Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Antimalware doctor turned into good-search?


  • This topic is locked This topic is locked
22 replies to this topic

#1 The Stegosaurus

The Stegosaurus

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:21 PM

Posted 19 July 2010 - 05:38 PM

Hi.

I went out and got myself some malware- browsed to a site that i thought I had blocked (and AVG even said was safe) because it gave me something bad before, woke up the next day with Antimalware doctor. Followed the instructions on bleeping computer to get rid of it (it was blocking mbam's site for awhile, but eventually gave up) and seem to have gotten rid of it, although it is still listed under "Add/remove programs." Should I be doing something about that?

Anyhow, now my AVG detects threats every so often, whether I'm online or not (I spent the last few weeks offline with the computer, but I had to go online for work,) and I have been having dll issues on startup the entire time. (See this image: http://www.flickr.com/photos/16969972@N08/4732039622/ ) Also, my google search in firefox seems to have been hijacked by some site called good-search.com that pretends to be google. Every so often, an Explorer page will open up with some javascript in the address bar, even if I'm not connected to the internet, as well. I may have picked up something else in the brief time that I was on; something that I can't remember the name of came up one night, but I turned off the wireless before (I think) anything happened.

I have since ran DDS, Defogger, and gmer, as per the preparation guide, though gmer has never ran to conclusion- whether the system restarts (It's been doing that occasionally, gmer or no) or it runs for a very long time (14 hours at last count), it causes the system to lock up (one time it did at the "save" screen, no less, and I did try running it again, it's never come close to finishing since then) or just gets really really slow.

I'm running WindowsXP Media Center Service Pack 3. Any help would be greatly appreciated.

Thanks,
-The Stegosaurus.
(log follows below)


DDS (Ver_10-03-17.01) - NTFSx86
Run by Lucien at 21:42:35.75 on Tue 07/13/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1363 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Sonic\RecordNow!\RecordNow.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Documents and Settings\Lucien\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://espnradio.espn.go.com/espnradio/index
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:5577
mSearchAssistant = hxxp://www.google.com/ie
mWinlogon: Taskman=c:\documents and settings\administrator\application data\onst.exe
uWinlogon: Shell=c:\recycler\s-1-5-21-2608713756-8148636172-488040742-9827\setupin.exe,c:\recycler\s-1-5-21-0113805982-2947037878-145462408-4128\setupin.exe,explorer.exe,c:\documents and settings\lucien\application data\onst.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Aim6]
uRun: [toscdspd] TOSCDSPD.EXE
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [Google Update] "c:\documents and settings\lucien\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [setupupdater0000.exe] c:\documents and settings\lucien\application data\c1f054b17eea400669601e4e46127f67\setupupdater0000.exe
uRun: [Rmusesabe] rundll32.exe "c:\windows\amsedcrt.dll",Startup
uRun: [68094a27-380e-4810-8513-fea5dd79af6c_37] rundll32.exe "c:\documents and settings\lucien\application data\68094a27-380e-4810-8513-fea5dd79af6c_37.avi", start
uRun: [V71IQL7HI7] c:\windows\Wlajed.exe
uRun: [M5T8QL3YW3] c:\docume~1\lucien\locals~1\temp\Wsl.exe
mRun: [TFncKy] TFncKy.exe
mRun: [TDispVol] TDispVol.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe
mRun: [TPSMain] TPSMain.exe
mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [dla] c:\windows\system32\dla\DLACTRLW.exe
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [EPSON Stylus CX4800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB002" /M "Stylus CX4800"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [T-Mobile webConnect Manager] "c:\program files\t-mobile\webconnect manager\TMobileCM.exe" -a
mRun: [LVCOMS] c:\program files\common files\logitech\qcdriver\LVCOMS.EXE
mRun: [HPPQVideo] "c:\program files\hp\scheduledlaunch\hp laserjet p2050 series\bin\hppschlnch.exe" -r software\hewlett-packard\scheduledlaunch\LJ_P2050_Series -f PQOptimizerVideo.xml -o RemindLater
mRun: [ToolBoxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
mRun: [<NO NAME>]
mRun: [HPUsageTracking] "c:\program files\hp\hp ut\bin\hppusg.exe" "c:\program files\hp\hp ut\"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [skb] rundll32 "iljguogo.dll",,Run
mRun: [Wrosuli] rundll32.exe "c:\windows\elayiqopacajuhi.dll",Startup
mRun: [lqgadvit] c:\documents and settings\administrator\local settings\application data\exrisd\fqnhqy.exe
mRun: [jrjxtcvs] c:\documents and settings\networkservice\local settings\application data\dgypkquku\onubadrtssd.exe
dRun: [jrjxtcvs] c:\documents and settings\networkservice\local settings\application data\dgypkquku\onubadrtssd.exe
StartupFolder: c:\docume~1\lucien\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~2.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autost~1.lnk - c:\program files\wintv\Ir.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1202317991359
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: NameServer = 93.188.162.60,93.188.161.190
TCP: {2C13734D-B58C-444E-9C83-EE4A913DF251} = 93.188.162.60,93.188.161.190
TCP: {37361F2E-A377-45EF-98F5-47356358733E} = 93.188.162.60,93.188.161.190
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\lucien\applic~1\mozilla\firefox\profiles\n403ym5k.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.hotmail.com
FF - prefs.js: keyword.URL - hxxp://search.good-search.net/?sid=10101023100&s=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\lucien\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\lucien\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\lucien\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\java\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPMGWRAP.DLL
FF - plugin: c:\program files\mozilla firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {3D41240C-3658-41E8-B4FF-9DCE7146BC66} - c:\documents and settings\lucien\local settings\application data\{3D41240C-3658-41E8-B4FF-9DCE7146BC66}

---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
FF - user.js: keyword.URL - hxxp://search.good-search.net/?sid=10101023100&s=
============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-12 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-11-12 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-12 242896]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-19 308064]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2009-8-10 2789672]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2008-3-30 11136]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2008-3-30 37248]
S0 tsrgq;tsrgq; [x]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2009-7-24 112640]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\wintv\HCWTVS~1.EXE [2008-6-11 815104]
S3 hcwAVD2;Hauppauge PVR USB2 AVS Video Capture;c:\windows\system32\drivers\HCWUSB2AV.sys [2008-6-11 150784]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2009-7-24 100480]
S3 IO_Memory;IO_Memory;\??\c:\sysprep\drivers\ioport.sys --> c:\sysprep\drivers\ioport.sys [?]
S3 LKNUCMP;Linksys Network USB Composite Device;c:\windows\system32\drivers\lknucmp.sys [2008-3-30 11648]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-6-29 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-6-29 7680]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2008-6-29 42112]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2008-6-29 23680]
S3 SVRPEDRV;SVRPEDRV;\??\c:\sysprep\pedrv.sys --> c:\sysprep\PEDrv.sys [?]
S3 TMobileRcAppSvc;T-Mobile RcApp Svc;c:\program files\t-mobile\webconnect manager\RcAppSvc.exe [2009-8-13 120088]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-8-10 15656]

=============== Created Last 30 ================

2010-07-14 01:40:59 0 ----a-w- c:\documents and settings\lucien\defogger_reenable
2010-06-15 03:56:31 180224 ----a-w- c:\windows\Wlajec.exe
2010-06-15 02:50:31 180224 ----a-w- c:\windows\Wlajeb.exe
2010-06-15 02:26:11 180224 ----a-w- c:\windows\Wlajea.exe
2010-06-15 02:26:06 74752 ----a-w- c:\windows\system32\ernel32.dll
2010-06-14 23:54:37 832 ----a-w- c:\windows\lsrslt.ini
2010-06-14 21:01:32 0 d-----w- c:\docume~1\alluse~1\applic~1\Update
2010-06-14 21:00:18 0 d-----w- c:\docume~1\lucien\applic~1\C1F054B17EEA400669601E4E46127F67

==================== Find3M ====================

2010-06-08 04:07:03 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-18 18:27:17 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-05-04 17:20:39 832512 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20:34 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20:32 17408 ----a-w- c:\windows\system32\corpol.dll
2010-05-02 05:22:50 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30:08 285696 ----a-w- c:\windows\system32\atmfd.dll
2008-09-07 16:14:13 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090720080908\index.dat

============= FINISH: 21:44:28.78 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:04:21 PM

Posted 25 July 2010 - 07:17 PM

Hi,

Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.

  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

  • Please reply to this post so I know you are there.
The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.

Once I receive a reply then I will return with your first instructions.

Thanks thumbup2.gif
Posted Image
m0le is a proud member of UNITE

#3 The Stegosaurus

The Stegosaurus
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:21 PM

Posted 27 July 2010 - 05:45 PM

Hi, thanks for helping me out. Looking forward to working with you.

#4 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:04:21 PM

Posted 27 July 2010 - 05:51 PM

Okay, the logs are crammed with malware files. We will try a quick fix but it may, like Gmer, not make it through.

Run Rkill

Download and Run RKill

Please download RKill by Grinler from one of the 4 links below and save it to your desktop.

Link 1
Link 2
Link 3
Link 4
  • Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.
  • Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
  • A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
  • Please post the resulting log in your next reply.

Then Combofix

Please download ComboFix from one of these locations:* IMPORTANT !!! Save ComboFix.exe to your Desktop making sure you rename it comfix.exe
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Comfix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Posted Image
m0le is a proud member of UNITE

#5 The Stegosaurus

The Stegosaurus
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:21 PM

Posted 28 July 2010 - 05:03 PM

Ok. so I turned off my AVG resident shield, like it said in the link you sent, though I couldn't figure out how to turn off the anti-spyware. I ran rkill then combofix, and left for work wile it was starting to search for infections. WHen I came back from work, the computer was off, and there was no log.

So i ran them both again. When combofix got to the log-creating process, the computer froze for about an hour before I realized that something was wrong. The system didn't respond to anything, and I had to turn it off manually. I did end up with a log file, but I don't think that it's got quite what you're looking for, although combofix DID say that it was deleting some folders in the process

After that, each time I run rkill, all my desktop icons disappear (including combofix), and i have to restart/shut down via the task manager and try again. It hasn't worked yet. I've attached the log that it made before, but I'm going to try again in the meantime. If there's anything else that I ought to be doing, please let me know.

Attached Files



#6 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:04:21 PM

Posted 28 July 2010 - 06:15 PM

The malware will attempt to stop all these tools from working.

Combofix may still have worked but I need to see if a log was produced.

Please go to Start >Run > and copy/paste the following, then press Enter

C:\QooBox\ComboFix-quarantined-files.txt

A log file should open. Please post that in your next reply.
Posted Image
m0le is a proud member of UNITE

#7 The Stegosaurus

The Stegosaurus
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:21 PM

Posted 29 July 2010 - 03:16 PM

Okay. I tried it one more time, and it seems to have run its course. I'm attaching the log it generated, along with the quarantine list.

Attached Files



#8 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:04:21 PM

Posted 29 July 2010 - 03:49 PM

Thanks, that's made it a bit more clear.

Please rerun Combofix as below:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the box below into it:

QUOTE
DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:5577

Folder::
c:\documents and settings\NetworkService\Local Settings\Application Data\dgypkquku

Driver::
tsrgq


Save this as CFScript.txt, in the same location as Comfix.exe (called ComboFix.exe in the below graphic)




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Posted Image
m0le is a proud member of UNITE

#9 The Stegosaurus

The Stegosaurus
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:21 PM

Posted 29 July 2010 - 04:27 PM

Okay.

It ran much more smoothly this time, although "PEV.exe" had an error and needed to close while combofix was running (I left the window up, and when combofix started deleting files, it disappeared). Combofix restarted the computer, and the dll errors didn't come up, though that might just hvre been because CF was running; I'm not assuming that I'm out of the woods yet!

Here is the log, thanks for your help so far.

Attached Files



#10 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:04:21 PM

Posted 29 July 2010 - 04:59 PM

The log looks good. Is that a chink of light past those woods?


Please run the ESET online scanner and let's see how we're doing.
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Leave the top box checked and then check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push
NOTE: If no malware is found then no log will be produced. Let me know if this is the case.
Posted Image
m0le is a proud member of UNITE

#11 The Stegosaurus

The Stegosaurus
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:21 PM

Posted 29 July 2010 - 10:36 PM

Yeah, there's still seventy-odd trees out there.

I didn't know if I ought to delete the quarantined files or not, so I didn't.

Attached Files



#12 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:04:21 PM

Posted 30 July 2010 - 04:57 AM

Quite a few of those trees have already been cut down - if you get my drift. Entries such as Qoobox and System Restore are not active but some of those are still very much a problem.

Please next run MBAM followed by Superantispyware

Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application or, if you are using Vista, right-click and select Run As Administrator on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Full Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes, they may alert you after scanning with MBAM. Please permit the program to allow the changes.


Then

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

Posted Image
m0le is a proud member of UNITE

#13 The Stegosaurus

The Stegosaurus
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:21 PM

Posted 30 July 2010 - 06:46 PM

Ok. MBAM crashed (or restarted, left the room for a few minutes, came back and computer was off), but then ran to completion, finding 20 items, which were removed. Here is the log, I am starting the Superantispyware now:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4372

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

7/30/2010 7:38:36 PM
mbam-log-2010-07-30 (19-38-36).txt

Scan type: Full scan (C:\|)
Objects scanned: 310214
Time elapsed: 1 hour(s), 15 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 18

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP694\A0142548.exe (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP715\A0155302.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP715\A0155303.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP715\A0155304.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155305.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155306.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155307.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155308.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155309.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155310.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155312.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155313.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155314.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155315.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155316.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155317.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155318.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155319.dll (Trojan.TDSS) -> Quarantined and deleted successfully.


#14 The Stegosaurus

The Stegosaurus
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:21 PM

Posted 31 July 2010 - 05:53 PM

Okay. Superantispyware found four hundred something things, many of which were cookies, but still...

Anyhow, here is the log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/31/2010 at 06:30 PM

Application Version : 4.41.1000

Core Rules Database Version : 5293
Trace Rules Database Version: 3105

Scan type : Complete Scan
Total Scan Time : 02:35:35

Memory items scanned : 605
Memory threats detected : 0
Registry items scanned : 8005
Registry threats detected : 2
File items scanned : 169971
File threats detected : 433

Adware.Flash Tracking Cookie
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\BANNERFARM.ACE.ADVERTISING.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\SERVICE.TWISTAGE.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\ESPN360.CHANNELFINDER.NET
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\BC.YOUPORN.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\FILES.YOUPORN.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\CONVOAD.TECHNORATIMEDIA.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\IA.MEDIA-IMDB.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\MEDIA.IGN.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\MEDIA.MTVNSERVICES.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\MEDIA.SCANSCOUT.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\MEDIA.TATTOMEDIA.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\MEDIA1.BREAK.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\OBJECTS.TREMORMEDIA.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\VIDEOMEDIA.IGN.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\INTERCLICK.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\UDN.SPECIFICCLICK.NET
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\CRACKLE.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\SPE.ATDMT.COM
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\M1.2MDN.NET
C:\Documents and Settings\Lucien\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\XBZBQRS2\SECURE-US.IMRWORLDWIDE.COM

Malware.Trace
HKU\.DEFAULT\SOFTWARE\AVSUITE
HKU\S-1-5-18\SOFTWARE\AVSUITE

Adware.Tracking Cookie
convoad.technoratimedia.com [ C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\F3HDP5R8 ]
.bizzclick.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.collective-media.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.collective-media.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.apmebf.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.mediaplex.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.doubleclick.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\q2jumywi.default\cookies.sqlite ]
C:\Documents and Settings\Administrator\Cookies\administrator@247realmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adcloudmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adecn[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.bcserving[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.bridgetrack[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.creafi[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.eyecuedigital[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.smartadx[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.us.e-planning[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adserving.claxon[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@advertise[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adx.bidsystem[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@as.gostats[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bannertgt[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bluestreak[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@board.gostats[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@bs.serving-sys[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@burstbeacon[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@clickpayz2.91485.blueseek[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@clicksor[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@content.yieldmanager[3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fidelity.rotator.hadj7.adjuggler[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@gostats[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@gostats[3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@gostats[4].txt
C:\Documents and Settings\Administrator\Cookies\administrator@imrworldwide[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@innovate.rotator.hadj7.adjuggler[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@invitemedia[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@legolas-media[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@lucidmedia[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@media6degrees[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@monster.gostats[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@myroitracking[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@oasn04.247realmedia[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@rotator.adjuggler[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@smartadx[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.burstbeacon[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@www.burstnet[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@xm.xtendmedia[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@zedo[1].txt
a.media.abcfamily.go.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
adsatt.espn.go.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
bannerfarm.ace.advertising.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
bc.youporn.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
cdn4.specificclick.net [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
convoad.technoratimedia.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
crackle.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
espn360.channelfinder.net [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
files.youporn.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
ia.media-imdb.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
indieclick.3janecdn.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
interclick.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
m1.2mdn.net [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
macromedia.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
media.geniusrocket.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
media.ign.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
media.mtvnservices.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
media.productorial.com.edgesuite.net [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
media.scanscout.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
media.tattomedia.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
media01.kyte.tv [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
media1.break.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
mediastore.verizonwireless.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
objects.tremormedia.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
secure-us.imrworldwide.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
service.twistage.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
spe.atdmt.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
tribalfusion.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
udn.specificclick.net [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
us.media.blizzard.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
videomedia.ign.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
www.pornhub.com [ C:\Documents and Settings\Lucien\Application Data\Macromedia\Flash Player\#SharedObjects\XBZBQRS2 ]
.collective-media.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.apmebf.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.bizrate.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-wizardsofthecoast.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-wizardsofthecoast.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-wizardsofthecoast.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-starbucks.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.avgtechnologies.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.dmtracker.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
data.coremetrics.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.nextag.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.nextag.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.nextag.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.nextag.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.black4porn.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
adprotraffic.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.black4porn.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www6.addfreestats.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.stpetersburgtimes.122.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.warnerbros.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
hornyteens4you.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.bleepbookdating.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www.excellentsextube.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
tsprotraffic.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sexblacksex.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.xxxblackbook.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www.xxxblackbook.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.xxxblackbook.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.xxxblackbook.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.xxxblackbook.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.xxxblackbook.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.exploitedblackteens.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
counter.hitslink.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.associatedcontent.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.latinaporn247.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
clickz.lonelycheatingwives.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www.latinaporn247.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.xiti.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www.uporn.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www.uporn.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.youporn.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.youporn.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.youporn.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.andomedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-wizardsofthecoast.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-wizardsofthecoast.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.paypal.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.stats.paypal.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.doubleclick.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.classmates.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.web-stat.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.web-stat.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.web-stat.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.bravenet.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
wsclick.infospace.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.thinkgeek.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.bnkinsur.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.microsoftsto.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.overture.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.overture.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
stat.dealtime.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.shopping.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
statse.webtrendslive.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.adultfriendfinder.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.adultfriendfinder.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.nakedchicksonpostitnotes.blogspot.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.coolsavings.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.coolsavings.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
stats.townnews.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
stats.townnews.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
stats.townnews.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
stats.townnews.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.leeenterprises.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.findamonster.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
stats.gamestop.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-verizon.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-verizon.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.tripod.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.tripod.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.bs.serving-sys.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.bluestreak.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.segainc.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.rambler.ru [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.yadro.ru [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.yadro.ru [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.msnportal.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.advertnews.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.advertnews.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.e-2dj6wjkyqjdpcfp.stats.esomniture.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.mediaplex.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.mediaplex.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ihire.122.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
flagcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
s06.flagcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
citi.bridgetrack.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
citi.bridgetrack.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.legolas-media.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
s05.flagcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.roiservice.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.snapfish.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.docu-track.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.docu-track.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
account.live.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.msnaccountservices.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.hg1.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.designpornography.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.designpornography.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.surveymonkey.122.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.findlocation.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.findlocation.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.pornhub.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.pornhub.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.pornhub.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-verizon.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-verizon.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-laptops.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.digitalpeaks.xxxfaster.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.borders.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
test.coremetrics.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.track.bestbuy.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.track.bestbuy.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
in.getclicky.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.linksynergy.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.linksynergy.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.linksynergy.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.broadwaycom.122.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.dhdmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.dhdmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.dhdmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.dhdmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.webpower.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.pearson.122.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.media.photobucket.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.lgelectronics.122.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.legolas-media.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.epson.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.charmingshoppes.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.f2network.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.marriottinternational.122.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www.virginmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www.virginmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.www.virginmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.www.virginmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.virginmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.virginmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.virginmedia.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.cx.sxtracking.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.clickboothlnk.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
publishers.clickbooth.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.stopzilla.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
www.stopzilla.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sdesapio-conversiontracker.appspot.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sdesapio-conversiontracker.appspot.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sdesapio-conversiontracker.appspot.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
sdesapio-conversiontracker.appspot.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.stopzilla.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.stopzilla.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.liveperson.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.wpni.112.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.cx.sxtracking.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.ehg-eset.hitbox.com [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
.farheap.122.2o7.net [ C:\Documents and Settings\Lucien\Application Data\Mozilla\Firefox\Profiles\n403ym5k.default\cookies.sqlite ]
C:\Documents and Settings\Lucien\Cookies\lucien@ar.atwola[1].txt
C:\Documents and Settings\Lucien\Cookies\lucien@at.atwola[1].txt
C:\Documents and Settings\Lucien\Cookies\lucien@atwola[2].txt
C:\Documents and Settings\Lucien\Cookies\lucien@bridge1.admarketplace[1].txt
C:\Documents and Settings\Lucien\Cookies\lucien@cdn.at.atwola[1].txt
C:\Documents and Settings\Lucien\Cookies\lucien@doubleclick[1].txt
C:\Documents and Settings\Lucien\Cookies\lucien@insightexpressai[1].txt
C:\Documents and Settings\Lucien\Cookies\lucien@linksynergy[1].txt
C:\Documents and Settings\Lucien\Cookies\lucien@statse.webtrendslive[2].txt
cdn4.specificclick.net [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\354QD3W5 ]
convoad.technoratimedia.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\354QD3W5 ]
media.mtvnservices.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\354QD3W5 ]
media.scanscout.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\354QD3W5 ]
media1.break.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\354QD3W5 ]
objects.tremormedia.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\354QD3W5 ]
secure-us.imrworldwide.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\354QD3W5 ]

Trojan.Agent/Gen-Chalgara
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4B1AEA69-B95E-4955-A6A6-502CD89CDA69}\RP716\A0155311.DLL

Thanks for all your help so far!

#15 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:04:21 PM

Posted 31 July 2010 - 05:57 PM

The problem threats are the first two. Cookies aren't great but they aren't the big boys. Please try and empty your cookies a bit more regularly though.

How is the PC running now?
Posted Image
m0le is a proud member of UNITE




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users