
adx.ibibo.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
rts.pgmediaserve.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.torontoseeker.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.torontoseeker.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.torstardigital.122.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
s04.flagcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
user-activity-tracking.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.phg.hitbox.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
findarticles.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.findarticles.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.findarticles.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.findarticles.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.ctv.122.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.lucidmedia.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
adserver.uproxx.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.samsungfunclub.122.2o7.net [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
rm.yieldmanager.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.gayteens.about.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
us.sitestat.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
us.sitestat.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.content.yieldmanager.com [ C:\Documents and Settings\JO\Application Data\Mozilla\Firefox\Profiles\u87t8o9s.default\cookies.sqlite ]
.doubleclick.net [ C:\Documents and Settings\JO\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.divx.112.2o7.net [ C:\Documents and Settings\JO\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
vitamine.networldmedia.net [ C:\Documents and Settings\LocalService\Application Data\Macromedia\Flash Player\#SharedObjects\FLBZGF2X ]

Trojan.Agent/Gen-Krpytik
C:\EWB5\EXT\CHIP.DLL
C:\EWB5\EXT\DIGITAL.DLL
C:\EWB5\EXT\EWBSPICE.DLL
C:\EWB5\EXT\SPICEEWB.DLL
C:\EWB5\XSPICE32.DLL
C:\WINDOWS\TEMP\_ISTMP1.DIR\CDCHECK.EXE

BearShare File Sharing Client
C:\PROGRAM FILES\BEARSHARE APPLICATIONS\BEARSHARE\BEARSHARE.EXE

Application.PowerReg Scheduler
C:\WINDOWS\PSS\POWERREG SCHEDULER V3.EXESTARTUP

Trojan.Agent/Gen-Kryp[Varver]
C:\WINDOWS\TEMP\F4E0BBD2.TMP
C:\WINDOWS\TEMP\FC5A2708.TMP


Thank you so much my computer is running and even looks better. The quick launch desktop icons located on the bottom of the screen are all present. For a while now the icons were gone! I would always use the actual desktop or start to get into programs like msn.

Now down to business

*Are the threats gone or just quarantined?
*Should I delete Internet explorer and just keep Mozilla?
*How should I maintain my PC? Should I do this every month or another specified time?
*Are there any other essential programs that I need or should have on my PC to keep it in good condition?
*Also how harmful are tracking cookies? Where do they come from and why did I have millions.
*How can I check if a website is safe?
*I basically want to know how to avoid these issues in the future? Any advice you have will be appreciated.

*I have two computers hooked up to the same internet network do I need to clean out that one as well? Also the other computer I believe has the audio virus/ hijack and has random IE internet explorer Pop ups. As I was reading the forum topics a random IE internet explorer window opened up? Strange.

*Luckily we don't do any online banking on this computer. I love technology but don't trust it to that extent.

Thank you so much for the time that you put into helping me. I was about to send it to the repair shop and cough up lots of money. Again thank you. <3

Edited by mimi_3, 11 July 2010 - 04:38 AM.


#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:48 PM

Posted 11 July 2010 - 12:15 PM

Hello mimi_3... First you are quite welcome..
What is your Antivirus App?

*Are the threats gone or just quarantined?
All were at least quarantinw and most deleted. A Quarantined file can no longer harm your PC. If you would like to empty the quarantine you can do so.

*Should I delete Internet explorer and just keep Mozilla?
No you need IE to get wondows critical security updates. If you haven't please update Windows. Then use Mozilla for your Primary browser.

*How should I maintain my PC? Should I do this every month or another specified time?
I run my AV,MBAM and SAS at least weekly after updating the apps.

*Are there any other essential programs that I need or should have on my PC to keep it in good condition?
Well your AV and firewall the 2 above. I would add Spywareblaster
Also update weekly.

*Also how harmful are tracking cookies? Where do they come from and why did I have millions.
Not harmful but they can aid in advertising being sent to you. A cookie is just some data that is placed on your computer when you visit a web site that is simply sent back to that website the next time you visit it. A short explanantion here Ask Leo

*How can I check if a website is safe? use AVG LinkScanner

*I basically want to know how to avoid these issues in the future? Any advice you have will be appreciated.
Tips to protect yourself against malware and reduce the potential for re-infection:Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Keeping Autorun enabled on USB and other removable drives has become a significant security risk due to the increasing number of malware variants that can infect them and transfer the infection to your computer. To learn more about this risk, please read:*I have two computers hooked up to the same internet network do I need to clean out that one as well? Also the other computer I believe has the audio virus/ hijack and has random IE internet explorer Pop ups. As I was reading the forum topics a random IE internet explorer window opened up? Strange.
You should scan this also wiyth MBAM and SAS..If there are more than one user on thes PC's you need to run SAS on all users.


*Luckily we don't do any online banking on this computer. I love technology but don't trust it to that extent.

Thank you so much for the time that you put into helping me. I was about to send it to the repair shop and cough up lots of money. Again thank you. <3



Now before we mop up I want to do and Online scan.

ESET
Please perform a scan with Eset Online Antiivirus Scanner.
(Requires Internet Explorer to work. If given the option, choose "Quarantine" instead of delete.)
Vista users need to run Internet Explorer as Administrator. Right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.
  • Click the green ESET Online Scanner button.
  • Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • You may receive an alert on the address bar that "This site might require the following ActiveX control...Click here to install...". Click on that alert and then click Insall ActiveX component.
  • A new window will appear asking "Do you want to install this software?"".
  • Answer Yes to download and install the ActiveX controls that allows the scan to run.
  • Click Start.
  • Check Remove found threats and Scan potentially unwanted applications.
  • Click Scan to start. (please be patient as the scan could take some time to complete)
  • If offered the option to get information or buy software. Just close the window.
  • When the scan has finished, a log.txt file will be created and automatically saved in the C:\Program Files\ESET\ESET Online Scanner\log.txt
    folder.
  • Click Posted Image > Run..., then copy and paste this command into the open box: C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • The scan results will open in Notepad. Copy and paste the contents of log.txt in your next reply.
Note: Some online scanners will detect existing anti-virus software and refuse to cooperate. You may have to disable the real-time protection components of your existing anti-virus and try running the scan again. If you do this, remember to turn them back on after you are finished.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 mimi_3

mimi_3
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:48 PM

Posted 12 July 2010 - 03:23 PM

Hello again,

I can't access the log and have been experiencing some difficulties.

1) I'm having issues which what i believe is the audio virus. Something or someone keeps turning off the wave and I hear sounds, creaks, music out of no where. (Its so annoying)

2) I keep getting this pop up msg every sec!
Posted Image

Thank you for your helping me out :thumbsup:. I would be worse off without you! :flowers:

Edited by mimi_3, 12 July 2010 - 03:28 PM.


#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:48 PM

Posted 12 July 2010 - 03:33 PM

Hi, no problem... We have to do 2 things now.. First the error loading..

Its not unusual to receive such an error after using specialized fix tools.

A "Cannot find...", "Could not run...", "Error loading... or "specific module could not be found" message is usually related to malware that was set to run at startup but has been deleted. Windows is trying to load this file but cannot locate it since the file was mostly likely removed during an anti-virus or anti-malware scan. However, an associated orphaned registry entry remains and is telling Windows to load the file when you boot up. Since the file no longer exists, Windows will display an error message. You need to remove this registry entry so Windows stops searching for the file when it loads.

To resolve this, download Autoruns, search for the related entry and then delete it.

Create a new folder on your hard drive called AutoRuns (C:\AutoRuns) and extract (unzip) the file there. (click here if you're not sure how to do this.)
Open the folder and double-click on autoruns.exe to launch it.
Please be patient as it scans and populates the entries.
When done scanning, it will say Ready at the bottom.
Scroll through the list and look for a startup entry related to the file(s) in the error message. {RNizet.dll}
Right-click on the entry and choose delete.
Reboot your computer and see if the startup error returns.


Now it appears we have a hidden rootkit so we need to move.
We need a deeper look. Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9,which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
If Gmer won't run,skip it and move on.

Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 mimi_3

mimi_3
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:48 PM

Posted 13 July 2010 - 12:08 AM

I found the file its called NKeti the issue is that every time i delete it pops back up. The pop up makes the computer unusable every second it pops up and i have to delete all the little msgs.

Edited by mimi_3, 13 July 2010 - 12:13 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users