Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

How do I remove a Google Redirect Virus??


  • Please log in to reply
10 replies to this topic

#1 ecwfan3052

ecwfan3052

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:38 PM

Posted 26 June 2011 - 05:13 PM

I opened up an .exe file (I now I wasn't suppose to but I was curious). Then I got the blue screen of death. I restarted in safe mode, installed avg antivirus free version and I scanned the computer and it removed some viruses. After that I was able to start windows normally (without safe mode). I ran avg pc tune up and it fixed some things. Then I scanned it again and it removed some more viruses. However the computer is running very slow and when I click a link in a google search result it redirects me to a random page (sometimes I might get a server error). I'm also getting random audio advertisements, even when I don't have anything open (I've even checked the running processes and everything looked normal). I'm using Google Chrome. What do I do?

Edited by Blade Zephon, 26 June 2011 - 05:28 PM.
Moved from Windows 7 to AII. ~BZ


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,026 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:38 PM

Posted 26 June 2011 - 07:47 PM

Hello and welcome.

Please run these ,post the logs and tell me how it is.

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
Be sure to download TDSSKiller.exe (v2.5.5.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.


If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to these[/color] instructions. In some cases it may be necessary to redownload TDSSKiller and randomly rename it before downloading and saving to the computer.


Next run MBAM (MalwareBytes):

Please download Malwarebytes Anti-Malware and save it to your desktop.
Download Link 1
Download Link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
[color=green]Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.


Troubleshoot Malwarebytes' Anti-Malware
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 ecwfan3052

ecwfan3052
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:38 PM

Posted 27 June 2011 - 04:09 AM

2011/06/27 04:54:46.0513 1572 TDSS rootkit removing tool 2.5.5.0 Jun 16 2011 15:25:15
2011/06/27 04:54:47.0517 1572 ================================================================================
2011/06/27 04:54:47.0517 1572 SystemInfo:
2011/06/27 04:54:47.0517 1572
2011/06/27 04:54:47.0518 1572 OS Version: 6.1.7600 ServicePack: 0.0
2011/06/27 04:54:47.0518 1572 Product type: Workstation
2011/06/27 04:54:47.0518 1572 ComputerName: ECWFAN3052-PC
2011/06/27 04:54:47.0518 1572 UserName: ecwfan3052
2011/06/27 04:54:47.0518 1572 Windows directory: C:\Windows
2011/06/27 04:54:47.0518 1572 System windows directory: C:\Windows
2011/06/27 04:54:47.0518 1572 Processor architecture: Intel x86
2011/06/27 04:54:47.0518 1572 Number of processors: 2
2011/06/27 04:54:47.0518 1572 Page size: 0x1000
2011/06/27 04:54:47.0518 1572 Boot type: Normal boot
2011/06/27 04:54:47.0518 1572 ================================================================================
2011/06/27 04:54:48.0927 1572 Initialize success
2011/06/27 04:57:07.0354 5260 ================================================================================
2011/06/27 04:57:07.0354 5260 Scan started
2011/06/27 04:57:07.0354 5260 Mode: Manual;
2011/06/27 04:57:07.0354 5260 ================================================================================
2011/06/27 04:57:10.0038 5260 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/06/27 04:57:10.0084 5260 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2011/06/27 04:57:10.0116 5260 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/06/27 04:57:10.0178 5260 adfs (73685e15ef8b0bd9c30f1af413f13d49) C:\Windows\system32\drivers\adfs.sys
2011/06/27 04:57:10.0256 5260 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/06/27 04:57:10.0287 5260 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/06/27 04:57:10.0318 5260 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/06/27 04:57:10.0396 5260 AFD (0db7a48388d54d154ebec120461a0fcd) C:\Windows\system32\drivers\afd.sys
2011/06/27 04:57:10.0443 5260 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2011/06/27 04:57:10.0490 5260 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/06/27 04:57:10.0537 5260 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2011/06/27 04:57:10.0568 5260 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2011/06/27 04:57:10.0599 5260 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2011/06/27 04:57:10.0646 5260 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/06/27 04:57:10.0677 5260 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/06/27 04:57:10.0724 5260 amdsata (19ce906b4cdc11fc4fef5745f33a63b6) C:\Windows\system32\drivers\amdsata.sys
2011/06/27 04:57:10.0755 5260 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/06/27 04:57:10.0786 5260 amdxata (869e67d66be326a5a9159fba8746fa70) C:\Windows\system32\drivers\amdxata.sys
2011/06/27 04:57:10.0849 5260 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2011/06/27 04:57:10.0927 5260 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/06/27 04:57:10.0974 5260 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/06/27 04:57:11.0036 5260 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/06/27 04:57:11.0067 5260 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2011/06/27 04:57:11.0145 5260 AVGIDSDriver (2177e7448c1ecfb35a5db417603d205a) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
2011/06/27 04:57:11.0192 5260 AVGIDSEH (13256fc72fa5b3f6d6e8c5957e579b7c) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
2011/06/27 04:57:11.0208 5260 AVGIDSFilter (fa0685cc51de5cfd804e7deaa6488e0e) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
2011/06/27 04:57:11.0239 5260 AVGIDSShim (f788b51100d0f40ea176798cce954a1a) C:\Windows\system32\DRIVERS\AVGIDSShim.Sys
2011/06/27 04:57:11.0301 5260 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\Windows\system32\DRIVERS\avgldx86.sys
2011/06/27 04:57:11.0332 5260 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\Windows\system32\DRIVERS\avgmfx86.sys
2011/06/27 04:57:11.0364 5260 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\Windows\system32\DRIVERS\avgrkx86.sys
2011/06/27 04:57:11.0410 5260 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\Windows\system32\DRIVERS\avgtdix.sys
2011/06/27 04:57:11.0473 5260 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/06/27 04:57:11.0535 5260 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/06/27 04:57:11.0582 5260 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/06/27 04:57:11.0629 5260 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/06/27 04:57:11.0691 5260 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys
2011/06/27 04:57:11.0738 5260 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/06/27 04:57:11.0769 5260 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/06/27 04:57:11.0800 5260 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/06/27 04:57:11.0832 5260 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/06/27 04:57:11.0863 5260 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/06/27 04:57:11.0894 5260 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/06/27 04:57:11.0941 5260 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/06/27 04:57:12.0097 5260 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/06/27 04:57:12.0159 5260 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
2011/06/27 04:57:12.0206 5260 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/06/27 04:57:12.0253 5260 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/06/27 04:57:12.0331 5260 clwvd (125c828bf3673406dfd642d7bee8434f) C:\Windows\system32\DRIVERS\clwvd.sys
2011/06/27 04:57:12.0362 5260 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/06/27 04:57:12.0409 5260 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2011/06/27 04:57:12.0440 5260 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/06/27 04:57:12.0456 5260 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/06/27 04:57:12.0518 5260 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/06/27 04:57:12.0674 5260 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/06/27 04:57:12.0736 5260 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
2011/06/27 04:57:12.0814 5260 DfsC (83d1ecea8faae75604c0fa49ac7ad996) C:\Windows\system32\Drivers\dfsc.sys
2011/06/27 04:57:12.0861 5260 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/06/27 04:57:12.0892 5260 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/06/27 04:57:12.0955 5260 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/06/27 04:57:13.0017 5260 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\Windows\System32\drivers\dxgkrnl.sys
2011/06/27 04:57:13.0064 5260 e1express (cf0a6015f437161698c5b2a0a12cf052) C:\Windows\system32\DRIVERS\e1e6032.sys
2011/06/27 04:57:13.0158 5260 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/06/27 04:57:13.0267 5260 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/06/27 04:57:13.0298 5260 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2011/06/27 04:57:13.0360 5260 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/06/27 04:57:13.0392 5260 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/06/27 04:57:13.0438 5260 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/06/27 04:57:13.0485 5260 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/06/27 04:57:13.0501 5260 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/06/27 04:57:13.0548 5260 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/06/27 04:57:13.0594 5260 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/06/27 04:57:13.0626 5260 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/06/27 04:57:13.0657 5260 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/06/27 04:57:13.0719 5260 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
2011/06/27 04:57:13.0750 5260 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/06/27 04:57:13.0797 5260 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/06/27 04:57:13.0860 5260 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/06/27 04:57:13.0922 5260 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
2011/06/27 04:57:13.0953 5260 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/06/27 04:57:13.0984 5260 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/06/27 04:57:14.0016 5260 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/06/27 04:57:14.0078 5260 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/06/27 04:57:14.0140 5260 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2011/06/27 04:57:14.0187 5260 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/06/27 04:57:14.0234 5260 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2011/06/27 04:57:14.0281 5260 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2011/06/27 04:57:14.0312 5260 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/06/27 04:57:14.0374 5260 iaStorV (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\Windows\system32\drivers\iaStorV.sys
2011/06/27 04:57:14.0515 5260 igfx (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/06/27 04:57:14.0624 5260 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/06/27 04:57:14.0671 5260 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2011/06/27 04:57:14.0702 5260 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/06/27 04:57:14.0749 5260 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/06/27 04:57:14.0796 5260 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/06/27 04:57:14.0827 5260 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/06/27 04:57:14.0874 5260 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/06/27 04:57:14.0905 5260 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2011/06/27 04:57:14.0952 5260 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/06/27 04:57:14.0983 5260 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/06/27 04:57:15.0014 5260 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/06/27 04:57:15.0061 5260 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2011/06/27 04:57:15.0108 5260 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2011/06/27 04:57:15.0170 5260 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/06/27 04:57:15.0232 5260 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/06/27 04:57:15.0264 5260 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/06/27 04:57:15.0295 5260 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/06/27 04:57:15.0310 5260 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/06/27 04:57:15.0357 5260 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/06/27 04:57:15.0420 5260 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/06/27 04:57:15.0451 5260 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/06/27 04:57:15.0498 5260 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/06/27 04:57:15.0576 5260 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/06/27 04:57:15.0591 5260 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2011/06/27 04:57:15.0638 5260 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/06/27 04:57:15.0654 5260 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2011/06/27 04:57:15.0685 5260 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2011/06/27 04:57:16.0059 5260 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/06/27 04:57:16.0106 5260 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2011/06/27 04:57:16.0153 5260 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/06/27 04:57:16.0200 5260 mrxsmb10 (c108952d3660375dcb716b222912e868) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/06/27 04:57:16.0231 5260 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/06/27 04:57:16.0262 5260 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2011/06/27 04:57:16.0293 5260 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2011/06/27 04:57:16.0356 5260 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/06/27 04:57:16.0387 5260 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/06/27 04:57:16.0418 5260 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/06/27 04:57:16.0465 5260 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/06/27 04:57:16.0496 5260 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/06/27 04:57:16.0527 5260 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/06/27 04:57:16.0574 5260 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/06/27 04:57:16.0605 5260 mssmbios (14a69744bff30ecffde1cafc131f01aa) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/06/27 04:57:16.0605 5260 Suspicious file (Forged): C:\Windows\system32\DRIVERS\mssmbios.sys. Real md5: 14a69744bff30ecffde1cafc131f01aa, Fake md5: fc6b9ff600cc585ea38b12589bd4e246
2011/06/27 04:57:16.0605 5260 mssmbios - detected Rootkit.Win32.TDSS.tdl3 (0)
2011/06/27 04:57:16.0652 5260 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/06/27 04:57:16.0683 5260 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/06/27 04:57:16.0714 5260 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/06/27 04:57:16.0761 5260 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/06/27 04:57:16.0808 5260 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
2011/06/27 04:57:16.0855 5260 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/06/27 04:57:16.0886 5260 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/06/27 04:57:16.0917 5260 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/06/27 04:57:16.0948 5260 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/06/27 04:57:16.0980 5260 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2011/06/27 04:57:17.0011 5260 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/06/27 04:57:17.0042 5260 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2011/06/27 04:57:17.0198 5260 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/06/27 04:57:17.0245 5260 NPF (b9730495e0cf674680121e34bd95a73b) C:\Windows\system32\drivers\npf.sys
2011/06/27 04:57:17.0276 5260 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/06/27 04:57:17.0307 5260 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/06/27 04:57:17.0385 5260 Ntfs (187002ce05693c306f43c873f821381f) C:\Windows\system32\drivers\Ntfs.sys
2011/06/27 04:57:17.0448 5260 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\Windows\system32\DRIVERS\NuidFltr.sys
2011/06/27 04:57:17.0479 5260 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/06/27 04:57:17.0510 5260 nvraid (f1b0bed906f97e16f6d0c3629d2f21c6) C:\Windows\system32\drivers\nvraid.sys
2011/06/27 04:57:17.0557 5260 nvstor (4520b63899e867f354ee012d34e11536) C:\Windows\system32\drivers\nvstor.sys
2011/06/27 04:57:17.0588 5260 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/06/27 04:57:17.0619 5260 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/06/27 04:57:17.0697 5260 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/06/27 04:57:17.0728 5260 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2011/06/27 04:57:17.0760 5260 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/06/27 04:57:17.0806 5260 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2011/06/27 04:57:17.0838 5260 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2011/06/27 04:57:17.0869 5260 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/06/27 04:57:17.0916 5260 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/06/27 04:57:17.0962 5260 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/06/27 04:57:18.0087 5260 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/06/27 04:57:18.0134 5260 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/06/27 04:57:18.0196 5260 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/06/27 04:57:18.0243 5260 PxHelp20 (d970470f8f39470bdae94d313a1ccdce) C:\Windows\system32\Drivers\PxHelp20.sys
2011/06/27 04:57:18.0352 5260 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/06/27 04:57:18.0430 5260 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/06/27 04:57:18.0477 5260 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/06/27 04:57:18.0524 5260 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/06/27 04:57:18.0555 5260 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/06/27 04:57:18.0618 5260 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/06/27 04:57:18.0664 5260 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/06/27 04:57:18.0696 5260 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/06/27 04:57:18.0742 5260 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2011/06/27 04:57:18.0774 5260 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/06/27 04:57:18.0805 5260 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/06/27 04:57:18.0852 5260 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
2011/06/27 04:57:18.0914 5260 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/06/27 04:57:18.0945 5260 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/06/27 04:57:18.0992 5260 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2011/06/27 04:57:19.0039 5260 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2011/06/27 04:57:19.0132 5260 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/06/27 04:57:19.0179 5260 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
2011/06/27 04:57:19.0210 5260 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/06/27 04:57:19.0257 5260 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2011/06/27 04:57:19.0320 5260 SCREAMINGBDRIVER (024411d283226deb158b88a465cb555c) C:\Windows\system32\drivers\ScreamingBAudio.sys
2011/06/27 04:57:19.0366 5260 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/06/27 04:57:19.0429 5260 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/06/27 04:57:19.0460 5260 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/06/27 04:57:19.0476 5260 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/06/27 04:57:19.0554 5260 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/06/27 04:57:19.0585 5260 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/06/27 04:57:19.0616 5260 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/06/27 04:57:19.0663 5260 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/06/27 04:57:19.0694 5260 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2011/06/27 04:57:19.0756 5260 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/06/27 04:57:19.0772 5260 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/06/27 04:57:19.0819 5260 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/06/27 04:57:19.0881 5260 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/06/27 04:57:19.0959 5260 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\Windows\system32\DRIVERS\srv.sys
2011/06/27 04:57:20.0006 5260 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\Windows\system32\DRIVERS\srv2.sys
2011/06/27 04:57:20.0037 5260 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\Windows\system32\DRIVERS\srvnet.sys
2011/06/27 04:57:20.0100 5260 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/06/27 04:57:20.0146 5260 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
2011/06/27 04:57:20.0193 5260 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
2011/06/27 04:57:20.0224 5260 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2011/06/27 04:57:20.0318 5260 Tcpip (0158d5e9982e9d6a90dfc802f618e130) C:\Windows\system32\drivers\tcpip.sys
2011/06/27 04:57:20.0412 5260 TCPIP6 (0158d5e9982e9d6a90dfc802f618e130) C:\Windows\system32\DRIVERS\tcpip.sys
2011/06/27 04:57:20.0458 5260 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2011/06/27 04:57:20.0521 5260 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2011/06/27 04:57:20.0536 5260 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2011/06/27 04:57:20.0583 5260 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2011/06/27 04:57:20.0614 5260 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2011/06/27 04:57:20.0708 5260 truecrypt (be45dad1c73a3216edc8c485916f6594) C:\Windows\system32\drivers\truecrypt.sys
2011/06/27 04:57:20.0755 5260 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/06/27 04:57:20.0802 5260 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2011/06/27 04:57:20.0833 5260 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/06/27 04:57:20.0864 5260 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2011/06/27 04:57:20.0926 5260 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/06/27 04:57:20.0973 5260 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2011/06/27 04:57:21.0004 5260 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/06/27 04:57:21.0051 5260 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\Windows\system32\Drivers\usbaapl.sys
2011/06/27 04:57:21.0129 5260 usbccgp (c31ae588e403042632dc796cf09e30b0) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/06/27 04:57:21.0176 5260 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2011/06/27 04:57:21.0207 5260 usbehci (e4c436d914768ce965d5e659ba7eebd8) C:\Windows\system32\DRIVERS\usbehci.sys
2011/06/27 04:57:21.0270 5260 usbhub (bdcd7156ec37448f08633fd899823620) C:\Windows\system32\DRIVERS\usbhub.sys
2011/06/27 04:57:21.0332 5260 usbohci (eb2d819a639015253c871cda09d91d58) C:\Windows\system32\drivers\usbohci.sys
2011/06/27 04:57:21.0363 5260 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/06/27 04:57:21.0410 5260 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
2011/06/27 04:57:21.0472 5260 USBSTOR (1c4287739a93594e57e2a9e6a3ed7353) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/06/27 04:57:21.0535 5260 usbuhci (22480bf4e5a09192e5e30ba4dde79fa4) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/06/27 04:57:21.0582 5260 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\Windows\system32\Drivers\usbvideo.sys
2011/06/27 04:57:21.0675 5260 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/06/27 04:57:21.0706 5260 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/06/27 04:57:21.0753 5260 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/06/27 04:57:21.0784 5260 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/06/27 04:57:21.0816 5260 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2011/06/27 04:57:21.0847 5260 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/06/27 04:57:21.0878 5260 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2011/06/27 04:57:21.0925 5260 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
2011/06/27 04:57:21.0956 5260 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
2011/06/27 04:57:21.0987 5260 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/06/27 04:57:22.0034 5260 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/06/27 04:57:22.0065 5260 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
2011/06/27 04:57:22.0112 5260 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/06/27 04:57:22.0174 5260 VSTHWBS2 (682fcf7d2eb5158cd30408e976562408) C:\Windows\system32\DRIVERS\VSTBS23.SYS
2011/06/27 04:57:22.0237 5260 VST_DPV (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS
2011/06/27 04:57:22.0284 5260 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2011/06/27 04:57:22.0330 5260 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/06/27 04:57:22.0377 5260 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/27 04:57:22.0393 5260 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/06/27 04:57:22.0471 5260 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/06/27 04:57:22.0502 5260 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/06/27 04:57:22.0596 5260 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/06/27 04:57:22.0627 5260 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/06/27 04:57:22.0674 5260 winachsf (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
2011/06/27 04:57:22.0798 5260 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/06/27 04:57:22.0861 5260 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/06/27 04:57:22.0923 5260 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/06/27 04:57:23.0001 5260 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2011/06/27 04:57:23.0032 5260 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/06/27 04:57:23.0095 5260 ================================================================================
2011/06/27 04:57:23.0095 5260 Scan finished
2011/06/27 04:57:23.0095 5260 ================================================================================
2011/06/27 04:57:23.0110 3456 Detected object count: 1
2011/06/27 04:57:23.0110 3456 Actual detected object count: 1
2011/06/27 04:58:10.0659 3456 mssmbios (14a69744bff30ecffde1cafc131f01aa) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/06/27 04:58:10.0660 3456 Suspicious file (Forged): C:\Windows\system32\DRIVERS\mssmbios.sys. Real md5: 14a69744bff30ecffde1cafc131f01aa, Fake md5: fc6b9ff600cc585ea38b12589bd4e246
2011/06/27 04:58:11.0015 3456 Backup copy found, using it..
2011/06/27 04:58:11.0107 3456 C:\Windows\system32\DRIVERS\mssmbios.sys - will be cured after reboot
2011/06/27 04:58:11.0108 3456 Rootkit.Win32.TDSS.tdl3(mssmbios) - User select action: Cure
2011/06/27 04:58:17.0046 2616 Deinitialize success

#4 ecwfan3052

ecwfan3052
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:38 PM

Posted 27 June 2011 - 04:32 AM

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6956

Windows 6.1.7600
Internet Explorer 9.0.8112.16421

6/27/2011 5:30:21 AM
mbam-log-2011-06-27 (05-30-21).txt

Scan type: Quick scan
Objects scanned: 167609
Time elapsed: 3 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 17
Registry Values Infected: 5
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\Users\ecwfan3052\AppData\Local\sFlsDT.dll (Trojan.Hiloti) -> Delete on reboot.
c:\Users\ecwfan3052\AppData\Local\uxihajileso.dll (Trojan.Agent.U) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{D2A123C3-A500-90BD-A820-04B53A2C8952} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2A123C3-A500-90BD-A820-04B53A2C8952} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2A123C3-A500-90BD-A820-04B53A2C8952} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2A123C3-A500-90BD-A820-04B53A2C8952} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E0DE227-5CE4-4EA3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Iferafoj (Trojan.Hiloti) -> Value: Iferafoj -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WINID (Malware.Trace) -> Value: WINID -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> Value: idstrf -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Value: NoFolderOptions -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Gpisufuqosejef (Trojan.Agent.U) -> Value: Gpisufuqosejef -> Delete on reboot.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (PUM.Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\ecwfan3052\AppData\Local\sFlsDT.dll (Trojan.Hiloti) -> Delete on reboot.
c:\Users\ecwfan3052\local settings\application data\sFlsDT.dll (Trojan.Hiloti) -> Delete on reboot.
c:\Windows\System32\winset.ini (Malware.Trace) -> Quarantined and deleted successfully.
c:\Windows\cftnom.bat (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\ecwfan3052\AppData\Local\uxihajileso.dll (Trojan.Agent.U) -> Delete on reboot.

#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,026 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:38 PM

Posted 27 June 2011 - 10:47 AM

Great reboot the PC.. Run an Online scan and tell me how it is now.

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image


NOTE: In some instances if no malware is found there will be no log produced.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 ecwfan3052

ecwfan3052
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:38 PM

Posted 27 June 2011 - 05:40 PM

C:\Users\ecwfan3052\AppData\Roaming\FrostWire\.AppSpecialShare\frostwire-4.21.8.windows.exe Win32/OpenCandy application deleted - quarantined
C:\Users\ecwfan3052\Documents\Google Chrome Downloads\avc-free.exe Win32/OpenCandy application deleted - quarantined
C:\Users\ecwfan3052\Documents\Google Chrome Downloads\CNET_TechTracker_2_0_3_59_a_Setup.exe Win32/OpenCandy application deleted - quarantined
C:\Users\ecwfan3052\Documents\Google Chrome Downloads\macomfort_setup.exe Win32/OpenCandy application deleted - quarantined
C:\Users\ecwfan3052\Documents\Google Chrome Downloads\XvidSetup.exe a variant of Win32/Adware.HotBar.H application cleaned by deleting - quarantined
C:\Windows\System32\drivers\etc\hosts Win32/Qhost trojan cleaned by deleting - quarantined

#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,026 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:38 PM

Posted 27 June 2011 - 06:26 PM

Well I think we should run a safe mode scan and an MVAM rerun as we still are finding things.. This should be it yho'.


Next run ATF and SAS:

Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

From your regular user account..
Download Attribune's ATF Cleaner and then SUPERAntiSpyware , Free Home Version. Save both to desktop ..
DO NOT run yet.
Open SUPER from icon and install and Update it
Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining
.
Click the "Close" button to leave the control center screen and exit the program. DO NOT run yet.

Now reboot into Safe Mode: How to enter safe mode(XP)
Using the F8 Method
Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode
.

Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.

NOW Scan with SUPER
Open from the desktop icon or the program Files list
On the left, make sure you check C:\Fixed Drive.
Perform a Complete scan. After scan,Verify they are all checked.
Click OK on the summary screen to quarantine all found items.
If asked if you want to reboot, click "Yes" and reboot normally.

To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log.
A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
Click Close to exit the program.


Reboot to Norma and Rerun MBAM (MalwareBytes) like this:

Open MBAM in normal mode and click Update tab, select Check for Updates,when done
click Scanner tab,select FULL scan and scan (normal mode).
After scan click Remove Selected, Post new scan log and Reboot into normal mode.

Please ask any needed questions,post logs and Let us know how the PC is running now.

Edited by boopme, 27 June 2011 - 06:27 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 ecwfan3052

ecwfan3052
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:38 PM

Posted 27 June 2011 - 10:54 PM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/27/2011 at 11:41 PM

Application Version : 4.54.1000

Core Rules Database Version : 7339
Trace Rules Database Version: 5151

Scan type : Complete Scan
Total Scan Time : 02:29:33

Memory items scanned : 395
Memory threats detected : 0
Registry items scanned : 9022
Registry threats detected : 1
File items scanned : 251734
File threats detected : 930

Malware.Trace
HKU\S-1-5-21-2969454735-850812967-3863087740-1000\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL

Adware.Tracking Cookie
.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.247realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adxpose.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eyewonder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.linksynergy.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.linksynergy.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.linksynergy.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.112.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.112.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtechus.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.yieldmanager.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2mdn.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.viacom.adbureau.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dmtracker.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
in.getclicky.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.googleads.g.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.linksynergy.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ero-advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad-g.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserving.cpxinteractive.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pubads.g.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaforge.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ar.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adinterax.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtech.de [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
r1-ads.ace.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
stat.onestat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
stat.onestat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.view.atdmt.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.c.gigcount.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
stat.onestat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.viacom.adbureau.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.viacom.adbureau.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.viacom.adbureau.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cdn.eyewonder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cdn.eyewonder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.freetoonporntube.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.freetoonporntube.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lucidmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
citi.bridgetrack.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserv.rotator.hadj7.adjuggler.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.overture.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.gostats.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lucidmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lfstmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
stat.onestat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adjuggler.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cbsdigitalmedia.112.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.69porns.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.69porns.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.69porns.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pornerbros.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pornerbros.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
clicktrace.info [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicktrace.info [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicktrace.info [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.pornerbros.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.pornerbros.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.pornerbros.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.vertadnet.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.vertadnet.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserv.rotator.hadj7.adjuggler.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
s03.flagcounter.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.edgeadx.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.test.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.test.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.test.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.test.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.test.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.test.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.webstat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.webstat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.webstat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediafire.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mtvn.112.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xxxchurch.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xxxchurch.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xxxchurch.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.myroitracking.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clicksor.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
click.fastpartner.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.findology.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.findology.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
clicks.thespecialsearch.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.find.10topsearches.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.find.10topsearches.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.foxfilmedentertainment.122.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bravenet.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.shorttailmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.shorttailmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.warezgeneration.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.draftfcb.112.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www9.addfreestats.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.react2media.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.react2media.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.crackle.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tracking.foxnews.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tracking.foxnews.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
s07.flagcounter.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
wstat.wibiya.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
eas.apm.emediate.eu [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.247realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
gotacha.rotator.hadj7.adjuggler.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
gotacha.rotator.hadj7.adjuggler.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
beacon.dmsinsights.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserver.twitpic.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pornaccess.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pornaccess.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pornaccess.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
gotacha.rotator.hadj7.adjuggler.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.h2porn.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.h2porn.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.h2porn.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.h2porn.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.h2porn.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pubads.g.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pubads.g.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
pubads.g.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.freewarezoom.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.freewarezoom.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.freewarezoom.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.freewarezoom.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ru4.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
statse.webtrendslive.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.smartadserver.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xiti.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.linksynergy.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.linksynergy.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.linksynergy.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.r1-ads.ace.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media.adfrontiers.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.network.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.newmedia.funnyjunk.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.newmedia.funnyjunk.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zanox.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.nudecelebritysexvideos.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.nudecelebritysexvideos.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kantarmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kantarmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
hpi.rotator.hadj7.adjuggler.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
hpi.rotator.hadj7.adjuggler.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.burstnet.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.stats.complex.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.stats.complex.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bassproshops.122.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.superstats.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.steelhousemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.steelhousemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.steelhousemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
optimize.indieclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
optimize.indieclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
optimize.indieclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.azjmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.azjmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adlegend.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adlegend.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
citi.bridgetrack.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
citi.bridgetrack.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
citi.bridgetrack.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.xm.xtendmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.rudefinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.rudefinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.rudefinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.rudefinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.rudefinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.rudefinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.rudefinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.rudefinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adultfriendfinder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.realmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.viacom.adbureau.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.viacom.adbureau.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.webstat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.webstat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.webstat.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.premiumtv.122.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
rotator.adjuggler.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
rotator.adjuggler.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
media.wwecreate.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mm.chitika.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adtechus.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.googleads.g.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
pluckit.demandmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
dc.tremormedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.track.freecoolgifts.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.track.freecoolgifts.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
track.freecoolgifts.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
track.freecoolgifts.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
track.freecoolgifts.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
d.mediaforge.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediabrandsww.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.andomedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.dailyheraldpaddockpublication.112.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.overture.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
beacon.dmsinsights.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
beacon.dmsinsights.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.burstbeacon.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstbeacon.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eyewonder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pornfortheblind.org [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pornfortheblind.org [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.legolas-media.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.a1.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tradedoubler.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adsby.webtraffic.se [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.server.cpmstar.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lucidmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.burstnet.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.geeksaresexy.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.geeksaresexy.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.geeksaresexy.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.geeksaresexy.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.geeksaresexy.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.tracklead.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kitaramedia.122.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ar.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.teens.drugabuse.gov [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.teens.drugabuse.gov [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.cool-teens.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cool-teens.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.cool-teens.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.cool-teens.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adinterax.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.martiniadnetwork.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.martiniadnetwork.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.martiniadnetwork.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.martiniadnetwork.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
lioness.younglegalporn.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.thinkgeek.112.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.trafficjunky.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
tjdelivery10.trafficjunky.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
pornografish.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ads.crakmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
xxxbunker.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
xxxbunker.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adxpansion.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
bridge2.admarketplace.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.admarketplace.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.avgtechnologies.112.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eyewonder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eyewonder.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertise.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.thetrafficstat.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
citi.bridgetrack.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
citi.bridgetrack.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
citi.bridgetrack.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
citi.bridgetrack.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pro-market.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.hornymatches.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.hornymatches.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.hornymatches.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.hornymatches.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.hornymatches.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.hornymatches.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
accounts.youtube.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.solvemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.solvemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.technoratimedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kaspersky.122.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
auth.breakmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.casalemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media2.legacy.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.revsci.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.shopica.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.traveladvertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.traveladvertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.clickfuse.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.lfstmedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.burstnet.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adserver.adtechus.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eset.122.2o7.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.stopzilla.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.stopzilla.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.stopzilla.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.stopzilla.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.zedo.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.at.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ar.atwola.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\ecwfan3052\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
banners.securedataimages.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
cdn1.image.freeporn.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
cdn1.pics.mofosex.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
cdn1.static1.pornrabbit.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
click.kink.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
cloud.video.unrulymedia.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
convoad.technoratimedia.net [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
core.insightexpressai.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
crackle.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
daywithapornstar.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
disgustingmedia.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
ds.serving-sys.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
ec.atdmt.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
files.youporn.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
h2porn.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
ia.media-imdb.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.cbs3springfield.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.ign.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.khou.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.lintvnews.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.movieweb.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.mtvnservices.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.scanscout.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.wfaa.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.whosay.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media1.break.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media1.shufuni.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
msnbcmedia.msn.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
objects.tremormedia.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
s0.2mdn.net [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
secure-uk.imrworldwide.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
secure-us.imrworldwide.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
serving-sys.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
sexier.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
sftrack.searchforce.net [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
spe.atdmt.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
stat.easydate.biz [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
static.eporner.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
static.pornetto.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
static.sunporno.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
tracker.sextorrents.ru [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
vidii.hardsextube.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
vitamine.networldmedia.net [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
wdw1.wdpromedia.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
wdw2.wdpromedia.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.99counters.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.alphaporno.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.empornium.me [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.bleep-vids.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.goodcholesterolcount.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.naiadsystems.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.nakedlesbianwrestling.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.nudecelebritysexvideos.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.pornerbros.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.porngol.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.pornhub.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.porntube.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.pornwall.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.pornyep.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
www.soundclick.com [ C:\Users\ecwfan3052\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\DXW9BCZ3 ]
media.mtvnservices.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\58BWXFQU ]
secure-us.imrworldwide.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\58BWXFQU ]
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@2o7[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@a1.interclick[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@ad.adpredictive[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@ad.yieldmanager[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@adbrite[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@admarketplace[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@ads.lycos[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@ads.pointroll[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@ads.pubmatic[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@ads.undertone[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@advertise[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@advertising[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@adxpose[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@apmebf[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@at.atwola[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@atdmt[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@azjmp[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@bridge1.admarketplace[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@bs.serving-sys[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@burstbeacon[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@burstnet[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@casalemedia[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@chitika[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@click.scour[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@collective-media[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@content.yieldmanager[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@content.yieldmanager[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@dc.tremormedia[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@deals.nextag[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@doubleclick[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@ehg-revlon.hitbox[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@equifaxps.122.2o7[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@farecastcom.122.2o7[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@fastclick[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@hitbox[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@homestore.122.2o7[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@imrworldwide[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@interclick[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@invitemedia[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@liveperson[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@liveperson[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@lucidmedia[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@media6degrees[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@mediabrandsww[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@mediaplex[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@miva.cinomedia[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@mm.chitika[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@network.realmedia[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@nextag[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@overture[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@pointroll[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@pro-market[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@questionmarket[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@r1-ads.ace.advertising[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@realmedia[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@revsci[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@rhapsodyinternationalinc.112.2o7[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@ru4[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@sales.liveperson[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@serving-sys[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@specificclick[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@stat.dealtime[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@tacoda.at.atwola[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@target.db.advertising[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@technoratimedia[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@trafficmp[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@traveladvertising[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@tribalfusion[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@viacom.adbureau[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@www.burstbeacon[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@www.burstnet[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@www.find-quick-results[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@yieldmanager[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ecwfan3052-pc$@zedo[1].txt

#9 ecwfan3052

ecwfan3052
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:38 PM

Posted 28 June 2011 - 04:17 AM

The Google search results are working and the computer is working normally again. Thank you so much.


Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6965

Windows 6.1.7600
Internet Explorer 9.0.8112.16421

6/28/2011 5:16:08 AM
mbam-log-2011-06-28 (05-16-08).txt

Scan type: Full scan (C:\|)
Objects scanned: 414908
Time elapsed: 1 hour(s), 21 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Gpisufuqosejef (Trojan.Agent.U) -> Value: Gpisufuqosejef -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Iferafoj (Trojan.Agent.U) -> Value: Iferafoj -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#10 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,026 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:38 PM

Posted 28 June 2011 - 09:59 AM

Looks good here . Now you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Posted Image > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Posted Image > Run... and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.
Vista and Windows 7 users can refer to these links:
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#11 ecwfan3052

ecwfan3052
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:38 PM

Posted 29 June 2011 - 10:04 AM

I created a restore point and used the disk cleanup and everything is back to normal. Thank you so much for all your help.

Edited by ecwfan3052, 29 June 2011 - 10:04 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users