Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Some kind of Adware


  • This topic is locked This topic is locked
27 replies to this topic

#1 professorchaos

professorchaos

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 18 December 2012 - 01:08 AM

Hi, I've become affected by some kind of adware originating from I know not where, since I haven't installed anything of questionable repute. In any case I keep getting pop-ups in the lower-right corner of my browser window that looks like a Facebook chat window, but providing a "Find & Compare Prices" link for some arbitrary search terms related to the page content. Occasionally, on clicking a link or entering a URL, I'll be redirected from my intended destination to an advertisement page. Thanks in advance for any offered assistance

I should add: I did a scan with Microsoft Security Essentials which found evidence of Rogue:Win32/FakeRean, which was removed, but symptoms failed to abate.

Edited by hamluis, 18 December 2012 - 05:44 PM.
Moved from Win 7 to Am I Infected - Hamluis.


BC AdBot (Login to Remove)

 


#2 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:03:27 AM

Posted 18 December 2012 - 01:16 AM

Hello -

Please download AdwCleaner by Xplode onto your desktop.
If you are prompted, please disable your Antivirus Information (temp disable) HERE
Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Delete.
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next answer.
You can find the logfile at C:\AdwCleaner[S1].txt as well.

NEXT -
Please download Junkware Removal Tool to your desktop
Junkware Removal Tool by thisisu
•Shut down your protection software now to avoid potential conflicts.
•Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
•The tool will open and start scanning your system.
•Please be patient as this can take a while to complete depending on your system's specifications.
•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
•Post the contents of JRT.txt into your next message.

Thank You -
EDIT -
I would also Download , Install , Update and run a scan with Malwarebytes Anti-Malware Free and SuperantiSpyware Free

Edited by noknojon, 18 December 2012 - 01:36 AM.


#3 professorchaos

professorchaos
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 18 December 2012 - 01:51 AM

# AdwCleaner v2.101 - Logfile created 12/18/2012 at 01:32:10
# Updated 16/12/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Prof Chaos - SEXMACHINE
# Boot Mode : Normal
# Running from : C:\Users\Prof Chaos\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Mozilla Firefox v17.0.1 (en-US)

Profile name : default
File : C:\Users\Prof Chaos\AppData\Roaming\Mozilla\Firefox\Profiles\uwl5simo.default\prefs.js

[OK] File is clean.

Profile name : default-1344973092455 [Profil par défaut]
File : C:\Users\Prof Chaos\AppData\Roaming\Mozilla\Firefox\Profiles\ys7pjk3r.default-1344973092455\prefs.js

[OK] File is clean.

*************************

AdwCleaner[S2].txt - [1620 octets] - [18/12/2012 01:32:10]

########## EOF - C:\AdwCleaner[S2].txt - [1680 octets] ##########

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.1.8 (12.17.2012:1)
OS: Windows 7 Home Premium x64
Ran by Prof Chaos on Tue 12/18/2012 at 1:35:38.40
Blog: http://thisisudax.blogspot.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}



~~~ Files

Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.1049.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.1049.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 12/18/2012 at 1:42:58.22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

#4 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:03:27 AM

Posted 18 December 2012 - 05:32 AM

Hi -
That removed a few minor problems > > >
Ask.com
Ask.com
Softonic
SearchScopes

Do you have a log from Malwarebytes and SUPERAntiSpyware ?? Malwarebytes logs are listed by date across the top under "Logs tab" -
SUPERAntiSpyware logs are found at the lower left side under "View Scan Logs" -

Is there any mention of "Find & Compare Prices" in Control Panel > Programs and Features ??

#5 buddy215

buddy215

  • Moderator
  • 13,406 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:11:27 AM

Posted 18 December 2012 - 07:29 AM

QUOTE: Microsoft Security Essentials which found evidence of Rogue:Win32/FakeRean

See Bleeping Computer info here: New FakeRean / Braviax Rogue called XP Defender 2013, Vista Defender 2013, and Win 7 Defender 2013 released.
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#6 professorchaos

professorchaos
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 18 December 2012 - 10:42 AM

Hi -
That removed a few minor problems > > >
Ask.com
Ask.com
Softonic
SearchScopes

Do you have a log from Malwarebytes and SUPERAntiSpyware ?? Malwarebytes logs are listed by date across the top under "Logs tab" -
SUPERAntiSpyware logs are found at the lower left side under "View Scan Logs" -

Is there any mention of "Find & Compare Prices" in Control Panel > Programs and Features ??

No to all questions

QUOTE: Microsoft Security Essentials which found evidence of Rogue:Win32/FakeRean

See Bleeping Computer info here: New FakeRean / Braviax Rogue called XP Defender 2013, Vista Defender 2013, and Win 7 Defender 2013 released.

Hey I looked at that link and although MSE said I was infected with this, my symptoms don't have anything to do with what's described. Thanks anyway

Edited by professorchaos, 18 December 2012 - 10:44 AM.


#7 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:03:27 AM

Posted 18 December 2012 - 03:04 PM

Download , Install , and Update both of these programs - They will produce a Log when finished - Please post them back here
Malwarebytes Anti-Malware Free and SuperantiSpyware Free

Do you have any current problems now, or are you just checking that they are gone -

Thanks -

#8 professorchaos

professorchaos
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 18 December 2012 - 03:14 PM

Download , Install , and Update both of these programs - They will produce a Log when finished - Please post them back here
Malwarebytes Anti-Malware Free and SuperantiSpyware Free

Do you have any current problems now, or are you just checking that they are gone -

Thanks -

Symptoms persist. I'll follow your suggestions and edit here later.

#9 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:03:27 AM

Posted 18 December 2012 - 03:18 PM

I will be missing for most of today (about 10 hours) so I hope someone else replies sooner -

Still run and post the logs from both programs :busy:

Thanks -

#10 professorchaos

professorchaos
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 18 December 2012 - 03:24 PM

No rush brotha, it's merely an annoyance at this point, not affecting processing perceptibly

#11 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:03:27 AM

Posted 19 December 2012 - 04:09 AM

Hi professor -
Have you had a chance to run those scans yet ??

#12 professorchaos

professorchaos
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 19 December 2012 - 03:17 PM

No, I got arrested yesterday so I didn't have the chance. Bout to do so.

EDIT:
Download, installed, and updated programs. No logs were produced

Edited by professorchaos, 19 December 2012 - 03:22 PM.


#13 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:03:27 AM

Posted 19 December 2012 - 03:37 PM

I got arrested yesterday so I didn't have the chance

You been Xmas shopping ...........B)

Download, installed, and updated programs. No logs were produced

No Way -
Malwarebytes always has a log even if it says No Infection Found - An OOld one of mine ----
4/05/2012 9:47:13 PM
mbam-log-2012-05-04 (21-47-13).txtScan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 330702
Time elapsed: 4 minute(s), 2 second(s)
Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)
(end)
This is the log you get - Without it I do not know what you did -



#14 professorchaos

professorchaos
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Local time:01:27 PM

Posted 19 December 2012 - 04:13 PM

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.19.08

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Prof Chaos :: SEXMACHINE [administrator]

12/19/2012 4:13:55 PM
mbam-log-2012-12-19 (20-16-11).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 701277
Time elapsed: 2 hour(s), 41 minute(s), 22 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKCR\CLSID\{b33ee05e-0e9f-5672-5ac7-4fedac3dbf5c} (Adware.Ezula) -> No action taken.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 2
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Prof Chaos\AppData\Local\omy.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> No action taken.
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Prof Chaos\AppData\Local\omy.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> No action taken.

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Users\Prof Chaos\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\557550a0-300c7480 (Trojan.Agent.FSA36) -> No action taken.
C:\Users\Prof Chaos\QuickTime 7.70.80.34\Keygen\Keygen.exe (RiskWare.Tool.CK) -> No action taken.

(end)

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/19/2012 at 09:28 PM

Application Version : 5.6.1014

Core Rules Database Version : 9765
Trace Rules Database Version: 7577

Scan type : Complete Scan
Total Scan Time : 01:08:09

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Administrator

Memory items scanned : 680
Memory threats detected : 0
Registry items scanned : 70797
Registry threats detected : 0
File items scanned : 101069
File threats detected : 259

Adware.Tracking Cookie
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\NR1EY986.txt [ /msnportal.112.2o7.net ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\8VZBIBT2.txt [ /atdmt.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\518HV4FY.txt [ /revsci.net ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\TKQSQZRX.txt [ /ad.yieldmanager.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\RUUY4XA5.txt [ /c.atdmt.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\VNU92Q4P.txt [ /invitemedia.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\VPM0PONP.txt [ /advertising.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\QY8MJXR8.txt [ /apmebf.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\A49VY9S7.txt [ /doubleclick.net ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\KU8C203Y.txt [ /adtech.de ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\JVYT3PM9.txt [ /ad.propellerads.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\396YA2J4.txt [ /xiti.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\HZ09XRIU.txt [ /insightexpressai.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\MUZU3Y5X.txt [ /serving-sys.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\43HEWRU8.txt [ /mediaplex.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\0F89OHIO.txt [ /fastclick.net ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\FL3OUTD0.txt [ /7.rotator.wigetmedia.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\U76DIBJW.txt [ /clickbooth.com ]
C:\Users\Prof Chaos\AppData\Roaming\Microsoft\Windows\Cookies\49702MDH.txt [ /imrworldwide.com ]
C:\USERS\PROF CHAOS\AppData\Roaming\Microsoft\Windows\Cookies\2V2K9J86.txt [ Cookie:prof chaos@adsonar.com/adserving ]
C:\USERS\PROF CHAOS\AppData\Roaming\Microsoft\Windows\Cookies\Low\2W0GPR73.txt [ Cookie:prof chaos@atdmt.com/ ]
C:\USERS\PROF CHAOS\AppData\Roaming\Microsoft\Windows\Cookies\Low\47R6YB60.txt [ Cookie:prof chaos@c.atdmt.com/ ]
C:\USERS\PROF CHAOS\Cookies\NR1EY986.txt [ Cookie:prof chaos@msnportal.112.2o7.net/ ]
C:\USERS\PROF CHAOS\Cookies\8VZBIBT2.txt [ Cookie:prof chaos@atdmt.com/ ]
C:\USERS\PROF CHAOS\Cookies\TKQSQZRX.txt [ Cookie:prof chaos@ad.yieldmanager.com/ ]
C:\USERS\PROF CHAOS\Cookies\2V2K9J86.txt [ Cookie:prof chaos@adsonar.com/adserving ]
C:\USERS\PROF CHAOS\Cookies\RUUY4XA5.txt [ Cookie:prof chaos@c.atdmt.com/ ]
C:\USERS\PROF CHAOS\Cookies\VNU92Q4P.txt [ Cookie:prof chaos@invitemedia.com/ ]
C:\USERS\PROF CHAOS\Cookies\VPM0PONP.txt [ Cookie:prof chaos@advertising.com/ ]
C:\USERS\PROF CHAOS\Cookies\QY8MJXR8.txt [ Cookie:prof chaos@apmebf.com/ ]
C:\USERS\PROF CHAOS\Cookies\A49VY9S7.txt [ Cookie:prof chaos@doubleclick.net/ ]
C:\USERS\PROF CHAOS\Cookies\HZ09XRIU.txt [ Cookie:prof chaos@insightexpressai.com/ ]
C:\USERS\PROF CHAOS\Cookies\MUZU3Y5X.txt [ Cookie:prof chaos@serving-sys.com/ ]
C:\USERS\PROF CHAOS\Cookies\43HEWRU8.txt [ Cookie:prof chaos@mediaplex.com/ ]
C:\USERS\PROF CHAOS\Cookies\0F89OHIO.txt [ Cookie:prof chaos@fastclick.net/ ]
C:\USERS\PROF CHAOS\Cookies\FL3OUTD0.txt [ Cookie:prof chaos@7.rotator.wigetmedia.com/ ]
C:\USERS\PROF CHAOS\Cookies\U76DIBJW.txt [ Cookie:prof chaos@clickbooth.com/ ]
C:\USERS\PROF CHAOS\Cookies\49702MDH.txt [ Cookie:prof chaos@imrworldwide.com/cgi-bin ]
cdn1.static.pornhub.phncdn.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
core.saymedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
ia.media-imdb.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
media.mtvnservices.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
primeloopstracking.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
secure-uk.imrworldwide.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
secure-us.imrworldwide.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
www.99counters.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
www.soundclick.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MYX6P66L ]
accounts.google.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\UWL5SIMO.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.histats.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.histats.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
7.rotator.wigetmedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
7.rotator.wigetmedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.meta.wikimedia.org [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.meta.wikimedia.org [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.commons.wikimedia.org [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.commons.wikimedia.org [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
in.getclicky.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.xiti.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.dmtracker.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
wmedia.rotator.hadj7.adjuggler.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
insight.torbit.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
wstat.wibiya.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.multimedialibrary.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.bs.serving-sys.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.flagcounter.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.tns-counter.ru [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.flagcounter.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.warez-bb.org [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.warez-bb.org [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.warez-bb.org [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.multimedialibrary.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.insightexpressai.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.insightexpressai.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.webstatsdomain.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.webstatsdomain.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.webstatsdomain.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
boards.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.everyscreenmedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www7.addfreestats.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.timeoutcommunications.122.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
torrent-tracker.info [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mmstat.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.cnzz.mmstat.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.etracker.de [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.etracker.de [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.timeinc.122.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
pulse-analytics-beacon.reutersmedia.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media2.legacy.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.pro-market.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.pentonmedia.122.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.eventbrite.122.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
uk.sitestat.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
uk.sitestat.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
nl.sitestat.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
nl.sitestat.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.webstats4u.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
stat.dealtime.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.nextag.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.nextag.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.nextag.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.nextag.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.nextag.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.nextag.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.nextag.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.growingelitemarijuana.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.growingelitemarijuana.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.geoadserving.coffeetree.info [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
search.freefind.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mtvn.112.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.solvemedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.solvemedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.solvemedia.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.stats.complex.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.stats.complex.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.findthebest.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.findthebest.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.rambler.ru [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.hotlog.ru [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www2.findbest-games.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.freescorefinder.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.freescorefinder.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.freescorefinder.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
click.filtreroomx9.in [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
bridge.ame.admarketplace.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.admarketplace.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.ipcmedia.122.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
click.livesearchnow.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www2.findbest-games.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media2.legacy.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media2.legacy.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.toplist.cz [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.otclick-adv.ru [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
counter.nn.ru [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.rambler.ru [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.toplist.sk [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.toplist.eu [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.s.clickability.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.s.clickability.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.prnewswire.122.2o7.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
server.iad.liveperson.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.liveperson.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
video.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
video.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.adultswim.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
www.mediafire.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\PROF CHAOS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YS7PJK3R.DEFAULT-1344973092455\COOKIES.SQLITE ]

Trojan.Agent/Gen-Barys
C:\USERS\PROF CHAOS\APPDATA\LOCALLOW\SUN\JAVA\DEPLOYMENT\CACHE\6.0\32\557550A0-300C7480

Edited by professorchaos, 19 December 2012 - 09:34 PM.


#15 noknojon

noknojon

  • Banned
  • 10,871 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:03:27 AM

Posted 20 December 2012 - 03:27 AM

Re-run Malwarebytes and make sure all of these are marked to be removed then Reboot
There are many infections shown in both scans - I need you to DELETE everything from both of these programs and REBOOT after -

This list below is Very Bad -

Registry Keys Detected: 1
HKCR\CLSID\{b33ee05e-0e9f-5672-5ac7-4fedac3dbf5c} (Adware.Ezula) -> No action taken.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 2
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Prof Chaos\AppData\Local\omy.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> No action taken.
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Prof Chaos\AppData\Local\omy.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> No action taken.

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Users\Prof Chaos\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\557550a0-300c7480 (Trojan.Agent.FSA36) -> No action taken.
C:\Users\Prof Chaos\QuickTime 7.70.80.34\Keygen\Keygen.exe (RiskWare.Tool.CK) -> No action taken.

Post back with new logs from Malwarebytes and SUPERAntiSpyware after you remove these listed problems -

Thank You - :)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users