Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Restricted site removal help.


  • Please log in to reply

#1
avajo4

avajo4

    Member

  • Member
  • PipPip
  • 52 posts
hi all and thanks right off the bat.

I am trying to go to commision junction www.cj.com and linkshare.com. I found cj.com on the restricted site list and removed it, but it still wont let me open the page.

There are a lot of pages that I want to access(i know they are safe or pretty safe anyway) but it keeps telling me they are restricted. As always, i either cant find them on any lists, or i remove and still can't get access, still says restricted site.

I have ewido, spybot search and destroy, ad aware, spyware blaster, spyware guard, and avg.

I am operating windows xp. I am using internet explorer. Are there numerous places I need to take these off of a restricted site list?

I have went to security and privacy to try to fix this. Linkshare.com was not on anything for me to remove.
I went to live chat and they said to post a HJT log here. Any help would be appreciated.


Thanks again


My HJT log


Logfile of HijackThis v1.99.1
Scan saved at 6:39:41 PM, on 11/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\lexpps.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\uWDF.exe
C:\WINDOWS\system32\uWDF.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Vania\Desktop\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Instant Update Reminder.lnk = ?
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe
O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.ancestry.com
O15 - Trusted Zone: www.cj.com
O15 - Trusted Zone: *.commisionjunction.com
O15 - Trusted Zone: http://www.genealogybuff.com
O15 - Trusted Zone: http://*.linkshare.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg...t/c381/chat.cab
O16 - DPF: Yahoo! Euchre - http://download.game...nts/y/et1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.game...ts/y/pote_x.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety....lscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1129227008656
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {92CA8ACC-4E99-4A2A-93F1-B2C5CADC8613} - http://a14.g.akamai....GAPANEL_USA.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinn...v45/wof/wof.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinn...man/hangman.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://lopes.armstro...timage40803.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.116...2/View22RTE.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinn...paint/paint.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A550C0AA-0AF5-44D9-BFF8-ABB004E6F58C}: NameServer = 216.49.160.28 216.49.160.66
O20 - AppInit_DLLs:
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\system32\ImapiRox.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
  • 0

Advertisements


#2
rambro

rambro

    Member 1K

  • Member
  • PipPipPipPip
  • 1,383 posts
Dear avajo4, :whistling:

Welcome to the Geeks to Go forums.

We are currently studying your log. :blink:
*************************************

You are currently running HijackThis from your desktop. Since HijackThis makes backups of any entries you fix, you should create a folder just to hold the HijackThis program and its backups, so the backups and the program are not accidentally deleted. Go to "My Computer", click on c:\ and then go to the "File" menu, choose New -> Folder. Name the folder "HJT" or "HijackThis" and then please move the "HijackThis.exe" executable there.
****************************************

The following is important. I would like you to disable the "real time" protection of your "Spywareguard" software. After your computer is clean of spyware, you can re-enable the real time protection for this software. Here is how it can be done:

SpywareGuard
  • Right click the running icon of SpywareGuard in the system tray to open the program.
  • Click on the "Options" button on the left hand side of the program. This will display a "SpywareGuard Options" dialog box.
  • Click on the "General" link, under "General Protection Options", uncheck the "Enable Real Time Scanning" checkbox and press the "Save Settings" button.
  • Then go to Menu, File, and choose Exit.
  • An "Exit SpywareGuard?" dialog box will pop up. Click on the "Yes" button.
rambro :help:
  • 0

#3
avajo4

avajo4

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
Thanks for the help.

I did what you have said to do.

I feel like diableing everything, I am so crazy right now.
  • 0

#4
rambro

rambro

    Member 1K

  • Member
  • PipPipPipPip
  • 1,383 posts
Dear avajo4, :whistling:

Just hang in there. I am in the process of analyzing your HijackThis log an will get a post out to you asap. :blink:

rambro :help:
  • 0

#5
avajo4

avajo4

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
I also have ie-spyad, maybe I should remove that.

Thanks
  • 0

#6
rambro

rambro

    Member 1K

  • Member
  • PipPipPipPip
  • 1,383 posts
Dear avajo4, :whistling:

No, don't uninstall iespyad.

(Note: Please read through these instructions a couple of times before executing the steps in this post.)

You may want to print out these instructions or save them as a text file with "Notepad" to your desktop.
******************************

Please download WinHelp2002's DelDomains by right-clicking on the following link, and choosing "Save Target As": http://www.mvps.org/.../DelDomains.inf. Save the file to the desktop. Then go to the desktop, right click on DelDomains.inf, and choose Install. You may not see any noticeable changes or prompts; this is normal. Certain programs will have to be reimmunized for example, SpywareBlaster, IE-SPYAD, and/or Spybot Search and Destroy, after doing the above procedure (i.e. that is, if you have these programs installed on your computer).

Please restart your computer.
**********************************

Click Start then Control Panel then Add and Remove Programs. Look for the following installed program/programs and if they are listed click on each one and then click on the Remove or Change button and if asked select "Yes" or "Ok" to remove:

Optional programs you can uninstall, through the Add/Remove program:

BitTorrent is a Peer to Peer (P2P) file-sharing client. Note - as with all P2P sharing programs they are susceptible to various forms of malware". That is, "BitTorrent" is a program that can be used as a vehicle for downloading spyware on to your computer system.

Uninstall the following program/programs through Add/Remove programs:

BitTorrent

See the following link as a reference: http://p2p.malwarere....com/index.html - You decide.
*****************************

Run HijackThis and click "Scan." Place checks next to the following entry/entries (if they exist):

O4 - Global Startup: Instant Update Reminder.lnk = ?

O15 - Trusted Zone: www.ancestry.com
O15 - Trusted Zone: www.cj.com
O15 - Trusted Zone: *.commisionjunction.com
O15 - Trusted Zone: http://www.genealogybuff.com
O15 - Trusted Zone: http://*.linkshare.com

O20 - AppInit_DLLs:

Optional Fixes

I highly recommend you fix thes items:

If you choose to remove BitTorrent, put a check next to the following entry as well:

O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
*********************

You have PowerReg Scheduler in your log. This is a registration reminder that is used by a number of different companies. It is not needed and some people think that it reports back to the company about your computer, so I suggest fixing it...

O4 - Startup: PowerReg Scheduler.exe

Close all browser and other windows except for HijackThis, and click "Fix Checked" button to finish the repair. Close the HijackThis application.

Next, make sure your PC is configured to show hidden files. Here is how to do this:

Windows XP

* Click "Start".
* Open "My Computer".
* Select the "Tools" menu and click "Folder Options".
* Select the "View" Tab.
* Under the "Hidden files and folders" heading select "Show hidden files and folders".
* Make sure "Hide extensions for known file types" is unchecked
* Uncheck the "Hide protected operating system files (recommended)" option.
* Click "Yes" to confirm.
* Click "OK".

Here is a link for further explanation: http://www.xtra.co.n...1916458,00.html

Delete the following file/files marked in blue (if they exist):

Delete the following folder/folders marked in blue (if they exist):

Optional folder/folders marked in blue to be deleted (if they exist):

If you uninstalled BitTorrent you need to remove the next folder also:

C:\Program Files\BitTorrent

Finally, clean out temporary and Temporary Internet files. Go to Start -> Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

Restart your computer.
****************************************************

Please download and run a Free Trial of Trojan Hunter at http://www.misec.net...rojanHunter.exe. Please restart your computer.
***********************************

TrendMicro™ HouseCall ActiveX Scan
  • Please go HERE to run the Trend Micro™ HouseCall Scan.
  • Click Scan now. It's free!
  • Read and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • Under "Browser plug-in" Installing and using Housecall kernel, click the Starting HouseCall>> button.
  • You may receive a prompt to install the ActiveX, click install.
  • If you are taken back to the main page, click Launching HouseCall>> button again.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.
When the scan is finished, please restart your computer.
*******************************

Download, install, update, configure and run a scan with Ad-Aware SE at the following link: http://rstones12.gee...areSE_setup.htm

Restart your computer.
************************************

Restart your computer and then please post a new HijackThis log.

In addition, let me know in detail how your computer system is running after performing the above steps. :blink:
  • 0

#7
avajo4

avajo4

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
Thanks for the help. I followed your instructions.

I still cannot access www.linkshare or www.cj.com. On msn search, it says we can't find www.linkshare.com. On Yahoo search, it brings me to a search page, but any links that I try to go into it takes me to This page cannot be diplayed. It is the same for commission junction sites, and a lot of other sites. This is nuts!, I feel like it is so simple to fix and for the life of me I can't figure this out.

I have been trying to find my ancestry as of late, a lot of newpaper sites that I have been trying to access does the same thing. They seem to be going through bfast.com but does never connect.

Here is my HJT log


Logfile of HijackThis v1.99.1
Scan saved at 6:51:11 PM, on 11/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe
O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg...t/c381/chat.cab
O16 - DPF: Yahoo! Euchre - http://download.game...nts/y/et1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.game...ts/y/pote_x.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety....lscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1129227008656
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {92CA8ACC-4E99-4A2A-93F1-B2C5CADC8613} - http://a14.g.akamai....GAPANEL_USA.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinn...v45/wof/wof.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinn...man/hangman.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://lopes.armstro...timage40803.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.116...2/View22RTE.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinn...paint/paint.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A550C0AA-0AF5-44D9-BFF8-ABB004E6F58C}: NameServer = 216.49.160.28 216.49.160.66
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\system32\ImapiRox.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

Thanks again

Edited by avajo4, 03 November 2006 - 06:07 PM.

  • 0

#8
avajo4

avajo4

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
Here ya go OSC

# This MVPS HOSTS file is a free download from: #
# http://www.mvps.org/winhelp2002/ #
# #
# Notes: the browser does not read this "#" symbol #
# You can create your own notes, after the # symbol #
# This *must* be the first line: 127.0.0.1 localhost #
# ********************************************************#
# ------------------Updated: 03-09-06---------------------#
# ********************************************************#
# Entries marked with Parasite or Trojan comments should #
# be placed in the Internet Explorer Restricted Zone. #
# http://mvps.org/winh.../restricted.htm #
# #
# Entries with other comments are searchable via Google. #
# #
# Disclaimer: this file is free to use, however it is NOT #
# permitted to post on any other site without permission. #
# #
# This work is licensed under the Creative Commons #
# Attribution-NonCommercial-ShareAlike License. #
# http://creativecommo...s/by-nc-sa/2.0/ #

127.0.0.1 localhost

#start of lines added by WinHelp2002
# [Misc A - Z]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net
127.0.0.1 b.abnad.net
127.0.0.1 c.abnad.net #[IE-SpyAd]
127.0.0.1 d.abnad.net
127.0.0.1 e.abnad.net
127.0.0.1 www.accoona.cn
127.0.0.1 www.accoona.com #[Adware-Accoona][Adware.Atoolb][Panda.Accoona]
127.0.0.1 gtcc1.acecounter.com
127.0.0.1 gtp1.acecounter.com
127.0.0.1 acestats.com
127.0.0.1 www.acestats.com
127.0.0.1 data2.activshopper.com #[Trackware.ActivShopper]
127.0.0.1 search.activshopper.com
127.0.0.1 www.activshopper.com #[McAfee.Adware-ActivShop]
127.0.0.1 www.activesearch.com #[Adware.ActiveSearch]
127.0.0.1 actualnames.com #[Parasite.ActualNames][Spyware.ActualNames]
127.0.0.1 www.actualnames.com
127.0.0.1 ad-up.com
127.0.0.1 www.ad-up.com
127.0.0.1 adbest.com #[IE-SpyAd]
127.0.0.1 ad.adbest.com
127.0.0.1 www.adcipta.net #[Norman.W32/Malware]
127.0.0.1 adserv.adbonus.com #[IE-SpyAd]
127.0.0.1 www.adbonus.com
127.0.0.1 james.adbutler.de #[Tenebril.TrackingCookie]
127.0.0.1 www.adbutler.de #[SunBelt.AdButler.de]
127.0.0.1 media.adcentriconline.com #[IE-SpyAd]
127.0.0.1 ad2.adcept.net
127.0.0.1 ad3.adcept.net
127.0.0.1 www.adcept.net #[IE-SpyAd]
127.0.0.1 adcomplete.com #[IE-SpyAd]
127.0.0.1 www.adcomplete.com
127.0.0.1 www.adcopy.info
127.0.0.1 ads.adcorps.com #[verticalwebventures.com]
127.0.0.1 ads2.adcorps.com
127.0.0.1 ads.addynamix.com #[IE-SpyAd][SpySweeper.Spy.Cookie]
127.0.0.1 ad5.adecn.com #[SpySweeper.Spy.Cookie][IE-SpyAd]
127.0.0.1 www.adengage.com
127.0.0.1 pt.server1.adexit.com
127.0.0.1 www.adexit.com #[IE-SpyAd]
127.0.0.1 www.ad4ever.com #[IE-SpyAd]
127.0.0.1 www.ad-groups.com #[Ban Man Pro Banner Code]
127.0.0.1 host1.adhese.be #[Adhese Datamine Tag]
127.0.0.1 host2.adhese.be
127.0.0.1 host3.adhese.be #[ad.be.doubleclick.net]
127.0.0.1 host4.adhese.be
127.0.0.1 ssl3.adhost.com #[IE-SpyAd]
127.0.0.1 www2.adhost.com
127.0.0.1 www.adimpact.com
127.0.0.1 adinterax.com
127.0.0.1 ad0.adinterax.com
127.0.0.1 mi.adinterax.com
127.0.0.1 tr.adinterax.com
127.0.0.1 www.adinterax.com
127.0.0.1 www.addme.com #[IE-SpyAd]
127.0.0.1 adsvr.adknowledge.com #[IE-SpyAd]
127.0.0.1 web.adknowledge.com #[McAfee.Cookie-Adknowledge]
127.0.0.1 te.adlandpro.com #[IE-SpyAd]
127.0.0.1 ad.adlegend.com #[blocks Webroot Amber Alert]
127.0.0.1 media.adlegend.com
127.0.0.1 classic.adlink.de #[IE-SpyAd]
127.0.0.1 regio.adlink.de
127.0.0.1 west.adlink.de
127.0.0.1 www.adminder.com #[IE-SpyAd][SpySweeper.Spy.Cookie]
127.0.0.1 s1.ad.adocean.pl #[Ewido.Spyware.Cookie.Adocean]
127.0.0.1 ad01.adonspot.com #[IE-SpyAd]
127.0.0.1 ad02.adonspot.com
127.0.0.1 isohunt.adonspot.com
127.0.0.1 www.adonweb.com
127.0.0.1 www.adquest.nl
127.0.0.1 adreactor.com #[IE-SpyAd]
127.0.0.1 adserver.adreactor.com #[Ad-Aware Tracking Cookie]
127.0.0.1 www.adrelevance.com #[NetRatings][IE-SpyAd]
127.0.0.1 adserver.adremedy.com #[Ad-Aware Tracking Cookie]
127.0.0.1 media.adrevolver.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 track.adrevolver.com #[IE-SpyAd][McAfee.Cookie-Adrevolver]
127.0.0.1 ad.adriver.ru
127.0.0.1 serv.ad-rotator.com #[SpySweeper.Spy.Cookie]
127.0.0.1 166.ads8.com
127.0.0.1 ad.ads8.com
127.0.0.1 vip.ads8.com
127.0.0.1 livelines.ads365.com
127.0.0.1 www.ads365.com #[IE-SpyAd]
127.0.0.1 ad.ads.dk #[IE-SpyAd]
127.0.0.1 tdkads.ads.dk
127.0.0.1 ads.adsag.com #[SpySweeper.Spy.Cookie]
127.0.0.1 di.adsag.com
127.0.0.1 img.adsag.com
127.0.0.1 adsfac.net #[Facilitate Tracking Code][IE-SpyAd]
127.0.0.1 37.adsonar.com
127.0.0.1 ads.adsonar.com
127.0.0.1 js.adsonar.com
127.0.0.1 serv.adspeed.com
127.0.0.1 www.adsprve1.com #[IE-SpyAd]
127.0.0.1 www.adsvillage.com #[AdPeeps.com]
127.0.0.1 adtology.com
127.0.0.1 downldcl.adtoolsinc.com
127.0.0.1 www.adtoolsinc.com #[IE-SpyAd]
127.0.0.1 www.adtrader.com #[IE-SpyAd]
127.0.0.1 adtraffic.com
127.0.0.1 www.adtraffic.net #[eTrust.Adtraffic]
127.0.0.1 survey.advantageresearch.com #[IE-SpyAd]
127.0.0.1 ad.adver.com.tw
127.0.0.1 ads.advertise.net #[IE-SpyAd]
127.0.0.1 advertisingvision.com #[IE-SpyAd]
127.0.0.1 www.advertisingvision.com #[Adware.Advision]
127.0.0.1 adviva.com #[IE-SpyAd]
127.0.0.1 www.adviva.com
127.0.0.1 ads.adviva.net #[IE-SpyAd]
127.0.0.1 adstats.adviva.net
127.0.0.1 aeoworld.de
127.0.0.1 www.aeoworld.de #[W32/WMF-exploit]
127.0.0.1 tracker.affistats.com #[IE-SpyAd][msvrl.dll]
127.0.0.1 fcds.affiliatetracking.net
127.0.0.1 our.affiliatetracking.net
127.0.0.1 www.affiliatetracking.net #[IE-SpyAd]
127.0.0.1 www.affiliatetracking.com #[IE-SpyAd]
127.0.0.1 adz.afterdawn.net
127.0.0.1 aams1.aim4media.com
127.0.0.1 adcodes.aim4media.com
127.0.0.1 adserver.aim4media.com #[SunBelt.Adserver.aim4media]
127.0.0.1 adtest.aim4media.com
127.0.0.1 artwork.aim4media.com
127.0.0.1 pops.aim4media.com
127.0.0.1 www.aim4media.com #[IE-SpyAd]
127.0.0.1 adlik2.akavita.com
127.0.0.1 download.alexa.com #[Trackware.Alexa][SPYW_ALEXA.A]
127.0.0.1 download.china.alibaba.com #[Adware.AlibabaTB][AdWare.ToolBar.Alibabar.b]
127.0.0.1 all-answers.info #[ISANS.Alert]
127.0.0.1 click.allfeeds.com #[IE-SpyAd]
127.0.0.1 tracking.allposters.com
127.0.0.1 www.allthatsearch.com #[IE-SpyAd]
127.0.0.1 www.almoso3h.com #[Trojan-PSW.Win32.VB.cl]
127.0.0.1 ads.as4x.tmcs.akadns.net #[Ticketmaster][IE-SpyAd]
127.0.0.1 bantam.ai.net #[IE-SpyAd]
127.0.0.1 fiona.ai.net
127.0.0.1 www.amazingcounters.com
127.0.0.1 ads.amazingmedia.com #[IE-SpyAd]
127.0.0.1 banner.ambercoastcasino.com #[IE-SpyAd]
127.0.0.1 adserver.ancestry.com #[RealMedia]
127.0.0.1 adserver04.ancestry.com #[RealMedia]
127.0.0.1 anico24.com #[Panda.AKStealer.A]
127.0.0.1 www.anico24.com
127.0.0.1 www.anosurfer.com #[Win32/Adware.SpySheriff][Trojan.Fakealert.Vp]
127.0.0.1 search.antarasystems.com #[Spyware.SearchPounder]
127.0.0.1 www.antarasystems.com
127.0.0.1 ads.antionline.com
127.0.0.1 junior.apk.net
127.0.0.1 banner.arttoday.com
127.0.0.1 ads.asia1.com.sg
127.0.0.1 asimpleinternet.com #[Parasite.SpecialOffers]
127.0.0.1 www.asimpleinternet.com #[IE-SpyAd]
127.0.0.1 ads.aspalliance.com
127.0.0.1 dist.atlas-ia.com #[ADW_ATLAST.A]
127.0.0.1 www.atlas-ia.com #[Adware.OfferAgent][Adware-Atlas]
127.0.0.1 audiogalaxy.com
127.0.0.1 www.audiogalaxy.com
127.0.0.1 www.autosurfpro.com #[IE-SpyAd]
127.0.0.1 adserving.autotrader.com #[SunBelt.AdServing.AutoTrader.com]
127.0.0.1 cploving.awmhost.net #[TrojanClicker.Win32.Lopin]
127.0.0.1 axload.to #[Adware.Webprefix]
127.0.0.1 valid.axload.to
127.0.0.1 www.azads.net #[IE-SpyAd]
# [B]
127.0.0.1 bar.baidu.com #[SPYW_BDPLUGIN.A][Sophos.JS/BDHelper-A]
127.0.0.1 www.baltictop.com
127.0.0.1 www.banex.ca #[IE-SpyAd]
127.0.0.1 adserver.banneradministration.com
127.0.0.1 bannerboxes.com #[BannerBoxes Ad Code]
127.0.0.1 clicks.bannerboxes.com
127.0.0.1 feeds.bannerboxes.com
127.0.0.1 www.bannerboxes.com
127.0.0.1 ad.bannerconnect.net
127.0.0.1 ads.bannerconnect.net
127.0.0.1 www.banner-exchange.nl #[IE-SpyAd]
127.0.0.1 ad.bannerhost.ru
127.0.0.1 www.bannermanagement.nl #[IE-SpyAd]
127.0.0.1 www.bannerpromotion.it #[IE-SpyAd]
127.0.0.1 www.banner-mania.com
127.0.0.1 www.bannerspace.com #[IE-SpyAd]
127.0.0.1 www2.bannerspace.com
127.0.0.1 www3.bannerspace.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www5.bannerspace.com
127.0.0.1 www6.bannerspace.com
127.0.0.1 www7.bannerspace.com #[Tenebril.Tracking Cookie]
127.0.0.1 bannerswap.com #[IE-SpyAd]
127.0.0.1 www.bannerswap.com
127.0.0.1 bardownload.com
127.0.0.1 www.bardownload.com #[MHTMLRedir.Exploit][007installer Control]
127.0.0.1 media.baventures.com
127.0.0.1 beehappyy.biz #[Kephyr.PUP][W32/PFV-Exploit.A]
127.0.0.1 www.beehappyy.biz #[Trojan-Downloader.Win32.Small.awa]
127.0.0.1 www.besttoolbars.net #[ADW_TBARWIN32.A]
127.0.0.1 ads.betanews.com
127.0.0.1 ads.bidclix.com #[IE-SpyAd]
127.0.0.1 www.bidclix.com
127.0.0.1 bidclix.net #[IE-SpyAd]
127.0.0.1 www.bidclix.net
127.0.0.1 ads.bidvertiser.com #[IE-SpyAd]
127.0.0.1 bdv.bidvertiser.com
127.0.0.1 www.bidvertiser.com
127.0.0.1 c.bigmir.net
127.0.0.1 bigtracker.com
127.0.0.1 bighits.net #[IE-SpyAd]
127.0.0.1 bigticker.bighits.net
127.0.0.1 bounty.bighits.net
127.0.0.1 www.bighits.net
127.0.0.1 download.bigwebportal.com #[IE-SpyAd]
127.0.0.1 www.bigwebportal.com #[hotwebsearch.com]
127.0.0.1 counter.bizland.com
127.0.0.1 webads.bizservers.com
127.0.0.1 www.black-hole.co.uk
127.0.0.1 blacksoft.info #[Trojan-Dropper.Win32.Microjoin.b][server down?]
127.0.0.1 ads.blick.ch
127.0.0.1 cluster.blingblingcontent.com
127.0.0.1 gb.blingblingcontent.com
127.0.0.1 s7.blingblingcontent.com #[HJTH.EasyWebSearch Hijacker]
127.0.0.1 blockchecker.com #[IE-SpyAd]
127.0.0.1 weblog.blogads.com
127.0.0.1 images.blogads.com
127.0.0.1 images2.blogads.com
127.0.0.1 proxy.blogads.com
127.0.0.1 lg.proxy.blogads.com
127.0.0.1 www.blogads.com
127.0.0.1 counter.blogexplosion.com
127.0.0.1 www.blogpatrol.com
127.0.0.1 blogmark.bokee.com #[Adware.BocaiToolbar]
127.0.0.1 www.borlander.cn #[Adware.Borlan]
127.0.0.1 download.bravesentry.com
127.0.0.1 support.bravesentry.com
127.0.0.1 www.bravesentry.com #[NOD32.Win32/Adware.SpySheriff.variant]
127.0.0.1 bans.bride.ru #[IE-SpyAd]
127.0.0.1 citi.bridgetrack.com #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 rccl.bridgetrack.com #[MVPS.Criteria]
127.0.0.1 www.browserplugin.com #[HJTH.EroticAccess][wobz.de]
127.0.0.1 redemption.bullseye-media.net
127.0.0.1 users.bullseye-media.net
127.0.0.1 www.bullseye-media.net #[IE-SpyAd]
127.0.0.1 www.buildtraffic.com
# [C]
127.0.0.1 images.cashfiesta.com #[AdWare.CashFiesta.a]
127.0.0.1 www.cashfiesta.com #[McAfee.Adware-CashFiesta]
127.0.0.1 www.cashfiesta.net
127.0.0.1 www.cashventure.com
127.0.0.1 affiliate.casinorewards.com
127.0.0.1 deliver.castads.com
127.0.0.1 images.castads.com
127.0.0.1 serve.castads.com
127.0.0.1 www.care2.com #[HJTH.TopMoxie]
127.0.0.1 ads.cars.com
127.0.0.1 msg.cd321.com #[Trojan.Startpage.Q]
127.0.0.1 www.cd321.com
127.0.0.1 ads.cdfreaks.com #[eTrust.Ads.cdfreaks]
127.0.0.1 cellaphone.net #[MHTMLRedir.Exploit]
127.0.0.1 www.celebritaspoglie.net #[IE-SpyAd]
127.0.0.1 mds.centrport.net #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 www.cerials.net #[HJTH.C2Media/LOP variant]
127.0.0.1 www.certdreams.com #[Trojan.Satiloler.D]
127.0.0.1 abc.checkm8.com
127.0.0.1 rmm1u.checkm8.com
127.0.0.1 web.checkm8.com #[CHECKM8 AD TAGS]
127.0.0.1 ads.chellomedia.com
127.0.0.1 ad.cibleclick.com
127.0.0.1 www.cibleclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.classifieds1000.com
127.0.0.1 clearfind.com
127.0.0.1 www.clearfind.com #[IE-SpyAd]
127.0.0.1 ads.clickad.com #[eTrust.Tracking Cookie]
127.0.0.1 hits.clickandtrack.net #[SpySweeper.Spy.Cookie]
127.0.0.1 clickbank.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 hop.clickbank.net #[Adware.Clickbank][Adware.ClickDLoader]
127.0.0.1 ssl.clickbank.net
127.0.0.1 zzz.clickbank.net #[Ewido.TrackingCookie.Clickbank]
127.0.0.1 www.clickexchange.ru #[IE-SpyAd]
127.0.0.1 click2boost.com #[IE-SpyAd]
127.0.0.1 secure.click2boost.com
127.0.0.1 service.click2boost.com
127.0.0.1 www.click2boost.com
127.0.0.1 www.clicks2you.com #[IE-SpyAd]
127.0.0.1 clicktracks.com #[McAfee.Cookie-Clicktracks]
127.0.0.1 stats.clicktracks.com #[Tenebril.Tracking Cookie]
127.0.0.1 stats1.clicktracks.com # [eTrust.Tracking Cookie]
127.0.0.1 stats2.clicktracks.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.clicktracks.com #[IE-SpyAd][SunBelt.ClickTracks]
127.0.0.1 www.is1.clixgalore.com
127.0.0.1 www.clixgalore.com #[IE-SpyAd]
127.0.0.1 www2.click-fr.com
127.0.0.1 www3.click-fr.com
127.0.0.1 www4.click-fr.com
127.0.0.1 www.clickhouse.com #[IE-SpyAd][SunBelt.ClickHouse]
127.0.0.1 www.clicks4u.com #[IE-SpyAd]
127.0.0.1 ad1.clickhype.com #[IE-SpyAd]
127.0.0.1 cfg.clipgenie.com
127.0.0.1 download.clipgenie.com
127.0.0.1 dldw.clipgenie.com
127.0.0.1 ss.clipgenie.com
127.0.0.1 www.clipgenie.com #[Adware.ClipGenie]
127.0.0.1 banner.clubdicecasino.com
127.0.0.1 www.cnstats.com
127.0.0.1 ads.cobrad.com
127.0.0.1 ct2.comclick.com #[Tenebril.Tracking Cookie]
127.0.0.1 fl01.ct2.comclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 ihm01.ct2.comclick.com
127.0.0.1 www.comclick.com #[Ewido.Spyware.Cookie.Comclick]
127.0.0.1 aa.connextra.com
127.0.0.1 bb.connextra.com
127.0.0.1 cc.connextra.com
127.0.0.1 dd.connextra.com
127.0.0.1 ee.connextra.com
127.0.0.1 ff.connextra.com
127.0.0.1 data.connextra.com
127.0.0.1 ads.contactmusic.com #[advertpro]
127.0.0.1 svp.contextuad.org #[IE-SpyAd]
127.0.0.1 ads.console.net
127.0.0.1 coolshader.com
127.0.0.1 c.coolshader.com #[Win32.Harnig]
127.0.0.1 www.coolshader.com
127.0.0.1 counted.com #[IE-SpyAd]
127.0.0.1 bilbo.counted.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.counted.com
127.0.0.1 www.counter-gratis.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.counterguide.com
127.0.0.1 counter4u.de #[IE-SpyAd]
127.0.0.1 www.counting4free.com #[IE-SpyAd]
127.0.0.1 www.countmypage.com
127.0.0.1 log1.countomat.com #[IE-SpyAd]
127.0.0.1 connectionzone.com
127.0.0.1 count.casino-trade.com
127.0.0.1 www.couponsandoffers.com #[Adware.TopMoxie]
127.0.0.1 data.coremetrics.com #[IE-SpyAd]
127.0.0.1 test.coremetrics.com #[SpySweeper.Spy.Cookie]
127.0.0.1 twci.coremetrics.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 server.cpmstar.com #[ads.shizmoo.com]
127.0.0.1 cracks.am #[eTrust.Cracks.am][ADW_CRAMTB.A]
127.0.0.1 www.cracks.am #[[bleep]-portal.com][Adware.CramToolbar]
127.0.0.1 www.crispads.com #[IE-SpyAd]
127.0.0.1 ads.crosswinds.net
127.0.0.1 megabyte.crosswinds.net
127.0.0.1 ads.crucialparadigm.com
127.0.0.1 cyberbounty.com #[IE-SpyAd]
127.0.0.1 js.cybermonitor.com #[McAfee.Cookie-Cybermonitor]
127.0.0.1 stat3.cybermonitor.com
127.0.0.1 search.cygo.net
127.0.0.1 www.cygo.net #[McAfee.Adware-Cygo]
127.0.0.1 cytron.com #[DailyWinner][eTrust.Cytron]
127.0.0.1 www.cytron.com
# [D]
127.0.0.1 dalvabrothersinc.com
127.0.0.1 www.dalvabrothersinc.com #[Trojan.Win32.Delf.qx]
127.0.0.1 banner.date.com #[Tenebril.Tracking Cookie]
127.0.0.1 ads.datinggold.com
127.0.0.1 au.track.decideinteractive.com
127.0.0.1 au.link.decideinteractive.com
127.0.0.1 eu.link.decideinteractive.com
127.0.0.1 link.decideinteractive.com
127.0.0.1 www.decideinteractive.com
127.0.0.1 www.decideinteractive.co.uk
127.0.0.1 www.deepcom.com #[TrojanDropper.Win32.Small.gt]
127.0.0.1 collector.deepmetrix.com
127.0.0.1 geo.deepmetrix.com
127.0.0.1 www.deepmetrix.com
127.0.0.1 delta2378493.com #[Download.Sumina]
127.0.0.1 deluxe-se.com #[Rogue/Suspect.sites]
127.0.0.1 ads.dennisnet.co.uk
127.0.0.1 ads.deviantart.com
127.0.0.1 track.did-it.com #[Panda.Spyware:Cookie/did-it]
127.0.0.1 diji-realm.net #[Backdoor.Mepcod]
127.0.0.1 www.digink.com #[PcTools.SysCheckBop32]
127.0.0.1 ads.digitalpoint.com
127.0.0.1 comm1.digits.com
127.0.0.1 counter.digits.com #[IE-SpyAd]
127.0.0.1 direct-ip.com #[Adware-DirectIP][SecurityRisk.DirectIP]
127.0.0.1 www.direct-ip.com #[Adware-DirectIP][Adware-CommanderNET]
127.0.0.1 banners.directnic.com
127.0.0.1 stats.directnic.com
127.0.0.1 cache.directorym.com #[c2.mii.instacontent.net]
127.0.0.1 www.divago.com #[Adware.Surfairy]
127.0.0.1 dlyasvobornyx.biz #[ISANS.Alert]
127.0.0.1 track.dmipartners.com
127.0.0.1 ad.dmpi.net
127.0.0.1 ad2.dmpi.net
127.0.0.1 ad3.dmpi.net
127.0.0.1 ad4.dmpi.net
127.0.0.1 ubnm.dmpi.net
127.0.0.1 www.dnscaching.net #[stickypops.com]
127.0.0.1 www.domamil.cz #[Trojan.Beagooz]
127.0.0.1 www.donttrip.org #[IE-SpyAd]
127.0.0.1 www.download-services.com #[VBA32.Trojan-Downloader.Agent.26]
127.0.0.1 www.downseek.com #[SunBelt.DownSeek Search]
127.0.0.1 dqmedia.net #[spam]
127.0.0.1 drmx01.net #[spam]
127.0.0.1 drc-group.net #[TR/Spy.Delf.MQ.2]
127.0.0.1 www.drc-group.net
127.0.0.1 www.claus.drehteile-rieche.de #[Win32.Formglieder.B]
127.0.0.1 www.drinkmagik.biz #[Trojan.Spbot.C]
127.0.0.1 ads.drugs.com
127.0.0.1 www.dudu.com #[Adware.DuDuAccelerator]
127.0.0.1 www.duenow.com
127.0.0.1 gfx.dvlabs.com #[IE-SpyAd]
127.0.0.1 klipads.dvlabs.com
# [E]
127.0.0.1 e2give.com #[Adware-E2Give][Spyware.e2give]
127.0.0.1 www.e2give.com
127.0.0.1 eaglehousing.com #[Trojan.Tabela.B]
127.0.0.1 www.eaglehousing.com #[Trojan.Eaghouse]
127.0.0.1 www.earncashontheinternet.com #[SunBelt.OpinionBar]
127.0.0.1 www.eastworldnetwork.com
127.0.0.1 easyhitcounters.com #[IE-SpyAd]
127.0.0.1 beta.easyhitcounters.com
127.0.0.1 www.easywebsearch.nl #[Easywebinstaller Control][IE-SpyAd]
127.0.0.1 www.e-bannerx.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.easycounter.com #[IE-SpyAd]
127.0.0.1 banners.easydns.com
127.0.0.1 banner.easyspace.com #[IE-SpyAd]
127.0.0.1 adserv1.ebates.com #[WebSavings]
127.0.0.1 www.ebates.com #[Adware.MoeMoney]
127.0.0.1 ads.ecrush.com #[AdvertPro]
127.0.0.1 www.ek21.com #[Trojan.Chost.B]
127.0.0.1 www.elancenet.org #[Worm/Eyeveg.CH]
127.0.0.1 ad1.emediate.dk
127.0.0.1 www.emusic.com #[McAfee.Adware-eMusic][F-Secure.Adware.eMusic]
127.0.0.1 entplanet.com #[McAfee.Painter]
127.0.0.1 www.entplanet.com
127.0.0.1 epeople.com
127.0.0.1 vipuk.escritorioactivo.com #[HJTH.123Messenger Hijacker]
127.0.0.1 www.escorcher.com #[IE-SpyAd]
127.0.0.1 www.eshopads2.com
127.0.0.1 estat.com #[IE-SpyAd]
127.0.0.1 perso.estat.com #[Ewido.Spyware.Cookie.Estat]
127.0.0.1 prof.estat.com
127.0.0.1 www.estat.com
127.0.0.1 adopt.euroclick.com
127.0.0.1 www.euroklik.nl #[EasyBar][HJTH.SinCity Dialer]
127.0.0.1 www.euros4click.de
127.0.0.1 engage.everyone.net
127.0.0.1 static.everyone.net #[IE-SpyAd]
127.0.0.1 ezcybersearch.mail.everyone.net
127.0.0.1 advert.exaccess.ru
127.0.0.1 dynamic.exaccess.ru #[IE-SpyAd]
127.0.0.1 www.exchangead.com #[IE-SpyAd]
127.0.0.1 exit-ad.de #[Ad-Aware.Tracking Cookie]
127.0.0.1 exitexchange.com #[IE-SpyAd]
127.0.0.1 count.exitexchange.com #[McAfee.Cookie-Exitexchange]
127.0.0.1 images.exitexchange.com
127.0.0.1 www.exitexchange.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.exchangeexit.com #[HJTH.Winupie]
127.0.0.1 www.exittrade.com
127.0.0.1 www.exittraffic.net #[IE-SpyAd]
127.0.0.1 nyton.experclick.com #[p.mii.instacontent.net]
127.0.0.1 www.experclick.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ads.expressindia.com
127.0.0.1 banners.expressindia.com
127.0.0.1 cdn.eyewonder.com #[IE-SpyAd][SunBelt.EyeWonder]
127.0.0.1 www.evidence-eliminator.com
127.0.0.1 www.eyeget.com #[McAfee.Adware-EyeGet]
127.0.0.1 eziin.com #[Adware.Eziin]
127.0.0.1 www.eziin.com
# [F]
127.0.0.1 www.fast-adv.it
127.0.0.1 www.fast2net.com
127.0.0.1 www.fastfind.org #[TROJ_STARTPAG.KF][Adware.Fastfind.B]
127.0.0.1 fasttrack.nu
127.0.0.1 counter.fateback.com
127.0.0.1 www.fatpickle.com #[FatPickle Toolbar][IE-SpyAd]
127.0.0.1 filesharingaccess.com #[MHTMLRedir.Exploit]
127.0.0.1 adserver.filefront.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.filemix.net #[Surf+][IE-SpyAd]
127.0.0.1 www.find.fm #[AdWare.SideSearch.g]
127.0.0.1 ads.firingsquad.com
127.0.0.1 ads2.firingsquad.com
127.0.0.1 firstname.com #[IE-SpyAd]
127.0.0.1 clicks.firstname.com
127.0.0.1 www.fish-screensaver.com #[AdWare.Win32.Gator.1008]
127.0.0.1 flyinads.com #[IE-SpyAd]
127.0.0.1 www.flyinads.com
127.0.0.1 cdn.flashedmail.com
127.0.0.1 tracker1.flashedmail.com #[IE-SpyAd]
127.0.0.1 adserver.fmpub.net
127.0.0.1 www.foofle.net #[Backdoor.Foobot]
127.0.0.1 js.forrestersurveys.com
127.0.0.1 charmedmadgic.free.fr #[PFV-Exploit.D]
127.0.0.1 securinews.free.fr #[Trojan.Hexem]
127.0.0.1 ads.freebannertrade.com #[AdNetPros Banner Code]
127.0.0.1 www.freedownloadhq.com #[SiteAdvisor.scam]
127.0.0.1 ad.freefind.com
127.0.0.1 www.freehistorycleaner.com #[Adware.Fapi][ADW_HISCLEAN.A]
127.0.0.1 freelogs.com
127.0.0.1 bar.freelogs.com
127.0.0.1 goo.freelogs.com
127.0.0.1 ico.freelogs.com
127.0.0.1 joe.freelogs.com
127.0.0.1 mom.freelogs.com
127.0.0.1 xyz.freelogs.com
127.0.0.1 adserver.freenet.de
127.0.0.1 free-stats.com
127.0.0.1 counters.freewebs.com
127.0.0.1 www.freewebsites.com
127.0.0.1 fullbizzone.com #[Trojan-Downloader.Win32.Small.caf]
127.0.0.1 www.fullbizzone.com
127.0.0.1 www.funbangladesh.com #[ysbweb.com][Purityscan]
127.0.0.1 funppc.com #[IE-SpyAd]
127.0.0.1 www.funppc.com
127.0.0.1 full-search.biz #[McAfee.StartPage-FC]
# [G]
127.0.0.1 oascentral.g4techtv.com #[RealMedia]
127.0.0.1 adserver.gadu-gadu.pl
127.0.0.1 ads.gamespy.com #[SpySweeper.Spy.Cookie]
127.0.0.1 adcontent.gamespy.com
127.0.0.1 ads.gamespyid.com
127.0.0.1 ad1.gamezone.com #[RealMedia]
127.0.0.1 server.gamyun.net
127.0.0.1 www.gamyun.net #[Adware.GamyunIeToolbar]
127.0.0.1 www.gebr-wachs.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 sda.geek.com #[AdvertPro]
127.0.0.1 adserver.geenstijl.nl
127.0.0.1 kassa.geenstijl.nl
127.0.0.1 gd.geobytes.com #[obtains users location]
127.0.0.1 banners.geotarget.info
127.0.0.1 www.geowhere.net #[SunBelt.GeoWhere Search]
127.0.0.1 www.getsmart.com
127.0.0.1 bp2.getredirect.com #[IE-SpyAd]
127.0.0.1 4.getredirect.com #[superlogy.com]
127.0.0.1 www.getredirect.com
127.0.0.1 getupdate.com
127.0.0.1 dlx.getupdate.com #[AdvWare.ToolBar.VB.b]
127.0.0.1 www.getupdate.com #[Adware.Getup]
127.0.0.1 toolbar.gimmeweb.com #[AdWare.ISearch.f][Adware.Softomate.A]
127.0.0.1 www.gimmeweb.com
127.0.0.1 banner.goldenpalace.com #[Tenebril.Tracking Cookie]
127.0.0.1 goldstats.net #[IE-SpyAd]
127.0.0.1 www.goldstats.net
127.0.0.1 www.goggle.com #[IE-SpyAd][typo squatter]
127.0.0.1 partner.gonamic.de
127.0.0.1 goodcounter.com #[IE-SpyAd]
127.0.0.1 www.goodcounter.com
127.0.0.1 adincl.gopher.com #[InfoSpace]
127.0.0.1 admonster.gorasoft.com #[TROJ_SMALL.AAL]
127.0.0.1 goserv.com #[Koffix Blocker]
127.0.0.1 gostats.com #[IE-SpyAd]
127.0.0.1 as.gostats.com
127.0.0.1 c1.gostats.com
127.0.0.1 c2.gostats.com #[SpySweeper.Spy.Cookie]
127.0.0.1 c3.gostats.com
127.0.0.1 c4.gostats.com
127.0.0.1 ded.gostats.com
127.0.0.1 monster.gostats.com
127.0.0.1 www.gotoo.com
127.0.0.1 webcounter.goweb.de #[IE-SpyAd]
127.0.0.1 greatsearch.biz #[Troj/Startpa-CE]
127.0.0.1 greatstartpage.com #[IE-SpyAd]
127.0.0.1 www.greatstartpage.com
127.0.0.1 www.greasypalm.co.uk #[PcTools.GreasyPalm bar]
127.0.0.1 ads.grokads.com
127.0.0.1 grokster.com #[IE-SpyAd][P2P]
127.0.0.1 dl.grokster.com
127.0.0.1 www.grokster.com
127.0.0.1 www.groovysearchesbar.com #[IE-SpyAd]
127.0.0.1 ads.guardian.co.uk
127.0.0.1 ads.guardianunlimited.co.uk
127.0.0.1 www.g-wizzads.net
# [H]
127.0.0.1 streamit.hardwarezone.com
127.0.0.1 www.harmonyhollow.net #[Adware Bundler]
127.0.0.1 ad0.haynet.com
127.0.0.1 stats.hecklerspray.com
127.0.0.1 www.henbang.net #[Adware.Henbang][SPYW_HAP.A]
127.0.0.1 hicuernavaca.com #[WMF-exploit]
127.0.0.1 www.hiperstat.com
127.0.0.1 ads.hitcents.com #[IE-SpyAd]
127.0.0.1 hits-counter.com
127.0.0.1 hithopper.com #[Adware.Hithopper]
127.0.0.1 www.hithopper.com #[ADW_HITHOPPER.A]
127.0.0.1 hitkorea.co.kr #[Adware.Atlcontrol]
127.0.0.1 www.hitlogger.com
127.0.0.1 hitmodel.net
127.0.0.1 www.hit-counts.com
127.0.0.1 hit-now.com
127.0.0.1 hit-parade.com
127.0.0.1 loga.hit-parade.com
127.0.0.1 hitstats.net
127.0.0.1 www.hittracking.com #[IE-SpyAd]
127.0.0.1 images.hitwise.co.uk
127.0.0.1 ads.home.net
127.0.0.1 anna.homeftp.net #[W32.Linkbot.A]
127.0.0.1 www.gontijoamaral.hpg.com.br #[Adware.Diginum]
127.0.0.1 counters.honesty.com
127.0.0.1 cgi.honesty.com #[MVPS.Criteria]
127.0.0.1 ad2.hotels.com
127.0.0.1 banners.hotlinks.net #[IE-SpyAd]
127.0.0.1 www.10s.com.br #[Trojan.Cargao]
127.0.0.1 cgi.hotstat.nl #[IE-SpyAd]
127.0.0.1 viewstat.hotstat.nl
127.0.0.1 ad.howstuffworks.com #[RealMedia][SpySweeper.Spy.Cookie]
127.0.0.1 vip.huigezi.com #[Backdoor.Graybird.Q][W32.Looked.F]
127.0.0.1 hc2.humanclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.humanclick.com #[IE-SpyAd][McAfee.Cookie-Humanclick]
127.0.0.1 custom1.hurricanedigitalmedia.com
127.0.0.1 custom3.hurricanedigitalmedia.com
127.0.0.1 www.hypertracker.com #[IE-SpyAd][SpySweeper.Spy.Cookie]
# [I]
127.0.0.1 ads.iafrica.com
127.0.0.1 ads.iboost.com
127.0.0.1 www.i-clicks.net
127.0.0.1 hits.icdirect.com #[SunBelt.ICDirect.com]
127.0.0.1 hitctr01.icdirect.com
127.0.0.1 ad.iconadserver.com #[ad.yieldmanager.com]
127.0.0.1 content.iconadserver.com
127.0.0.1 image-catcher.com
127.0.0.1 bar.iebar8.com #[Adware.Navihelper]
127.0.0.1 stats.surfaid.ihost.com #[IE-SpyAd]
127.0.0.1 gate.ilogbox.com
127.0.0.1 www.impregnable.net #[TrojanDownloader.Win32.VB.dw][Trojan.Win32.StartPage.kk]
127.0.0.1 ads.ims.nl
127.0.0.1 stats.indextools.com #[IE-SpyAd][eTrust.Tracking Cookie]
127.0.0.1 campaign.indieclick.com
127.0.0.1 adcenter.in2.com
127.0.0.1 ads.inet1.com
127.0.0.1 ads7.inet1.com
127.0.0.1 get.inetbar.com #[SunBelt.INetBar]
127.0.0.1 juggler.inetinteractive.com
127.0.0.1 rotator.juggler.inetinteractive.com
127.0.0.1 banners.inetfast.com
127.0.0.1 bn.inf3ct3d.info #[Backdoor.Shellbot]
127.0.0.1 ads.infospace.com #[ADW_DEALHELPER.C]
127.0.0.1 bvads.infospace.com
127.0.0.1 xads.infospace.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.infotelsrl.com #[eTrust.Infotel srl]
127.0.0.1 ads.injersey.com #[RealMedia]
127.0.0.1 bimonline.insites.be
127.0.0.1 ads.intellicast.com #[weather.com]
127.0.0.1 ads.intelihealth.com
127.0.0.1 strtt.interfree.it #[W32.Iberio]
127.0.0.1 indiads.com #[IE-SpyAd]
127.0.0.1 images.indiads.com
127.0.0.1 servedby.indiads.com #[RealMedia]
127.0.0.1 infostart.com #[IE-SpyAd]
127.0.0.1 popups.infostart.com #[eTrust.Popups.infostart.com]
127.0.0.1 oc.inspectorclick.com
127.0.0.1 trax.inspectorclick.com #[IE-SpyAd]
127.0.0.1 v2.inspectorclick.com
127.0.0.1 v3.inspectorclick.com
127.0.0.1 instadia.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.instadia.net
127.0.0.1 www.instantattention.com #[adimpact.com]
127.0.0.1 instantbuzz.com #[NOD32.Win32/Adware.InstantBuzz]
127.0.0.1 www2.instantbuzz.com
127.0.0.1 www.instantbuzz.com #[Adware.ToolBar.InstantBuzz.a]
127.0.0.1 anm.intelli-direct.com
127.0.0.1 oxfam.intelli-direct.com
127.0.0.1 www.intelli-tracker.com
127.0.0.1 newadserver.interfree.it #[Adcycle]
127.0.0.1 channels.intwined.com #[Adware/ToolBar.ISearch.c]
127.0.0.1 search.intwined.com
127.0.0.1 www.intwined.com #[McAfee.Adware-SSF!Hosts]
127.0.0.1 www.invinc.com #[Troj/Dloader-J]
127.0.0.1 ads.ipowerweb.com
127.0.0.1 www.ipstat.com #[IE-SpyAd]
127.0.0.1 adzones.ircspy.com
127.0.0.1 www.istats.nl #[IE-SpyAd]
127.0.0.1 adserver1.isohunt.com
127.0.0.1 ads.isoftmarketing.com
127.0.0.1 ads1.itadnetwork.co.uk
127.0.0.1 www.itrafficstar.com #[IE-SpyAd]
127.0.0.1 ilead.itrack.it
# [J]
127.0.0.1 www.j4sb.com #[Trojan.Jasbom]
127.0.0.1 ad.jamba.net #[IE-SpyAd]
127.0.0.1 ad.jamster.com
127.0.0.1 www.japan213.com #[Trojan.Finfanse]
127.0.0.1 www.jcount.com #[IE-SpyAd]
127.0.0.1 www.jellycounter.com
127.0.0.1 www.jm-my.com #[BackDoor-CXI]
127.0.0.1 jpedownload.joltid.com
127.0.0.1 www.joltid.com #[Adware.P2PNetworking][SPYW_PPNETWORK.B]
127.0.0.1 promotion.jpds.com
# [K]
127.0.0.1 www.k265.com #[Adware.Borlan]
127.0.0.1 kazaalite.pl
127.0.0.1 www.kazaalite.pl #[MHTMLRedir.Exploit]
127.0.0.1 kidda.de #[Adware.Kidda]
127.0.0.1 adserve.kikizo.com
127.0.0.1 affiliates.kliks.nl
127.0.0.1 www1.kliks.nl #[IE-SpyAd]
127.0.0.1 www2.kliks.nl
127.0.0.1 www.kliks.nl
127.0.0.1 kt3.kliptracker.com #[IE-SpyAd]
127.0.0.1 kt4.kliptracker.com
127.0.0.1 www.kliptracker.com
127.0.0.1 www.kmindex.ru
127.0.0.1 ads.kmpads.com #[IE-SpyAd]
127.0.0.1 koolbar.net #[Adware Bundler][ADW_KOOLBAR.A]
127.0.0.1 www.koolbar.net #[eTrust.AutoSearch][IE-SpyAd]
127.0.0.1 promo.ktvad1.com
127.0.0.1 kutsap.com #[Trojan.Anicmoo]
# [L]
127.0.0.1 www.latinbusca.com #[Adware-CommanderNET]
127.0.0.1 layer-ads.de
127.0.0.1 www2.layer-ads.de
127.0.0.1 www3.layer-ads.de
127.0.0.1 www4.layer-ads.de
127.0.0.1 www.layer-ads.de
127.0.0.1 www.leopardsearch.com
127.0.0.1 ts1.lexmark.com
127.0.0.1 www.linkads.net #[IE-SpyAd]
127.0.0.1 www.lineage0.com #[Trojan.Rohoteng]
127.0.0.1 linkbuddies.com #[IE-SpyAd]
127.0.0.1 banners.linkbuddies.com
127.0.0.1 www.linkbuddies.com
127.0.0.1 www.linkcounter.com
127.0.0.1 linkexchange.ru #[IE-SpyAd]
127.0.0.1 web.linkexchange.ru
127.0.0.1 www.linkexchange.ru
127.0.0.1 link4link.com #[IE-SpyAd]
127.0.0.1 plus.link4link.com
127.0.0.1 www.links4trade.com #[IE-SpyAd]
127.0.0.1 escati.linkopp.net #[IE-SpyAd]
127.0.0.1 www.linkopp.net
127.0.0.1 js.livehelper.com #[IE-SpyAd]
127.0.0.1 newbrowse.livehelper.com
127.0.0.1 www.liveperson.com
127.0.0.1 liveperson.net #[IE-SpyAd][McAfee.Cookie-Liveperson]
127.0.0.1 sales.liveperson.net #[Tenebril.Tracking Cookie]
127.0.0.1 sec1.liveperson.net #[SpySweeper.Spy.Cookie]
127.0.0.1 server.iad.liveperson.net #[Ad-Aware.Data Miner][HumanTag Monitor]
127.0.0.1 locators.com #[Adware.Locator]
127.0.0.1 ads.locators.com
127.0.0.1 toolbar.locators.com #[SunBelt.Locators Toolbar]
127.0.0.1 www.locators.com
127.0.0.1 www.lookde5.com #[W32.Looked]
127.0.0.1 lookoutsoft.net #[Adware Bundler]
127.0.0.1 www.lookoutsoft.net #[AdWare.Win32.WinAD.b]
127.0.0.1 www.loomcompany.com #[WMF-exploit]
127.0.0.1 www.lords-of-havoc.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 jama.lovinghost.com #[Trojan-Proxy.Win32.Agemt.ei]
127.0.0.1 exploited.lsass.cc #[Backdoor.Win32.SdBot.gen]
127.0.0.1 luckyhomepage.com #[search.targetwords.com\1stblaze.com]
127.0.0.1 www.luckyhomepage.com #[IE-SpyAd]
127.0.0.1 www.lvip.net #[McAfee.StartPage-HI]
127.0.0.1 counter.lyricsdownload.com
127.0.0.1 www.lyricspy.com #[PluginAccess]
# [M]
127.0.0.1 www.madoogali.com #[Madoogali][IE-SpyAd]
127.0.0.1 go.mailbits.com
127.0.0.1 mair.net #[Realtracker]
127.0.0.1 we.malresearch.org #[Backdoor.Win32.IRCBot.ay]
127.0.0.1 manwithnoname.biz #[Avira.TR/Proxy.Mitgl.DQ.1]
127.0.0.1 www.manwithnoname.biz
127.0.0.1 aw.masterstats.com
127.0.0.1 erotic.masterstats.com
127.0.0.1 image.masterstats.com #[IE-SpyAd]
127.0.0.1 link.masterstats.com
127.0.0.1 vw.masterstats.com #[Ewido.TrackingCookie.Masterstats]
127.0.0.1 ads.affiliates.match.com
127.0.0.1 associmage.match.com #[IE-SpyAd]
127.0.0.1 adserver.matchcraft.com
127.0.0.1 ads.mcafee.com
127.0.0.1 directads.mcafee.com #[Tenebril.Tracking Cookie]
127.0.0.1 ads.mdchoice.com
127.0.0.1 ads.mediaodyssey.com
127.0.0.1 acvs.mediaonenetwork.net
127.0.0.1 acvsrv.mediaonenetwork.net
127.0.0.1 ads.mediaturf.net #[McAfee.Cookie-Mediaturf]
127.0.0.1 www.meet2k.com #[W32.Peerload.A]
127.0.0.1 exit.megago.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.megago.com #[typo squatter][IE-SpyAd]
127.0.0.1 mmxo.megaman-network.com #[toolbarpartner.com]
127.0.0.1 www.megaseek.net #[IE-SpyAd]
127.0.0.1 adserv2.meritdesigns.com
127.0.0.1 ads.metropol.dk
127.0.0.1 line01.metriweb.be #[Ad-Aware.Tracking Cookie]
127.0.0.1 line02.metriweb.be
127.0.0.1 line03.metriweb.be
127.0.0.1 line04.metriweb.be #[SpySweeper.Spy Cookie]
127.0.0.1 line05.metriweb.be
127.0.0.1 line06.metriweb.be
127.0.0.1 line07.metriweb.be #[Panda.Spyware:Cookie]
127.0.0.1 line08.metriweb.be
127.0.0.1 line09.metriweb.be
127.0.0.1 line10.metriweb.be
127.0.0.1 line11.metriweb.be
127.0.0.1 line12.metriweb.be
127.0.0.1 line13.metriweb.be
127.0.0.1 line14.metriweb.be
127.0.0.1 line15.metriweb.be
127.0.0.1 line16.metriweb.be
127.0.0.1 line17.metriweb.be
127.0.0.1 line18.metriweb.be
127.0.0.1 line19.metriweb.be
127.0.0.1 line20.metriweb.be
127.0.0.1 pubs.mgn.net #[Grolier Network]
127.0.0.1 www.mgshareware.com #[Adware Bundler][Parasite.MySearch]
127.0.0.1 ads.mindviz.com #[IE-SpyAd]
127.0.0.1 ads.miniclip.com #[RealMedia]
127.0.0.1 www.mini-player.com #[5MOF Mini-Player]
127.0.0.1 banner.missingkids.com
127.0.0.1 ads.mixtraffic.com #[IE-SpyAd]
127.0.0.1 smile.modchipstore.com
127.0.0.1 ads.monster.com
127.0.0.1 adserver.monster.com #[SunBelt.AdServer.Monster.com]
127.0.0.1 adserver.a.in.monster.com
127.0.0.1 www.monstermarket.com #[McAfee.Cookie-Monstermarket]
127.0.0.1 ads.monstermoving.com
127.0.0.1 cookie.monster.com #[SunBelt.cookie.monster]
127.0.0.1 mp3today.net
127.0.0.1 mpamexit.com
127.0.0.1 adfarm.mserve.ca
127.0.0.1 www.messagetag.com #[Email tracker][IE-SpyAd]
127.0.0.1 www.mrx-server.com #[Trojan.Meheerwar]
127.0.0.1 msgtag.com
127.0.0.1 img.msgtag.com #[IE-SpyAd]
127.0.0.1 www.msgtag.com
127.0.0.1 msnguard.cc #[McAfee.AdClicker-AJ]
127.0.0.1 www.msnguard.cc
127.0.0.1 msxpsupport.com #[Adware.SearchMaid]
127.0.0.1 www.msxpsupport.com #[Trojan.Win32.Fakespy.a]
127.0.0.1 multi1.rmuk.co.uk #[RealMedia]
127.0.0.1 www.musicmass.com #[HJTH.C2Media/LOP variant]
127.0.0.1 www.musicsonglyrics.com #[MVPS.Criteria]
127.0.0.1 mvtracker.com #[IE-SpyAd]
127.0.0.1 www.mvtracker.com
127.0.0.1 mvr3d.net #[Adware Bundler]
127.0.0.1 www.mvr3d.net
127.0.0.1 mvr.us #[Parasite.NavExcel]
127.0.0.1 www.mvr.us
127.0.0.1 www.my990.com #[McAfee.StartPage-JC]
127.0.0.1 www.myadtrack.com #[Email Tracker][IE-SpyAd]
127.0.0.1 www.myaffiliateprogram.com #[IE-SpyAd][SpySweeper.Spy.Cookie]
127.0.0.1 www.myarmory.com #[Spyware.Bazookabar]
127.0.0.1 www.mycriteria.com #[Adware-CommanderNET]
127.0.0.1 www.myemessenger.com
127.0.0.1 www.mylinker.net #[Adware.MyLinker]
127.0.0.1 rm.myoc.com
127.0.0.1 myhitlogger.com
127.0.0.1 www.mystats.nl #[IE-SpyAd]
127.0.0.1 www2.mystats.nl
127.0.0.1 liveupdate.myim.cn #[Adware.BeSys]
# [N]
127.0.0.1 hit.namimedia.com #[IE-SpyAd]
127.0.0.1 ads.nandomedia.com #[McAfee.Cookie-Nandomedia]
127.0.0.1 ads.nationalenquirer.com
127.0.0.1 naupoint.com #[Parasite.Naupoint][ADW_NAUPONT.A]
127.0.0.1 feed.naupoint.com #[eTrust.Win32.Dudrev.A]
127.0.0.1 hp.naupoint.com #[SunBelt.NauPoint Installer]
127.0.0.1 www.naupoint.com #[TROJ_STARTPAG.X]
127.0.0.1 ads.neowin.net
127.0.0.1 banman.nepsecure.co.uk #[Ban Man Pro Banner Code]
127.0.0.1 code.netbreak.com.au
127.0.0.1 banners.netcraft.com
127.0.0.1 www.netdirect.nl
127.0.0.1 www.netflip.com #[IE-SpyAd]
127.0.0.1 money2.netfirms.com #[The Money Toolbar]
127.0.0.1 hints.netflame.cc #[Fireclick Web Analytics]
127.0.0.1 ssl-hints.netflame.cc
127.0.0.1 tracker.netklix.com
127.0.0.1 stat.netlogic.ru #[NetLogic Logger]
127.0.0.1 partner.netmechanic.com
127.0.0.1 tracker.netmechanic.com
127.0.0.1 counter.netmore.net
127.0.0.1 www.netpoll.nl
127.0.0.1 www.netpumper.com #[CounterSpy.Adware Bundler]
127.0.0.1 servedby.netshelter.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.net-stat.net
127.0.0.1 www.network-tool.net #[Trojan.Magise]
127.0.0.1 a.networkworld.com #[hitbox.com]
127.0.0.1 www.newsh.com #[Kephyr.PUP][server down?]
127.0.0.1 ads.newsint.co.uk
127.0.0.1 adq.nextag.com #[McAfee.Cookie-Nextag]
127.0.0.1 www.nipr.ws #[Trojan.Chuvazada]
127.0.0.1 www.nlbanner.nl #[IE-SpyAd]
127.0.0.1 www.nortonproject.com #[ClickPix Cursorbar][zango.com]
127.0.0.1 nowbox.com
127.0.0.1 www.nowbox.com #[Parasite.NowBox]
127.0.0.1 ad.nozonedata.com #[Ad-Aware Tracking Cookie]
127.0.0.1 ad1.nozonedata.com
127.0.0.1 ns2.iad1.nssrv.com #[IE-SpyAd]
127.0.0.1 nugget-sales.com #[ISC.Alert]
127.0.0.1 nzads.net.nz
# [O]
127.0.0.1 node2.ocslab.com #[TROJ_LOADER.D][TROJ_APROPO.H]
127.0.0.1 www.officialtvoffers.com #[IE-SpyAd]
127.0.0.1 www.offshore-traffic.com #[Trojan.Satiloler.C]
127.0.0.1 okcounter.com #[IE-SpyAd][eTrust.Tracking Cookie]
127.0.0.1 www.okww.net #[Trojan.StartPage.C]
127.0.0.1 stat.onestat.com #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 www.onestat.com #[Ewido.TrackingCookie.Onestat]
127.0.0.1 one.ru
127.0.0.1 cnt.one.ru
127.0.0.1 stats0.one.ru
127.0.0.1 stats1.one.ru
127.0.0.1 stats2.one.ru
127.0.0.1 ads.oneandonlynetwork.com
127.0.0.1 www.oneandonlynetwork.com #[Ticketmaster][IE-SpyAd]
127.0.0.1 ads.onemodelplace.com
127.0.0.1 reklama.onet.pl
127.0.0.1 online-service.cc
127.0.0.1 www.online-service.cc #[Trojan.Magise]
127.0.0.1 adserver.online-tech.com
127.0.0.1 server1.opentracker.net
127.0.0.1 ccc00.opinionlab.com
127.0.0.1 ccc01.opinionlab.com #[msn.com]
127.0.0.1 rate.opinionlab.com
127.0.0.1 www.opinionlab.com #[IE-SpyAd]
127.0.0.1 by.optimost.com
127.0.0.1 banner.orb.net
127.0.0.1 tg-images.osdn.com
127.0.0.1 otx5.otxresearch.com
127.0.0.1 otx.ifilm.com #[OTXMedia.dll]
127.0.0.1 survey.otxresearch.com #[TrojanDownloader.OTXloader.A]
127.0.0.1 www.otxresearch.com #[OTXMovie Class]
127.0.0.1 our-counter.biz #[ISANS.Alert]
127.0.0.1 www.ourxin.com #[Dr.Web.Adware.CFS][Trojan.Cfs]
127.0.0.1 adpopper.outblaze.com #[ADW_BBINSTALL.B][bargain-buddy.net]
127.0.0.1 adp4.us4.outblaze.com
127.0.0.1 adserver.hk.outblaze.com
127.0.0.1 adserver.us.outblaze.com
127.0.0.1 download2.us4.outblaze.com #[HJTH.Bargain Buddy]
127.0.0.1 www.overpeer.com #[Trojan.Wimad]
# [P]
127.0.0.1 www.p2p-load.de #[W32.Peerload.A]
127.0.0.1 www.p3marketing.com #[Zapspot]
127.0.0.1 ad1.pamedia.com.au
127.0.0.1 ad2.pamedia.com.au
127.0.0.1 www.pantanalvip.com.br #[McAfee.Downloader-AFV]
127.0.0.1 update.passivecow.com #[Trojan.Win32.VB.aft][Adware.Superlogy]
127.0.0.1 www.passivecow.com #[ADW_SUPERLOGY.A][Panda.Adware/Getup]
127.0.0.1 click.payserve.com #[IE-SpyAd]
127.0.0.1 www.pcbutts1.com #[Unauthorized Downloads]
127.0.0.1 www.pc-test.net
127.0.0.1 ad1.peel.com
127.0.0.1 ad3.peel.com #[SunBelt.Peel]
127.0.0.1 ads.peel.com
127.0.0.1 ad4.peel.com #[Tenebril.Tracking Cookie]
127.0.0.1 ads5.peel.com
127.0.0.1 freeps3.peel.com
127.0.0.1 www.peel.com #[IE-SpyAd]
127.0.0.1 www.peel.net
127.0.0.1 ads.pennyweb.com #[addynamix.com]
127.0.0.1 banners.pennyweb.com #[IE-SpyAd]
127.0.0.1 pluginx.perfectgonzo.com
127.0.0.1 www.peruvianmarket.com #[Trojan.Beagooz.D]
127.0.0.1 ads.photosight.ru
127.0.0.1 phpadsnew.com
127.0.0.1 www.phpadsnew.com
127.0.0.1 pizdato.biz #[Trojan.TrustedZone]
127.0.0.1 ads.planetactive.com
127.0.0.1 ads2.playnet.com
127.0.0.1 adserver.pollstar.com #[eTrust.Tracking Cookie]
127.0.0.1 popfind.net #[Adware.Ddpop]
127.0.0.1 www.pops-stop.com #[Spyware.SafeSurfing]
127.0.0.1 www.popupads.com #[IE-SpyAd]
127.0.0.1 www.popupad.net #[IE-SpyAd][SunBelt.PopUpAd]
127.0.0.1 popupmoney.com #[IE-SpyAd]
127.0.0.1 server01.popupmoney.com
127.0.0.1 www.popupmoney.com
127.0.0.1 popadstop.com #[Adware.PopAdStop]
127.0.0.1 www.popadstop.com
127.0.0.1 www.popunder.info #[TROJ_CHECKIN.B]
127.0.0.1 www2.portdetective.com
127.0.0.1 www.ppctracking.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 adview.ppro.de
127.0.0.1 x0x0l.pp.ru #[BKDR_CCT.A]
127.0.0.1 www.praize.com #[Adware.Praize]
127.0.0.1 ads.primeinteractive.net
127.0.0.1 ad.profiwin.de
127.0.0.1 bn.profiwin.de
127.0.0.1 www.promarketingclub.com
127.0.0.1 www.prtracker.com
127.0.0.1 products-gold.net #[WMF-exploit][TR/Spy.Delf.MQ.2]
127.0.0.1 www.products-gold.net #[Trojan-Spy.Win32.Delf.mq]
127.0.0.1 www.profitzone.com #[SunBelt.ProfitZONE Adbar]
127.0.0.1 www.promo.com.au
127.0.0.1 www.prutect.com #[Spyware.e2give][Win32.Prutec.A]
127.0.0.1 www.protectedmedia.com #[Trojan.Wimad][Panda.WmvDown.B]
127.0.0.1 ad.prv.pl
127.0.0.1 pulsix.com #[maxalbums.com]
127.0.0.1 www.pulsix.com
127.0.0.1 ad.sma.punto.net
127.0.0.1 sma.punto.net
127.0.0.1 www.pureseeker.com #[HJTH.C2Media/LOP variant][IE-SpyAd]
127.0.0.1 www.pwallet.com #[IE-SpyAd]
# [Q]
127.0.0.1 qanmqqoiw.com #[Trojan.Gamqowi]
127.0.0.1 adserv.quality-channel.de
127.0.0.1 ads-205.quarterserver.de
127.0.0.1 questionmarket.com #[IE-SpyAd][SpySweeper.Spy.Cookie]
127.0.0.1 amch.questionmarket.com #[McAfee.Cookie-Questionmarket]
127.0.0.1 ch.questionmarket.com
127.0.0.1 survey.questionmarket.com
127.0.0.1 www.questionmarket.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.qq886.com #[Backdoor.Semes]
# [R]
127.0.0.1 clientreport.random-logic.com #[McAfee.Adware-CasOnline]
127.0.0.1 reportinstaller.random-logic.com
127.0.0.1 www.random-logic.com
127.0.0.1 ranking-hits.de #[IE-SpyAd]
127.0.0.1 www.ranking-hits.de
127.0.0.1 counter.rapidcounter.com
127.0.0.1 www.rapidcounter.com
127.0.0.1 www.autoraskrutka.ru #[Spyware.Acext]
127.0.0.1 www.raskrutim.ru #[Spyware.Acext]
127.0.0.1 www.realclicks.com
127.0.0.1 ads.rediff.com
127.0.0.1 adworks.rediff.com
127.0.0.1 imadworks.rediff.com
127.0.0.1 www.redirad.de #[Adware.Redir]
127.0.0.1 visit.referralware.com
127.0.0.1 ads.register.com
127.0.0.1 www.registrarads.com
127.0.0.1 235.regvista.com #[WMF-exploit]
127.0.0.1 counter.relmaxtop.com
127.0.0.1 www.relmaxtop.com
127.0.0.1 banner.relcom.ru
127.0.0.1 adservice.recon-networks.com
127.0.0.1 dae.responsetarget.com #[AutoGK][IE-SpyAd][MVPS.Criteria]
127.0.0.1 banners.resultonline.com
127.0.0.1 ads.revenews.com
127.0.0.1 ads.revsci.net
127.0.0.1 js.revsci.net
127.0.0.1 pix01.revsci.net
127.0.0.1 rightstats.com
127.0.0.1 www.rightstats.com
127.0.0.1 www.ritztours.com #[Backdoor.Win32.Bifrose.kt]
127.0.0.1 m.rmbclick.com #[IE-SpyAd]
127.0.0.1 www.rgs-rostock.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 ad.ro2cn.com #[Adware.Ro2cn]
127.0.0.1 ldkiekxc.rr.nu #[Backdoor.Ryejet.B]
# [S]
127.0.0.1 judo.salon.com
127.0.0.1 oas.salon.com
127.0.0.1 www.savehits.com #[IE-SpyAd]
127.0.0.1 amp.st.sageanalyst.net
127.0.0.1 matchnet.st.sageanalyst.net #[McAfee.Cookie-Sageanalyst]
127.0.0.1 st.sageanalyst.net #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 scaredback.com #[PWSteal.Tarno.R][Downloader-ATM]
127.0.0.1 scorpionsearch.com #[W32.Adclicker.C.Trojan]
127.0.0.1 www.scorpionsearch.com #[x10.com][Trojan.Clicker.NetBuie a-b]
127.0.0.1 www.scratchindian.com #[Backdoor.Samkams]
127.0.0.1 adsremote.scripps.com #[McAfee.Cookie-Scripps]
127.0.0.1 te.scripps.com
127.0.0.1 counter.search.bg #[IE-SpyAd]
127.0.0.1 search3.com #[SunBelt.Search3 Hijacker]
127.0.0.1 www.search3.com
127.0.0.1 www.search4help.net
127.0.0.1 www.searchgauge.com
127.0.0.1 searchitquick.com #[IE-SpyAd]
127.0.0.1 tb.searchitquick.com #[hotwebsearch.com][HJTH.Begin2Search Adware]
127.0.0.1 www.searchitquick.com #[SunBelt.SearchItQuick Toolbar]
127.0.0.1 www.searchlistings.biz #[IE-SpyAd][server down?]
127.0.0.1 www.searchmachine.com #[IE-SpyAd]
127.0.0.1 searchproject.net #[Trojan.Phel.A]
127.0.0.1 www.searchrelevancy.com #[Spyware.Relevancy]
127.0.0.1 www.searchresult.net #[Parasite.IgetNet]
127.0.0.1 as.searchrover.net
127.0.0.1 www.searchrover.net #[Adware.Starware]
127.0.0.1 searchtofind.net #[W32/Agent.DIR][server down?]
127.0.0.1 home.searchwords.com #[eTrust.AdRoad.Cpr]
127.0.0.1 weather.searchwords.com #[McAfee.Adware-Searchwords]
127.0.0.1 www.searchwords.com #[Adware.SearchWords]
127.0.0.1 plugin.secureservicepack.com #[HJTH.GoDOTLess]
127.0.0.1 adserver.securityfocus.com #[RealMedia]
127.0.0.1 www.sedotracker.com
127.0.0.1 www.sedotracker.de #[IE-SpyAd]
127.0.0.1 www.selfsurveys.com #[IE-SpyAd]
127.0.0.1 www.seehits.com
127.0.0.1 www.seekmp3.com #[HJTH.C2Media/LOP variant]
127.0.0.1 www.send-safe.com #[Spamware]
127.0.0.1 ad.sensismediasmart.com.au
127.0.0.1 serialkey.net #[Kephyr.PUP]
127.0.0.1 www.serialkey.net
127.0.0.1 servirc1.servebeer.com
127.0.0.1 servirc2.servebeer.com #[Backdoor.Sparta.D]
127.0.0.1 counterstrike.server.us #[Downloader.CDT]
127.0.0.1 www.sexyads.net #[SunBelt.SexyAds.net]
127.0.0.1 simplenter.com #[Adware.UniversalTB]
127.0.0.1 www.simplenter.com
127.0.0.1 www.simpletoolbar.com #[SunBelt.UniversalSearchToolbar]
127.0.0.1 sincooweb.com #[Backdoor.Graybird.N]
127.0.0.1 www.smellout.com #[MHTMLRedir.Exploit][Koffix Blocker]
127.0.0.1 startpunt.nu.site-id.nl
127.0.0.1 www.site-id.nl
127.0.0.1 quasar.sitegauge.com
127.0.0.1 tracker.sitescout.com #[IE-SpyAd]
127.0.0.1 advertpro.sitepoint.com
127.0.0.1 www.sitestatslive.com
127.0.0.1 adserver.sharewareonline.com #[nictechnetworks.com]
127.0.0.1 ads.shizmoo.com #[IE-SpyAd][Kephyr.PUP]
127.0.0.1 www.shockcounter.com #[IE-SpyAd]
127.0.0.1 www.skeech.com #[IE-SpyAd][SunBelt.Skeech]
127.0.0.1 www.smartadserver.com #[SunBelt.SmartAdServer.com]
127.0.0.1 www.smartadstats.com #[IE-SpyAd]
127.0.0.1 smart-browser.com #[eTrust.SmartBrowser]
127.0.0.1 update.smart-browser.com #[Parasite.SmartBrowser]
127.0.0.1 www.smart-browser.com #[Adware.SmartBrowser]
127.0.0.1 smartclicks.net #[IE-SpyAd]
127.0.0.1 www.smartclicks.net
127.0.0.1 smarter.com #[IE-SpyAd][SunBelt.Smarter.com]
127.0.0.1 sidebar.smarter.com
127.0.0.1 www.smarter.com #[SunBelt.eBates.WebSearch]
127.0.0.1 www.smileyworld.com #[AdWare.Win32.SHBar.a][Adware.Smiley]
127.0.0.1 ads.smni.com #[SpySweeper.Spy.Cookie]
127.0.0.1 static.smni.com
127.0.0.1 ivox.socratos.net
127.0.0.1 a.softpedia.com
127.0.0.1 adserver.softwareonline.com
127.0.0.1 www1.spaex.com #[searchboss.com][IE-SpyAd]
127.0.0.1 www.specialstat.com #[IE-SpyAd]
127.0.0.1 www.spedia.net #[SunBelt.SpediaBar][IE-SpyAd]
127.0.0.1 sploso.com #[WMF-exploit]
127.0.0.1 www.sponsorads.de
127.0.0.1 ads-fr.spray.net #[SpySweeper.Spy.Cookie]
127.0.0.1 ftp.sptr.info
127.0.0.1 www.sptr.info #[AVG.PSW.Generic.DLE][Backdoor.Zagaban]
127.0.0.1 www.spyarsenal.com #[Spyware.DesktopSpy][Spyware.FamilyKeylog]
127.0.0.1 www.spymoon.com #[Trojan.Eaghouse.B]
127.0.0.1 www.spywareno.net #[IE-SpyAd]
127.0.0.1 ss999ss.com #[Trojan.Snines]
127.0.0.1 www.ssppyy.com #[Spyware.Ssppyy]
127.0.0.1 www.s-tracking.com
127.0.0.1 ads.starpulse.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.startsurfing.com #[McAfee.Adware-StartSurfing]
127.0.0.1 adsintl.starwave.com
127.0.0.1 js.statistici.ro
127.0.0.1 log.statistici.ro
127.0.0.1 s.statistici.ro #[IE-SpyAd]
127.0.0.1 www.statomatic.com #[IE-SpyAd]
127.0.0.1 statistik-gallup.net
127.0.0.1 www.stats4free.de
127.0.0.1 stats4you.com #[IE-SpyAd]
127.0.0.1 reg.stats4all.com
127.0.0.1 www.stats4you.com #[IE-SpyAd]
127.0.0.1 stats4all.cc
127.0.0.1 stats4all.ws
127.0.0.1 log3.stats24.net #[IE-SpyAd]
127.0.0.1 www.stats4all.ws
127.0.0.1 www.statsmachine.com
127.0.0.1 statswhere.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.stickypops.com #[eTrust.Stickypops][IE-SpyAd]
127.0.0.1 i.stealfrommvps.org
127.0.0.1 www.super-barre.com #[Dr.Web.Adware.SideSearch]
127.0.0.1 www.sublimemedia.net
127.0.0.1 clix.superclix.de #[IE-SpyAd]
127.0.0.1 www.superclix.de
127.0.0.1 www.superlogy.com #[AdvWare.ToolBar.VB.b][Adware.Superlogy]
127.0.0.1 adidm.supermedia.pl
127.0.0.1 sqwire.com #[Adware.Sqwire][Xupiter.Sqwire]
127.0.0.1 www.sqwire.com #[Parasite.Xupiter][Adware-PornKings]
127.0.0.1 rd1.surfernetwork.com #[SurferNETWORK Plugin]
127.0.0.1 www.surfernetwork.com
127.0.0.1 www.surveynetworks.com
127.0.0.1 www1.sweetbar.com #[ADW_SWEETBAR.A]
127.0.0.1 www.sweetbar.com #[SecurityRisk.Downldr]
127.0.0.1 www.symantic.com #[Typo Squatter][IE-SpyAd]
127.0.0.1 www.syamantec.com #[Typo Squatter]
127.0.0.1 adpick.switchboard.com
127.0.0.1 adtag.sympatico.ca
127.0.0.1 www.szadk.com #[PWSteal.Trojan]
# [T]
127.0.0.1 freeware-ad.t35.com #[umaxsearch.com]
127.0.0.1 spyware-re.t35.com #[umaxsearch.com]
127.0.0.1 www.ud7swe.t35.com #[W32.Dinoxi][W32/Style-A]
127.0.0.1 ads.tagword.com
127.0.0.1 ad.uk.tangozebra.com
127.0.0.1 dev.targetpoint.com
127.0.0.1 srs.targetpoint.com
127.0.0.1 tat-neftbank.ru #[Backdoor.Berbew.H]
127.0.0.1 ad.gen.tbn.ru
127.0.0.1 ad.120-gen.tbn.ru
127.0.0.1 www.tencent.com #[Backdoor.Prosti]
127.0.0.1 www.tenmonkey.com
127.0.0.1 dy.testnet.nl
127.0.0.1 www.textads.biz
127.0.0.1 www.text-link-ads.com
127.0.0.1 www.textlinkads.com
127.0.0.1 a.tfag.de
127.0.0.1 ak.tfag.de
127.0.0.1 www.tfcco.com #[W32/PFV-Exploit.A]
127.0.0.1 theaffiliateprogram.com
127.0.0.1 adbot.theonion.com
127.0.0.1 oascentral.theonionavclub.com
127.0.0.1 www.thepokerclub.com #[SecurityRisk.ClubPoker]
127.0.0.1 therichmedia.com
127.0.0.1 webtrends.thisis.co.uk #[Hitbox]
127.0.0.1 www.ting789.com #[McAfee.StartPage-HR]
127.0.0.1 ad.tiscali.com
127.0.0.1 ads.as4x.tmcs.net
127.0.0.1 tnc4u.com #[Parasite.DownloadPlus]
127.0.0.1 new.tnc4u.com
127.0.0.1 www.tnc4u.com #[Adware.DownloadPlus]
127.0.0.1 www.toilet.com #[IE-SpyAd]
127.0.0.1 ad.tomshardware.com
127.0.0.1 topinstalls.com #[AVG.Trojan.Dropper.Agent.PP]
127.0.0.1 www.topinstalls.com #[TROJ_SMALL.AAL][Adware.Links]
127.0.0.1 log.trafic.ro #[IE-SpyAd]
127.0.0.1 storage.trafic.ro
127.0.0.1 www.toolshack.com #[IE-SpyAd]
127.0.0.1 www.top-search.com #[Adware-SSF.dr]
127.0.0.1 ad.topstat.com
127.0.0.1 nl.topstat.com #[IE-SpyAd]
127.0.0.1 s26.topstat.com
127.0.0.1 xl.topstat.com
127.0.0.1 total-search.info #[ISANS.Alert]
127.0.0.1 banners.toteme.com
127.0.0.1 cachebanners.toteme.com
127.0.0.1 ads.track-star.com #[SunBelt.Track-Star.com]
127.0.0.1 adserver.track-star.com
127.0.0.1 geo2.track-star.com
127.0.0.1 www.track-star.com
127.0.0.1 traff4ppc.biz #[WMF-exploit][server down?]
127.0.0.1 www.traffic-stock.com #[Parasite.RichFind]
127.0.0.1 ads.traderonline.com #[RealMedia]
127.0.0.1 traffic-acc.com #[Spyware.TrafficAccProc]
127.0.0.1 www.trafficbeamer.nl
127.0.0.1 trafficg.com #[IE-SpyAd]
127.0.0.1 www.trafficg.com
127.0.0.1 www.trafficflame.com
127.0.0.1 trafficfile.com #[IE-SpyAd]
127.0.0.1 www.trafficfile.com
127.0.0.1 www.trafficzap.com #[IE-SpyAd]
127.0.0.1 trackyourstats.com #[IE-SpyAd]
127.0.0.1 www.trackyourstats.com
127.0.0.1 hit.traxdb.net
127.0.0.1 media.travelzoo.com
127.0.0.1 media2.travelzoo.com
127.0.0.1 trustbid.ws
127.0.0.1 www.trustbid.ws
127.0.0.1 www.trusttoolbar.com #[eTrust.Trust Toolbar]
127.0.0.1 counts.tucows.com
127.0.0.1 google.tucows.com
127.0.0.1 www.turbomemorycharger.com #[Adware.Fapi]
127.0.0.1 ads.tweakxp.com
# [U]
127.0.0.1 ads.ucomics.com #[RealMedia]
127.0.0.1 image.ugo.com
127.0.0.1 mediamgr.ugo.com #[McAfee.Cookie-UGOr]
127.0.0.1 www.ukbanners.com #[IE-SpyAd]
127.0.0.1 ukstories.net #[Trojan-Spy.Win32.Goldun.bk][Trojan.Repsamo]
127.0.0.1 ultimatecounter.com #[IE-SpyAd]
127.0.0.1 www.ultimatecounter.com
127.0.0.1 adcontroller.unicast.com
127.0.0.1 ads.unlimitedbanners.com #[IE-SpyAd]
127.0.0.1 undertonenetworks.com #[zedo.com][IE-SpyAd]
127.0.0.1 www.undertonenetworks.com
127.0.0.1 ads1.updated.com
127.0.0.1 www.updatehq.net #[Spyware.Surfcomp]
127.0.0.1 www.up-the-creek.com #[MHTMLRedir.Exploit]
127.0.0.1 www.upspiral.com #[Adware.UpSpiralBar]
127.0.0.1 www.urpo.com #[SunBelt.Urpo][IE-SpyAd]
127.0.0.1 usachoice.net #[IE-SpyAd]
127.0.0.1 ads.userfriendly.org #[AdvertPro]
127.0.0.1 adsnew.userfriendly.org
127.0.0.1 ushuistov.net #[Win32.Chisyne.F][Downloader-ASN][Trojan.Awax]
127.0.0.1 www.utarget.co.uk #[utarget Ad code]
# [V]
127.0.0.1 ad.valencemedia.com #[ad.yieldmanager.com]
127.0.0.1 beacon.valeoip.com
127.0.0.1 ad.valuehost.ru #[IE-SpyAd]
127.0.0.1 counters.vendio.com
127.0.0.1 www.verticlick.com #[IE-SpyAd]
127.0.0.1 image.versiontracker.com #[McAfee.Cookie-Versiontrack]
127.0.0.1 spinbox.versiontracker.com
127.0.0.1 ads.vesperexchange.com
127.0.0.1 www.vesperexchange.com
127.0.0.1 cinnam.vibrahost.com #[PWSteal.Revcuss.C][Win32.Revcuss.C]
127.0.0.1 vivi.vibrahost.com #[PWSteal.Revcuss.A]
127.0.0.1 www.view4cash.de
127.0.0.1 oas.villagevoice.com
127.0.0.1 banners.vipprofits.com
127.0.0.1 visit-link.com
127.0.0.1 www.voonda.com #[Spyware.TAFbar]
127.0.0.1 www.vstats.net #[IE-SpyAd]
127.0.0.1 ads.vnuemedia.com #[VNUAdTag]
127.0.0.1 sevenc.vze.com #[VBS.Powcox@mm]
# [W]
127.0.0.1 www.w3exit.com
127.0.0.1 www.want2c.com #[IE-SpyAd]
127.0.0.1 www.warezdownload.ws #[TROJ_BANKER.DC]
127.0.0.1 ng3.ads.warnerbros.com
127.0.0.1 wcft.net #[Parasite.LinkReplacer]
127.0.0.1 www.wcft.net
127.0.0.1 ads.weather.com
127.0.0.1 100webads.com #[IE-SpyAd]
127.0.0.1 ad.webadvertising.ch
127.0.0.1 adv.webadvertising.ch
127.0.0.1 nx-adv.webadvertising.ch #[RealMedia]
127.0.0.1 ads.webattack.com #[server down?]
127.0.0.1 webcounter.com #[IE-SpyAd]
127.0.0.1 www.webcounter.com
127.0.0.1 ads.webhosting.info
127.0.0.1 banners.webmasterplan.com
127.0.0.1 fc.webmasterpro.de
127.0.0.1 adv.webmd.com
127.0.0.1 webhits.de #[IE-SpyAd]
127.0.0.1 stat.webmedia.pl #[IE-SpyAd]
127.0.0.1 bannervip.web1000.com #[IE-SpyAd]
127.0.0.1 ads.webads360.com #[IE-SpyAd]
127.0.0.1 webfastlink-us.com #[TR/Spy.Falis]
127.0.0.1 www.webfastlink-us.com #[Trojan-Dropper.Win32.Agent.agh]
127.0.0.1 img.webring.com
127.0.0.1 img1.webring.com
127.0.0.1 ss.webring.com
127.0.0.1 track.websitetrafficreport.com #[VisitorTrack Code]
127.0.0.1 ads.website-guru.com #[AdvertPro]
127.0.0.1 ads.webshots.com
127.0.0.1 www.webstars2000.com
127.0.0.1 www.webstat.net
127.0.0.1 fry.webtistic.com
127.0.0.1 www.webtistic.com #[IE-SpyAd]
127.0.0.1 toolbar.webtoolbars.com #[IE-SpyAd]
127.0.0.1 wefed.biz #[Win32.Bagz.D][Trojan-Proxy.Win32.Agent.hs]
127.0.0.1 weirdontheweb.net #[SunBelt.Cok.weirdontheweb]
127.0.0.1 oascentral.weirdontheweb.net #[RealMedia]
127.0.0.1 www.weirdontheweb.net #[Adware.WeirdOnTheWeb]
127.0.0.1 wetrack.it #[IE-SpyAd]
127.0.0.1 st.wetrack.it #[SunBelt.Wetrack.it]
127.0.0.1 www.wgutv.com #[Adware.BuddyLinks]
127.0.0.1 partner1.whatsfind.com
127.0.0.1 www.whatsfind.com #[HTML_STARTPAGE.C]
127.0.0.1 oasads.whitepages.com #[RealMedia]
127.0.0.1 y0.windows-center.com #[Backdoor.Shellbot][Troj/Agent-DR]
127.0.0.1 join1.winhundred.com
127.0.0.1 www.win-update.net #[Trojan.Magise]
127.0.0.1 window1.com #[IE-SpyAd]
127.0.0.1 ads.winhelp2002.com
127.0.0.1 ads.winsite.com
127.0.0.1 winstream.com #[Parasite.Searchex]
127.0.0.1 www.winstream.com
127.0.0.1 http.down.love.witlog.net #[Backdoor.Win32.Aimbot]
127.0.0.1 clicktrack.wnu.com
127.0.0.1 www.wowweb.net #[Adware.WWWBar]
127.0.0.1 www.wslm.net #[REG_SEEKER.N]
# [X]
127.0.0.1 x0x.biz
127.0.0.1 www.x0x.biz #[Backdoor.Berbew.D]
127.0.0.1 xcounters.com
127.0.0.1 a.xcounters.com
127.0.0.1 count.xhit.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 xlonhcld.xlontech.net #[IE-SpyAd]
127.0.0.1 nedstats.xs4all.nl
127.0.0.1 hit1.xstats.com
127.0.0.1 view1.xstats.com
127.0.0.1 ads.xtra.co.nz
# [Y]
127.0.0.1 freegames.yaboo.dk #[W32.Guapim]
127.0.0.1 ads.yadio.com
127.0.0.1 dl.yadio.com
127.0.0.1 www.yadio.com
127.0.0.1 ad.yadro.ru #[IE-SpyAd][SpySweeper.Spy.Cookie]
127.0.0.1 counter.yadro.ru #[McAfee.Cookie-Yadro]
127.0.0.1 bs.yandex.ru
127.0.0.1 www.yandex.ru #[SunBelt.Yandex]
127.0.0.1 crsky2004.yeah.net #[Backdoor.Singu.B]
127.0.0.1 lb1.youbettersearch.com
127.0.0.1 www.yourenhancement.com #[eTrust.YourEnhancement][Trojan.Win32.VB.tg]
127.0.0.1 ysearchus.com #[Parasite.TinyBar]
127.0.0.1 www.ysearchus.com
127.0.0.1 www.yyue.com #[TROJ_STARTPAG.OC]
# [Z]
127.0.0.1 ad.zanox.com
127.0.0.1 zanox-affiliate.de
127.0.0.1 www.zcounter.com
127.0.0.1 zlex.org
127.0.0.1 counter.zone.ee
127.0.0.1 mp3.zonebg.com #[HJTH.C2Media/LOP variant]
127.0.0.1 ads.zone-media.com #[Troj/Swizzor-CN]
127.0.0.1 ayb.zone-media.com
127.0.0.1 www.zone-media.com
127.0.0.1 bannerads.zwire.com
127.0.0.1 zxserv0.com #[Trojan.Zhopa][F-Secure.Small.wy]
127.0.0.1 www.zxserv0.com #[eTrust.Win32/Beovens][server down?]
# [Misc]
127.0.0.1 banner.0catch.com
127.0.0.1 www.0stats.com
127.0.0.1 cc.1asphost.com #[Trojan.Bansap]
127.0.0.1 123mania.com #[ADW_123MANIA.A]
127.0.0.1 www.123mania.com #[Parasite.123Mania][Adware.MatrixSearch]
127.0.0.1 123stat.com #[IE-SpyAd]
127.0.0.1 ad2.163.com
127.0.0.1 adclient.163.com
127.0.0.1 images.163.com
127.0.0.1 popme.163.com
127.0.0.1 1234.2bro.com #[Adware.Satbo]
127.0.0.1 www.241hits.com
127.0.0.1 up.isp.2ch.net #[Trojan.Upchan]
127.0.0.1 2z0o.net #[Trojan.Popper]
127.0.0.1 pop1.2z0o.net #[admarketplace.net]
127.0.0.1 pop2.2z0o.net #[TROJ_DLOADER.AGS]
127.0.0.1 req2.2z0o.net #[McAfee.Downloader-ACV]
127.0.0.1 www.3d-icons.com #[Adware bundler]
127.0.0.1 www.3find.com #[Trojan-Clicker.Win32.Small.hn]
127.0.0.1 www.3241.com #[Troj/Zikdow-B]
127.0.0.1 guannan.3322.net #[IE-SpyAd]
127.0.0.1 download.35mb.com #[impregnable.net]
127.0.0.1 static.35mb.com #[HJTH.Win32.IstBar.fa]
127.0.0.1 www.35mb.com #[HJTH.MediaTickets Installer]
127.0.0.1 ad.37.com
127.0.0.1 www.40best.com #[HJTH.C2Media/LOP variant]
127.0.0.1 banners.4d5.net
127.0.0.1 41m.com #[HJTH.XXXToolbar Variant][Trojan.Clicker.BL]
127.0.0.1 msncheck.41m.com
127.0.0.1 www.41m.com
127.0.0.1 4pokertips.com
127.0.0.1 www.4pokertips.com
127.0.0.1 5sec.biz #[Backdoor.Fivsec]
127.0.0.1 5sec.info
127.0.0.1 www.5sec.info
127.0.0.1 5sec.org
127.0.0.1 www.ff.iij4u.or.jp #[Trojan.Upchan]
127.0.0.1 7am.com
127.0.0.1 www.75558889.com #[Panda.Hupigon.BS]
127.0.0.1 www.777search.com #[C2Media/LOP]
127.0.0.1 www.7000n.com #[Adware.7000n]
127.0.0.1 7oo.meibu.com #[McAfee.BackDoor-CKB]
127.0.0.1 ajim.delphibbs.com #[Trojan.PSW.Ajim_bbs]
127.0.0.1 banners.dot.tk
127.0.0.1 topsites.us #[Parasite.eStart]
127.0.0.1 www.9ringtone.com
127.0.0.1 www.18hi.net #[McAfee.StartPage-HR]
127.0.0.1 www.19ku.com #[McAfee.StartPage-HR]
127.0.0.1 10000hits.net #[
  • 0

#9
OSC

OSC

    Malware Expert

  • Retired Staff
  • 301 posts
Hi avajo4 (and rambro)!

rambro, avajo4 came into the chat today looking for you. I happened to be there and asked for the export of the hosts file. Now I'm going to do a search of the registry for those sites. Feel free to pick the thread up again!! :whistling:

1. Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: all files to your desktop.

RegSearch Options File

[Search]

linkshare.com
cj.com


[Exclude]


[Options]



2.
Download Registry Search to your desktop.
  • Right click on the compressed RegSearch folder, and choose "Extract All". In the box that pops open, click "Next", then "Next" again, and then "Finish". You now have another RegSearch folder on your desktop.
  • Open the new folder, and double click on regsearch.exe
  • Click "Import" in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
  • Click OK and Registry Search will scan your registry for the file(s), and a Notepad box will open with a report.
  • Please reply here with the entire contents of the Notepad file from RegSearch.

  • 0

#10
rambro

rambro

    Member 1K

  • Member
  • PipPipPipPip
  • 1,383 posts
Dear avajo4, :whistling:

I would like you to use the "Window Search feature" (i.e. http://www.cyberwalk.../find-file.html ) or go to "window explorer" and located the following file marked in blue:

C:\windows\system32\drivers\etc\hosts

Double click on the hosts file and the file should open up in "notepad" (if it does not open in notepad, open it up with the "notepad.exe" application).

Copy the contents of the file in a reply to this post.
******************************

I also what you to open up your SpywareBlaster version 3.5.1 application.

On the left hand side of the application, I want you to click on the "protection" option.

Then on the top of the application I want you to click the "Restricted Sites" application.

Then under the "Customize the Block List" section, I want you to look in the the "scrolling listbox".

In the "scrolling listbox", I would like you to search for the websites in question under the "address" heading and then uncheck the checkboxes for the websites in question.

Then click on the "Remove protection for unchecked items" button.

Let me know if you can access the websites in question.

rambro :blink:
  • 0

Advertisements


#11
rambro

rambro

    Member 1K

  • Member
  • PipPipPipPip
  • 1,383 posts
lol, you guys couldn't wait, for my response?

Edited by rambro, 04 November 2006 - 01:05 PM.

  • 0

#12
avajo4

avajo4

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
Thank yuu both very much. I have asked a lot of friends(who say they know computers) but really don't know what to tell me to do. I knew I should have come here first. You all rock!

REGEDIT4

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.1.0

; Results at 11/4/2006 2:10:02 PM for strings:
; 'linkshare.com'
; 'cj.com'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\cj.com]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freecj.com]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freecj.com]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freecj.com]

[HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Microsoft\Internet Explorer\New Windows\Allow]
; Contents of value:
;
"www.cj.com"=hex:
; Contents of value:
;
"www.linkshare.com"=hex:

[HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"="http://linkshare.com/"
"url3"="www.linkshare.com"
"url4"="www.cj.com"

[HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\cj.com]

[HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linkshare.com]

[HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Siber Systems\RoboForm\Query-MRU]
"b"="cj.com"

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freecj.com]

; End Of The Log...


I have been to these sites before, that is why I am so perplexed, that I can't seem to access them now.
  • 0

#13
rambro

rambro

    Member 1K

  • Member
  • PipPipPipPip
  • 1,383 posts
Dear avajo4, :whistling:

Did you look at the second part of my last post, that is, post #10, dealing with the spywareblaster application. Let me know in detail what happened as a result. Let me know if you could access the websites in question.

rambro :blink:
  • 0

#14
avajo4

avajo4

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
Sorry for the impatience. I have been dealing with this for a while. I thought it was too trivial to bother you all with it. Thought it should be an easy fix.

I unchecked all of the restricted sites yesterday and tried to access cj.com with no avail.

Thanks
  • 0

#15
rambro

rambro

    Member 1K

  • Member
  • PipPipPipPip
  • 1,383 posts
Dear avajo4, :whistling:

(Note: Please read through these instructions a couple of times before executing the steps in this post.)

You may want to print out these instructions or save them as a text file with "Notepad" to your desktop.
******************************

Dear avajo4, I would like you to edit your "registry settings", but before you do that, I want you to make a back up copy of your "registry" in case something goes wrong. Here is how this is done:

Back up your current registry

1) Click on the Start button.

2) From the menu that appears, choose Run.

3) In the window that appears, there is a text area labeled Open. In that area, type "regedit" (without the quotation marks").

4) Click the OK button (or hit the Enter or Return key on your keyboard).

5) The Registry Editor window should open.

6) If My Computer is not highlighted, click on it once so that it is highlighted.

7) On the menu bar, click on Registry and then click on Export Registry File.

8) The Export Registry File window will appear. In the Save In drop-down box at the top, choose Desktop.

9) In the File Name box at the bottom, type "backup" (without the quotation marks), then click the Save button.

10) A backup copy of the entire registry will now be saved to your desktop in case something goes wrong.

Notes:

* To restore the registry from the backup file you made, follow the same steps as above, but in step 2 choose Import Registry File instead of Export Registry File. Or, alternatively, you could double-click on the backup file on the desktop and answer Yes when it asks if you want to import the information into the registry.
* Once you've made changes to the registry and you are sure that you no longer need the backup file you made, simply delete it from the desktop.

See the following link: http://helpdesk.umd....ndows_2000/555/. Pay attention to the following sections: Starting the Registry Editor and Backing Up the Registry.
**************************

Edit your registry

Please run Notepad and paste the following text into a new file:

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\cj.com]

[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freecj.com]

[-HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freecj.com]

[-HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freecj.com]

[HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Microsoft\Internet Explorer\New Windows\Allow]
"www.cj.com"=-
"www.linkshare.com"=-

[HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"=-
"url3"=-
"url4"=-

[-HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\cj.com]

[-HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linkshare.com]

[HKEY_USERS\S-1-5-21-1177238915-1708537768-1801674531-1004\Software\Siber Systems\RoboForm\Query-MRU]
"b"=-

[-HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freecj.com]


Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files".

Please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.
**************************************

Restart your computer and then please post a new HijackThis log.

In addition, let me know in detail how your computer system is running after performing the above steps. :blink:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP