Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

My computer is infected Malware and Trojan Virus found [RESOLVED]


  • This topic is locked This topic is locked

#1
Kizzy

Kizzy

    Member

  • Member
  • PipPip
  • 39 posts
Help!!!!!!!!! :)
It all started when all of a sudden I begin to get pop ups. one said "Security Alert: Spyware Found Your computer is infected with the last version of PSW.x'Vir trojan. PSW trojans steal your Private information such as: passwords, Ip-addresses, credit card information, registration details, documents, etc. click this baloon to remove PSW.x-vir spyware."
Another one said "System Alert: Malware threats Your computer is infected with a back door Trojan taht allows the remote attacker to perform various malicious actions. click this baloon to download malware removal software."
The third one said "Security warning: New variant of SpyBot@MXt Your system in unprotected from new verision of SpyBot@MXt trojan. SpyBot@MXt is a trojan Hourse that steals information and gathers email addresses from the compromised computer. click ok to download antivirus software and pass system scan to delete/quarantine infected files."
Then my Desktop background changed to a red color and it said "Your privacy is in danger download privacy protection software now." I already had Spybot, Spyware Blaster, Spyware Guard, and Avast Antivirus installed before I got the pop ups. Could I had too much spyware protection on my computer? Well, I ran my Spybot and It found Smitfraud-c, SpyLocked. FakeAlart, Win32.BHD.je, Zlob. Downloader.vdt, Zlob. Downloader.vcd. When I tried to remove the problems my computer froze up.
I did the preparation and when I ran the AVG scan in safe mode and restart my computer my desktop turns white and I get a message that has Windows Internet Explorer on top and says"Cannot find 'file:///C:/WINDOWS/Privacy-danger/index.htm'.Make sure the path or Internet address is correct.
I nolonger get the Security Alerts or Security warnings but I dont know if my computer is free of Spyware and Trojans. Please help!!!!

HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:36:28 AM, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec....000030.0000010e
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2f...earch.html?p=KL
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.co...ALStreaming.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1172946596421
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...224/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O21 - SSODL: bdmanager - {DC027BDA-0C73-459B-A461-C984940276F1} - C:\WINDOWS\bdmanager.dll (file missing)
O21 - SSODL: KbdPrx - {4086594d-4bc7-46f9-8b62-fad73d7207d5} - C:\WINDOWS\Installer\{4086594d-4bc7-46f9-8b62-fad73d7207d5}\KbdPrx.dll
O21 - SSODL: bxlrvps - {E32133B8-BFB6-4DF5-A308-51AF9F0E1C47} - C:\WINDOWS\bxlrvps.dll (file missing)
O21 - SSODL: alofkmn - {840C24E6-87BB-4FDB-9F13-408A22B512D0} - C:\WINDOWS\alofkmn.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 11587 bytes

SUPERAntiSpyware Scan Log
Generated 02/28/2008 at 11:39 AM

Application Version : 3.6.1000

Core Rules Database Version : 3411
Trace Rules Database Version: 1403

Scan type : Complete Scan
Total Scan Time : 01:50:52

Memory items scanned : 532
Memory threats detected : 3
Registry items scanned : 6003
Registry threats detected : 20
File items scanned : 61020
File threats detected : 13

Trojan.Media-Codec/V5
C:\PROGRAM FILES\NETPROJECT\SCM.EXE
C:\PROGRAM FILES\NETPROJECT\SCM.EXE
C:\PROGRAM FILES\NETPROJECT\SBUN.EXE

Trojan.Smitfraud Variant
C:\WINDOWS\SYSTEM32\HEUVTH.DLL
C:\WINDOWS\SYSTEM32\HEUVTH.DLL
HKLM\Software\Classes\CLSID\{699fabf8-1087-491f-b57c-80a68929d82b}
HKCR\CLSID\{699FABF8-1087-491F-B57C-80A68929D82B}
HKCR\CLSID\{699FABF8-1087-491F-B57C-80A68929D82B}\InProcServer32
HKCR\CLSID\{699FABF8-1087-491F-B57C-80A68929D82B}\InProcServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{699fabf8-1087-491f-b57c-80a68929d82b}

Trojan.Net-ALO/NMC
C:\WINDOWS\ALOFKMN.DLL
C:\WINDOWS\ALOFKMN.DLL

Desktop Hijacker.AboutYourPrivacy
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\images
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\privacy_danger

Trojan.Media-Codec/V4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#some [ C:\Program Files\NetProject\scit.exe ]
HKCR\videoPl.chl
HKCR\videoPl.chl\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software#ProductionEnvironment
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software#DisplayVersion
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software#Publisher

Adware.E404 Helper/Hij
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid32
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib#Version

Trojan.Net-AGX/NMC
C:\WINDOWS\ADMGCX.DLL

Adware.SXGAdvisor
C:\WINDOWS\DMDVPNWGP.DLL

Edited by Kizzy, 29 February 2008 - 11:14 AM.

  • 0

Advertisements


#2
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Hi Kizzy

welcome back to geekstogo.

looks like you had a smitfraud infection. so before we tackle the other malware i can see in your logs we will ensure that this infection is all gone.

Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlog...processutil.htm

andrewuk
  • 0

#3
Kizzy

Kizzy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Hi andrewuk,
Thank you for your reply. I've downloaded and ran SmitfraudFix. Here is a copy of my report.

SmitFraudFix v2.299

Scan done at 17:39:20.35, Fri 02/29/2008
Run from C:\Documents and Settings\Kirsten\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

hosts file corrupted !

127.0.0.1 hk.digitaltrends.com
127.0.0.1 microsoft.com.org
127.0.0.1 www.www.microsoft.com.org
127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

C:\WINDOWS\fkxvkns.exe FOUND !
C:\WINDOWS\fsxloqf.exe FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kirsten


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Kirsten\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Kirsten\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="file:///C:\\WINDOWS\\privacy_danger\\index.htm"
"SubscribedURL"=""
"FriendlyName"="Privacy Protection"


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
+--------------------------------------------------+
[!] Suspicious: KbdPrx.dll
SSODL: KbdPrx - {4086594d-4bc7-46f9-8b62-fad73d7207d5}


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 192.168.0.1
DNS Server Search Order: 192.168.0.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{2810EB22-763D-4D0C-9450-64BBD1758685}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{BE506650-0D08-4C39-92D6-A97C94492D8C}: DhcpNameServer=192.168.0.1 192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{BE506650-0D08-4C39-92D6-A97C94492D8C}: DhcpNameServer=192.168.0.1 192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{2810EB22-763D-4D0C-9450-64BBD1758685}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS2\Services\Tcpip\..\{BE506650-0D08-4C39-92D6-A97C94492D8C}: DhcpNameServer=192.168.0.1 192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{2810EB22-763D-4D0C-9450-64BBD1758685}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{BE506650-0D08-4C39-92D6-A97C94492D8C}: DhcpNameServer=192.168.0.1 192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 192.168.0.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
  • 0

#4
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
ok, i can still see traces of the smitfraud infection, so we will remove it now and then do a deeper scan of your machine.


====STEP 1====
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.


====STEP 2====
Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.


In your next reply could i see:
1. the rapport.txt log
2. the 2 DSS logs

there will be a lot of information to post, so you may have to post it over more than one reply to ensure it is all posted.

andrewuk
  • 0

#5
Kizzy

Kizzy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
I did the SmitfraudFix.exe clean in safe mode and ran the Deckard's System Scanner the only notepad that opened was the main.txt notepad. Here is the copy of the SmitFraud report. The DSS main.txt will be in one of the following post because my post was too long and I had to break them up.

SmitFraudFix v2.299

Scan done at 19:13:44.04, Fri 02/29/2008
Run from C:\Documents and Settings\Kirsten\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 www.aaa-livedoor.net #[Trojan-PSW.Win32.Maran.ei]
127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net
127.0.0.1 b.abnad.net
127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
127.0.0.1 d.abnad.net
127.0.0.1 e.abnad.net
127.0.0.1 t.abnad.net
127.0.0.1 banners.absolpublisher.com
127.0.0.1 tracking.absolstats.com
127.0.0.1 adv.abv.bg
127.0.0.1 bimg.abv.bg
127.0.0.1 www2.a-counter.kiev.ua
127.0.0.1 accuserveadsystem.com
127.0.0.1 www.accuserveadsystem.com
127.0.0.1 gtcc1.acecounter.com
127.0.0.1 gtp1.acecounter.com #[eTrust.Tracking.Cookie]
127.0.0.1 acestats.com
127.0.0.1 www.acestats.com
127.0.0.1 acilot.cn #[Malicious.Links.Codec]
127.0.0.1 ads.active.com
127.0.0.1 am1.activemeter.com
127.0.0.1 www.activemeter.com #[eTrust.Tracking.Cookie]
127.0.0.1 ads.activepower.net
127.0.0.1 stat.active24stats.nl #[eTrust.Tracking.Cookie]
127.0.0.1 web.acumenpi.com #[AdvertPro]
127.0.0.1 ad.ad24.ru
127.0.0.1 at.ad2click.nl
127.0.0.1 cms.ad2click.nl
127.0.0.1 banner.ad.nu
127.0.0.1 ad-up.com
127.0.0.1 www.ad-up.com
127.0.0.1 www.adagencypro.com
127.0.0.1 ads.adap.tv
127.0.0.1 ad.pop1.adbn.ru
127.0.0.1 adserv.adbonus.com
127.0.0.1 www.adbonus.com
127.0.0.1 james.adbutler.de #[Tenebril.TrackingCookie]
127.0.0.1 www.adbutler.de #[SunBelt.AdButler.de]
127.0.0.1 adc2.adcentriconline.com
127.0.0.1 adcp.adcentriconline.com
127.0.0.1 bell.adcentriconline.com #[Wildcard DNS]
127.0.0.1 content.adcentriconline.com
127.0.0.1 media.adcentriconline.com
127.0.0.1 publicis.adcentriconline.com
127.0.0.1 ad-clix.com
127.0.0.1 www.ad-clix.com
127.0.0.1 adcomplete.com
127.0.0.1 www.adcomplete.com
127.0.0.1 axa.addcontrol.net #[Ewido.TrackingCookie.Addcontrol]
127.0.0.1 ads.addynamix.com #[SpySweeper.Spy.Cookie]
127.0.0.1 e13.media.addynamix.com
127.0.0.1 www.adeos.eu
127.0.0.1 adcode.adengage.com
127.0.0.1 stats2.adengage.com
127.0.0.1 www.adengage.com
127.0.0.1 pt.server1.adexit.com
127.0.0.1 www.adexit.com
127.0.0.1 www.ad4ever.com
127.0.0.1 track.adform.net
127.0.0.1 adfun.ru
127.0.0.1 ad1.adfun.ru
127.0.0.1 ad2.adfun.ru
127.0.0.1 ad3.adfun.ru
127.0.0.1 ad4.adfun.ru
127.0.0.1 www.adfusion.com
127.0.0.1 harvest.adgardener.com
127.0.0.1 harvest6.adgardener.com
127.0.0.1 harvest7.adgardener.com
127.0.0.1 harvest8.adgardener.com
127.0.0.1 harvest11.adgardener.com
127.0.0.1 harvest12.adgardener.com
127.0.0.1 harvest13.adgardener.com
127.0.0.1 harvest163.adgardener.com
127.0.0.1 harvest176.adgardener.com
127.0.0.1 seeds.adgardener.com
127.0.0.1 www.adgroups.net
127.0.0.1 www.ad-groups.com #[Ban Man Pro Banner Code]
127.0.0.1 www.adgauge.com
127.0.0.1 host1.adhese.be #[Adhese Datamine Tag]
127.0.0.1 host2.adhese.be
127.0.0.1 host3.adhese.be #[ad.be.doubleclick.net]
127.0.0.1 host4.adhese.be
127.0.0.1 ads.adhsm.adhese.com
127.0.0.1 pool.adhsm.adhese.com
127.0.0.1 ssl3.adhost.com
127.0.0.1 www2.adhost.com
127.0.0.1 ads.adhostingsolutions.com #[eTrust.Tracking.Cookie]
127.0.0.1 www.adimpact.com
127.0.0.1 www.adinventoryrecorder.com #[server down?]
127.0.0.1 adfarm1.adition.com
127.0.0.1 imagesrv.adition.com
127.0.0.1 ad.adition.net
127.0.0.1 adsearch.adkontekst.pl
127.0.0.1 community.adlandpro.com #[Ad-Aware Tracking.Cookie]
127.0.0.1 pk.adlandpro.com
127.0.0.1 te.adlandpro.com #[eTrust.Tracking.Cookie]
127.0.0.1 trafficex.adlandpro.com
127.0.0.1 www.adlandpro.com #[Ad-Aware Tracking.Cookie]
127.0.0.1 engine.adland.ru #[eTrust.Tracking.Cookie]
127.0.0.1 publicidad.adlead.com
127.0.0.1 www.adlimg03.com
127.0.0.1 classic.adlink.de
127.0.0.1 regio.adlink.de
127.0.0.1 west.adlink.de
127.0.0.1 rc.de.adlink.net #[eTrust.Tracking.Cookie]
127.0.0.1 tr.de.adlink.net
127.0.0.1 ads3.adman.gr #[eTrust.Tracking.Cookie]
127.0.0.1 r2d2.adman.gr
127.0.0.1 www.adminder.com #[SpySweeper.Spy.Cookie]
127.0.0.1 apps.admission.net #[Spotlight Ads]
127.0.0.1 appcache.admission.net
127.0.0.1 view.admission.net
127.0.0.1 rms.admeta.com #[admeta.basefarm.net][eTrust.Tracking.Cookie]
127.0.0.1 ads.admodus.com #[eTrust.Tracking.Cookie]
127.0.0.1 ad.adnet.biz #[eTrust.Tracking.Cookie]
127.0.0.1 engine.adnet.ru
127.0.0.1 ad2.adnetinteractive.com
127.0.0.1 ad.adnetwork.com.br
127.0.0.1 s1.ad.adocean.pl #[Ewido.Tracking.Cookie]
127.0.0.1 s2.ad.adocean.pl
127.0.0.1 s1.centrumcz.adocean.pl #[eTrust.Tracking.Cookie]
127.0.0.1 s1.cz.adocean.pl
127.0.0.1 s1.czgde.adocean.pl
127.0.0.1 s1.myao.adocean.pl
127.0.0.1 s1.skgde.adocean.pl
127.0.0.1 ad01.adonspot.com
127.0.0.1 ad02.adonspot.com
127.0.0.1 isohunt.adonspot.com
127.0.0.1 ab.adpro.com.ua
127.0.0.1 ac.adpro.com.ua
127.0.0.1 system.adquick.nl
127.0.0.1 www.adquest.nl
127.0.0.1 adreactor.com
127.0.0.1 adserver.adreactor.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 adx.adrenaline.cz
127.0.0.1 www.adscampaign.com
127.0.0.1 www.adsforindians.com
127.0.0.1 ad.adrefer.net
127.0.0.1 www.adreporting.com #[SunBelt.Adreporting.com]
127.0.0.1 cntr.adrime.com
127.0.0.1 images.adrime.com
127.0.0.1 ad.adriver.ru
127.0.0.1 www.adrotate.net
127.0.0.1 serv.ad-rotator.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ad.ads8.com
127.0.0.1 vip.ads8.com
127.0.0.1 www.ads183.com
127.0.0.1 ad.adsandads.net #[Trojan.Advatrix]
127.0.0.1 cpv.adsandads.net
127.0.0.1 antevenio.flux.ads-click.com
127.0.0.1 ad.ads.dk
127.0.0.1 tdkads.ads.dk
127.0.0.1 adservercentral.com
127.0.0.1 banners.adservercentral.com
127.0.0.1 www.adservercentral.com #[SunBelt.adservercentral.com]
127.0.0.1 adservicedomain.info
127.0.0.1 adsfac.net #[Facilitate Tracking Code]
127.0.0.1 images.adshuffle.com
127.0.0.1 this.content.served.by.adshuffle.com
127.0.0.1 adsaway.com #[HTML/TrojanDownloader.Agent.BP trojan]
127.0.0.1 www.adsaway.com #[Google.Warning]
127.0.0.1 adsfac.eu
127.0.0.1 www.adshot.de
127.0.0.1 network.adsmarket.com
127.0.0.1 allchix.adsmax.com
127.0.0.1 www2.adsmax.com
127.0.0.1 www.adsodainteractive.com
127.0.0.1 www.adspace.be
127.0.0.1 g.adspeed.net
127.0.0.1 ad-rotator.com #[adspeed.com]
127.0.0.1 serv.adspeed.com
127.0.0.1 www.adspeed.com
127.0.0.1 ads.adsponse.de
127.0.0.1 banner.adsrevenue.net
127.0.0.1 creative.adsrevenue.net
127.0.0.1 popunder.adsrevenue.net
127.0.0.1 adserve.adster.com
127.0.0.1 images.adster.com
127.0.0.1 adsvert.com
127.0.0.1 o.adtargeter.com
127.0.0.1 ads.adtiger.de
127.0.0.1 www.adtiger.de
127.0.0.1 ads.adgoto.com
127.0.0.1 adsrv.admindshare.com
127.0.0.1 adtology.com
127.0.0.1 adtology2.com
127.0.0.1 ad.adtoma.com
127.0.0.1 downldcl.adtoolsinc.com
127.0.0.1 www.adtoolsinc.com
127.0.0.1 www.adtrade.net
127.0.0.1 www.adtrader.com
127.0.0.1 ads.advancedpcmedia.com
127.0.0.1 survey.advantageresearch.com
127.0.0.1 ad.adver.com.tw
127.0.0.1 www.adventideas.com #[Adcycle]
127.0.0.1 www.adversal.com
127.0.0.1 www.adversalservers.com
127.0.0.1 ads.advertise.net
127.0.0.1 www.advertisingspaces.net
127.0.0.1 www.advertisingstats.com
127.0.0.1 advertisingpurchase.com
127.0.0.1 ad.adverticum.net
127.0.0.1 img.adverticum.net
127.0.0.1 imgs.adverticum.net
127.0.0.1 www.advertising365.com
127.0.0.1 ads.advertisingz.com
127.0.0.1 ad.advertstream.com
127.0.0.1 adviva.com
127.0.0.1 www.adviva.com
127.0.0.1 ads.adviva.net #[Panda.Spyware:Cookie/Adviva]
127.0.0.1 de.ads.adviva.net
127.0.0.1 adstats.adviva.net
127.0.0.1 www.traf.advscripts.com
127.0.0.1 ad.adworx.at
127.0.0.1 www.ad-z.de
127.0.0.1 banners.adzones.com
127.0.0.1 clicks.adzones.com
127.0.0.1 feeds.adzones.com
127.0.0.1 www.adzones.com
127.0.0.1 w.aeaer.com #[Google.Warning]
127.0.0.1 aeoworld.de
127.0.0.1 www.aeoworld.de #[W32/WMF-exploit]
127.0.0.1 banners.affilimatch.de
127.0.0.1 tracker.affistats.com #[msvrl.dll]
127.0.0.1 adz.afterdawn.net
127.0.0.1 ad.afy11.net
127.0.0.1 stats.agent.co.il
127.0.0.1 agentmediagroup.com #[Javascript.Exploit]
127.0.0.1 www.agentmediagroup.com
127.0.0.1 rmbannerserver.agestado.com.br
127.0.0.1 stats.agentinteractive.com
127.0.0.1 api.aggregateknowledge.com
127.0.0.1 aams1.aim4media.com
127.0.0.1 artwork.aim4media.com
127.0.0.1 www.aim4media.com #[SunBelt.Adserver.aim4media]
127.0.0.1 ads.airamerica.com
127.0.0.1 adserver.akqa.net #[Ad-Aware Tracking.Cookie]
127.0.0.1 aldorawar.com
127.0.0.1 www.aldorawar.com #[JS/Exploit.ADODB.Stream.NAP]
127.0.0.1 download.alexa.com #[Trackware.Alexa][SPYW_ALEXA.A]
127.0.0.1 download.china.alibaba.com #[Adware.AlibabaTB][AdWare.ToolBar.Alibabar.b]
127.0.0.1 ad.alldanzradio.com
127.0.0.1 tracking.allposters.com
127.0.0.1 ad.allstar.cz
127.0.0.1 bokee.allyes.com
127.0.0.1 demoafp.allyes.com
127.0.0.1 eastmoney.allyes.com
127.0.0.1 smarttrade.allyes.com
127.0.0.1 sroomafp.allyes.com
127.0.0.1 taobaoafp.allyes.com
127.0.0.1 tom.allyes.com
127.0.0.1 uuseeafp.allyes.com
127.0.0.1 www.almondnetworks.com
127.0.0.1 www.almoso3h.com #[Trojan-PSW.Win32.VB.cl]
127.0.0.1 www.alsaloumainvestment.com #[Win32/SpamTool.Gadina]
127.0.0.1 ad.altervista.org
127.0.0.1 pqwaker.altervista.org
127.0.0.1 bantam.ai.net
127.0.0.1 fiona.ai.net
127.0.0.1 adimg.alice.it
127.0.0.1 adv.alice.it
127.0.0.1 altmedia101.com
127.0.0.1 www.alldep.com #[Spamdexing]
127.0.0.1 adserver.alt.com
127.0.0.1 count1.altastat.com
127.0.0.1 feed1.altastat.com
127.0.0.1 www.alwayson-network.com
127.0.0.1 rcm.amazon.com
127.0.0.1 rcm-images.amazon.com
127.0.0.1 banner.ambercoastcasino.com
127.0.0.1 ads.amdmb.com
127.0.0.1 whos.amung.us #[WebBug]
127.0.0.1 advert.ananzi.co.za
127.0.0.1 advert2.ananzi.co.za
127.0.0.1 adserver.ancestry.com #[RealMedia]
127.0.0.1 adserver04.ancestry.com #[RealMedia]
127.0.0.1 www.andyhoppe.com
127.0.0.1 ads.angryape.com
127.0.0.1 banners.ads.angryape.com
127.0.0.1 www.antarasystems.com
127.0.0.1 www.anticlown.com
127.0.0.1 ads.antionline.com
127.0.0.1 junior.apk.net
127.0.0.1 www.arcadebannerexchange.com
127.0.0.1 ard114.info #[Spamdexing]
127.0.0.1 nu.arnostat.nl
127.0.0.1 demiurge.arstechnica.com
127.0.0.1 banner.arttoday.com
127.0.0.1 ads.asia1.com.sg
127.0.0.1 asimpleinternet.com #[Tenebril.SpecialOffers]
127.0.0.1 www.asimpleinternet.com
127.0.0.1 ads.ask.com #[sv-click.looksmart.com]
127.0.0.1 www.askyaya.com #[SunBelt.AskYaya]
127.0.0.1 ads.aspalliance.com
127.0.0.1 ads.associatedcontent.com
127.0.0.1 f.astaz.info #[Malicious.Links.Codec]
127.0.0.1 www.ati-etailer.de
127.0.0.1 dist.atlas-ia.com #[ADW_ATLAST.A]
127.0.0.1 www.atlas-ia.com #[Adware.OfferAgent][Adware-Atlas]
127.0.0.1 ads.auctionads.com
127.0.0.1 audiogalaxy.com
127.0.0.1 www.audiogalaxy.com
127.0.0.1 ads.auctioncity.co.nz
127.0.0.1 www.autosurfpro.com
127.0.0.1 ads.autotrader.co.za
127.0.0.1 adserving.autotrader.com #[SunBelt.AdServing.AutoTrader.com]
127.0.0.1 www.avsads.com
127.0.0.1 engine.awaps.net
127.0.0.1 www.axill.com
127.0.0.1 images.axill.in
127.0.0.1 www.axill.in
127.0.0.1 axload.to #[Adware.Webprefix][Trojan.Downloader.6588.E]
127.0.0.1 valid.axload.to
127.0.0.1 ayiosamvrosios.com #[Javascript.Exploit]
127.0.0.1 www.azads.net
127.0.0.1 azresults.com #[Spamdexing]
127.0.0.1 www.azresults.com
127.0.0.1 azsearch.org
127.0.0.1 adserver1.backbeatmedia.com
127.0.0.1 adserver1-images.backbeatmedia.com
127.0.0.1 bullseye.backbeatmedia.com
127.0.0.1 www.badhyip.org #[Google.Warning]
127.0.0.1 ads.badische-zeitung.de
127.0.0.1 bar.baidu.com #[Win32/Adware.Toolbar.Baidu][Sophos.JS/BDHelper-A]
127.0.0.1 download.baigoo.com #[AdWare.Win32.Baigoo.a][Trackware.Baigoo]
127.0.0.1 balticaffiliate.com #[Spamdexing]
127.0.0.1 www.baltictop.com
127.0.0.1 adsrv.bankrate.com
127.0.0.1 click.banneradv.com
127.0.0.1 adserver.banneradministration.com
127.0.0.1 www.bannerbox.cn
127.0.0.1 bannerboxes.com #[BannerBoxes Ad Code]
127.0.0.1 clicks.bannerboxes.com
127.0.0.1 feeds.bannerboxes.com
127.0.0.1 www.bannerboxes.com
127.0.0.1 www.banner-exchange.nl
127.0.0.1 ad.bannerhost.ru
127.0.0.1 www.bannerhouse.ru
127.0.0.1 banners.bannerlandia.com.ar
127.0.0.1 www.bannermanagement.nl
127.0.0.1 www.bannerout.com
127.0.0.1 www.banneroverdrive.com
127.0.0.1 www.bannerpromotion.it
127.0.0.1 www.bannerspace.com
127.0.0.1 www3.bannerspace.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www5.bannerspace.com
127.0.0.1 www6.bannerspace.com
127.0.0.1 www7.bannerspace.com #[Tenebril.Tracking.Cookie]
127.0.0.1 www.bannerswap.ca
127.0.0.1 ads.vg.basefarm.net #[RealMedia]
127.0.0.1 ads.baz.ch
127.0.0.1 ad2.bbmedia.cz
127.0.0.1 bbeplayer.com #[WebBug]
127.0.0.1 stat.bdirect.ru
127.0.0.1 autocontext.begun.ru
127.0.0.1 promo.begun.ru
127.0.0.1 referal.begun.ru
127.0.0.1 adlogger.bertgeens.be
127.0.0.1 www.belstat.be
127.0.0.1 www.belstat.com
127.0.0.1 www.belstat.nl
127.0.0.1 oas.benchmark.fr #[RealMedia]
127.0.0.1 bengilani.com #[VBS/Envary.A]
127.0.0.1 bestinshowjewelry.com #[HTML/TrojanDownloader.Agent.BP]
127.0.0.1 www.bestinshowjewelry.com
127.0.0.1 webtrends.besite.be
127.0.0.1 www.bestofferdirect.com
127.0.0.1 bestsites.net.ru
127.0.0.1 www.besttoolbars.net #[ADW_TBARWIN32.A]
127.0.0.1 ads.betanews.com
127.0.0.1 banner.betfred.com
127.0.0.1 www.bettertextads.com
127.0.0.1 big4top.com
127.0.0.1 www.big4top.com #[IFrame.Exploit]
127.0.0.1 stats.big-boards.com
127.0.0.1 ad0.bigmir.net
127.0.0.1 ad1.bigmir.net
127.0.0.1 ad4.bigmir.net
127.0.0.1 ad5.bigmir.net
127.0.0.1 ad6.bigmir.net
127.0.0.1 ad7.bigmir.net
127.0.0.1 adi.bigmir.net
127.0.0.1 c.bigmir.net #[SecuritySpace.WebBug]
127.0.0.1 i.bigmir.net
127.0.0.1 bigtracker.com
127.0.0.1 bighits.net
127.0.0.1 bigticker.bighits.net
127.0.0.1 bounty.bighits.net
127.0.0.1 www.bighits.net
127.0.0.1 counter.bigli.ru
127.0.0.1 bigstats.net
127.0.0.1 banex.bikers-engine.com
127.0.0.1 ad2.billboard.cz
127.0.0.1 adserver.bizhat.com
127.0.0.1 counter.bizland.com
127.0.0.1 dc.bizjournals.com
127.0.0.1 www1.bkyes.com
127.0.0.1 www.black-hole.co.uk
127.0.0.1 ads2.blastro.com
127.0.0.1 ads3.blastro.com
127.0.0.1 ads4.blastro.com
127.0.0.1 ads.blick.ch
127.0.0.1 streamstats1.blinkx.com
127.0.0.1 ads.blizzard.com
127.0.0.1 blogadswap.com
127.0.0.1 tracker.blogbeat.net
127.0.0.1 ads.blogdrive.com
127.0.0.1 banners.blogexplosion.com
127.0.0.1 counter.blogexplosion.com
127.0.0.1 blogtextlinks.blogexplosion.com
127.0.0.1 rentblog.blogexplosion.com
127.0.0.1 mapstats.blogflux.com
127.0.0.1 www.blogplaync.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 pcbutts1-therealtruth.blogspot.com
127.0.0.1 t.blogreaderproject.com #[WebBug]
127.0.0.1 blogmark.bokee.com #[Adware.BocaiToolbar]
127.0.0.1 track.blogcounter.de
127.0.0.1 www.blogcounter.de
127.0.0.1 adserver.bluewin.ch
127.0.0.1 www.bmmetrix.com #[WebBug][Tracking.Cookie]
127.0.0.1 ads.boardtracker.com
127.0.0.1 ranks.boardtracker.com
127.0.0.1 adimage.bokee.com
127.0.0.1 ad.bol.bg
127.0.0.1 adv.bol.bg
127.0.0.1 ads.bomis.com
127.0.0.1 banners.bookmaker.com
127.0.0.1 ccc.boolans.com #[Adware.Rugo]
127.0.0.1 err.boom.ru
127.0.0.1 www.borlander.cn #[Adware.Borlan]
127.0.0.1 www.borlander.com.cn #[ADSPY/Boran.X.19.C]
127.0.0.1 ads.brainiads.com #[server down?]
127.0.0.1 ads.breakthru.com
127.0.0.1 bans.bride.ru
127.0.0.1 ads.bridgetrack.com
127.0.0.1 cc.bridgetrack.com
127.0.0.1 citi.bridgetrack.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 citi.bridgetrack.com.edgesuite.net
127.0.0.1 rccl.bridgetrack.com #[MVPS.Criteria]
127.0.0.1 banners.broadwayworld.com
127.0.0.1 www.browserplugin.com #[HJTH.EroticAccess][wobz.de]
127.0.0.1 bsdpng.info
127.0.0.1 btbilgisayarkursu.com #[Win32/TrojanDownloader.Small.AWA]
127.0.0.1 www.btbilgisayarkursu.com #[Win32/TrojanDownloader.Small.AWA]
127.0.0.1 www.bulletads.com
127.0.0.1 redemption.bullseye-media.net
127.0.0.1 users.bullseye-media.net
127.0.0.1 www.bullseye-media.net
127.0.0.1 bunnezone.com #[Win32/Jep.Russ]
127.0.0.1 burnsrecyclinginc.com #[Win32/TrojanDropper.Agent.NBX]
127.0.0.1 www.burnsrecyclinginc.com
127.0.0.1 ad1.bustcash.com
127.0.0.1 www.buy404s.com
127.0.0.1 www.buycheapadvertising.com
127.0.0.1 buytraffic.cn
127.0.0.1 www.buzzclick.com
127.0.0.1 tr.buzzlogic.com
127.0.0.1 tracking.byindia.com
127.0.0.1 www.byip.cn #[Google.Warning]
127.0.0.1 multi.byulcom.com #[Win32/TrojanDownloader.Small.BIV]
127.0.0.1 ads.calgarystampede.com
127.0.0.1 canadianhw.ca #[VBS/Envary.A]
127.0.0.1 www.canadianhw.ca
127.0.0.1 ads.capablenet.com
127.0.0.1 images.cashfiesta.com #[AdWare.CashFiesta.a]
127.0.0.1 www.cashfiesta.com #[McAfee.Adware-CashFiesta]
127.0.0.1 www.cashfiesta.net
127.0.0.1 banner.casinoking.com #[AdWare.Win32.Casino.ae]
127.0.0.1 www.cashventure.com
127.0.0.1 ad.caradisiac.com
127.0.0.1 ads.cars.com
127.0.0.1 qi.ccbtv.net #[Google.Warning]
127.0.0.1 blockbuster.com.7.ccg360.com
127.0.0.1 blockbuster.med.ccg360.com
127.0.0.1 www.cd321.com
127.0.0.1 ads.cdfreaks.com #[eTrust.Ads.cdfreaks]
127.0.0.1 ads.cdrinfo.com
127.0.0.1 stats.cdrinfo.com #[WebBug]
127.0.0.1 www.celebritypicturesarchive.com #[Trojan-Downloader.Win32.IstBar.nn]
127.0.0.1 www.celebrity-pictures-world.com #[Trojan-Downloader.Win32.IstBar.nn]
127.0.0.1 clicktracker.centrum.cz
127.0.0.1 cetrk.com #[Crazy Egg]
127.0.0.1 cesp.be #[HTML/TrojanDownloader.Agent.NAB]
127.0.0.1 adserver.cducinema.com
127.0.0.1 counter.cgiworld.net
127.0.0.1 tracker.cgiworld.net
127.0.0.1 cts.channelintelligence.com #[switch.atdmt.com]
127.0.0.1 abc.checkm8.com
127.0.0.1 ny.checkm8.com
127.0.0.1 rmm1u.checkm8.com
127.0.0.1 web.checkm8.com #[CHECKM8 AD TAGS]
127.0.0.1 web2.checkm8.com
127.0.0.1 ads.checkm8.co.za
127.0.0.1 ads.chellomedia.com
127.0.0.1 ads.china.com
127.0.0.1 ad.chip.de
127.0.0.1 www.chsniper.com #[Downloader.Sniper]
127.0.0.1 chunkypig.com #[AdWare.Win32.Chiem.c]
127.0.0.1 www.chunkypig.com
127.0.0.1 ad.cibleclick.com #[eTrust.Cibleclick]
127.0.0.1 www.cibleclick.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 www.classicequipment.com #[Google.Warning]
127.0.0.1 board.classifieds1000.com
127.0.0.1 xp.classifieds1000.com
127.0.0.1 www.classifieds1000.com #[SiteAdvisor.classifieds1000.com]
127.0.0.1 images.clckm.com
127.0.0.1 pics.clckm.com #[Parking Service]
127.0.0.1 ads.clickad.com #[eTrust.Tracking.Cookie]
127.0.0.1 clickbank.net #[Ad-Aware.Tracking.Cookie]
127.0.0.1 hop.clickbank.net #[Adware.Clickbank][Adware.ClickDLoader]
127.0.0.1 ssl.clickbank.net
127.0.0.1 zzz.clickbank.net #[Ewido.TrackingCookie.Clickbank]
127.0.0.1 publishers.clickbooth.com #[directleads.com]
127.0.0.1 clickboothlnk.com
127.0.0.1 www.clickboothlnk.com
127.0.0.1 j.clickdensity.com
127.0.0.1 r.clickdensity.com
127.0.0.1 cf-db01.clickfacts.com
127.0.0.1 server104.clickfacts.com #[ClickFacts Tracking Beacon]
127.0.0.1 www.clickmanage.com
127.0.0.1 clicktracks.com #[McAfee.Cookie-Clicktracks]
127.0.0.1 stats.clicktracks.com #[Tenebril.Tracking.Cookie]
127.0.0.1 stats1.clicktracks.com # [eTrust.Tracking.Cookie]
127.0.0.1 stats2.clicktracks.com #[SpySweeper.Spy.Cookie]
127.0.0.1 stats3.clicktracks.com
127.0.0.1 stats4.clicktracks.com
127.0.0.1 www.clicktracks.com #[SunBelt.ClickTracks]
127.0.0.1 www.is1.clixgalore.com
127.0.0.1 www.clixgalore.com
127.0.0.1 hit.click2006.com
127.0.0.1 www2.click-fr.com
127.0.0.1 www3.click-fr.com
127.0.0.1 www4.click-fr.com
127.0.0.1 www.clickhouse.com #[SunBelt.ClickHouse]
127.0.0.1 www.click-power.com #[Win32/TrojanDownloader.VB.JL][Win32.Virtumonde.by]
127.0.0.1 www.clicksbroker.com
127.0.0.1 ad1.clickhype.com #[Ewido.TrackingCookie.Clickhype]
127.0.0.1 redirect.clickshield.net
127.0.0.1 clickthru.net
127.0.0.1 ads.clickthru.net
127.0.0.1 icon.clickthru.net
127.0.0.1 clicktorrent.info
127.0.0.1 static.clicktorrent.info
127.0.0.1 www.clicktorrent.info #[phpAds]
127.0.0.1 www1.clicktorrent.info
127.0.0.1 norbert_sirot.club.fr #[Trojan-Spy.Win32.Banker.anv]
127.0.0.1 banner.clubdicecasino.com
127.0.0.1 adserver.clix.pt
127.0.0.1 ad.cmfu.com
127.0.0.1 www.cnstats.com
127.0.0.1 ad.coas2.co.kr
127.0.0.1 ads.cobrad.com
127.0.0.1 collectiveads.net
127.0.0.1 com.au.com #[Rogue/Suspect Affiliate.sites]
127.0.0.1 www.comclean.co.kr #[Spyware.Comclean]
127.0.0.1 comcord.info #[Spamdexing][server down?]
127.0.0.1 www.combimedia.nl #[server down?]
127.0.0.1 bdx.comclick.com
127.0.0.1 br.comclick.com
127.0.0.1 ct2.comclick.com #[Tenebril.Tracking.Cookie]
127.0.0.1 fl01.ct2.comclick.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 ihm01.ct2.comclick.com
127.0.0.1 www.comclick.com #[Ewido.TrackingCookie.Comclick]
127.0.0.1 banners.commissionking.com
127.0.0.1 members.commissionmonster.com
127.0.0.1 aa.connextra.com
127.0.0.1 bb.connextra.com #[a22.g.akamai.net]
127.0.0.1 cc.connextra.com
127.0.0.1 dd.connextra.com
127.0.0.1 ee.connextra.com
127.0.0.1 ff.connextra.com #[a22.g.akamai.net]
127.0.0.1 data.connextra.com
127.0.0.1 linkexchange.consoleunderground.com
127.0.0.1 www.consoleunderground.com #[Adware.Begin2search]
127.0.0.1 ads.consumeraffairs.com
127.0.0.1 ads.contact.md
127.0.0.1 ads.contactmusic.com #[AdvertPro]
127.0.0.1 servedby.contextuad.org
127.0.0.1 svp.contextuad.org #[SunBelt.ContextuAd]
127.0.0.1 www.contextpanel.com #[searchant.com]
127.0.0.1 ads.console.net
127.0.0.1 banners.copyscape.com
127.0.0.1 www.counter-x.com
127.0.0.1 www.countit.ch
127.0.0.1 counter.co.kz
127.0.0.1 www.counter-gratis.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 www.countercentral.com
127.0.0.1 www.counterdata.com
127.0.0.1 www.counterguide.com
127.0.0.1 counter-shop.net
127.0.0.1 htm-pop-ky.counterstat.net
127.0.0.1 www.counting4free.com
127.0.0.1 www.counter.cz
127.0.0.1 www.counti.de
127.0.0.1 www.countmypage.com
127.0.0.1 log1.countomat.com
127.0.0.1 connectionzone.com
127.0.0.1 www.couponsandoffers.com #[Adware.TopMoxie]
127.0.0.1 data.coremetrics.com
127.0.0.1 test.coremetrics.com #[SpySweeper.Spy.Cookie]
127.0.0.1 twci.coremetrics.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 banner.coza.com
127.0.0.1 cp16688.cn #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 www.cp16688.cn #[VBS/TrojanDownloader.Psyme.FM]
127.0.0.1 www.cpaclicks.com #[Spamdexing]
127.0.0.1 server.cpmstar.com #[ads.shizmoo.com]
127.0.0.1 cracks.am #[eTrust.Cracks.am][ADW_CRAMTB.A]
127.0.0.1 www.cracks.am #[[bleep]-portal.com][Adware.CramToolbar]
127.0.0.1 ads.cracked.com
127.0.0.1 track.cracked.com
127.0.0.1 new.crashextads.co.uk
127.0.0.1 crawl.ws
127.0.0.1 cont.crawl.ws #[AdWare.Win32.MegaKiss.b]
127.0.0.1 www.crawl.ws
127.0.0.1 counter.credo.ru
127.0.0.1 www.cridem.org #[Win32/Spy.Banker.AHY]
127.0.0.1 ads.crosswinds.net
127.0.0.1 ads.crucialparadigm.com
127.0.0.1 cdn.crwdcntrl.net
127.0.0.1 media.customeracquisitionsite.com #[customeracquisitionsite.adlegend.com]
127.0.0.1 cxss358.com #[HTML/TrojanDownloader.Agent.BP]
127.0.0.1 banner.cybertechdev.com
127.0.0.1 cybertown.ru
127.0.0.1 search.cygo.net
127.0.0.1 www.cygo.net #[McAfee.Adware-Cygo]
127.0.0.1 ads.dada.it
127.0.0.1 www.dailykeys.com #[Google.Warning]
127.0.0.1 aj.daniweb.com
127.0.0.1 www.data-jpn.com #[Trojan.Pajatan]
127.0.0.1 banner.date.com #[Tenebril.Tracking.Cookie]
127.0.0.1 www.dateclix.com #[DateClix.com Banner Exchange Code]
127.0.0.1 datingbanners.net
127.0.0.1 ads.datinggold.com
127.0.0.1 ad.db3nf.com
127.0.0.1 dcstat.com
127.0.0.1 ads.dealnews.com
127.0.0.1 au.track.decideinteractive.com
127.0.0.1 au.link.decideinteractive.com
127.0.0.1 eu.link.decideinteractive.com
127.0.0.1 link.decideinteractive.com
127.0.0.1 www.decideinteractive.com
127.0.0.1 www.decideinteractive.co.uk
127.0.0.1 deepcom.com #[SiteAdvisor.deepcom.com]
127.0.0.1 www.deepcom.com #[TrojanDropper.Win32.Small.gt]
127.0.0.1 collector.deepmetrix.com
127.0.0.1 geo.deepmetrix.com
127.0.0.1 www.deepmetrix.com #[Microsoft]
127.0.0.1 ads.dennisnet.co.uk
127.0.0.1 ad.depositfiles.com
127.0.0.1 ad.detik.com
127.0.0.1 desire-search.com #[Spamdexing]
127.0.0.1 ads.deviantart.com
127.0.0.1 adsvr.deviantart.com
127.0.0.1 phpadsnew.devstart.com
127.0.0.1 www.dhtianyu.net #[Spamdexing]
127.0.0.1 banners.diariodelaltoaragon.es
127.0.0.1 track.did-it.com #[Panda.Spyware:Cookie/did-it]
127.0.0.1 counter.dieit.de
127.0.0.1 digiwexonline.com #[W32/Kibik.a]
127.0.0.1 www.digink.com #[PcTools.SysCheckBop32][server down?]
127.0.0.1 ads.digitalpoint.com
127.0.0.1 geo.digitalpoint.com
127.0.0.1 comm1.digits.com
127.0.0.1 counter.digits.com
127.0.0.1 ads.dir.bg
127.0.0.1 banners.dir.bg
127.0.0.1 ad.directaclick.com
127.0.0.1 direct-ip.com #[Adware-DirectIP][SecurityRisk.DirectIP][server down?]
127.0.0.1 www.direct-ip.com #[Adware-DirectIP][Adware-CommanderNET]
127.0.0.1 ad.directconnect.se
127.0.0.1 banners.directnic.com #[SecuritySpace.WebBug][MVPS.Criteria]
127.0.0.1 dnads.directnic.com
127.0.0.1 parked.directnic.com
127.0.0.1 stats.directnic.com
127.0.0.1 www.directnicparking.com
127.0.0.1 cache.directorym.com #[c2.mii.instacontent.net]
127.0.0.1 ads.directnetadvertising.net #[SiteAdvisor.directnetadvertising.net]
127.0.0.1 www.directnetadvertising.net #[Ad-Aware Tracking.Cookie]
127.0.0.1 direct-web.co.kr #[Adware-DirectWeb]
127.0.0.1 agentq.ditto.com
127.0.0.1 js.ditto.com
127.0.0.1 matrix.ditto.com
127.0.0.1 media.ditto.com #[a232.x.akamai.net]
127.0.0.1 www.ditto.com #[AdWare.Win32.Softomate.c]
127.0.0.1 cnads.dixcom.com
127.0.0.1 ads.djindexes.com
127.0.0.1 openads.dlg.cz
127.0.0.1 a.dlqm.net
127.0.0.1 dcww.dmcast.com #[Adware-DesktopMedia]
127.0.0.1 ad1.dmcmedia.co.kr
127.0.0.1 dmdl.dmcast.com
127.0.0.1 install.dmcast.com #[Adware-DesktopMedia.dr]
127.0.0.1 track.dmipartners.com
127.0.0.1 ad.dmpi.net
127.0.0.1 ad2.dmpi.net
127.0.0.1 ad3.dmpi.net
127.0.0.1 ad4.dmpi.net
127.0.0.1 ubnm.dmpi.net
127.0.0.1 rotabanner.dni.ru
127.0.0.1 searchportal.dnparking.com #[Parking Service]
127.0.0.1 www.dnscaching.net #[SiteAdvisor.dnscaching.net]
127.0.0.1 dnv-counter.com
127.0.0.1 www.domamil.cz #[Trojan.Beagooz]
127.0.0.1 www.dodostats.com
127.0.0.1 a.doginhispen.com #[Downloader-BEW]
127.0.0.1 doorgen.com #[Spamdexing]
127.0.0.1 www.doorgen.com
127.0.0.1 ads.dotomi.com
127.0.0.1 www.download-services.com #[VBA32.Trojan-Downloader.Agent.26]
127.0.0.1 www.downseek.com #[SunBelt.DownSeek Search]
127.0.0.1 banners.dpnet.com.br
127.0.0.1 drmx01.net #[Spamdexing]
127.0.0.1 counter.dreamhost.com
127.0.0.1 www.claus.drehteile-rieche.de #[Win32.Formglieder.B]
127.0.0.1 www.dreamadvert.com #[SunBelt.Dreamadvert]
127.0.0.1 www.dropthehammer.com #[Win32/Spy.Banker.AHY]
127.0.0.1 ads.drugs.com
127.0.0.1 b.ds1.nl
127.0.0.1 ddd.dudu.com #[Tenebril.DuDu Accelerator]
127.0.0.1 ulink4.dudu.com #[Adware.DDDClient][SunBelt.DuDuAccelerator]
127.0.0.1 ulink13.dudu.com #[Win32/Adware.DM]
127.0.0.1 www.dudu.com #[McAfee.Downloader-AVV]
127.0.0.1 www.duenow.com
127.0.0.1 dukasound.info #[Javascript.Exploit]
127.0.0.1 www.dutty.de #[W32.Peerload.A]
127.0.0.1 www.dzy520.com #[Google.Warning]
127.0.0.1 hits.e.cl
127.0.0.1 banners.earnunited.com
127.0.0.1 blogads.ebanner.nl
127.0.0.1 www.e-bannerx.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 www.earncashontheinternet.com #[SunBelt.OpinionBar]
127.0.0.1 click.easilyfound.com #[Tenebril.AdTraffic]
127.0.0.1 www.easilyfound.com
127.0.0.1 www.eastworldnetwork.com
127.0.0.1 www.easycounter.com
127.0.0.1 banners.easydns.com
127.0.0.1 easyhitcounters.com
127.0.0.1 beta.easyhitcounters.com
127.0.0.1 easytrader.bg
127.0.0.1 static.easytrader.bg
127.0.0.1 www.ebannertraffic.com
127.0.0.1 easy-web-stats.com
127.0.0.1 mailer.ebates.com
127.0.0.1 www.ebates.com #[Adware.MoeMoney]
127.0.0.1 ads.eccentrix.com
127.0.0.1 b.economedia.bg #[ban.etaligent.net]
127.0.0.1 ads.ecrush.com #[AdvertPro]
127.0.0.1 www.eden21.net #[Win32/Haxdoor][TR/Dldr.Botol.D.1]
127.0.0.1 c6.edgesuite.net #[RealMedia]
127.0.0.1 einfachstarten.com #[Trojan.Firpage]
127.0.0.1 eisenstein.dk #[tracking.ping]
127.0.0.1 www.ejmx.com #[Adware.ElectroJMX]
127.0.0.1 ad.e-kolay.net
127.0.0.1 www.ek21.com #[Trojan.Chost.B]
127.0.0.1 ads.elmaz.com
127.0.0.1 now.eloqua.com #[WebBug]
127.0.0.1 ads.eluniversal.com.mx
127.0.0.1 hits.eluniversal.com.mx
127.0.0.1 publicidad.eluniversal.com.mx
127.0.0.1 elwebsearch.info #[Malicious.Links.Umax]
127.0.0.1 wwv.elwebsearch.info
127.0.0.1 www.elwebsearch.info
127.0.0.1 ad1.emediate.dk
127.0.0.1 eas.apm.emediate.eu
127.0.0.1 ad1.emediate.se
127.0.0.1 www.emoinstaller.com #[Win32/Adware.NdotNet][SiteAdvisor.emoinstaller.com]
127.0.0.1 www.emusic.com #[Win32/Adware.Comet][MVPS.Criteria]
127.0.0.1 dotnet.endai.com
127.0.0.1 stats.engineseeker.com
127.0.0.1 entk.net
127.0.0.1 log.enquisite.com
127.0.0.1 adv.entercasino.com #[Adware.Casino.V]
127.0.0.1 enthro.com
127.0.0.1 enthro.info #[Malicious.Links.DriveCleaner]
127.0.0.1 enthro.net
127.0.0.1 enthro.org
127.0.0.1 ads.eog.com
127.0.0.1 ads.e-planning.net
127.0.0.1 ads.us.e-planning.net
127.0.0.1 adserving03.epi.es
127.0.0.1 www.e-referrer.com
127.0.0.1 launcheruk.escritorioactivo.com
127.0.0.1 vipuk.escritorioactivo.com #[HJTH.123Messenger Hijacker]
127.0.0.1 www.escorcher.com #[eTrust.EScorcher]
127.0.0.1 search.etargetnet.com
127.0.0.1 bg.search.etargetnet.com
127.0.0.1 cz.search.etargetnet.com
127.0.0.1 gtb.etology.com
127.0.0.1 pages.etology.com
127.0.0.1 www.etracker.de
127.0.0.1 www.etxh.com #[Win32/Prosti.C]
127.0.0.1 ads.ere.net
127.0.0.1 ads.ero-advertising.com
127.0.0.1 banners.ero-advertising.com
127.0.0.1 data.ero-advertising.com
127.0.0.1 thumbs.ero-advertising.com
127.0.0.1 adopt.euroclick.com #[Ewido.TrackingCookie.Euroclick]
127.0.0.1 cdn.euroclick.com
127.0.0.1 www.euroklik.nl #[EasyBar][HJTH.SinCity Dialer]
127.0.0.1 advert.eurotip.cz
127.0.0.1 www.euros4click.de
127.0.0.1 ad.eurosport.com #[oas.eurosport.com]
127.0.0.1 www.eurowebstats.com
127.0.0.1 www.everestpoker.com #[AdWare.Win32.Casino.t]
127.0.0.1 advert.exaccess.ru
127.0.0.1 dynamic.exaccess.ru
127.0.0.1 static.exaccess.ru
127.0.0.1 www.exchangead.com
127.0.0.1 exchange.bg
127.0.0.1 media.exchange.bg
127.0.0.1 www.exchange.bg
127.0.0.1 exitexchange.com #[SiteAdvisor.exitexchange.com]
127.0.0.1 ads.exitexchange.com
127.0.0.1 count.exitexchange.com #[McAfee.Cookie-Exitexchange]
127.0.0.1 images.exitexchange.com
127.0.0.1 www.exitexchange.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.exittrade.com
127.0.0.1 nyton.experclick.com #[p.mii.instacontent.net]
127.0.0.1 www.experclick.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ads.expressindia.com
127.0.0.1 banners.expressindia.com
127.0.0.1 cdn.eyewonder.com #[SunBelt.EyeWonder]
127.0.0.1 cdn4.eyewonder.com
127.0.0.1 pixel1097.everesttech.net
127.0.0.1 pixel1324.everesttech.net
127.0.0.1 pixel1370.everesttech.net
127.0.0.1 www.evidence-eliminator.com
127.0.0.1 www.ewebcounter.com
127.0.0.1 ads2.exhedra.com
127.0.0.1 ads.expedia.com
127.0.0.1 www.eyeget.com #[McAfee.Adware-EyeGet]
127.0.0.1 feedback.eyereturn.com
127.0.0.1 resources.eyereturn.com
127.0.0.1 timespent.eyereturn.com
127.0.0.1 voken.eyereturn.com
127.0.0.1 ads.ezboard.com
127.0.0.1 eziin.com #[Adware.Eziin]
127.0.0.1 www.eziin.com
127.0.0.1 www.ezurl.co.kr #[Spyware.Ezurl]
127.0.0.1 ads.facebook.com #[facebook-ads.vo.llnwd.net]
127.0.0.1 ads.ak.facebook.com
127.0.0.1 www.factorygames.com #[SiteAdvisor.factorygames.com]
127.0.0.1 banner.fairpoker.com #[AdWare.Win32.Casino.w]
127.0.0.1 ehs.familydoctor.org #[ads.digitalhealthcare.com]
127.0.0.1 tmp.farfly.org #[Trojan.Farfli]
127.0.0.1 www.fast-adv.it
127.0.0.1 www.fastfind.org #[TROJ_STARTPAG.KF][Win32/Adware.MediaBack]
127.0.0.1 fastonlineusers.com
127.0.0.1 fasttrack.nu
127.0.0.1 fastwebcounter.com
127.0.0.1 counter.fateback.com
127.0.0.1 www.fatpenguinmedia.com
127.0.0.1 counter1.fc2.com
127.0.0.1 filcu.cn #[Malicious.Links.Codec]
127.0.0.1 alex.fileburst.com #[Win32/TrojanDropper.Agent.NBT]
127.0.0.1 adserver.filefront.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 adserver.finditquick.com
127.0.0.1 findover.org #[Spamdexing]
127.0.0.1 search.findscout.com
127.0.0.1 www.findscout.com #[W32/Delf.KPZ]
127.0.0.1 ai.p.findology.com
127.0.0.1 banner.finn.no
127.0.0.1 ads.firingsquad.com
127.0.0.1 ads2.firingsquad.com
127.0.0.1 firstdor.info #[Spamdexing]
127.0.0.1 ads.firstgrand.com
127.0.0.1 fishclix.com
127.0.0.1 www.fishclix.com
127.0.0.1 www.fish-screensaver.com #[AdWare.Win32.Gator.1008]
127.0.0.1 www.fjordbergen.com #[Win32/Spy.Banker.BIG]
127.0.0.1 www.fjjyjy.net #[Win32/Hipigon][W32.Fijjy]
127.0.0.1 www.flashadengine.com
127.0.0.1 cdn.flashedmail.com #[Parked?]
127.0.0.1 tracker1.flashedmail.com
127.0.0.1 adserver4.fluent.ltd.uk
127.0.0.1 adserver.fmpub.net
127.0.0.1 dynamic.fmpub.net
127.0.0.1 static.fmpub.net
127.0.0.1 ads.fmwinc.com
127.0.0.1 rnews.focus-news.net
127.0.0.1 adcycle.footymad.net
127.0.0.1 www.forodeortodoncia.com #[Backdoor.IRC.Zapchast]
127.0.0.1 js.forrestersurveys.com
127.0.0.1 socratos.forrestersurveys.com
127.0.0.1 forso.info #[Malicious.Links.Codec]
127.0.0.1 akcr.free.fr #[Win32/Spy.Bancos.U]
127.0.0.1 googlelite.free.fr #[Spamdexing]
127.0.0.1 ad.freecity.de
127.0.0.1 ads05.freecity.de
127.0.0.1 freecounters.xp.tl
127.0.0.1 www.free-counter.com
127.0.0.1 maurobb.freecounter.it
127.0.0.1 www.freecounter.it
127.0.0.1 securinews.free.fr #[Trojan.Hexem]
127.0.0.1 www.freedownloadhq.com #[SiteAdvisor.freedownloadhq.com]
127.0.0.1 ad.freefind.com
127.0.0.1 adverts.freeloader.com
127.0.0.1 freelogs.com
127.0.0.1 bar.freelogs.com
127.0.0.1 goo.freelogs.com
127.0.0.1 htm.freelogs.com
127.0.0.1 ico.freelogs.com
127.0.0.1 joe.freelogs.com
127.0.0.1 mom.freelogs.com
127.0.0.1 xyz.freelogs.com
127.0.0.1 freemoviepro.com #[Win32/Adware.Webdesk]
127.0.0.1 www.freemoviepro.com
127.0.0.1 adserver.freenet.de
127.0.0.1 freeonlineusers.com
127.0.0.1 www.free-ranking.de
127.0.0.1 www.freerip.com #[AdTool.Win32.MyWebSearch.ak]
127.0.0.1 banner-server.freerun.com
127.0.0.1 free-stats.com
127.0.0.1 abbyssh.freestats.com
127.0.0.1 insurancejournal.freestats.com
127.0.0.1 www.freestats.ws
127.0.0.1 banners.freett.com
127.0.0.1 count.freett.com
127.0.0.1 counters.freewebs.com
127.0.0.1 ads.freeonlinegames.com
127.0.0.1 stats.freeonlinegames.com
127.0.0.1 error.freewebsites.com
127.0.0.1 www.freewebsites.com
127.0.0.1 tracking.fsjmp.com
127.0.0.1 ftpiframer.org #[Javascript.Exploit]
127.0.0.1 media.ftv-publicite.fr #[RealMedia]
127.0.0.1 fullddl.com
127.0.0.1 www.fullddl.com #[HTML/TrojanDownloader.XXXToolbar]
127.0.0.1 404.funpic.de
127.0.0.1 www.fusestats.com
127.0.0.1 ads.gad-network.com
127.0.0.1 adserver.gadu-gadu.pl
127.0.0.1 banners.gamblingmasters.com
127.0.0.1 www.gamersbanner.com
127.0.0.1 ads.gameservers.com
127.0.0.1 ads.gamespy.com #[SpySweeper.Spy.Cookie]
127.0.0.1 adcontent.gamespy.com
127.0.0.1 ads.gamespyid.com
127.0.0.1 www.gameurdr.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 server.gamyun.net
127.0.0.1 www.gamyun.net #[Adware.GamyunIeToolbar]
127.0.0.1 ad.garantiarkadas.com
127.0.0.1 gasan.ru #[Trojan.Codec]
127.0.0.1 ads.gather.com
127.0.0.1 track.gawker.com #[WebBug]
127.0.0.1 haymarket-adserver.gcnpublishing.com
127.0.0.1 www.gebr-wachs.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 sda.geek.com #[AdvertPro]
127.0.0.1 adserver.geenstijl.nl
127.0.0.1 kassa.geenstijl.nl
127.0.0.1 schoorsteen.geenstijl.nl
127.0.0.1 adserver.geizkragen.de
127.0.0.1 gnt01.generation-nt.com
127.0.0.1 gd.geobytes.com
127.0.0.1 www.geocitygame.com #[Javascript.Exploit]
127.0.0.1 geotarget.info #[Whois.Blacklisted]
127.0.0.1 banners.geotarget.info
127.0.0.1 www.geotarget.info
127.0.0.1 www.geowhere.net #[SunBelt.GeoWhere Search]
127.0.0.1 get-access.host.sk #[McAfee.StartPage-IR]
127.0.0.1 getclicky.com
127.0.0.1 static.getclicky.com
127.0.0.1 www.getmusicvideocodes.com #[Malicious.Links.Zango]
127.0.0.1 www.getsmart.com
127.0.0.1 dlx.getupdate.com #[AdvWare.ToolBar.VB.b][Adware.Getup]
127.0.0.1 banner.giantvegas.com
127.0.0.1 counters.gigya.com
127.0.0.1 truehits.gits.net.th
127.0.0.1 truehits1.gits.net.th
127.0.0.1 ads.globo.com
127.0.0.1 ads.img.globo.com
127.0.0.1 glory-movy.net #[Javascript.Exploit]
127.0.0.1 duke.gocomics.com #[ads.uclick.com]
127.0.0.1 www.godesktop.com #[SiteAdvisor.godesktop.com]
127.0.0.1 adserver2.goals365.com
127.0.0.1 banner.goldenpalace.com #[Tenebril.Tracking.Cookie]
127.0.0.1 stage.goldkey.com #[Parking Service]
127.0.0.1 goldstats.net
127.0.0.1 www.goldstats.net
127.0.0.1 www.goodhealth-search.com #[Spamdexing]
127.0.0.1 google9.info
127.0.0.1 www.google9.info
127.0.0.1 www.google-hard.com #[Win32/TrojanProxy.Agent.LK]
127.0.0.1 goooglegulp.com #[Spamdexing]
127.0.0.1 goopssearch.com #[Google.Warning][server down?]
127.0.0.1 www.goopssearch.com
127.0.0.1 www.gogogo.com #[PremiumTraffic.Parking Service]
127.0.0.1 partner.gonamic.de
127.0.0.1 googlus.com #[Spamdexing]
127.0.0.1 adincl.gopher.com #[InfoSpace]
127.0.0.1 gostats.com
127.0.0.1 as.gostats.com
127.0.0.1 c1.gostats.com
127.0.0.1 c2.gostats.com #[SpySweeper.Spy.Cookie]
127.0.0.1 c3.gostats.com
127.0.0.1 c4.gostats.com #[Panda.Spyware:Cookie/GoStats]
127.0.0.1 ded.gostats.com
127.0.0.1 monster.gostats.com
127.0.0.1 webcounter.goweb.de
127.0.0.1 ads.goyk.com
127.0.0.1 graffitifonts.com
127.0.0.1 www.graffitifonts.com #[Malicious.Links.Zango]
127.0.0.1 graficastrigo.com #[Trojan.Tabela.E]
127.0.0.1 www.gratis-counter-gratis.de
127.0.0.1 www.gratis-toplist.de
127.0.0.1 adv.gratuito.st
127.0.0.1 www.greasypalm.co.uk #[PcTools.GreasyPalm bar]
127.0.0.1 adserver.gruprc.ro
127.0.0.1 publi.grupocorreo.es #[RealMedia][server down?]
127.0.0.1 ad4.gueb.com
127.0.0.1 ad7.gueb.com
127.0.0.1 ads.guru3d.com
127.0.0.1 ads.gusanito.com
127.0.0.1 www.g-wizzads.net #[adbureau.net]
127.0.0.1 x.gxgxy.net #[Trojan-Downloader.Win32.Agent.hkc]
127.0.0.1 www.h148.cn #[Google.Warning]
127.0.0.1 ads2.haber3.com
127.0.0.1 cc9905.counter.hackers.lv
127.0.0.1 www.handyarchive.com #[SiteAdvisor.handyarchive.com]
127.0.0.1 www.haosf128.com #[Google.Warning]
127.0.0.1 streamit.hardwarezone.com
127.0.0.1 ad1.hardware.no #[AdvertPro]
127.0.0.1 adserver.hardwareanalysis.com
127.0.0.1 ad.harmony-central.com
127.0.0.1 ds1.harmony-central.com
127.0.0.1 www.harmonyhollow.net #[SiteAdvisor.harmonyhollow.net]
127.0.0.1 ads.harpers.org
127.0.0.1 hartim.com
127.0.0.1 ad0.haynet.com
127.0.0.1 ad.hbv.de
127.0.0.1 w.hcden.com #[Google.Warning]
127.0.0.1 ads.heias.com
127.0.0.1 www.hentaibanners.com
127.0.0.1 www.hentaicashmachine.com
127.0.0.1 www.hentaiclicks.com
127.0.0.1 www.hentaicounter.com
127.0.0.1 www.hentaihits.com
127.0.0.1 www.hentaipop.com #[Electronic Group Dialer]
127.0.0.1 www.hentaiseeker.com
127.0.0.1 www.hentaitoonami.com
127.0.0.1 www.henwo.com
127.0.0.1 ads.herbalsmokeshop.com
127.0.0.1 www.herbalsmokeshops.com
127.0.0.1 www2.hermoment.com
127.0.0.1 www.hermoment.com
127.0.0.1 ads.hexun.com
127.0.0.1 www.hey.lt
127.0.0.1 ads.highdefdigest.com
127.0.0.1 openads.hiphopsite.com
127.0.0.1 adserver.hispanoclick.com
127.0.0.1 www.hitscount.com
127.0.0.1 hits-counter.com
127.0.0.1 www.hits-counter.com
127.0.0.1 ctr.hitcounter-1.com
127.0.0.1 www.hit-counter-download.com
127.0.0.1 hithopper.com #[Adware.Hithopper]
127.0.0.1 www.hithopper.com #[ADW_HITHOPPER.A]
127.0.0.1 rdr.hitmngr.com #[WinFixer]
127.0.0.1 sxp.hitmngr.com
127.0.0.1 hitmodel.net
127.0.0.1 www.hit-counts.com
127.0.0.1 hit-now.com
127.0.0.1 www.hitscreamer.com
127.0.0.1 hitslog.com
127.0.0.1 h1.hitslog.com
127.0.0.1 s4.histats.com
127.0.0.1 s10.histats.com
127.0.0.1 s11.histats.com
127.0.0.1 www.hitstats.co.uk
127.0.0.1 hitstats.net
127.0.0.1 www.hittracking.com
127.0.0.1 images.hitwise.co.uk
127.0.0.1 anna.homeftp.net #[W32.Linkbot.A]
127.0.0.1 www.gontijoamaral.hpg.com.br #[Adware.Diginum]
127.0.0.1 www.adserver.home.pl
127.0.0.1 www.homeoffun.com #[SiteAdvisor.homeoffun.com]
127.0.0.1 counters.honesty.com
127.0.0.1 cgi.honesty.com #[MVPS.Criteria]
127.0.0.1 ad.hosting.pl
127.0.0.1 ns1.hosting101.biz #[JS/Small.DN][server down?]
127.0.0.1 hot8888.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 hot8888.cn #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 ad2.hotels.com
127.0.0.1 www.hot-lindsay.com #[Malicious.Links.Zango]
127.0.0.1 hotlinkbanners.com
127.0.0.1 www.hotlinkbanners.com
127.0.0.1 cgi.hotstat.nl
127.0.0.1 viewstat.hotstat.nl
127.0.0.1 ad.howstuffworks.com #[RealMedia][SpySweeper.Spy.Cookie]
127.0.0.1 hpod.com
127.0.0.1 htepo.com #[Rogue/Suspect Affiliate.sites]
127.0.0.1 www.htmate2.com #[Cursor.MySpace]
127.0.0.1 adserver.html.it
127.0.0.1 click.html.it
127.0.0.1 ad.httpool.com
127.0.0.1 vip.huigezi.com #[Backdoor.Graybird.Q][W32.Looked.F]
127.0.0.1 down.hunll.com #[BDS/Agent.ahj.701]
127.0.0.1 ads.hurra.de
127.0.0.1 www.huxley-online.net #[Win32/Spy.Elite.10.A]
127.0.0.1 ads2000.hw.net
127.0.0.1 dserver.hw.net
127.0.0.1 www.hypercounter.com
127.0.0.1 www.hypertracker.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ads.iafrica.com
127.0.0.1 ads.iboost.com
127.0.0.1 ads.ibox.bg
127.0.0.1 www.i-clicks.net
127.0.0.1 hits.icdirect.com #[SunBelt.ICDirect.com]
127.0.0.1 hitctr01.icdirect.com
127.0.0.1 tracker.icerocket.com
127.0.0.1 ictkt.com
127.0.0.1 ads.idgnow.com.br
127.0.0.1 banners.idg.com.br
127.0.0.1 adidm07.idmnet.pl
127.0.0.1 adidm.idmnet.pl
127.0.0.1 dot.idot.cz #[WebBug]
127.0.0.1 bar.iebar8.com #[Adware.Navihelper]
127.0.0.1 down.iedoumi.com #[Trojan-Downloader.Win32.Delf.bpn]
127.0.0.1 ieicon.com
127.0.0.1 www.ieicon.com
127.0.0.1 ie-exe.com #[AdWare.Win32.Softomate.x]
127.0.0.1 ad.ifrance.com
127.0.0.1 stats.surfaid.ihost.com
127.0.0.1 adserver.ig.com.br
127.0.0.1 i.iinfo.cz
127.0.0.1 k.iinfo.cz
127.0.0.1 adserver.ilmessaggero.it
127.0.0.1 gate.ilogbox.com
127.0.0.1 stats.ilsemedia.nl
127.0.0.1 image-catcher.com
127.0.0.1 ads.imeem.com
127.0.0.1 bbn.img.com.ua
127.0.0.1 content-ads.impactengine.com
127.0.0.1 www.impregnable.net #[TrojanDownloader.Win32.VB.dw][Trojan.Win32.StartPage.kk]
127.0.0.1 ads.ims.nl
127.0.0.1 in2search.org #[JS/TrojanDropper.Tivso.gen]
127.0.0.1 1.in2search.org
127.0.0.1 2.in2search.org
127.0.0.1 dns.in2search.org
127.0.0.1 c.incomeppc.com
127.0.0.1 s201.indexstats.com
127.0.0.1 secure.indexstats.com
127.0.0.1 stats.indexstats.com #[Analytics Tracking Code]
127.0.0.1 stats.indextools.com #[eTrust.Tracking.Cookie]
127.0.0.1 campaign.indieclick.com
127.0.0.1 optimize.indieclick.com
127.0.0.1 adcenter.in2.com
127.0.0.1 juggler.inetinteractive.com
127.0.0.1 rotator.juggler.inetinteractive.com
127.0.0.1 banners.inetfast.com
127.0.0.1 inetlog.ru
127.0.0.1 www.infineo.de #[Win32/Spy.Banker.AWA]
127.0.0.1 infospot.infocious.com
127.0.0.1 ads.infospace.com #[ADW_DEALHELPER.C]
127.0.0.1 msxml.infospace.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.infotelsrl.com #[eTrust.Infotel srl]
127.0.0.1 bimonline.insites.be
127.0.0.1 ads.intellicast.com #[weather.com]
127.0.0.1 strtt.interfree.it #[W32.Iberio]
127.0.0.1 counter.internet.ge
127.0.0.1 ad.interreklame.de
127.0.0.1 indiads.com
127.0.0.1 images.indiads.com
127.0.0.1 servedby.indiads.com #[RealMedia]
127.0.0.1 www.imiclk.com
127.0.0.1 inexplorer.com
127.0.0.1 local.inexplorer.com
127.0.0.1 toolbar.inexplorer.com #[Win32/Parite.B]
127.0.0.1 www.inexplorer.com
127.0.0.1 www.inpopo.com #[W32.Validin]
127.0.0.1 oc.inspectorclick.com
127.0.0.1 trax.inspectorclick.com
127.0.0.1 v2.inspectorclick.com
127.0.0.1 v3.inspectorclick.com
127.0.0.1 instantbuzz.com #[NOD32.Win32/Adware.InstantBuzz]
127.0.0.1 www2.instantbuzz.com
127.0.0.1 www.instantbuzz.com #[Adware.ToolBar.InstantBuzz.a]
127.0.0.1 media.intelia.it
127.0.0.1 anm.intelli-direct.com #[IntelliTracker]
127.0.0.1 info.intelli-direct.com
127.0.0.1 oxfam.intelli-direct.com
127.0.0.1 tui.intelli-direct.com
127.0.0.1 www.intelli-tracker.com
127.0.0.1 newadserver.interfree.it #[Adcycle]
127.0.0.1 internet-explorer.name #[Trojan-Clicker.Win32.Agent.ip]
127.0.0.1 www.internet-explorer.name
127.0.0.1 ad.internetradioinc.com
127.0.0.1 www.interstats.nl
127.0.0.1 www.intrastats.com
127.0.0.1 channels.intwined.com #[Adware/ToolBar.ISearch.c]
127.0.0.1 search.intwined.com
127.0.0.1 www.intwined.com #[McAfee.Adware-SSF!Hosts]
127.0.0.1 ad.investor.bg
127.0.0.1 www.invinc.com #[Troj/Dloader-J]
127.0.0.1 www.ip530.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 www.ipcounter.de
127.0.0.1 ad2.ip.ro
127.0.0.1 ads.ipowerweb.com
127.0.0.1 content.ipro.com #[WebBug]
127.0.0.1 adserver.iprom.net
127.0.0.1 central.iprom.net
127.0.0.1 www.ipstat.com
127.0.0.1 a.isohunt.com
127.0.0.1 adserver1.isohunt.com
127.0.0.1 ads.isoftmarketing.com
127.0.0.1 banman.isoftmarketing.com
127.0.0.1 ads1.itadnetwork.co.uk
127.0.0.1 itcompany.com #[SunBelt.Family Cyber Alert]
127.0.0.1 www.itcompany.com #[Symantec.Spyware.CyberAlert]
127.0.0.1 itisbest.info #[Spamdexing]
127.0.0.1 www.itrackpages.com
127.0.0.1 ilead.itrack.it
127.0.0.1 adserver.itsfogo.com
127.0.0.1 partnerfeed.itsfogo.com
127.0.0.1 www1.itsun.com
127.0.0.1 www8.itsun.com
127.0.0.1 ads.itv.com #[adbureau.net]
127.0.0.1 barafranca.iwarp.com #[Win32/Spy.ProAgent]
127.0.0.1 www.iwebmusic.com
127.0.0.1 ad.jamba.de
127.0.0.1 ad.jamba.net
127.0.0.1 ad.jamster.com
127.0.0.1 www.jcount.com
127.0.0.1 www.jellycounter.com
127.0.0.1 www.jethit.com
127.0.0.1 t1.jfglass.net #[Trojan.Booha]
127.0.0.1 dl.jiangmin.com #[Adware-BDSearch.dr]
127.0.0.1 www.jm-my.com #[BackDoor-CXI]
127.0.0.1 ad.joetec.net
127.0.0.1 jointmediagroup.com #[Trojan-Spy.Win32.Delf.uc]
127.0.0.1 jpedownload.joltid.com
127.0.0.1 ad.jopenqb.com #[Google.Warning]
127.0.0.1 banners.joost.com
127.0.0.1 ads.jossip.com
127.0.0.1 pastorale.jpn.org #[Win32/Spy.Banker.AHY]
127.0.0.1 www.joltid.com #[Adware.P2PNetworking][SPYW_PPNETWORK.B]
127.0.0.1 promotion.jpds.com
127.0.0.1 www.jstracker.com
127.0.0.1 ads.jt.org
127.0.0.1 925.vip.jx828.net #[HTML/Exploit.IframeBof]
127.0.0.1 jxdoe.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 www.k265.com #[Adware.Borlan]
127.0.0.1 stat.katalysatormedia.no
127.0.0.1 kazantip-top.com
127.0.0.1 www.kazantip-top.com #[HTML/Exploit.VMLFill]
127.0.0.1 ads.webfever.kadserver.com
127.0.0.1 ads.deblok.net.kadserver.com
127.0.0.1 ads.zebest-3000.net.kadserver.com
127.0.0.1 countus.get.kadserver.com
127.0.0.1 geo113prod.kadserver.com
127.0.0.1 get.kadserver.com
127.0.0.1 scripts.kataweb.it
127.0.0.1 kazaalite.pl
127.0.0.1 www.kazaalite.pl #[MHTMLRedir.Exploit]
127.0.0.1 gavzad.keenspot.com
127.0.0.1 ad.kewlbox.com
127.0.0.1 a.keyrun.com #[Adware-TargetAD]
127.0.0.1 u.keyrun.com
127.0.0.1 union.keyrun.com
127.0.0.1 ww.keyrun.com
127.0.0.1 www1.keyrun.com
127.0.0.1 www.keyrun.com
127.0.0.1 banner.kiev.ua
127.0.0.1 adserve.kikizo.com
127.0.0.1 union.db.kingsoft.com #[PopupAds]
127.0.0.1 www.kiss-search.net
127.0.0.1 ebay.kisswin.com #[Adware.Kiswin]
127.0.0.1 kjsc.org #[Win32/Spy.Banker.ANV]
127.0.0.1 ads.kleinman.com #[Adcycle]
127.0.0.1 kt3.kliptracker.com
127.0.0.1 kt4.kliptracker.com
127.0.0.1 www.kliptracker.com
127.0.0.1 ads.klixxx.com
127.0.0.1 www.km-nyc.com #[W32.Lecna.A]
127.0.0.1 click.kmindex.ru
127.0.0.1 counter.kmindex.ru
127.0.0.1 counting.kmindex.ru
127.0.0.1 www.kmindex.ru
127.0.0.1 www.knacads.com
127.0.0.1 images.kolmic.com
127.0.0.1 pics.kolmic.com #[Parking Service]
127.0.0.1 ads.komli.com
127.0.0.1 www.kompass-intl.com #[Win32/Adware.Toolbar.PowerSearch]
127.0.0.1 de.komtrack.com
127.0.0.1 koolbar.net #[Adware Bundler][ADW_KOOLBAR.A]
127.0.0.1 www.koolbar.net #[eTrust.AutoSearch]
127.0.0.1 sitestat.kpn-is.nl
127.0.0.1 kuaiso.com #[AdWare.Win32.Kuaiso.a]
127.0.0.1 toolsbar.kuaiso.com #[Adware.Kuaiso]
127.0.0.1 www.kuaiso.com
127.0.0.1 kukkakreck.com #[Rogue/Suspect Affiliate]
127.0.0.1 kustusch.com #[Javascript.Exploit]
127.0.0.1 adserver.kyoceramita-europe.com
127.0.0.1 www.kz163.net #[Win32/Virut]
127.0.0.1 laconicsoftware.org #[Malicious.Links.Codec]
127.0.0.1 alwaysforfriend.land.ru #[Trojan-Downloader.Win32.Banload.bdp]
127.0.0.1 www.animacoes.land.ru #[Downloader.Swif.B]
127.0.0.1 www.latinbusca.com #[Adware-CommanderNET]
127.0.0.1 ads.lawnsite.com
127.0.0.1 layer-ads.de
127.0.0.1 www.layer-ads.de
127.0.0.1 fun.lbn.ru
127.0.0.1 business.lbn.ru
127.0.0.1 www.business.lbn.ru
127.0.0.1 www.fun.lbn.ru
127.0.0.1 234.media.lbn.ru
127.0.0.1 banner.lbs.km.ru
127.0.0.1 iframe.leadacceptor.com
127.0.0.1 leakedcelebvideos.com #[Win32/TrojanDownloader.Agent.BCZ]
127.0.0.1 www.leakedcelebvideos.com
127.0.0.1 pubs.lemonde.fr
127.0.0.1 www.leopardsearch.com
127.0.0.1 www.letzebuerg.biz
127.0.0.1 ts1.lexmark.com
127.0.0.1 leythosthestalker.com
127.0.0.1 www.leythosthestalker.com
127.0.0.1 adserver.libero.it
127.0.0.1 adv-banner.libero.it
127.0.0.1 phpads.lime.com
127.0.0.1 link.ru
127.0.0.1 link.link.ru
127.0.0.1 www.linkads.net
127.0.0.1 ads.linki.nl
127.0.0.1 www.linkads.de
127.0.0.1 linkbuddies.com
127.0.0.1 banners.linkbuddies.com
127.0.0.1 www.linkbuddies.com
127.0.0.1 www.linkcounter.com
127.0.0.1 linksexchange.net
127.0.0.1 linkexchange.ru
127.0.0.1 web.linkexchange.ru
127.0.0.1 www.linkexchange.ru
127.0.0.1 link4link.com
127.0.0.1 plus.link4link.com
127.0.0.1 www.links4trade.com
127.0.0.1 escati.linkopp.net
127.0.0.1 www.linkopp.net
127.0.0.1 click.linkstattrack.com #[SiteAdvisor.linkstattrack.com]
127.0.0.1 linktarget.com
127.0.0.1 banner.linktech.cn
127.0.0.1 www.linkworth.com
127.0.0.1 ads.linuxjournal.com
127.0.0.1 www.ligue13.com #[Win32/Spy.Banker.BIG]
127.0.0.1 www.liveads.org
127.0.0.1 livecounter.net
127.0.0.1 www.livecounter.net
127.0.0.1 image.adv.livedoor.com
127.0.0.1 js.livehelper.com
127.0.0.1 newbrowse.livehelper.com
127.0.0.1 ads.livescore.com
127.0.0.1 traffic.liveuniversenetwork.com
127.0.0.1 trafficcdn.liveuniversenetwork.com
127.0.0.1 traffic.livevideo.com
127.0.0.1 broadent.vo.llnwd.net
127.0.0.1 aa.llsging.com #[Javascript.Exploit]
127.0.0.1 lw.lnkworld.com
127.0.0.1 omnituretrack.local.com
127.0.0.1 www.lojastal.com.br #[Win32/Spy.Banker.ANV]
127.0.0.1 lol.to #[HTML/Exploit.Mht]
127.0.0.1 err.lolipop.jp
127.0.0.1 www.lookde5.com #[W32.Looked]
127.0.0.1 lookoutsoft.net #[SiteAdvisor.lookoutsoft.net]
127.0.0.1 screensavers.lookoutsoft.net
127.0.0.1 a.loomia.com #[Tracking.Cookie]
127.0.0.1 www.lookoutsoft.net #[AdWare.Win32.WinAD.b]
127.0.0.1 www.lords-of-havoc.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 ermei.loveyoushipin.com #[Google.Warning]
127.0.0.1 niang.loveyoushipin.com
127.0.0.1 hexusads.fluent.ltd.uk
127.0.0.1 www.luxemil.com #[Google.Warning]
127.0.0.1 ads-apsa.lvz-online.de
127.0.0.1 www.lynxtrack.com
127.0.0.1 counter.lyricsdownload.com
127.0.0.1 m2k.ru
127.0.0.1 ad.m5prod.net
127.0.0.1 ad.m-adx.com
127.0.0.1 media.m-adx.com
127.0.0.1 www.macrcmedia.com #[Exploit.ANI]
127.0.0.1 www.macrcmedia.net
127.0.0.1 ads.madisonavenue.com
127.0.0.1 resource.madisonavenue.com
127.0.0.1 textads.madisonavenue.com
127.0.0.1 banner.magicboxcasino.com #[AdWare.Win32.Casino.w]
127.0.0.1 msn-sexoweb.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 humortadela.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 www.novogerador.mail15.com
127.0.0.1 www.uolcard.mail15.com #[Trojan-Spy.Win32.Banker.ark]
127.0.0.1 voegol.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 humortadela0.mail333.com #[Win32/Spy.Banker.AHY]
127.0.0.1 destino-gol.mail333.com #[Win32/Spy.Banker.BCK]
127.0.0.1 www.messengerbeta.mail333.com #[Win32/Spy.Banker.BCK]
127.0.0.1 mair.net #[Realtracker]
127.0.0.1 ads.marketing-internet.com
127.0.0.1 marketing-know-how.com #[TR/Dldr.iBill.V]
127.0.0.1 adsnew.maktoob.com #[AdvertPro]
127.0.0.1 aw.masterstats.com
127.0.0.1 erotic.masterstats.com
127.0.0.1 image.masterstats.com
127.0.0.1 link.masterstats.com
127.0.0.1 vw.masterstats.com #[Ewido.TrackingCookie.Masterstats]
127.0.0.1 mbe.ru #[adrevolver]
127.0.0.1 www.mbspro6uic.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 ads.affiliates.match.com
127.0.0.1 adserver.matchcraft.com
127.0.0.1 www.maxi-music.fr #[Win32/Spy.Banker.ANV]
127.0.0.1 ads.maxivip.fr
127.0.0.1 sitestat.mayoclinic.com
127.0.0.1 mbn.com.ua
127.0.0.1 120.mbn.com.ua
127.0.0.1 160.mbn.com.ua
127.0.0.1 classic.mbn.com.ua
127.0.0.1 ads.mcafee.com
127.0.0.1 directads.mcafee.com #[Tenebril.Tracking.Cookie]
127.0.0.1 md55.net #[Google.Warning]
127.0.0.1 www2.md80.cn
127.0.0.1 www.md80.cn #[W32.Validin]
127.0.0.1 tracker.measuremap.com
127.0.0.1 mcmads.mediacapital.pt #[DoubleClick]
127.0.0.1 matrix.mediavantage.de #[server down?]
127.0.0.1 adland.medialand.ru
127.0.0.1 adnet.medialand.ru
127.0.0.1 content.medialand.ru
127.0.0.1 ads.mediamayhemcorp.com
127.0.0.1 ads.mediaodyssey.com
127.0.0.1 acvs.mediaonenetwork.net
127.0.0.1 acvsrv.mediaonenetwork.net
127.0.0.1 ads1.mediaops.com.br
127.0.0.1 ad2.pl.mediainter.net
127.0.0.1 servedby.mediaplace.tv #[ad.firstadsolution.com]
127.0.0.1 tizer.mediarotator.ru
127.0.0.1 media-servers.net
127.0.0.1 search.mediatarget.com
127.0.0.1 ads.mediaturf.net #[McAfee.Cookie-Mediaturf]
127.0.0.1 adv.medscape.com #[ads.webmd.com]
127.0.0.1 b.megaban.com.ua
127.0.0.1 ad.megaclick.com
127.0.0.1 www.megapromition.net #[SiteAdvisor.megapromition.net]
127.0.0.1 exit.megago.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.megago.com #[typo squatter]
127.0.0.1 www.mercuras.com
127.0.0.1 reklama.metacafe.com
127.0.0.1 adserv2.meritdesigns.com
127.0.0.1 action.metaffiliation.com
127.0.0.1 ads.metropol.dk
127.0.0.1 automagazine.metriweb.be
127.0.0.1 hln-frinfos.metriweb.be
127.0.0.1 levif.metriweb.be
127.0.0.1 line01.metriweb.be #[Ad-Aware.Tracking.Cookie]
127.0.0.1 line02.metriweb.be
127.0.0.1 line03.metriweb.be
127.0.0.1 line04.metriweb.be #[SpySweeper.Spy Cookie]
127.0.0.1 line05.metriweb.be
127.0.0.1 line06.metriweb.be
127.0.0.1 line07.metriweb.be #[Panda.Spyware:Cookie]
127.0.0.1 line08.metriweb.be
127.0.0.1 line09.metriweb.be
127.0.0.1 line10.metriweb.be
127.0.0.1 line11.metriweb.be
127.0.0.1 line12.metriweb.be
127.0.0.1 line13.metriweb.be
127.0.0.1 line14.metriweb.be
127.0.0.1 line15.metriweb.be
127.0.0.1 line16.metriweb.be
127.0.0.1 line17.metriweb.be
127.0.0.1 line18.metriweb.be
127.0.0.1 line19.metriweb.be
127.0.0.1 line20.metriweb.be
127.0.0.1 line24.metriweb.be
127.0.0.1 line26.metriweb.be
127.0.0.1 line32.metriweb.be
127.0.0.1 rtbf09.metriweb.be
127.0.0.1 skynet-news.metriweb.be
127.0.0.1 startpagina.metriweb.be
127.0.0.1 pubs.mgn.net #[Grolier Network]
127.0.0.1 www.mgshareware.com #[AdTool.Win32.MyWebSearch.ak]
127.0.0.1 microadsystem.com
127.0.0.1 down.microadsystem.com
127.0.0.1 program.microadsystem.com #[TR/Dldr.FakeAV.F.1]
127.0.0.1 ver.microadsystem.com
127.0.0.1 www.microadsystem.com
127.0.0.1 ads.milenio.com
127.0.0.1 ads.mininova.org
127.0.0.1 www.mini-player.com #[5MOF Mini-Player]
127.0.0.1 counter.mirohost.net
127.0.0.1 banner.missbingo.com #[AdWare.Win32.Casino.ae]
127.0.0.1 banner.missingkids.com
127.0.0.1 ads.mixi.jp
127.0.0.1 img.ads.mixi.jp
127.0.0.1 www.mlclick.com
127.0.0.1 www.mlspharm.ru #[Google.Warning]
127.0.0.1 mmcodecs.com #[Trojan.Codec]
127.0.0.1 www.mmcodecs.com
127.0.0.1 vod.mmdy.org #[McAfee.StartPage-JN!CC32C55]
127.0.0.1 xxx.mmma.biz #[JS/Exploit.BO.NAE]
127.0.0.1 banners.mobilesidewalk.com
127.0.0.1 ads.mobygames.com
127.0.0.1 survey2.modernmindsoftware.com
127.0.0.1 ad.mokead.com #[Trojan.Daekom]
127.0.0.1 w5.mokead.com
127.0.0.1 www.mokead.com #[W32/DLoader.VZN]
127.0.0.1 ads.monster.com
127.0.0.1 adserver.monster.com #[SunBelt.AdServer.Monster.com]
127.0.0.1 adserver.a.in.monster.com
127.0.0.1 ads.monstermoving.com
127.0.0.1 cookie.monster.com #[SunBelt.cookie.monster]
127.0.0.1 m1.webstats.motigo.com
127.0.0.1 ads.monitor.bg
127.0.0.1 www.motioncodecs.com #[Win32/TrojanDownloader.Mediket]
127.0.0.1 www.m-phage.com #[VBS/TrojanDownloader.Agent.AW]
127.0.0.1 www.mp3downloadhq.com #[SiteAdvisor.mp3downloadhq.com]
127.0.0.1 www.mp3sugar.com
127.0.0.1 mp3today.net
127.0.0.1 mpamexit.com
127.0.0.1 adfarm.mserve.ca
127.0.0.1 www.messagetag.com #[Email tracker]
127.0.0.1 live.msgdiscovery.com #[Adware.DiscoveryLive]
127.0.0.1 msgtag.com
127.0.0.1 img.msgtag.com
127.0.0.1 www.msgtag.com
127.0.0.1 mswindowsupdate.info
127.0.0.1 www.mswindowsupdate.info
127.0.0.1 h.mt12.net #[Win32/PSW.Lineage.AEL][W32/HLLP.Philis.ar]
127.0.0.1 multi1.rmuk.co.uk #[RealMedia]
127.0.0.1 www.muangboranjournal.com #[Win32/Spy.Banker.AHY]
127.0.0.1 www.multiclinmed.com.br #[Win32/PSW.Legendmir.ATE]
127.0.0.1 mussicalcardss.smtp.ru #[Win32/Spy.Banker.AHY]
127.0.0.1 www.musicmass.com #[HJTH.C2Media/LOP variant]
127.0.0.1 click.myad.cn
127.0.0.1 click2.myad.cn
127.0.0.1 im
  • 0

#6
Kizzy

Kizzy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
part 2 of SmitfraudFix report

127.0.0.1 www.winfirewall.com
127.0.0.1 winnanny.com #[Trojan.TrustedZone]
127.0.0.1 www.winnanny.com
127.0.0.1 www.winpluspak.com
127.0.0.1 ls.winpopupguard.com
127.0.0.1 www.winpopupguard.com
127.0.0.1 winprivacyguard.com
127.0.0.1 www.winprivacyguard.com
127.0.0.1 www.winproductions.com
127.0.0.1 activate.winsoftware.com
127.0.0.1 download.cdn.winsoftware.com #[Win32/Adware.WinFixer]
127.0.0.1 updates.winsoftware.com
127.0.0.1 secure.winsoftware.com
127.0.0.1 trial.updates.winsoftware.com
127.0.0.1 www.winsoftware.com
127.0.0.1 antiworm2008.com #[SunBelt.Antiworm2008]
127.0.0.1 hit.antiworm2008.com
127.0.0.1 sale.antiworm2008.com
127.0.0.1 www.antiworm2008.com
127.0.0.1 bugsdestroyer.com
127.0.0.1 secure.bugsdestroyer.com
127.0.0.1 www.bugsdestroyer.com
127.0.0.1 goldenantispy.com
127.0.0.1 rescue.goldenantispy.com
127.0.0.1 sale.goldenantispy.com
127.0.0.1 www.goldenantispy.com
127.0.0.1 onlinepcguard.com
127.0.0.1 free.version.onlinepcguard.com
127.0.0.1 sale.onlinepcguard.com
127.0.0.1 www.onlinepcguard.com
127.0.0.1 pc-prot.com
127.0.0.1 www.pc-prot.com
127.0.0.1 pcprivacytool.com #[Symantec.PCPrivacyTool]
127.0.0.1 il.pcprivacytool.com
127.0.0.1 privacy.pcprivacytool.com
127.0.0.1 shop.pcprivacytool.com
127.0.0.1 www.pcprivacytool.com
127.0.0.1 privacyconductor.com
127.0.0.1 jsp.privacyconductor.com
127.0.0.1 privacy.privacyconductor.com
127.0.0.1 shop.privacyconductor.com
127.0.0.1 www.privacyconductor.com
127.0.0.1 spyguardpro.com #[Google.Warning]
127.0.0.1 jsp.spyguardpro.com
127.0.0.1 protect.spyguardpro.com #[Win32/Adware.AVSystemCare]
127.0.0.1 sale.spyguardpro.com
127.0.0.1 ykeeper.spyguardpro.com
127.0.0.1 www.spyguardpro.com
127.0.0.1 winsecureav.com
127.0.0.1 protect.winsecureav.com
127.0.0.1 sale.winsecureav.com
127.0.0.1 www.winsecureav.com
127.0.0.1 winspycontrol.com
127.0.0.1 protect.winspycontrol.com
127.0.0.1 sale.winspycontrol.com
127.0.0.1 www.winspycontrol.com
127.0.0.1 filterprogram.com #[SiteAdvisor.filterprogram.com]
127.0.0.1 shop.filterprogram.com
127.0.0.1 www.filterprogram.com #[server down.all]
127.0.0.1 harddrivefilter.com
127.0.0.1 secure.harddrivefilter.com
127.0.0.1 www.harddrivefilter.com
127.0.0.1 adnetserver.com
127.0.0.1 www.adnetserver.com
127.0.0.1 adverdaemon.com
127.0.0.1 akamahi.net #[Trojan-Downloader.SWF.Gida.a]
127.0.0.1 www.akamahi.net #[server down?]
127.0.0.1 www.antivirussecuritypro.com
127.0.0.1 b2adz.com #[Rogue/Suspect Affiliate.sites]
127.0.0.1 www.bestsearchnet.com
127.0.0.1 blessedads.com
127.0.0.1 www.casinoaceking.com
127.0.0.1 cryptdrive.com #[Symantec.CryptDrive]
127.0.0.1 count.cryptdrive.com
127.0.0.1 protected.cryptdrive.com
127.0.0.1 setup.cryptdrive.com
127.0.0.1 slogs.cryptdrive.com
127.0.0.1 www.cryptdrive.com
127.0.0.1 secure.fantazybill.com
127.0.0.1 stats.fantazybill.com
127.0.0.1 www.fileprotector.com
127.0.0.1 freepcsecure.com #[Win32/Adware.WinFixer]
127.0.0.1 www.freepcsecure.com #[SiteAdvisor.freepcsecure.com]
127.0.0.1 getfreecar.com
127.0.0.1 www.getfreecar.com
127.0.0.1 installprovider.com #[Adware.InstallProvider]
127.0.0.1 download.installprovider.com
127.0.0.1 www.installprovider.com
127.0.0.1 internetanonymizer.com
127.0.0.1 inner.internetanonymizer.com
127.0.0.1 logs.internetanonymizer.com
127.0.0.1 www.internetanonymizer.com
127.0.0.1 mysurvey4u.com
127.0.0.1 www.mysurvey4u.com
127.0.0.1 www.netturbopro.com
127.0.0.1 newbieadguide.com #[SiteAdvisor.newbieadguide.com]
127.0.0.1 www.newbieadguide.com
127.0.0.1 pcsoftw.com
127.0.0.1 www.pcsupercharger.com
127.0.0.1 popadprovider.com
127.0.0.1 popsmedia.com
127.0.0.1 popupnukerpro.com
127.0.0.1 www.popupnukerpro.com
127.0.0.1 prevedmarketing.com
127.0.0.1 quinquecahue.com #[SWF/TrojanDownloader.Gida.A]
127.0.0.1 r2d2adverising.com
127.0.0.1 sellmoresoft.com
127.0.0.1 secure.sellmosoft.net
127.0.0.1 stats.sellmosoft.net
127.0.0.1 shivanetworking.com
127.0.0.1 softwcs.com
127.0.0.1 thetechnorati.com #[server down?]
127.0.0.1 www.thetechnorati.com
127.0.0.1 traveltray.com
127.0.0.1 www.traveltray.com
127.0.0.1 vitecmedia.com
127.0.0.1 www.vitecmedia.com
127.0.0.1 vozemiliogaranon.com #[SWF/TrojanDownloader.Gida.A]
127.0.0.1 www.vozemiliogaranon.com #[server down?]
127.0.0.1 uk.workhomecenter.com
127.0.0.1 www.workhomecenter.com
127.0.0.1 zappinads.com
127.0.0.1 www.zappinads.com
127.0.0.1 www.asn.com
127.0.0.1 www.broadnetsoftware.com
127.0.0.1 www.broadspring.com
127.0.0.1 www.flashgamejunkie.com
127.0.0.1 www.flyordie.com #[Microsoft VM]
127.0.0.1 www.idealgamebar.com
127.0.0.1 www.idealringtones.com
127.0.0.1 www.idealshopperrewards.com
127.0.0.1 www.igamebar.com
127.0.0.1 instafinder.com #[Adware.InstaFinder]
127.0.0.1 ww2.instafinder.com #[Parasite.MegaSearch]
127.0.0.1 www.instafinder.com #[ADW_INSTAFIND.B]
127.0.0.1 www.mindsetinteractive.com
127.0.0.1 www.netpalgames.com
127.0.0.1 searchenginebar.com #[Parasite.RXToolbar]
127.0.0.1 www.searchenginebar.com #[Adware.RXToolbar]
127.0.0.1 www.ileadmedia.com
127.0.0.1 a-d-w-a-r-e.com #[Troj/Dloader-IG]
127.0.0.1 www.a-d-w-a-r-e.com
127.0.0.1 ad-w-a-r-e.com #[Win32.Canbede][Troj/Dloader-IG]
127.0.0.1 www.ad-w-a-r-e.com #[AdWare.Win32.Look2Me.ab]
127.0.0.1 www.look2me1.com #[Spyware.Look2Me]
127.0.0.1 www.barzellette.tv #[Win32/Dialer.HZ]
127.0.0.1 www.celebritaspoglie.net
127.0.0.1 www.desktoplife.net #[HJTH.Trojan.Downloader.Small]
127.0.0.1 deposito.hostance.net #[Trojan.Win32.Diamin.t]
127.0.0.1 netvision.hostance.net
127.0.0.1 trk.hostance.net
127.0.0.1 deposito.traffic-advance.net #[Win32/Diamin]
127.0.0.1 flat.trafficadvance.net #[Dialer.Trafficadvance]
127.0.0.1 netvision.traffic-advance.net #[Wildcard DNS]
127.0.0.1 pv.trafficadvance.net
127.0.0.1 stat.trafficadvance.net #[Trojan.Win32.Dialer.q]
127.0.0.1 www.trafficadvance.net #[SunBelt.TrafficAdvance]
127.0.0.1 deposito.trafficredlight.net #[Win32/Diamin]
127.0.0.1 flat.trafficredlight.net
127.0.0.1 adsl.carpediem.fr #[DIAL_FEMME.A]
127.0.0.1 dialup.carpediem.fr #[HJTH.AccessMembre]
127.0.0.1 faq.carpediem.fr
127.0.0.1 kit.carpediem.fr #[SiteAdvisor.parisvoyeur.com]
127.0.0.1 10661.kit.carpediem.fr
127.0.0.1 11731.kit.carpediem.fr #[Win32/Dialer.CDDial]
127.0.0.1 16643.kit.carpediem.fr #[HJTH.Carpediem Dialer]
127.0.0.1 live.carpediem.fr
127.0.0.1 live-2.carpediem.fr
127.0.0.1 lsda.carpediem.fr
127.0.0.1 media.carpediem.fr
127.0.0.1 media2.carpediem.fr
127.0.0.1 polyfolie.carpediem.fr
127.0.0.1 public.carpediem.fr
127.0.0.1 secure.carpediem.fr
127.0.0.1 stats.carpediem.fr
127.0.0.1 support.carpediem.fr
127.0.0.1 www.carpediem.fr
127.0.0.1 www.dingophone.com
127.0.0.1 dialer.eurodialer.com #[Win32/TrojanDropper.Agent.ACS]
127.0.0.1 www.eurodialer.com
127.0.0.1 www.eurolive.com
127.0.0.1 statsv3.gaycash.com
127.0.0.1 ipigz.com
127.0.0.1 www.ipigz.com
127.0.0.1 16755.dialer.lincassa.com #[HJTH.Carpediem Dialer]
127.0.0.1 17067.dialer.lincassa.com
127.0.0.1 20429.dialer.lincassa.com #[Win32/Dialer.CDDial]
127.0.0.1 21294.dialer.lincassa.com
127.0.0.1 www.monliveshow.com
127.0.0.1 htmldialer.parisvoyeur.com
127.0.0.1 www.parisvoyeur.com #[Dialer.Pornosex][Trojan.Win32.Dialer.eg]
127.0.0.1 www.sfondatanale.com
127.0.0.1 dialer.sponsorhispano.com #[Win32/Dialer.CDDial]
127.0.0.1 carpediem.sv2.biz
127.0.0.1 dvdmanager-203.sv2.biz
127.0.0.1 ktu.sv2.biz
127.0.0.1 www.coulomb.co.uk #[Dialer.Flatfive\Girlshost\Pornpaq]
127.0.0.1 www.globalcharge.com
127.0.0.1 dload.ipbill.com #[MVPS.Criteria][Win32/TrojanDownloader.Small.ON]
127.0.0.1 mojo.ipbill.com
127.0.0.1 pornsites.ipbill.com
127.0.0.1 soldproxy1.ipbill.com
127.0.0.1 tracking.ipbill.com
127.0.0.1 mobilesexpalace.com
127.0.0.1 www.pornsexpalace.com
127.0.0.1 adm.gw.premiumbilling.com
127.0.0.1 gw.premiumbilling.com
127.0.0.1 www.premiumbilling.com
127.0.0.1 www.saristar.com
127.0.0.1 www.smssexpalace.com
127.0.0.1 www.valentinesmms.com #[mojo.ipbill.com]
127.0.0.1 www.valmob.com #[mojo.ipbill.com]
127.0.0.1 ws.aissys.com
127.0.0.1 www.sesso-it.com #[Trojan.Win32.Dialer.hz]
127.0.0.1 www.dialerplatform.com #[Trojan.Ibiza]
127.0.0.1 www.ezdialeronline.com
127.0.0.1 www.global-acces.com #[Dialer.Globalacces]
127.0.0.1 www.global-access.com
127.0.0.1 access.juicyteenporn.com #[Dialer.Juicyteen][directplugin.com]
127.0.0.1 members.juicyteenporn.com #[DIAL_ATMOS.A][Porn-Dialer.Win32.GBDialer.d]
127.0.0.1 093qpeuqpmz6ebfa.com #[Trojan.TrustedZone]
127.0.0.1 0texkax7c6hzuidk.com #[usa-scripts.downloadv3.com]
127.0.0.1 www.1qiq0okzb7hcb3xr.com #[scripts.dlv4.com]
127.0.0.1 www.0texkax7c6hzuidk.com
127.0.0.1 www.02kmky1xgzbmsdfx.com
127.0.0.1 api.aveno.net
127.0.0.1 em.aveno.net
127.0.0.1 pics.aveno.net
127.0.0.1 secure.aveno.net
127.0.0.1 cash-explorer.com
127.0.0.1 www.cash-explorer.com
127.0.0.1 akamai.downloadv3.com #[EGP2ECOM Class][InstantAccess]
127.0.0.1 fr4-scripts.downloadv3.com
127.0.0.1 scripts.downloadv3.com
127.0.0.1 update.downloadv3.com
127.0.0.1 usa-scripts.downloadv3.com
127.0.0.1 es6-scripts.dlv4.com #[Win32/P2E]
127.0.0.1 scripts.dlv4.com #[Backdoor.Win32.PcClient.pb]
127.0.0.1 us2-scripts.dlv4.com
127.0.0.1 www.dvd-explorer.com
127.0.0.1 www.egisupport.com
127.0.0.1 mirrors.egwn.net
127.0.0.1 pubvideo3.egwn.net
127.0.0.1 server02.us2.egwn.net
127.0.0.1 static.egwn.net
127.0.0.1 www.e-group.org
127.0.0.1 support.electronic-group.com
127.0.0.1 www.electronic-group.com #[Win32.Wintrim.U]
127.0.0.1 legal.electronic-group.com
127.0.0.1 www.email-explorer.com
127.0.0.1 promo.epass-key.com
127.0.0.1 www.epass-key.com
127.0.0.1 ispdialer.com #[Parasite.ACXInstall]
127.0.0.1 www.ispdialer.com
127.0.0.1 es6-scripts.nccgateway.com
127.0.0.1 access.rapid-pass.net #[network.nocreditcard.com]
127.0.0.1 help.rapid-pass.net
127.0.0.1 media.rapid-pass.net #[SunBelt.Rapid-pass.net]
127.0.0.1 public-contentv4.rapid-pass.net
127.0.0.1 www.rapid-pass.net #[Dialer.InstantAccess][DIAL_NSTANTXS.A]
127.0.0.1 spyware-secure.com
127.0.0.1 www.spyware-secure.com #[Symantec.SpywareSecure]
127.0.0.1 www.traffic-converter.com
127.0.0.1 usa-network.video-party.com #[HTMLAccess Class]
127.0.0.1 www.videoparty.com
127.0.0.1 banners.vizit.us
127.0.0.1 network.vizit.us
127.0.0.1 www.vizit.us
127.0.0.1 www.123ticket.com
127.0.0.1 www.chargemelater.com
127.0.0.1 banners.nocreditcardgay.com
127.0.0.1 instant-access.nocreditcardgay.com
127.0.0.1 network.nocreditcardgay.com
127.0.0.1 usa-network.nocreditcardgay.com
127.0.0.1 www.nocreditcardgay.com
127.0.0.1 nocreditcard.com #[TROJ_ISBAR.A]
127.0.0.1 banners.nocreditcard.com
127.0.0.1 fr4-network.nocreditcard.com
127.0.0.1 instant-access.nocreditcard.com #[Parasite.MagicControl]
127.0.0.1 network.nocreditcard.com
127.0.0.1 usa-network.nocreditcard.com
127.0.0.1 webmaster.nocreditcard.com
127.0.0.1 nocreditcard.net #[ACXInstall][DIAL_DIALEX.A]
127.0.0.1 instant-access.nocreditcard.net
127.0.0.1 network.nocreditcard.net
127.0.0.1 www.nocreditcard.net #[McAfee.Adware-EGroup]
127.0.0.1 www.one2one.com #[One2One Viewer]
127.0.0.1 cc.sex-explorer.com
127.0.0.1 contents.sex-explorer.com
127.0.0.1 static.contents.sex-explorer.com
127.0.0.1 freecc.sex-explorer.com
127.0.0.1 instant-access.sex-explorer.com
127.0.0.1 live.sex-explorer.com #[McAfee.Adware-EGroup]
127.0.0.1 lives.sex-explorer.com
127.0.0.1 ncc.sex-explorer.com
127.0.0.1 static.sex-explorer.com
127.0.0.1 trial.sex-explorer.com
127.0.0.1 xxx.sex-explorer.com
127.0.0.1 www.sex-explorer.com
127.0.0.1 network.strip-player.com
127.0.0.1 stripplayer.com #[Parasite.StripPlayer]
127.0.0.1 network.stripplayer.com
127.0.0.1 webmaster.stripplayer.com
127.0.0.1 www.strip-player.com
127.0.0.1 fun.zipzappromos.com
127.0.0.1 promo.zipzappromos.com
127.0.0.1 www.zipzappromos.com
127.0.0.1 99culi.com
127.0.0.1 www.99culi.com #[Win32/Dialer.HZ]
127.0.0.1 www.areasex.biz #[Trojan.Win32.Dialer.hz][server down?]
127.0.0.1 www.archiviosex.net #[Trojan.TrustedZones]
127.0.0.1 hastalavista.it #[Trojan.Win32.Dialer.hz]
127.0.0.1 www.hastalavista.it #[Trojan.TrustedZones]
127.0.0.1 www.linkautomatici.com #[Trojan.TrustedZones]
127.0.0.1 redfunny.com #[SiteAdvisor.redfunny.com]
127.0.0.1 www.redfunny.com #[Adult Content Dialer][Trojan.TrustedZones]
127.0.0.1 skymasters.biz #[SiteAdvisor.skymasters.biz][server down?]
127.0.0.1 www.skymasters.biz #[Trojan.TrustedZones][HJTH.Adult Content Dialer]
127.0.0.1 banners.amoestecuzinho.com
127.0.0.1 banners.animeerotico.com
127.0.0.1 banners.bebadasousadas.com
127.0.0.1 banners.chicashumedas.com
127.0.0.1 banners.colegialasdesvirgadas.com
127.0.0.1 banners.debuteamador.com
127.0.0.1 galleries.ebonyempire.com
127.0.0.1 banners.espiasadictos.com
127.0.0.1 banners.[bleep]ingdrunks.com
127.0.0.1 galleries.[bleep]ingdrunks.com
127.0.0.1 banners.imperioanal.com
127.0.0.1 banners.lesbianascerdas.com
127.0.0.1 www.mildescargas.com #[HJTH.SponsorAdulto Dialer]
127.0.0.1 banners.mulherescomcigarros.com
127.0.0.1 galleries.negrasporno.com
127.0.0.1 www.negrasporno.com
127.0.0.1 banners.orgiasreales.com
127.0.0.1 adult.phoneaccess.com
127.0.0.1 ad1.banners.phoneaccess.com
127.0.0.1 exit.phoneaccess.com
127.0.0.1 iframe.phoneaccess.com
127.0.0.1 ipdata.phoneaccess.com #[HJTH.Dialer.NBQ]
127.0.0.1 promos.phoneaccess.com
127.0.0.1 banners.paixaogay.com
127.0.0.1 banners.paixaoasiatica.com
127.0.0.1 banners.passeilimitado.com
127.0.0.1 banners.pollasde30cm.com
127.0.0.1 banners.prazerlesbico.com
127.0.0.1 banners.sandralatina.com
127.0.0.1 galleries.schwarzesimperium.com
127.0.0.1 banners.showdeinfieles.com
127.0.0.1 banners.showdeinfieis.com
127.0.0.1 banners.sotransexuais.com
127.0.0.1 banners.spacash.com
127.0.0.1 banners2.spacash.com
127.0.0.1 banners3.spacash.com
127.0.0.1 cams.spacash.com
127.0.0.1 cdnimg01.spacash.com
127.0.0.1 cdnimg02.spacash.com
127.0.0.1 dvdcovers.spacash.com
127.0.0.1 exit.spacash.com
127.0.0.1 freesites.spacash.com
127.0.0.1 ip.spacash.com #[HJTH.SponsorAdulto Dialer]
127.0.0.1 layers.spacash.com
127.0.0.1 movies.spacash.com
127.0.0.1 notice.spacash.com
127.0.0.1 rotations.spacash.com
127.0.0.1 www.spacash.com
127.0.0.1 sponsoradulto.com
127.0.0.1 banners.sponsoradulto.com
127.0.0.1 banners2.sponsoradulto.com
127.0.0.1 ip.sponsoradulto.com #[Trojan.Win32.Dialer.fu]
127.0.0.1 www.sponsoradulto.com #[HJTH.SponsorAdulto Dialer]
127.0.0.1 ip.sponsorix.com
127.0.0.1 banners.taxindecente.com
127.0.0.1 banners.teenfunzone.com
127.0.0.1 galleries.teenfunzone.com
127.0.0.1 banners.vivilatina.com
127.0.0.1 www.webspacemania.com #[SiteAdvisor.webspacemania.com]
127.0.0.1 www.celebrita-nude.com
127.0.0.1 www.eros-[bleep].com
127.0.0.1 www.omniasex.com
127.0.0.1 7adpower.com #[ADW_ADPOWER.D]
127.0.0.1 www.7adpower.com #[HJTH.Svezia.Dialer]
127.0.0.1 www.globalphon.com #[Dialer.7AdPower]
127.0.0.1 faq.mainpean.de
127.0.0.1 voicecall.mainpean.de
127.0.0.1 www.mainpean.de #[Dailer.Megateens]
127.0.0.1 stardialer.de #[DIAL_PORNDIAL.CA]
127.0.0.1 help.stardialer.de #[Parasite.StarDialer]
127.0.0.1 install.stardialer.de #[Installations Assistent]
127.0.0.1 www.stardialer.de #[Dialer.Stardial]
127.0.0.1 www.247cams.com
127.0.0.1 mediacharger.com
127.0.0.1 devfast.mediacharger.com
127.0.0.1 download.mediacharger.com
127.0.0.1 fast.mediacharger.com #[MediaCharger/MoviePlace]
127.0.0.1 www.pml.mediacharger.com
127.0.0.1 www.movienetworks.com
127.0.0.1 members.swimsuitnetwork.com #[Panda.Adware:swimsuitnetwork]
127.0.0.1 www.swimsuitnetwork.com #[SwimSuitNetwork Direct]
127.0.0.1 www.adslconnection.name #[Trojan.TrustedZone]
127.0.0.1 www.xxx-content.name #[Trojan.TrustedZone]
127.0.0.1 www.analcord.com #[Downloader.Goobiz]
127.0.0.1 www.preferiti-windows.com #[Trojan-Clicker.Win32.Agent.ip]
127.0.0.1 www.erodynamics.nl
127.0.0.1 klikbonus.com
127.0.0.1 www.klikbonus.com
127.0.0.1 x0.nl #[dialXS]
127.0.0.1 www.x0.nl #[Win32/Dialer.DialSX]
127.0.0.1 download.energy-factor.com #[HJTH.Trojan.Downloader.Small]
127.0.0.1 www.energyplugin.com #[eTrust.EnergyPlugin][Trojan.Win32.Energy.A]
127.0.0.1 teen.0no0.com #[Malicious.Links.Codec]
127.0.0.1 1amanda.info #[Spamdexing]
127.0.0.1 103bees.com
127.0.0.1 18girl-av.com #[Javascript.Exploit]
127.0.0.1 www.18girl-av.com
127.0.0.1 www.1987324.com #[McAfee.Downloader-AVT][Win32/Dialer.NCD]
127.0.0.1 2k-sex.com #[Porn-Dialer.Win32.Madial.a]
127.0.0.1 www.5000freebanners.com
127.0.0.1 69galeries.com #[Google.Warning]
127.0.0.1 www.69galeries.com
127.0.0.1 ads.6agenten.dk
127.0.0.1 8v8.biz #[Javascript.Exploit][server down?]
127.0.0.1 aaasss.biz #[Spamdexing.Codec]
127.0.0.1 www.abb-girls.com #[Javascript.Exploit]
127.0.0.1 www.absolutefreesmut.com #[Win32/TrojanDownloader.IstBar.S]
127.0.0.1 www.accessoveloce.com #[HJTH.Svezia Dialer]
127.0.0.1 www.accerispartners.com #[[Dialer.Paydial]
127.0.0.1 www.accesoplugin.com #[PremiumHTML Dialer]
127.0.0.1 acemedia.info #[Malicious.Links.Codec]
127.0.0.1 aconti.net
127.0.0.1 www.aconti.net #[Dialer.Aconti]
127.0.0.1 adchimp.com
127.0.0.1 ad.abum.com
127.0.0.1 ads.adgenta.com
127.0.0.1 www.adloader.com
127.0.0.1 www.ad-pay.de
127.0.0.1 www.ads180.com
127.0.0.1 adserv01.com
127.0.0.1 www.adsforadults.com
127.0.0.1 www.adult2006.com
127.0.0.1 www.adultadbroker.com
127.0.0.1 www.adultads.biz
127.0.0.1 www.adultbannerexchange.nl
127.0.0.1 www.adultscandy.com #[SiteAdvisor.adultscandy.com]
127.0.0.1 counter.adultcheck.com
127.0.0.1 scripts.adultcheck.com
127.0.0.1 www.adultbanners.co.uk
127.0.0.1 www.adultbannerswap.co.uk
127.0.0.1 www.adultdvdhits.com
127.0.0.1 www.adult-guide.us #[IFrame.Exploit]
127.0.0.1 www.adult-models.org #[JS/Exploit.MS05-013]
127.0.0.1 www.adultpla.net #[Malicious.Links]
127.0.0.1 www.adultpagerank.com
127.0.0.1 www.adult-profit-files.com
127.0.0.1 adultwebmastersonline.com #[MHTMLRedir.Exploit][traffnew.biz]
127.0.0.1 www.adultwebmastersonline.com #[SiteAdvisor.adultwebmastersonline.com]
127.0.0.1 cluster.adworldmedia.com
127.0.0.1 results.adworldmedia.com
127.0.0.1 www.adworldmedia.com
127.0.0.1 aduvid.com #[Malicious.Links.Codec]
127.0.0.1 girls.aduvid.com
127.0.0.1 www.adv-italia.com
127.0.0.1 advert.hu
127.0.0.1 www.advertising-department.com
127.0.0.1 dn.adzerver.com
127.0.0.1 temp.adzerver.com
127.0.0.1 banners.affiliatefuture.com
127.0.0.1 ads.afixi.com
127.0.0.1 err.agava.ru
127.0.0.1 allcontents.biz #[Trojan.Win32.Dialer.hz]
127.0.0.1 www.allcontents.biz
127.0.0.1 all-here.org #[Spamdexing]
127.0.0.1 www.all-here.org
127.0.0.1 allniches.com #[Google.Warning]
127.0.0.1 www.allniches.com
127.0.0.1 aloudbox.com #[Malicious.Links.Codec]
127.0.0.1 www.aloudbox.com
127.0.0.1 alltraff.info #[Spamdexing]
127.0.0.1 ads.amateurmatch.com
127.0.0.1 ads2.amateurmatch.com
127.0.0.1 amhen.com.ru #[Umax]
127.0.0.1 www.amp69.com #[NOD32.Win32/Dialer.HZ]
127.0.0.1 banners.amsterdamcash.com
127.0.0.1 track.apexstats.com
127.0.0.1 www.appunti-tesine.net #[Trojan.Win32.Dialer.hh]
127.0.0.1 archiviosesso.com
127.0.0.1 www.archiviosesso.com #[Win32/Dialer.HZ]
127.0.0.1 web16.saturn101.art-customer.net #[JS/Exploit.MS05-013]
127.0.0.1 ads.asexstories.com
127.0.0.1 ads.asredas.com
127.0.0.1 www.attractivesex.com #[Malicious.Links]
127.0.0.1 adson.awempire.com
127.0.0.1 counter.awempire.com
127.0.0.1 iframes.awempire.com
127.0.0.1 promo.awempire.com
127.0.0.1 azkempire.com
127.0.0.1 www.azkempire.com #[Malicious.Links.Codec]
127.0.0.1 azureteens.com #[Malicious.Links.Codec]
127.0.0.1 free.azureteens.com
127.0.0.1 www.azureteens.com
127.0.0.1 banners.babylon-x.com
127.0.0.1 banit.info #[Spamdexing]
127.0.0.1 www.banner.cz
127.0.0.1 adv.bannercity.ru
127.0.0.1 link.bannersystem.cz
127.0.0.1 barmalei.info #[Spamdexing]
127.0.0.1 baxet.com #[Spamdexing]
127.0.0.1 beam.to #[Spamdexing.Codec]
127.0.0.1 ad.beleveyou.com
127.0.0.1 bellepoppe.com
127.0.0.1 www.bellepoppe.com #[HJTH.Trojan.Dialer.hz]
127.0.0.1 www.best-adult-pics.org #[Spamdexing]
127.0.0.1 bestadultsearch.net
127.0.0.1 bestga.biz #[thetraff.com]
127.0.0.1 www.bestmoms.net
127.0.0.1 www.best-top.de
127.0.0.1 betterclips.com
127.0.0.1 www.betterclips.com
127.0.0.1 www.bigmpegx.com #[Malicious.Links]
127.0.0.1 billpics.com #[Malicious.Links]
127.0.0.1 banners.blingbucks.com
127.0.0.1 www.bocata.net #[HJTH.Marcador]
127.0.0.1 www.bocchinimania.com #[Trojan.Win32.Dialer.qi]
127.0.0.1 bonass.net #[Malicious.Links.winantispyware.com]
127.0.0.1 www.bonass.net
127.0.0.1 bootylist.com #[HTML/TrojanDownloader.XXXToolbar]
127.0.0.1 braix.net #[Spamdexing]
127.0.0.1 nl.browserupdate.co.uk
127.0.0.1 www.browserupdate.co.uk #[Browserupdate Dialer]
127.0.0.1 bullai.net
127.0.0.1 ads.host.camz.com
127.0.0.1 cappa.pl #[Spamdexing]
127.0.0.1 logger.cash-media.de
127.0.0.1 stats.cashring.com
127.0.0.1 adv.casinopays.com
127.0.0.1 crbanner.casinopays.com
127.0.0.1 banner.cdpoker.com
127.0.0.1 www.celebritaemodelle.com #[Win32/Dialer.HZ]
127.0.0.1 centralcoastihop.net #[Spamdexing]
127.0.0.1 www.cercoporno.com #[Trojan.Win32.Dialer.hh]
127.0.0.1 adv.cgiworld.net
127.0.0.1 count.cgiworld.net
127.0.0.1 err.chicappa.jp
127.0.0.1 chicks4jerk.com #[Malicious.Links]
127.0.0.1 chincho.net #[IFrame.Exploit]
127.0.0.1 www.chincho.net
127.0.0.1 best.clean-[bleep].com #[Spamdexing]
127.0.0.1 hit.clickaider.com
127.0.0.1 hit.dev.clickaider.com
127.0.0.1 banners.clickthrucash.com
127.0.0.1 www.clickthruserver.com
127.0.0.1 clicktrace.info
127.0.0.1 banners.clips4sale.com
127.0.0.1 clipsbest.info #[Malicious.Links.Codec]
127.0.0.1 www.clipsbest.info
127.0.0.1 img.comparefacil.com
127.0.0.1 www.comparefacil.com
127.0.0.1 content-loader.com
127.0.0.1 www.content-loader.com #[SunBelt.Dialer.CCAccess][Win32/Dialer.KS]
127.0.0.1 counter.cnw.cz
127.0.0.1 www.count24.de
127.0.0.1 counter4all.dk
127.0.0.1 d.crackedearth.com #[Parasite.CrackedEarth]
127.0.0.1 www.crackedearth.com #[SPYW_SRCHHOOK.A]
127.0.0.1 ads.crakmedia.com
127.0.0.1 crazyegg.com
127.0.0.1 www.cunnilinguo.com
127.0.0.1 www.cybilling.com
127.0.0.1 cyberfind10.info #[Spamdexing]
127.0.0.1 banner.czech-sex.cz
127.0.0.1 dailyporn.biz #[Malicious.Links.Codec]
127.0.0.1 www.dailyporn.biz
127.0.0.1 dan-online.biz #[Spamdexing]
127.0.0.1 www.danworld.net #[content.yieldmanager.com]
127.0.0.1 www.date.se #[SMS Dialer][Date Regon]
127.0.0.1 top.dating.lt #[counter.top.dating.lt]
127.0.0.1 www.dbobs.com #[Spamdexing]
127.0.0.1 banners.deseoasiatico.com
127.0.0.1 ads.desktopscans.com
127.0.0.1 ads.devicebondage.com
127.0.0.1 diablo.name #[Malicious.Links.Codec]
127.0.0.1 www.dialerfactory.com
127.0.0.1 dialxs.nl #[HJTH.DialXS][DialXSCtl Object]
127.0.0.1 dialxs.com #[DIAL_DIALXS.A]
127.0.0.1 adv.digieros.it
127.0.0.1 w3.dinerotica.com
127.0.0.1 www.dinerotica.com #[HJTH.Adult Content Dialer]
127.0.0.1 www.dikai.com #[HJTH.Adult Content Dialer]
127.0.0.1 banners.direction-x.com
127.0.0.1 www.directoryadult.com
127.0.0.1 server2.discountclick.com
127.0.0.1 www.divx.it
127.0.0.1 downloadz.us #[Spamdexing]
127.0.0.1 click.dpbill.com
127.0.0.1 www.dragon-balls.com
127.0.0.1 dzheker.com
127.0.0.1 easyadservice.com
127.0.0.1 elitemovieszone.com #[Trojan.Codec]
127.0.0.1 elmansion.com
127.0.0.1 www.elmansion.com #[Malicious.Links][server down?]
127.0.0.1 clicks.equantum.com
127.0.0.1 top.er.cz
127.0.0.1 erofan.com #[Malicious.Links.Codec]
127.0.0.1 www.erostorie.com #[SiteAdvisor.erostorie.com]
127.0.0.1 www.erostars.de #[Dialer.Erostars]
127.0.0.1 www.eroticdialer.com #[Trojan.Win32.Toras]
127.0.0.1 gayporn.erotic-place.org
127.0.0.1 pustoaice.erotic-place.org
127.0.0.1 ban.erovideo.ru
127.0.0.1 www.etushow.com
127.0.0.1 plugin.euro-infomedia.com #[EuroInfoMedia Dialer]
127.0.0.1 www.exitmoney.com
127.0.0.1 extreme-mpeg.com #[Malicious.Links]
127.0.0.1 exxxtravids.com #[Malicious.Links.Codec]
127.0.0.1 faccesborrate.com #[Win32/Dialer.HZ]
127.0.0.1 www.faccesborrate.com
127.0.0.1 a0e6.ffx23wl.nl #[ConnectSwitch Dialer Variant]
127.0.0.1 www.fickads.net
127.0.0.1 fillmypussy.net #[Malicious.Exploit]
127.0.0.1 www.fillmypussy.net
127.0.0.1 www.filminiporno.net #[Win32/Dialer.HZ]
127.0.0.1 www.filmpjes.us #[DIAL_DIALXS.A]
127.0.0.1 www.film-x-gratos.com #[Malicious.Links]
127.0.0.1 findsnd.com #[Spamdexing]
127.0.0.1 www.firebanner.com
127.0.0.1 www.flash-stat.com
127.0.0.1 promos.fling.com
127.0.0.1 track.fling.com
127.0.0.1 www.forestincest.com #[IFrame.Exploit]
127.0.0.1 foteens.com #[IFrame.Exploit]
127.0.0.1 fragolapiccante.com #[Win32/Dialer.HZ]
127.0.0.1 www.fragolapiccante.com
127.0.0.1 freedataweb.com
127.0.0.1 www.freexvideo.net #[NOD32.Win32/Dialer.HZ]
127.0.0.1 xyz.freeweblogger.com
127.0.0.1 ltds.freeporn4you.info
127.0.0.1 free-porn-sample-movies.com #[Google.Warning]
127.0.0.1 www.free-porn-sample-movies.com
127.0.0.1 www.free-rape-pics.us
127.0.0.1 freeskivideo.info #[Malicious.Links]
127.0.0.1 free-sex-movie-post.com #[Google.Warning]
127.0.0.1 www.free-sex-movie-post.com
127.0.0.1 www.free-toplisten.at
127.0.0.1 freeteenies.net
127.0.0.1 freexxxlvideo.info
127.0.0.1 www.freshpornlinks.com
127.0.0.1 c.fsx.com
127.0.0.1 ads.[bleep]ingmachines.com
127.0.0.1 www.[bleep]teenpussy.net #[Malicious.Links]
127.0.0.1 ads.[bleep]youpayme.com
127.0.0.1 www.gagne-un-max.com #[Edipole Dialer]
127.0.0.1 xxx.galleryporn.net #[MHTMLRedir.Exploit]
127.0.0.1 adserver.gallerytrafficservice.com
127.0.0.1 www.gamatgp.com #[HTML/Exploit.CodeBaseExec]
127.0.0.1 www.gayexchangebanner.com
127.0.0.1 gaytrafficbroker.com
127.0.0.1 gaytraffic.biz
127.0.0.1 gem-inc.com
127.0.0.1 gpads.geniproj.com
127.0.0.1 get-vids.com #[Malicious.Links.Codec]
127.0.0.1 www.get-vids.com
127.0.0.1 www.giovanifichette.com #[NOD32.Win32/Dialer.HZ]
127.0.0.1 arsconsole.global-intermedia.com
127.0.0.1 feeds.global-intermedia.com
127.0.0.1 global-netcom.de #[Parasite.GlobalNetcom][Wildcard DNS]
127.0.0.1 install.global-netcom.de #[IELoaderCtl Class]
127.0.0.1 software.global-netcom.de
127.0.0.1 www.global-netcom.de #[Dialer.Coder]
127.0.0.1 clicks.globaltrafficservice.com
127.0.0.1 feeds.globaltrafficservice.com #[Spamdexing]
127.0.0.1 go4433.net #[Malicious.Links.Codec]
127.0.0.1 godefloration.net #[Malicious.Links.Codec]
127.0.0.1 ads.go[bleep]yourself.com
127.0.0.1 www.gonorar.com #[Spamdexing]
127.0.0.1 secure.goodthinxx.com
127.0.0.1 go-porn.to #[Trojan.Codec]
127.0.0.1 www.grannycenter.com #[IFrame.Exploit]
127.0.0.1 error404.gratishost.com
127.0.0.1 free.great-porn.net
127.0.0.1 r.great-porn.net #[Spamdexing]
127.0.0.1 banner.greatpokerclub.org #[Adware.Casino]
127.0.0.1 gx-host.com #[Spamdexing]
127.0.0.1 www.gxplugin.com #[HJTH.Adult Content Dialer]
127.0.0.1 hanklist.com
127.0.0.1 www.hanklist.com
127.0.0.1 hard-core-xxx.com
127.0.0.1 adult.hard-core-xxx.com
127.0.0.1 lsex.hard-core-xxx.com
127.0.0.1 osex.hard-core-xxx.com #[Porn-Dialer.Win32.Agent.aj]
127.0.0.1 www.hardfootballbabes.com #[REG_EPLUGIN.AC][Trojan.TrustedZone]
127.0.0.1 www.healthsourceuk.com #[Malicious.Links.Codec]
127.0.0.1 adserver.hispavista.com
127.0.0.1 ads.hogtied.com
127.0.0.1 adweb1.hornymatches.com
127.0.0.1 adweb2.hornymatches.com
127.0.0.1 www.hostedbanners.com
127.0.0.1 hot-incest.com #[MHTMLRedir.Exploit]
127.0.0.1 www.hot-incest.com
127.0.0.1 hotpornmovie.info #[Malicious.Links]
127.0.0.1 www.hotpornmovie.info
127.0.0.1 blowjob.hot-porn-clips.com #[Spamdexing]
127.0.0.1 ad3.hornymatches.com
127.0.0.1 gbanners.hornymatches.com
127.0.0.1 ext.host-tracker.com
127.0.0.1 403.hqhost.net
127.0.0.1 404.hqhost.net
127.0.0.1 hqpornportal.com #[Spamdexing]
127.0.0.1 hqualitysex.com
127.0.0.1 www.hqualitysex.com #[Google.Warning]
127.0.0.1 www.hugetraffic.com
127.0.0.1 humorcash.nl
127.0.0.1 www.humorcash.nl
127.0.0.1 ads.iawsnetwork.com
127.0.0.1 oreo.iawsnetwork.com
127.0.0.1 inbabes.com #[IFrame.Exploit]
127.0.0.1 incesta.com
127.0.0.1 www.incesta.com #[IFrame.Exploit]
127.0.0.1 www.incestcatalog.com #[IFrame.Exploit]
127.0.0.1 incesttop.com #[IFrame.Exploit]
127.0.0.1 stats.industryinc.com
127.0.0.1 www.infodialer3000.com #[HJTH.nfoDialer3000]
127.0.0.1 exitstitial.infospacehosting.net #[InfoSpace]
127.0.0.1 deposito.instantdoor.com #[Win32/Diamin.NAF]
127.0.0.1 flat.instantdoor.com
127.0.0.1 server2.internetdump.com
127.0.0.1 bds.invitations.fr #[Javascript.Exploit]
127.0.0.1 www.iperbanner.com
127.0.0.1 ciscom1.iquebec.com #[Spamdexing]
127.0.0.1 yxcv.is-a-geek.net #[smutserver.com][HJTH.Adult Content Dialer]
127.0.0.1 isralink.net
127.0.0.1 italiaxxxtop.com
127.0.0.1 janit.info #[Spamdexing]
127.0.0.1 counter.jasmin.hu
127.0.0.1 www.jointraffic.com
127.0.0.1 ads.jolinko.com
127.0.0.1 errors.jp18.com
127.0.0.1 j-rx.com
127.0.0.1 www.juicyads.com
127.0.0.1 adserver.juicybucks.com
127.0.0.1 barbieshemale.just-a-porn.com #[IFrame.Exploit]
127.0.0.1 just-traffic.com
127.0.0.1 ads.kaktuz.net
127.0.0.1 www.kidzilla.info #[JS/Exploit.MS05-013]
127.0.0.1 banners.largecash.com
127.0.0.1 laungers.cn #[Spamdexing.Codec]
127.0.0.1 lesbian-porn.in #[Malicious.Links]
127.0.0.1 ads.lesbianpersonals.com
127.0.0.1 counter.lgg.ru
127.0.0.1 libereco.net
127.0.0.1 www.libereco.net #[Parasite.OnlineDialer]
127.0.0.1 limewax.org #[Malicious.Links.Codec]
127.0.0.1 hostit.liveadulthost.com #[Javascript.Exploit]
127.0.0.1 livecams.nl
127.0.0.1 www.livecams.nl #[Dialer.LiveCams]
127.0.0.1 liveusasex.com #[Malicious.Links]
127.0.0.1 www.livewebstats.net
127.0.0.1 www.logging.to
127.0.0.1 lolafree.com #[Malicious.Links]
127.0.0.1 loosing-virginity.com #[Malicious.Links]
127.0.0.1 www2.lovely-search.com #[Spamdexing]
127.0.0.1 partner.loveplanet.ru
127.0.0.1 www.love-world.de #[Troj/Tps]
127.0.0.1 sexvideo.lussuria.org #[JS/Exploit.ObjCode.I]
127.0.0.1 lzda.com
127.0.0.1 rewards.macandbumble.com
127.0.0.1 nub9r.maisonx.com #[BKDR_WOMANIZ.H]
127.0.0.1 www.male-celeb-videos.com #[Malicious.Links.Zango]
127.0.0.1 ads.maleflixxx.tv
127.0.0.1 www.manga-erotico.com #[Rubuskizo Dialer]
127.0.0.1 adult.master-tv.net
127.0.0.1 acceso.masminutos.com #[HJTH.Marcador]
127.0.0.1 masterdialer.de #[Parasite.MasterDialer]
127.0.0.1 www.masterdialer.de
127.0.0.1 www.mediaswitch.nl #[Win32/Trojan.Downloader.VB.FH]
127.0.0.1 mass-traffic.com
127.0.0.1 crtv.mate1.com
127.0.0.1 mature-pussy.us
127.0.0.1 j.maxmind.com
127.0.0.1 click.maxxandmore.com
127.0.0.1 link.maxxandmore.com #[Spamdexing]
127.0.0.1 resources.maxcash.com
127.0.0.1 stats.maximumcash.com #[SunBelt.MaximumCash.com]
127.0.0.1 www.maximumcash.com #[Tenebril.Tracking.Cookie]
127.0.0.1 www.mdexitconsole.com
127.0.0.1 audit.median.hu
127.0.0.1 dialer.medianed.nl #[HJTH.Tintel Dialer]
127.0.0.1 www.mederotica.com
127.0.0.1 www.megacounter.de
127.0.0.1 ads.memberarea.cc
127.0.0.1 smartad.mercadolivre.com.br
127.0.0.1 ads.miarroba.com
127.0.0.1 www.milunuda.com #[Google Warning]
127.0.0.1 minigirls.biz #[IFrame.Exploit]
127.0.0.1 www.minigirls.biz
127.0.0.1 www.mistersesso.com #[Win32/Dialer.HZ]
127.0.0.1 www.momsbusters.com
127.0.0.1 moneyboobs.com #[IFrame.Exploit]
127.0.0.1 ads.movieflix.com
127.0.0.1 www.movieflowers.com #[Malicious.Links]
127.0.0.1 mrbigcock.net #[Malicious.Links.Codec]
127.0.0.1 galls.mrbigcock.net
127.0.0.1 www.mrbigcock.net
127.0.0.1 ads.mrskin.com
127.0.0.1 adserving.muppetism.com
127.0.0.1 muschi-tgp.com #[IFrame.Exploit]
127.0.0.1 myfriendcamlive.com #[Trojan.Codec]
127.0.0.1 mygalleries.biz #[SiteAdvisor.mygalleries.biz]
127.0.0.1 www.mygalleries.biz #[Win32/Dialer.HZ]
127.0.0.1 myxgirls.com #[IFrame.Exploit]
127.0.0.1 www.mypgn.com #[HTML.Exploit]
127.0.0.1 www.mysexfolder.com
127.0.0.1 mytraf.info
127.0.0.1 nakedgirlsporn.net #[Malicious.Links.Codec]
127.0.0.1 banner.nastycash.com
127.0.0.1 clicks.nastydollars.com
127.0.0.1 grab.nastydollars.com
127.0.0.1 graphics.nastydollars.com
127.0.0.1 nemo-movies.com #[Malicious.Links]
127.0.0.1 nerisuperdotati.com
127.0.0.1 www.nerisuperdotati.com #[Win32/Dialer.HZ]
127.0.0.1 notetol.com #[SunBelt.Trojan.LinkOptimizer]
127.0.0.1 www.notetol.com #[AdWare.Win32.LinkOptimizer.a]
127.0.0.1 newmediadriver.com #[HTML/Exploit.Iframe.FileDownload.K]
127.0.0.1 newsvr.info #[Malicious.Links]
127.0.0.1 www.newsvr.info
127.0.0.1 banners.nichepromotion.com
127.0.0.1 www.nightherb.com
127.0.0.1 counter.nope.dk
127.0.0.1 www.nudegayvideos.com #[Malicious.Links.Zango]
127.0.0.1 www.nzads.net.nz
127.0.0.1 www.obanner.net
127.0.0.1 counter.ok.ee
127.0.0.1 www.onlinewebservice3.de
127.0.0.1 onlybestsex.com #[Win32/Adware.Toolbar.WinThirtyTwo]
127.0.0.1 www.onlybestsex.com
127.0.0.1 www.onmpeg.com #[Malicious.Links]
127.0.0.1 www.onporn.info #[Spamdexing]
127.0.0.1 orgeamatoriali.com
127.0.0.1 www.orgeamatoriali.com #[Win32/Dialer.HZ]
127.0.0.1 www.orgygallery.net
127.0.0.1 www.orray.com #[Spamdexing]
127.0.0.1 www.otherchance.com #[Dial/Chivio-AN][Trojan.TrustedZone]
127.0.0.1 www.pagerank10.co.uk
127.0.0.1 banners.paneuromedia.com
127.0.0.1 promotion.partnercash.de
127.0.0.1 promo.passioncams.com
127.0.0.1 access.passwordbyphone.com
127.0.0.1 banners.passwordbyphone.com
127.0.0.1 gfx.passwordbyphone.com
127.0.0.1 interface.passwordbyphone.com
127.0.0.1 www.passwordbyphone.com
127.0.0.1 www.pay-ads.com
127.0.0.1 www.paysefeed.com #[Hayter Merchants Group][server down?]
127.0.0.1 banners.payserve.com
127.0.0.1 perfectgirls.net
127.0.0.1 www.perfectgirls.net
127.0.0.1 banners.perfectgonzo.com
127.0.0.1 bannershotlink.perfectgonzo.com
127.0.0.1 picsandmovs.com #[Trojan.Codec]
127.0.0.1 www.picsandmovs.com
127.0.0.1 error.pimproll.com
127.0.0.1 pinkcount.com
127.0.0.1 www.pinkcount.com
127.0.0.1 pinkteentop.com #[IFrame.Exploit]
127.0.0.1 www.pinkyellow.com
127.0.0.1 pixyoung.com #[Javascript.Exploit]
127.0.0.1 pei-ads.playboy.com #[RealMedia]
127.0.0.1 www.playitalia.com #[NOD32.Win32/Dialer.HZ]
127.0.0.1 ads.pno.net
127.0.0.1 pop3mailers.info #[Javascript.Exploit]
127.0.0.1 poratech.com #[Spamdexing]
127.0.0.1 ad.porkolt.com
127.0.0.1 www.porn2world.com
127.0.0.1 my.porn-info.info #[Spamdexing]
127.0.0.1 www.porncash.de
127.0.0.1 ads.porncash.tv
127.0.0.1 www.porncash.tv
127.0.0.1 www.porn-google.com
127.0.0.1 bearsxxx.porn-host.org #[HTML/TrojanDownloader.XXXToolbar]
127.0.0.1 www.pornmail.com #[CrackedEarth]
127.0.0.1 porn0site.org #[Malicious.Links]
127.0.0.1 www.filmy.[bleep].pl #[Dialer.Connect]
127.0.0.1 www.pornoitalia.it #[NOD32.Win32/Dialer.HZ]
127.0.0.1 www.pornoitalianogratis.com #[NOD32.Win32/Dialer.HZ]
127.0.0.1 www.pornrose.com #[Google Warning]
127.0.0.1 www.power-counter.com
127.0.0.1 ads.privatefeeds.com
127.0.0.1 redirect.pr0-search.biz
127.0.0.1 protect-x.com
127.0.0.1 www.psbbanners.com
127.0.0.1 banners.publipagos.com
127.0.0.1 pure[bleep].com
127.0.0.1 ads.pure[bleep].com
127.0.0.1 stream.pussyharem.com
127.0.0.1 www.pussyharem.com #[HJTH.Adult Content Dialer]
127.0.0.1 pxporn.com
127.0.0.1 www.pxporn.com #[Google.Warning]
127.0.0.1 banners.pythonvideo.com
127.0.0.1 banners2.pythonvideo.com
127.0.0.1 tracker.pythonvideo.com
127.0.0.1 www.pythonpays.com
127.0.0.1 q21.info
127.0.0.1 quickuseronline.com
127.0.0.1 www.ranking-charts.de
127.0.0.1 www.rank-guru.com
127.0.0.1 www.ranking-links.de
127.0.0.1 www.ranksexo.com
127.0.0.1 gay.rated100.com
127.0.0.1 realarea.biz
127.0.0.1 www.realarea.biz #[Win32/Dialer.HZ]
127.0.0.1 relax-site.name #[Spamdexing]
127.0.0.1 redirectx.net #[Malicious.Links]
127.0.0.1 redirweb.info
127.0.0.1 ads.redtube.com
127.0.0.1 hit.reference-sexe.com
127.0.0.1 banners.reginepompinare.com
127.0.0.1 www2.reliablebanners.com
127.0.0.1 www3.reliablebanners.com
127.0.0.1 banners.rexmag.com
127.0.0.1 banner.ringofon.com
127.0.0.1 www.robsxxx.com
127.0.0.1 www.roccomovies.net #[Malicious.Links]
127.0.0.1 stats.rhyman.com
127.0.0.1 sadomasogratuito.com #[TR/Agent.3024]
127.0.0.1 www.sadomasogratuito.com #[NOD32.Win32/Dialer.HZ]
127.0.0.1 satirika.com #[HTML/Exploit.CodeBaseExec]
127.0.0.1 www.satirika.com #[Win32/Dialer.HZ][Google Warning]
127.0.0.1 savagechicks.com #[Malicious.Links.Codec]
127.0.0.1 www.savagechicks.com
127.0.0.1 adserver.saxonsoft.hu
127.0.0.1 www.screamingvideos.com
127.0.0.1 screengirls.net #[Trojan.Codec]
127.0.0.1 www.screengirls.net
127.0.0.1 st.seblg.com #[Spamdexing]
127.0.0.1 go.securecasting.com #[DIAL_EXDIAL.A]
127.0.0.1 www.sessosubito.net
127.0.0.1 ads.sexandsubmission.com
127.0.0.1 imageads.sexmoney.com
127.0.0.1 www.sexas.us
127.0.0.1 ad.sexcount.de
127.0.0.1 www.sexcount.de
127.0.0.1 adv.sexcounter.com #[Ewido.TrackingCookie.Sexcounter]
127.0.0.1 cs.sexcounter.com #[Panda.Spyware:Cookie/cs.sexcounter]
127.0.0.1 sexcox.net #[Malicious.Links.drivecleaner.com]
127.0.0.1 sexempire.biz #[Malicious.Links]
127.0.0.1 www.sexempire.biz
127.0.0.1 www.sexfiles.nu #[SMS Dialer][Date Regon]
127.0.0.1 www.sexhit.com
127.0.0.1 freeporn.sexhooonline.com #[Spamdexing]
127.0.0.1 www.sexhooonline.com
127.0.0.1 www.sexleech.com
127.0.0.1 www.sexlinksnow.com #[HJTH.Adult Content Dialer]
127.0.0.1 click.sexmoney.com
127.0.0.1 pagepeels.sexmoney.com
127.0.0.1 www.sexmoney.com
127.0.0.1 bannerrotation.sexmoney.com
127.0.0.1 www.sexop.tv #[SinCity Dialer]
127.0.0.1 banners.sexsearch.com
127.0.0.1 textad.sexsearch.com
127.0.0.1 wt.sexsearchcom.com #[WebTrends]
127.0.0.1 counter.sexsuche.tv
127.0.0.1 banner.sextorrent.to
127.0.0.1 www.sextriere.com #[Malicious.Links.Zango]
127.0.0.1 ads.sextube.si
127.0.0.1 www.sexxxpass.com #[SecurityRisk.SexxPass]
127.0.0.1 members.sexroulette.com
127.0.0.1 wts.sexrouter.net
127.0.0.1 hestia.sextrail.com
127.0.0.1 sexwave.com #[IFrame.Exploit]
127.0.0.1 www.sexwave.com
127.0.0.1 reseller.sexyads.com
127.0.0.1 sexyfamouscelebs.com #[Javascript.Exploit]
127.0.0.1 www.sexyfamouscelebs.com
127.0.0.1 logs.sexy-parade.com
127.0.0.1 sexyteen-pictures.com #[Malicious.Links]
127.0.0.1 sexytraffic.info #[Spamdexing]
127.0.0.1 sexy-vids.info #[Malicious.Links]
127.0.0.1 sexyoung.us
127.0.0.1 www.sexysportschicks.com #[Malicious.Links.Zango]
127.0.0.1 sfonditalia.biz #[Trojan.TrustedZones]
127.0.0.1 www.sfonditalia.biz #[Dialer.Sfonditalia][Trojan.Win32.Dialer.hz]
127.0.0.1 www.sfondimania.net #[Win32/Dialer.HZ]
127.0.0.1 sgrunt.biz #[Dialer.Yeaknet][Trojan.TrustedZones]
127.0.0.1 www.sgrunt.biz #[DIAL_SGRUNT.A][Troj/QLowZon-E]
127.0.0.1 www.shinypics.com
127.0.0.1 link.siccash.com
127.0.0.1 click.silvercash.com
127.0.0.1 exit.silvercash.com
127.0.0.1 smc.silvercash.com
127.0.0.1 www.silvercash.com #[SiteAdvisor.silvercash.com]
127.0.0.1 simple-buy.net #[Spamdexing]
127.0.0.1 www.slackernetwork.com #[Malicious.Links]
127.0.0.1 sleazygalleries.com #[Malicious.Links.Codec]
127.0.0.1 stats.smartbucks.com
127.0.0.1 smart-counter.com
127.0.0.1 ad.smsmovies.net
127.0.0.1 ad.smsmovie.tv
127.0.0.1 www.smutgod.com #[JS/TrojanDownloader.Agent.AB]
127.0.0.1 www.sockshots.com #[Malicious.Content.Zango]
127.0.0.1 counters.soft-com.biz
127.0.0.1 amare.softwaregarden.com #[Win32/TrojanDownloader.Small.AWA]
127.0.0.1 banners.solocazzienormi.com
127.0.0.1 www.splem.net
127.0.0.1 www.spycamvideo.net #[Win32/Dialer.QI]
127.0.0.1 39051.www1.ssaabb.com
127.0.0.1 65916.www1.ssaabb.com
127.0.0.1 www.www2.ssaabb.com
127.0.0.1 ds.starmedia.com
127.0.0.1 statsgold.com
127.0.0.1 www.stockway.net #[Spamdexing]
127.0.0.1 www.storage-tasp.com #[HJTH.Virgilio Dialer]
127.0.0.1 banners.sublimedirectory.com
127.0.0.1 www.sunnygals.com #[Spamdexing]
127.0.0.1 landingpages.sunnytoolz.com
127.0.0.1 superfastsservers.com #[Spamdexing]
127.0.0.1 www.superfastsservers.com
127.0.0.1 supersexpass.com #[SunBelt.SuperSexPass]
127.0.0.1 www.supersexpass.com
127.0.0.1 superxxxhot.com #[Malicious.Links.Codec]
127.0.0.1 ads.tarrobads.com
127.0.0.1 www.tds69.com #[Malicious.Links]
127.0.0.1 banners.teeniemovies.com
127.0.0.1 teenhotpix.com
127.0.0.1 www.teenhotpix.com #[IFrame.Exploit]
127.0.0.1 teen-images.net #[Malicious.Links]
127.0.0.1 teenlemon.com #[IFrame.Exploit]
127.0.0.1 www.teenschicks.com
127.0.0.1 teens-girls.org
127.0.0.1 th.teens-girls.org #[Trojan.Codec]
127.0.0.1 www.teens-girls.org #[Google Warning]
127.0.0.1 teensparty.net #[Malicious.Links.Codec]
127.0.0.1 www.teenporn18.eu #[Malicious.Links]
127.0.0.1 www.teensales.com
127.0.0.1 teens-dream.com
127.0.0.1 www.teens-dream.com
127.0.0.1 teenssex.info #[Google Warning]
127.0.0.1 teentop.biz #[IFrame.Exploit]
127.0.0.1 www.temisvolti.info #[Trojan.Win32.Dialer.hh]
127.0.0.1 teyzemx.info #[Malicious.Links]
127.0.0.1 tgp69.info
127.0.0.1 www.tgp69.info #[Malicious.Links]
127.0.0.1 thecollegeslut.com #[Google.Warning]
127.0.0.1 thefreenude.com
127.0.0.1 www.thehon.com
127.0.0.1 www.thehun.com #[Win32.Lospad.B]
127.0.0.1 thehun.net
127.0.0.1 www.thehun.net
127.0.0.1 banner.thenudelist.com
127.0.0.1 www.thesexcinema.com #[McAfee.Cookie-TheSexCinema]
127.0.0.1 theteenxxx.com #[IFrame.Exploit]
127.0.0.1 www.theteenxxx.com
127.0.0.1 thetraff.com
127.0.0.1 banners.thirdmovies.com
127.0.0.1 camz.tintel.nl #[HJTH.Tintel Dialer]
127.0.0.1 hpintermedia.tintel.nl #[HJTH.Tintel Dialer]
127.0.0.1 xenium.tintel.nl #[HJTH.Tintel Dialer]
127.0.0.1 www.todayshunks.com #[Malicious.Links.Zango]
127.0.0.1 top11.ru
127.0.0.1 counter.top.dating.lt
127.0.0.1 www.toons-for-adult.com #[Google.Warning]
127.0.0.1 www.top-porn-sites.info
127.0.0.1 images.top66.ro
127.0.0.1 script.top66.ro
127.0.0.1 www.top66.ro
127.0.0.1 www.topsesso69.com #[NOD32.Win32/Dialer.HZ]
127.0.0.1 www.topsites24.de
127.0.0.1 www.tossoffads.com
127.0.0.1 www.tracker123.com
127.0.0.1 www.trafficadept.com
127.0.0.1 www.trafficrank.de
127.0.0.1 trafficwide.com #[Malicious.Links]
127.0.0.1 traffcommunity.com
127.0.0.1 traffdirect.info
127.0.0.1 thumb.trafficroup.com
127.0.0.1 trafficscripts.net
127.0.0.1 www.traffic-trades.com
127.0.0.1 clicks.traffictrader.net
127.0.0.1 clicks2.traffictrader.net
127.0.0.1 clicks3.traffictrader.net
127.0.0.1 clicks.eutopia.traffictrader.net
127.0.0.1 hestia.sextrail.trakkerd.net
127.0.0.1 dialer.tranent.nl
127.0.0.1 pay.tranent.nl
127.0.0.1 www.triplexcounter.com
127.0.0.1 affiliates.thrixxx.com
127.0.0.1 content.thrixxx.com
127.0.0.1 bannerexchange.troglod.com
127.0.0.1 troiegratis.net
127.0.0.1 www.troiegratis.net
127.0.0.1 tropezitalia.com #[McAfee.Downloader-AVT]
127.0.0.1 banner.tropezitalia.com #[Adware.Casino]
127.0.0.1 www.tropezitalia.com #[Malicious.Links]
127.0.0.1 truebbw.net #[Google.Warning]
127.0.0.1 www.tuttoagratis.com #[Trojan.Win32.Dialer.hh]
127.0.0.1 tv69.com
127.0.0.1 streaming.tv69.com
127.0.0.1 www.tv69.com #[JS/NoClose-G]
127.0.0.1 twinklane.com
127.0.0.1 www.twinklane.com #[Malicious.Links]
127.0.0.1 ads.ultimatesurrender.com
127.0.0.1 freecounter.unms.com
127.0.0.1 us-team.us #[Malicious.Links]
127.0.0.1 best-sellers.vegnews.com
127.0.0.1 consultive.vegnews.com
127.0.0.1 glo.vegnews.com
127.0.0.1 lance.vegnews.com #[Win32/TrojanDownloader.Small.AWA]
127.0.0.1 margara.vegnews.com
127.0.0.1 ads.velcom.com
127.0.0.1 videofree.biz
127.0.0.1 www.videofree.biz #[Win32/Dialer.HZ]
127.0.0.1 www.video-[bleep].cc #[Trojan.Win32.Dialer.hh]
127.0.0.1 banners.videosz.com
127.0.0.1 vidsparade.com #[Malicious.Links]
127.0.0.1 www.virgilio.in #[Malicious.Links.Zango]
127.0.0.1 virginfoto.com #[IFrame.Exploit]
127.0.0.1 virginsplay.com #[IFrame.Exploit]
127.0.0.1 banners.virtuagirlhd.com
127.0.0.1 cbanners.virtuagirlhd.com
127.0.0.1 www.vispateresa.biz #[Win32/TrojanProxy.Agent.LK]
127.0.0.1 vote4me.de
127.0.0.1 promotools.vpscash.nl
127.0.0.1 banner.vrs.cz
127.0.0.1 www.w3counter.com
127.0.0.1 wanktool.com #[IFrame.Exploit]
127.0.0.1 www.warningpages.com
127.0.0.1 promos.wealthymen.com
127.0.0.1 ads.webcamclub.com
127.0.0.1 webfreepornmovies.com #[Malicious.Links]
127.0.0.1 webhosthit.com
127.0.0.1 www.webhostingcounter.com
127.0.0.1 ads.webmasterprofitcenter.com
127.0.0.1 gfx.webmasterprofitcenter.com
127.0.0.1 peel.webmasterprofitcenter.com
127.0.0.1 promo.webmasterprofitcenter.com
127.0.0.1 banners.weboverdrive.com
127.0.0.1 www.wellcams.biz #[Spamdexing]
127.0.0.1 banners.weselltraffic.com
127.0.0.1 clicks.weselltraffic.com
127.0.0.1 feeds.weselltraffic.com
127.0.0.1 www.websitealive3.com
127.0.0.1 www.whatpornsite.com #[Backdoor.Nibu.G]
127.0.0.1 ads.whippedass.com
127.0.0.1 www.wickedpictures.com #[Win32/Agent.PA]
127.0.0.1 www.wmsonic.com #[Spamdexing]
127.0.0.1 www.world-dialer.net #[W32/Dialer.gen]
127.0.0.1 adlink.worldprofitcenter.com
127.0.0.1 promo.worldprofitcenter.com
127.0.0.1 www.worldxchange.com #[Dialer.Paydial]
127.0.0.1 www.wtfmedia.com
127.0.0.1 x9search.com #[Spamdexing]
127.0.0.1 www.xbeta69.com
127.0.0.1 ads.xbiz.com
127.0.0.1 engine.xbiz.com
127.0.0.1 exchange.xbiz.com
127.0.0.1 x2.xclicks.net
127.0.0.1 x3.xclicks.net
127.0.0.1 x4.xclicks.net
127.0.0.1 x5.xclicks.net
127.0.0.1 x6.xclicks.net
127.0.0.1 www.xclicks.net
127.0.0.1 amour-xxx-angels.xhostar.com #[Malicious.Links]
127.0.0.1 cocovideo.xhostar.com #[IFrame.Exploit]
127.0.0.1 www.x-india.com #[Malicious.Links.Codec]
127.0.0.1 xkxempire.com
127.0.0.1 www.xkxempire.com #[Malicious.Links.Codec]
127.0.0.1 xlocator.com #[PcTools.XLocator]
127.0.0.1 adblocks.xmlscope.net
127.0.0.1 www.xlocator.com #[HJTH.Xlocator/WinLocator Adware]
127.0.0.1 neorsoft.xost.ru #[Javascript.Exploit]
127.0.0.1 x-road.co.kr
127.0.0.1 www.xstat.pl
127.0.0.1 a1.x-traceur.com
127.0.0.1 a3.x-traceur.com
127.0.0.1 a12.x-traceur.com
127.0.0.1 a18.x-traceur.com
127.0.0.1 a20.x-traceur.com
127.0.0.1 logos.x-traceur.com
127.0.0.1 services.x-traceur.com
127.0.0.1 www.xtporn.com #[Trojan.Codec]
127.0.0.1 x-videoz.org #[Malicious.Links.Codec]
127.0.0.1 xxpornxx.net #[Malicious.Links.Codec]
127.0.0.1 www.xxx-banner.com
127.0.0.1 xxxdatabase.info #[Malicious.Links.Codec]
127.0.0.1 www.xxx-exits.com
127.0.0.1 xxxfreesexmovie.info #[Spamdexing.Codec]
127.0.0.1 xxx-galleries.info #[Malicious.Links.Codec]
127.0.0.1 stats.xxxkey.com
127.0.0.1 xxxmaidens.com
127.0.0.1 www.xxxmaidens.com #[Malicious.Links.Codec]
127.0.0.1 nudist.xxx-pics.biz #[Malicious.Links.Codec]
127.0.0.1 teen.xxx-pics.biz
127.0.0.1 xxxpornonline.net #[Malicious.Links]
127.0.0.1 www.xxxpornonline.net
127.0.0.1 bannerlink.xxxtreams.com
127.0.0.1 xxx-videos.to #[Trojan.Codec]
127.0.0.1 stats.xxxrewards.com
127.0.0.1 xxxvogue.net #[Trojan.Ruindem]
127.0.0.1 www.xxxvogue.net
127.0.0.1 benjamin.xww.de #[W32/Kazoa.B]
127.0.0.1 voyour-cams.xww.de #[W32.DSS.Trojan]
127.0.0.1 counter.yakcash.com
127.0.0.1 yeak.net #[Dialer.Yeaknet]
127.0.0.1 www.yeak.net #[Trojan.TrustedZones]
127.0.0.1 ads.ynot.com
127.0.0.1 youngteenmodel.info #[Trojan.Codec]
127.0.0.1 analyze.yourfilehost.com #[Urchin Tracking]
127.0.0.1 tracking.yourfilehost.com
127.0.0.1 yourthumbnails.com #[IFrame.Exploit]
127.0.0.1 www.yourthumbnails.com #[Exploit.WMF]
127.0.0.1 ypka.com #[Spamdexing]
127.0.0.1 www.yukselt.net #[Exploit.PsyBotInstaller]
127.0.0.1 zalupa.net
127.0.0.1 zbiornik.com
127.0.0.1 zdrqmpad.com #[Javascript.Exploit]
127.0.0.1 zoldgonit.com #[Malicious.Links.Codec]
127.0.0.1 www.zoldgonit.com
127.0.0.1 www.zoo-[bleep].net #[Win32/Dialer.E]
127.0.0.1 banners.ztod.com
127.0.0.1 defloration.zvca.com
127.0.0.1 zvids.com #[Malicious.Links]
127.0.0.1 www.zvids.com
127.0.0.1 campaigns.de.euserv.adaos-ads.net
127.0.0.1 cpx.v1.de.euserv.adaos-ads.net
127.0.0.1 img.v1.de.euban.adaos-ads.net
127.0.0.1 js.v1.de.euserv.adaos-ads.net
127.0.0.1 js.v1.de.euserv.fox.adaos-ads.net
127.0.0.1 mailserv.v1.de.euserv.adaos-ads.net
127.0.0.1 static.de.euserv.adaos-ads.net
127.0.0.1 viewcount.v1.de.euserv.adaos-ads.net
127.0.0.1 iscoolfunny.com #[server down?]
127.0.0.1 iscoolstars.com #[server down?]
127.0.0.1 isfunnynetwork.com #[server down?]
127.0.0.1 thisfreemovies.com #[Google.Warning]
127.0.0.1 webfunny-a.com
127.0.0.1 websoft-a.com #[TR/Dldr.Zlob.KA][server down?]
127.0.0.1 websoft-c.com #[Win32/Statik][server down?]
127.0.0.1 webstars-a.com
127.0.0.1 0traff.com
127.0.0.1 crunet.info #[Win32/TrojanDownloader.Ani.Gen][server down?]
127.0.0.1 www.gp-eurocapital.com #[scam site]
127.0.0.1 hack-off.info #[Win32/TrojanDropper.Agent][server down?]
127.0.0.1 hightstats.net #[JS/TrojanDownloader.Psyme.HX]
127.0.0.1 traff.justcount.net
127.0.0.1 milk0soft.com
127.0.0.1 www.milk0soft.com #[JS/TrojanDownloader.Agent.ZZ]
127.0.0.1 softspydelete.com #[JS/TrojanDownloader.Psyme.HX]
127.0.0.1 www.americangreetings.2484711.com #[PhishTank.Alert][server down?]
127.0.0.1 www.americangreetings.6184511.com[server down?]
127.0.0.1 candy-country.com #[Javascript.Exploit]
127.0.0.1 www.candy-country.com
127.0.0.1 fernando123.ws #[Javascript.Exploit][server down?]
127.0.0.1 msupdate.org #[Javascript.Exploit]
127.0.0.1 www.msupdate.org
127.0.0.1 tstats.org
127.0.0.1 lskdfjlerjvm.com #[Javascript.Exploit]
127.0.0.1 adultcomix.biz
127.0.0.1 free.adultcomix.biz
127.0.0.1 alivegirls.com #[Malicious.Links.Codec]
127.0.0.1 www.alivegirls.com #[SiteAdvisor.alivegirls.com]
127.0.0.1 artcomix.com
127.0.0.1 top.artcomix.com
127.0.0.1 www.artcomix.com
127.0.0.1 cartoonpornguide.com
127.0.0.1 free.cartoonpornguide.com
127.0.0.1 www.cartoonpornguide.com
127.0.0.1 dvdhentai.net
127.0.0.1 gallfree.com #[Trojan.Codec]
127.0.0.1 img.gallfree.com
127.0.0.1 www.gallfree.com
127.0.0.1 toon-families.com
127.0.0.1 www.toon-families.com
127.0.0.1 toonfamilies.net
127.0.0.1 www.toonfamilies.net
127.0.0.1 wildmistress.com
127.0.0.1 www.wildmistress.com
127.0.0.1 ads.adultadworld.com
127.0.0.1 ads3.adultadworld.com
127.0.0.1 ads6.adultadworld.com
127.0.0.1 cluster.adultadworld.com
127.0.0.1 hippo.adultadworld.com
127.0.0.1 newt1.adultadworld.com
127.0.0.1 partners.adultadworld.com
127.0.0.1 textads.adultadworld.com
127.0.0.1 tigershark.adultadworld.com
127.0.0.1 eroticlick.net
127.0.0.1 www.eroticlick.net #[Malicious.Links]
127.0.0.1 adultgayvideo.net
127.0.0.1 anamateur.net
127.0.0.1 andpornomovies.com #[Google.Warning]
127.0.0.1 adult-toon.net
127.0.0.1 bbwlibrary.net #[SiteAdvisor.bbwlibrary.net]
127.0.0.1 bdsmorgy.net
127.0.0.1 best4all.net
127.0.0.1 bestfreemature.com
127.0.0.1 bestteenspics.com
127.0.0.1 bigboobsmovies.info
127.0.0.1 blowjobsmovies.net
127.0.0.1 everymatures.com
127.0.0.1 excitingfetish.net
127.0.0.1 fetishvideoclips.net
127.0.0.1 freeanalvideo.net
127.0.0.1 freebbwmovies.net
127.0.0.1 free-babies.com
127.0.0.1 freebigboobs.info #[IFrame.Exploit]
127.0.0.1 img.freebigboobs.info
127.0.0.1 free-cutie.com
127.0.0.1 freeebonymovies.net
127.0.0.1 free-guy-movie.com
127.0.0.1 free-mature-videos.net
127.0.0.1 free-[bleep]-movie.net #[IFrame.Exploit]
127.0.0.1 www.free-[bleep]-movie.net
127.0.0.1 free-voyeur-video.net
127.0.0.1 [bleep]inggay.net
127.0.0.1 gaysportal.net
127.0.0.1 hardcorebook.net
127.0.0.1 hotpornflow.net
127.0.0.1 maturepass.net
127.0.0.1 maturesexmovies.info
127.0.0.1 maturestime.net
127.0.0.1 no1sex.net
127.0.0.1 onlinesexmovie.net
127.0.0.1 orgygalleries.net
127.0.0.1 img.orgygalleries.net
127.0.0.1 www.orgygalleries.net
127.0.0.1 pornmoviesfree.net
127.0.0.1 promogals.com
127.0.0.1 sexasianvideo.net
127.0.0.1 sexlesbianmovies.com
127.0.0.1 straightgay.net
127.0.0.1 teendvdmovies.info
127.0.0.1 topmatures.net
127.0.0.1 trannysvideos.com
127.0.0.1 xxxamateurvideo.net
127.0.0.1 xxxteensfree.com
127.0.0.1 schoolgayboy.com
127.0.0.1 www.schoolgayboy.com
127.0.0.1 authorizedsearchagents.com
127.0.0.1 domainplayersclub.com
127.0.0.1 reviews.domainplayersclub.com
127.0.0.1 ebtmarketing.com
127.0.0.1 www.ebtmarketing.com
127.0.0.1 www.freeezinebucks.com #[SiteAdvisor.freeezinebucks.com]
127.0.0.1 freeticketcash.com
127.0.0.1 www.freeticketcash.com
127.0.0.1 www.searchape.com #[Adware.DailyToolbar]
127.0.0.1 www.topsearchdog.com #[Adware.DailyToolbar]
127.0.0.1 bigstoreus.info
127.0.0.1 reddii.org #[Javascript.Exploit]
127.0.0.1 www.wowchian.com #[Win32/PSW.Lineage.DN][W32.Looked.P]
127.0.0.1 ad.wretch.cc
127.0.0.1 adserver.[bleep]aroo.org
127.0.0.1 exchange.ggmedia.ca
127.0.0.1 lustler.com
127.0.0.1 www.lustler.com
127.0.0.1 www.myxratedlinks.com
127.0.0.1 adserver2.n9nedegrees.com
127.0.0.1 www.naughtysaints.com #[Malicious.Content.Zango]
127.0.0.1 sharmanka.info
127.0.0.1 www.sharmanka.info
127.0.0.1 adserver.weakgame.com
127.0.0.1 whoisonline.net
127.0.0.1 www.whoisonline.net
127.0.0.1 katelyn-model.com #[Spamdexing.Codec]
127.0.0.1 little-models.biz #[Malicious.Links.Codec]
127.0.0.1 lolita-models.org #[Spamdexing.Codec]
127.0.0.1 oxcash.com #[SunBelt.OxCash]
127.0.0.1 clicks2.oxcash.com
127.0.0.1 popup.oxcash.com
127.0.0.1 track.oxcash.com
127.0.0.1 exit.oxcash2.com
127.0.0.1 ceporno.com
127.0.0.1 finesexpix.com
127.0.0.1 momsporno.com #[Google.Warning]
127.0.0.1 sexyteenspix.com #[Malicious.Links.Codec]
127.0.0.1 www.sexyteenspix.com
127.0.0.1 zetincest.com
127.0.0.1 antispywarehelp.com
127.0.0.1 www.antispywarehelp.com
127.0.0.1 blacksnake.com
127.0.0.1 www.blacksnake.com #[IRC.Trojan.Fgt]
127.0.0.1 cunnyhoney.com
127.0.0.1 www.cunnyhoney.com
127.0.0.1 cytron.com #[DailyWinner][eTrust.Cytron]
127.0.0.1 www.cytron.com
127.0.0.1 dailyxxvids.com #[Malicious.Links.Codec]
127.0.0.1 www.dailyxxvids.com
127.0.0.1 exoticbaby.us
127.0.0.1 freex3movies.com
127.0.0.1 www.freex3movies.com
127.0.0.1 gaylovetwinks.com #[Malicious.Links]
127.0.0.1 www.gaylovetwinks.com
127.0.0.1 www.hotelmgp.com #[Malicious.Links]
127.0.0.1 jakpot.org #[Trojan.Codec]
127.0.0.1 www.jakpot.org
127.0.0.1 mentolix.info #[Malicious.Links]
127.0.0.1 nudegalleries.org #[Malicious.Links.Codec]
127.0.0.1 www.nudegalleries.org
127.0.0.1 pussybabes.net
127.0.0.1 www.pussybabes.net
127.0.0.1 seosfive.info
127.0.0.1 sexualblondes.net
127.0.0.1 www.sexualblondes.net
127.0.0.1 special-movies.com #[Malicious.Links]
127.0.0.1 spunkyvids.com
127.0.0.1 www.spunkyvids.com #[Malicious.Links.Codec]
127.0.0.1 banners.truecash.com
127.0.0.1 www.vineyteen.com
127.0.0.1 vipmpg.net #[Malicious.Links]
127.0.0.1 winfixmaster.com
127.0.0.1 www.winfixmaster.com
127.0.0.1 nm.xxxeuropean.com
127.0.0.1 xxxnrg.com
127.0.0.1 www.xxxnrg.com #[IFrame.Exploit]
127.0.0.1 zuluzazaee.com #[Spamdexing]
127.0.0.1 advancedhunt.com #[Google Warning]
127.0.0.1 www.advancedhunt.com #[JS/Exploit.IEPageSpoof]
127.0.0.1 www.bestscripting.com
127.0.0.1 www.impliedscripting.com
127.0.0.1 topdatasearch.com
127.0.0.1 www.topdatasearch.com
127.0.0.1 directmovs.com
127.0.0.1 www.directmovs.com
127.0.0.1 [bleep]ergalleries.com
127.0.0.1 www.[bleep]ergalleries.com #[IFrame.Exploit]
127.0.0.1 all3xxx.com #[Malicious.Links]
127.0.0.1 beregs.info #[Google.Warning]
127.0.0.1 xxx.dataseeq.com
127.0.0.1 extremevideoz.net #[Malicious.Links]
127.0.0.1 extreme-tranny.extremevideoz.net #[IFrame.Exploit]
127.0.0.1 freevideo.in #[Malicious.Links.Codec]
127.0.0.1 homevidz.net #[IFrame.Exploit]
127.0.0.1 hot-images.net
127.0.0.1 www.hot-images.net #[Malicious.Links.Codec]
127.0.0.1 lovepic.net #[HTML/TrojanDownloader.XXXToolbar]
127.0.0.1 www.lovepic.net
127.0.0.1 newpornonline.net #[Malicious.Links]
127.0.0.1 pumpherhump.com #[Malicious.Links]
127.0.0.1 russ-girl.biz #[Google.Warning]
127.0.0.1 www.russ-girl.biz
127.0.0.1 saletraffic.info #[Trojan.Codec]
127.0.0.1 searchmeup.biz #[Trojan.Downloader.Small.CML]
127.0.0.1 ads.svnt.com
127.0.0.1 videoweststudio.com #[Malicious.Links.Codec]
127.0.0.1 allsexvids.net
127.0.0.1 www.allsexvids.net #[Malicious.Links]
127.0.0.1 amazing-gals.com
127.0.0.1 www.amazing-gals.com #[Malicious.Links.Codec]
127.0.0.1 bestestporn.com #[Malicious.Links.Codec]
127.0.0.1 bestsexyhairy.com #[Javascript.Exploit]
127.0.0.1 z.dataseeq.com #[Spamdexing]
127.0.0.1 drugs-here.com #[Malicious.Links.Codec]
127.0.0.1 extreme-juggs.com #[Malicious.Links.Codec]
127.0.0.1 www.extreme-juggs.com
127.0.0.1 gobigtits.com #[IFrame.Exploit]
127.0.0.1 www.gobigtits.com
127.0.0.1 www.phallosdei.com #[Malicious.Links]
127.0.0.1 www.sexproper.com #[Malicious.Links]
127.0.0.1 smashingvids.com
127.0.0.1 www.smashingvids.com #[Malicious.Links.Codec]
127.0.0.1 xexexe.info
127.0.0.1 xxxvideossite.com
127.0.0.1 www.xxxvideossite.com #[Malicious.Links.Codec]
127.0.0.1 www.yummyclips.com #[Malicious.Links]
127.0.0.1 page1.adroup.com
127.0.0.1 drunkporn.us
127.0.0.1 funppc.com
127.0.0.1 www.funppc.com
127.0.0.1 jizzmyhole.com #[Malicious.Links]
127.0.0.1 www.jizzmyhole.com
127.0.0.1 www.jsporting.com #[Spamdexing.Codec]
127.0.0.1 pornonavigate.com #[JS/Exploit.IEPageSpoof]
127.0.0.1 www.pornonavigate.com
127.0.0.1 traffchange.com
127.0.0.1 wl.traffchange.com
127.0.0.1 0ml.net
127.0.0.1 b0o.net
127.0.0.1 esearchmaster.info
127.0.0.1 www.enormousdating.com
127.0.0.1 www.giantdating.com #[Spamdexing.adultfriendfinder]
127.0.0.1 www.worlddatinghere.com
127.0.0.1 1-se.com #[CWS.Aboutblank][W32.Tuoba.Trojan]
127.0.0.1 www.1-se.com #[VBS.Startpage.C]
127.0.0.1 ie-search.com #[CWS.Loadbat][umaxsearch.com]
127.0.0.1 www.ie-search.com
127.0.0.1 search-ing.com
127.0.0.1 www.search-ing.com
127.0.0.1 findloss.com #[umaxsearch.com]
127.0.0.1 www.findloss.com
127.0.0.1 www.foxseek.com
127.0.0.1 www.lookuplive.com
127.0.0.1 www.payse.com #[server down?]
127.0.0.1 paysefeed.net
127.0.0.1 searchadv.com
127.0.0.1 www.searchadv.com #[Spamdexing]
127.0.0.1 searchmeup.com #[CWS.Svcinit.3]
127.0.0.1 www.searchmeup.com #[SunBelt.SearchMeUp Hijacker]
127.0.0.1 topadult10.com
127.0.0.1 www.topadult10.com
127.0.0.1 www.topauto10.com #[Spamdexing][Microsoft.Strider]
127.0.0.1 topcasino10.com
127.0.0.1 www.topcasino10.com
127.0.0.1 topmeds10.com
127.0.0.1 www.topmeds10.c
  • 0

#7
Kizzy

Kizzy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
part 3 of Smitfraud report

127.0.0.1 cotriere.it
127.0.0.1 www.cotrriere.it
127.0.0.1 cotrriere.it
127.0.0.1 count.hitscount.net
127.0.0.1 count-all.com
127.0.0.1 www.countdutycall.info
127.0.0.1 countdutycall.info
127.0.0.1 counter.sexmaniack.com
127.0.0.1 www.courtrecordslookup.com
127.0.0.1 courtrecordslookup.com
127.0.0.1 www.cporriere.it
127.0.0.1 cporriere.it
127.0.0.1 www.cprriere.it
127.0.0.1 cprriere.it
127.0.0.1 cpvfeed.com
127.0.0.1 cracks.me.uk
127.0.0.1 www.cracks4all.com
127.0.0.1 cracks4all.com
127.0.0.1 www.crapsgold.info
127.0.0.1 crapsgold.info
127.0.0.1 Crazygirls-world.com
127.0.0.1 www.crazywinnings.com
127.0.0.1 crazywinnings.com
127.0.0.1 creamedcutties.com
127.0.0.1 www.createaccesskey.com
127.0.0.1 createaccesskey.com
127.0.0.1 creditsearchonline.com
127.0.0.1 crestring.com
127.0.0.1 crooder.com
127.0.0.1 www.crriere.it
127.0.0.1 crriere.it
127.0.0.1 www.crystalysmedia.com
127.0.0.1 crystalysmedia.com
127.0.0.1 www.csx.adservs.com
127.0.0.1 www.cuisinartoven.com
127.0.0.1 cuisinartoven.com
127.0.0.1 www.curedc.info
127.0.0.1 curedc.info
127.0.0.1 www.curepcsolutions.com
127.0.0.1 curepcsolutions.com
127.0.0.1 curvedspaces.com
127.0.0.1 www.cvirgilio.it
127.0.0.1 cvirgilio.it
127.0.0.1 www.cvorriere.it
127.0.0.1 cvorriere.it
127.0.0.1 cvs.jps.ru
127.0.0.1 cvsymphony.com
127.0.0.1 www.cxorriere.it
127.0.0.1 cxorriere.it
127.0.0.1 www.cyberrape.com
127.0.0.1 cyberrape.com
127.0.0.1 cydom.com
127.0.0.1 daily-gals.com
127.0.0.1 dailykeys.com
127.0.0.1 www.dailypornmag.com
127.0.0.1 dailypornmag.com
127.0.0.1 dailyteenspic.com
127.0.0.1 www.dailytoolbar.com
127.0.0.1 dailytoolbar.com
127.0.0.1 www.dailyxvids.com
127.0.0.1 dailyxvids.com
127.0.0.1 dancingbabycd.com
127.0.0.1 www.dapsol.com
127.0.0.1 dapsol.com
127.0.0.1 www.data-hoster.com
127.0.0.1 data-hoster.com
127.0.0.1 datanotary.com
127.0.0.1 datareco.com
127.0.0.1 www.dateanybabe.com
127.0.0.1 dateanybabe.com
127.0.0.1 www.dateanychick.com
127.0.0.1 dateanychick.com
127.0.0.1 www.datingdoctorsite.com
127.0.0.1 datingdoctorsite.com
127.0.0.1 www.dating-galaxy.info
127.0.0.1 dating-galaxy.info
127.0.0.1 dating-search.net
127.0.0.1 davemarshall.org
127.0.0.1 db105.com
127.0.0.1 www.dbdecicated.com
127.0.0.1 dbdecicated.com
127.0.0.1 www.dbxcompany.com
127.0.0.1 dbxcompany.com
127.0.0.1 dcdl.dmcast.com
127.0.0.1 dcfitusa.com
127.0.0.1 www.dcorriere.it
127.0.0.1 dcorriere.it
127.0.0.1 www.dcurtis.com
127.0.0.1 dcurtis.com
127.0.0.1 de.ag
127.0.0.1 de.drivecleaner.com
127.0.0.1 de98.remsys.org
127.0.0.1 www.debay.it
127.0.0.1 debay.it
127.0.0.1 www.decknews.com
127.0.0.1 decknews.com
127.0.0.1 dedmazay.3322.org
127.0.0.1 www.dedsearch.com
127.0.0.1 dedsearch.com
127.0.0.1 defaultsearch.net
127.0.0.1 www.Defensaantimalware.com
127.0.0.1 Defensaantimalware.com
127.0.0.1 www.deja-rue.com
127.0.0.1 deja-rue.com
127.0.0.1 www.delficodec.com
127.0.0.1 www.democodec.com
127.0.0.1 www.derklaif.biz
127.0.0.1 derklaif.biz
127.0.0.1 www.derrari.it
127.0.0.1 derrari.it
127.0.0.1 desarrollocreativo.com
127.0.0.1 www.deskbar.worldtostart.com
127.0.0.1 deskbar.worldtostart.com
127.0.0.1 www.destruktor.to.pl
127.0.0.1 destruktor.to.pl
127.0.0.1 www.detectivehound.com
127.0.0.1 detectivehound.com
127.0.0.1 www.detectivesearches.com
127.0.0.1 detectivesearches.com
127.0.0.1 dev.ntcor.com
127.0.0.1 develip.com
127.0.0.1 dewis.spb.ru
127.0.0.1 dewis.us
127.0.0.1 df809jow4wj2304lfd0sf9fsd0a2t4ldf809jow4wj2304lfd0sf9fsd0a2t4ld.biz
127.0.0.1 www.dgbusiness.com
127.0.0.1 dgbusiness.com
127.0.0.1 dialer2004.com
127.0.0.1 www.dialerclub.com
127.0.0.1 dialerclub.com
127.0.0.1 www.dialer-shop.com
127.0.0.1 dialer-shop.com
127.0.0.1 www.dialoff.com
127.0.0.1 dialoff.com
127.0.0.1 www.did.i-used.cc
127.0.0.1 did.i-used.cc
127.0.0.1 dietpills4free.com
127.0.0.1 dietpussy.com
127.0.0.1 www.digikeygen.com
127.0.0.1 digikeygen.com
127.0.0.1 digistreamsa.com
127.0.0.1 www.digitalcoders.net
127.0.0.1 digitalcoders.net
127.0.0.1 www.digitalfan.com
127.0.0.1 digital-pornography.com
127.0.0.1 dionforvalleycouncil.org
127.0.0.1 www.directdvdpro.com
127.0.0.1 directdvdpro.com
127.0.0.1 www.directporta.info
127.0.0.1 directporta.info
127.0.0.1 directsearchzone.com
127.0.0.1 www.diskretter.com
127.0.0.1 diskretter.com
127.0.0.1 dl.ad-ware.cc
127.0.0.1 dl.malwarewipe.com
127.0.0.1 www.dl.targetsaver.com
127.0.0.1 dl10.spyfalcon.com
127.0.0.1 dl16.spyfalcon.com
127.0.0.1 dl2.spyfalcon.com
127.0.0.1 dl2.spyheal.com
127.0.0.1 dl2.spywarestrike.com
127.0.0.1 dl3.spyfalcon.com
127.0.0.1 dl3.spyheal.com
127.0.0.1 dl3.spywarestrike.com
127.0.0.1 dl4.spyfalcon.com
127.0.0.1 dl4.spywarestrike.com
127.0.0.1 dl5.spyfalcon.com
127.0.0.1 dl5.spywarestrike.com
127.0.0.1 dl6.spywarestrike.com
127.0.0.1 dl7.spywarestrike.com
127.0.0.1 dl8.spyheal.com
127.0.0.1 dl8.spywarestrike.com
127.0.0.1 dl9.spyfalcon.com
127.0.0.1 dload.contextplus.net
127.0.0.1 www.dltsolution.com
127.0.0.1 dltsolution.com
127.0.0.1 www.dmcast.com
127.0.0.1 dmcast.com
127.0.0.1 www.dmqfirm.com
127.0.0.1 dmqfirm.com
127.0.0.1 www.dnaads.com
127.0.0.1 dnaads.com
127.0.0.1 dnl.mabou.org
127.0.0.1 www.dns-look-up.com
127.0.0.1 doctorwaldron.com
127.0.0.1 document-not-found.pornpic.org
127.0.0.1 doggyaction.com
127.0.0.1 www.dogproblemswebsite.com
127.0.0.1 dogproblemswebsite.com
127.0.0.1 doktorxxx.com
127.0.0.1 dollarrevenue.com
127.0.0.1 www.domaincar.com
127.0.0.1 domaincar.com
127.0.0.1 domains2003.net
127.0.0.1 domains-for-you-online.com
127.0.0.1 domain-your-registration.com
127.0.0.1 domkrat.com
127.0.0.1 www.dotcomtoolbar.com
127.0.0.1 dotcomtoolbar.com
127.0.0.1 down.136136.net
127.0.0.1 download.abetterinternet.com
127.0.0.1 www.download.antispywarebot.com
127.0.0.1 www.download.bardownload.com
127.0.0.1 www.download.bravesentry.com
127.0.0.1 download.cdn.drivecleaner.com
127.0.0.1 download.cdn.errorsafe.com
127.0.0.1 download.contextplus.net
127.0.0.1 www.download.jupitersatellites.biz
127.0.0.1 download.jupitersatellites.biz
127.0.0.1 download.MalwareAlarm.com
127.0.0.1 download.searchtabs.net
127.0.0.1 www.download.secureyournet.biz
127.0.0.1 download.secureyournet.biz
127.0.0.1 download.spy-shredder.com
127.0.0.1 download.winantivirus.com
127.0.0.1 download.winfixer.com
127.0.0.1 download10.spywarequake.com
127.0.0.1 download11.spywarequake.com
127.0.0.1 download12.spywarequake.com
127.0.0.1 download13.spywarequake.com
127.0.0.1 download15.spywarequake.com
127.0.0.1 download2.spywarequake.com
127.0.0.1 www.download-2007.com
127.0.0.1 download-2007.com
127.0.0.1 download3.spyaxe.com
127.0.0.1 download3.spywarequake.com
127.0.0.1 www.download3xpics.com
127.0.0.1 download3xpics.com
127.0.0.1 download4.spyaxe.com
127.0.0.1 download4.spywarequake.com
127.0.0.1 download5.spyaxe.com
127.0.0.1 download5.spywarequake.com
127.0.0.1 download6.spyaxe.com
127.0.0.1 download7.spywarequake.com
127.0.0.1 download8.spywarequake.com
127.0.0.1 download9.spywarequake.com
127.0.0.1 www.downloadacceleratorsite.com
127.0.0.1 downloadacceleratorsite.com
127.0.0.1 www.download-ad-aware.com
127.0.0.1 download-ad-aware.com
127.0.0.1 www.download-all-4-free.com
127.0.0.1 download-all-4-free.com
127.0.0.1 www.download-all-area.com
127.0.0.1 download-all-area.com
127.0.0.1 www.download-antivir.com
127.0.0.1 download-antivir.com
127.0.0.1 www.downloadanysong.com
127.0.0.1 downloadanysong.com
127.0.0.1 www.downloadaresnow.com
127.0.0.1 downloadaresnow.com
127.0.0.1 www.download-avast.com
127.0.0.1 download-avast.com
127.0.0.1 www.downloadcorporation.com
127.0.0.1 downloadcorporation.com
127.0.0.1 www.download-dvdshrink.com
127.0.0.1 download-dvdshrink.com
127.0.0.1 www.download-for-free.net
127.0.0.1 download-for-free.net
127.0.0.1 www.downloadfreesoft.com
127.0.0.1 downloadfreesoft.com
127.0.0.1 www.downloadfreeway.com
127.0.0.1 downloadfreeway.com
127.0.0.1 www.downloadimesh.com
127.0.0.1 downloadimesh.com
127.0.0.1 www.download-itunes-now.com
127.0.0.1 download-itunes-now.com
127.0.0.1 www.download-limewire.org
127.0.0.1 download-limewire.org
127.0.0.1 www.downloadlost.tv
127.0.0.1 downloadlost.tv
127.0.0.1 www.downloadmax.net
127.0.0.1 downloadmax.net
127.0.0.1 www.download-mcafee.com
127.0.0.1 download-mcafee.com
127.0.0.1 download-me.info
127.0.0.1 www.downloadmediaax.com
127.0.0.1 downloadmediaax.com
127.0.0.1 www.downloadpics.net
127.0.0.1 downloadpics.net
127.0.0.1 www.downloadprovider.net
127.0.0.1 downloadprovider.net
127.0.0.1 www.download-real-player.com
127.0.0.1 download-real-player.com
127.0.0.1 downloads.180solutions.com
127.0.0.1 downloads.adaware.cc
127.0.0.1 www.downloadservicearea.com
127.0.0.1 downloadservicearea.com
127.0.0.1 www.downloads-free.org
127.0.0.1 downloads-free.org
127.0.0.1 www.downloadsglobe.com
127.0.0.1 downloadsglobe.com
127.0.0.1 www.download-this.us
127.0.0.1 download-this.us
127.0.0.1 www.download-trillian.com
127.0.0.1 download-trillian.com
127.0.0.1 www.downloadv3.com
127.0.0.1 downloadv3.com
127.0.0.1 www.downloadvax.com
127.0.0.1 downloadvax.com
127.0.0.1 www.download-windvd.com
127.0.0.1 download-windvd.com
127.0.0.1 www.download-winrar.com
127.0.0.1 download-winrar.com
127.0.0.1 downloadwizard.com
127.0.0.1 www.downloadxmoveis.com
127.0.0.1 downloadxmoveis.com
127.0.0.1 www.downloadxvids.com
127.0.0.1 downloadxvids.com
127.0.0.1 downloadzcenter.com
127.0.0.1 downloadzcentral.com
127.0.0.1 www.downloadzfree.com
127.0.0.1 downloadzfree.com
127.0.0.1 downloadznow.net
127.0.0.1 www.download-zone-free.com
127.0.0.1 download-zone-free.com
127.0.0.1 www.download-zone-free.net
127.0.0.1 download-zone-free.net
127.0.0.1 dp-host.com
127.0.0.1 www.dr.webhancer.com
127.0.0.1 dr.webhancer.com
127.0.0.1 www.dr2.webhancer.com
127.0.0.1 dr47.mcboo.com
127.0.0.1 dragqueen.gay-clan.com
127.0.0.1 www.drepubblica.it
127.0.0.1 drepubblica.it
127.0.0.1 www.drivecleanr.com
127.0.0.1 drivecleanr.com
127.0.0.1 drocherway.com
127.0.0.1 dropspam.com
127.0.0.1 drug-sources-exposed.com
127.0.0.1 drvvv.com
127.0.0.1 www.dsupereva.it
127.0.0.1 dsupereva.it
127.0.0.1 www.dtlproduct.com
127.0.0.1 dtlproduct.com
127.0.0.1 dudu.com
127.0.0.1 dulcineasystems.net
127.0.0.1 dumpserv.com
127.0.0.1 duolaimi.net
127.0.0.1 dutch-sex.com
127.0.0.1 www.dvdaccess.net
127.0.0.1 dvdaccess.net
127.0.0.1 dvdbank.org
127.0.0.1 www.dvdcodec.net
127.0.0.1 dvdcodec.net
127.0.0.1 www.dvdsmovies.net
127.0.0.1 dvdsmovies.net
127.0.0.1 www.dvdsvideos.net
127.0.0.1 dvdsvideos.net
127.0.0.1 www.dvdtocdsite.com
127.0.0.1 dvdtocdsite.com
127.0.0.1 www.dvdxgold.com
127.0.0.1 dvdxgold.com
127.0.0.1 www.dvdxpremium.com
127.0.0.1 dvdxpremium.com
127.0.0.1 www.dvicodec.com
127.0.0.1 dvicodec.com
127.0.0.1 www.e3bay.it
127.0.0.1 e3bay.it
127.0.0.1 www.e4bay.it
127.0.0.1 e4bay.it
127.0.0.1 eager-sex.com
127.0.0.1 www.earthllnk.net
127.0.0.1 earthllnk.net
127.0.0.1 eases.net
127.0.0.1 www.easybestdeals.com
127.0.0.1 easybestdeals.com
127.0.0.1 easycategories.com
127.0.0.1 www.easycdrip.com
127.0.0.1 easycdrip.com
127.0.0.1 www.easymovieplayer.com
127.0.0.1 easymovieplayer.com
127.0.0.1 www.easymp3musicnow.com
127.0.0.1 easymp3musicnow.com
127.0.0.1 www.easymus.cn
127.0.0.1 easymus.cn
127.0.0.1 www.easy-pharmacy.info
127.0.0.1 easy-pharmacy.info
127.0.0.1 www.easypspdownloads.com
127.0.0.1 easypspdownloads.com
127.0.0.1 easy-search.net
127.0.0.1 www.easyspyware.com
127.0.0.1 easyspyware.com
127.0.0.1 www.easywww.info
127.0.0.1 easywww.info
127.0.0.1 www.eba6y.it
127.0.0.1 eba6y.it
127.0.0.1 www.eba7y.it
127.0.0.1 eba7y.it
127.0.0.1 www.ebaay.it
127.0.0.1 ebaay.it
127.0.0.1 www.ebagy.it
127.0.0.1 ebagy.it
127.0.0.1 www.ebahy.it
127.0.0.1 ebahy.it
127.0.0.1 www.ebajy.it
127.0.0.1 ebajy.it
127.0.0.1 www.ebaqy.it
127.0.0.1 ebaqy.it
127.0.0.1 www.ebasy.it
127.0.0.1 ebasy.it
127.0.0.1 www.ebaty.it
127.0.0.1 ebaty.it
127.0.0.1 www.ebauy.it
127.0.0.1 ebauy.it
127.0.0.1 ebav.com
127.0.0.1 ebaw.com
127.0.0.1 www.ebawy.it
127.0.0.1 ebawy.it
127.0.0.1 www.ebaxy.it
127.0.0.1 ebaxy.it
127.0.0.1 www.ebay6.it
127.0.0.1 ebay6.it
127.0.0.1 www.ebay7.it
127.0.0.1 ebay7.it
127.0.0.1 www.ebayg.it
127.0.0.1 ebayg.it
127.0.0.1 www.ebayh.it
127.0.0.1 ebayh.it
127.0.0.1 www.ebayj.it
127.0.0.1 ebayj.it
127.0.0.1 www.ebayt.it
127.0.0.1 ebayt.it
127.0.0.1 www.ebayu.it
127.0.0.1 ebayu.it
127.0.0.1 www.ebazy.it
127.0.0.1 ebazy.it
127.0.0.1 ebch.com
127.0.0.1 ebdv.com
127.0.0.1 ebdw.com
127.0.0.1 www.ebestfind.org
127.0.0.1 ebestfind.org
127.0.0.1 www.ebgay.it
127.0.0.1 ebgay.it
127.0.0.1 ebgo.com
127.0.0.1 www.ebhay.it
127.0.0.1 ebhay.it
127.0.0.1 ebjp.com
127.0.0.1 ebkb.com
127.0.0.1 ebkn.com
127.0.0.1 ebky.com
127.0.0.1 eblv.com
127.0.0.1 ebmu.com
127.0.0.1 www.ebnay.it
127.0.0.1 ebnay.it
127.0.0.1 ebonypornmag.com
127.0.0.1 www.ebonypornmag.com
127.0.0.1 ebony-pornmag.com
127.0.0.1 www.ebony-pornmag.com
127.0.0.1 www.ebqay.it
127.0.0.1 ebqay.it
127.0.0.1 www.ebsay.it
127.0.0.1 ebsay.it
127.0.0.1 www.ebsy.it
127.0.0.1 ebsy.it
127.0.0.1 www.ebvay.it
127.0.0.1 ebvay.it
127.0.0.1 ebvr.com
127.0.0.1 www.ebway.it
127.0.0.1 ebway.it
127.0.0.1 www.ebwmanufacture.com
127.0.0.1 ebwmanufacture.com
127.0.0.1 www.ebxay.it
127.0.0.1 ebxay.it
127.0.0.1 www.ebzay.it
127.0.0.1 ebzay.it
127.0.0.1 www.echterschutz.com
127.0.0.1 echterschutz.com
127.0.0.1 ecmh.com
127.0.0.1 ecmp.com
127.0.0.1 ecosrioplatenses.org
127.0.0.1 ecstasyporn.net
127.0.0.1 ecwz.com
127.0.0.1 ecyb.com
127.0.0.1 www.edbay.it
127.0.0.1 edbay.it
127.0.0.1 edhq.com
127.0.0.1 www.edietprogram.com
127.0.0.1 edietprogram.com
127.0.0.1 edty.com
127.0.0.1 eduy.com
127.0.0.1 www.eebay.it
127.0.0.1 eebay.it
127.0.0.1 eeev.com
127.0.0.1 www.eepubblica.it
127.0.0.1 eepubblica.it
127.0.0.1 www.efbay.it
127.0.0.1 efbay.it
127.0.0.1 www.efcsoftware.com
127.0.0.1 efcsoftware.com
127.0.0.1 www.egbay.it
127.0.0.1 egbay.it
127.0.0.1 www.ehbay.it
127.0.0.1 ehbay.it
127.0.0.1 eikokoike.com
127.0.0.1 www.elitecodec.com
127.0.0.1 elitecodec.com
127.0.0.1 e-localad.com
127.0.0.1 www.elseif.biz
127.0.0.1 elseif.biz
127.0.0.1 www.emailicon.org
127.0.0.1 emailicon.org
127.0.0.1 emch.com
127.0.0.1 www.emcodec.com
127.0.0.1 emcodec.com
127.0.0.1 www.emediacodec.com
127.0.0.1 emediacodec.com
127.0.0.1 www.e-mp3now.com
127.0.0.1 e-mp3now.com
127.0.0.1 www.emule.click-new-download.com
127.0.0.1 emule.click-new-download.com
127.0.0.1 www.emule.mp3-muzic.com
127.0.0.1 emule.mp3-muzic.com
127.0.0.1 www.emuledownloadhome.com
127.0.0.1 emuledownloadhome.com
127.0.0.1 www.emule-freebie.com
127.0.0.1 emule-freebie.com
127.0.0.1 www.enay.it
127.0.0.1 enay.it
127.0.0.1 www.enbay.it
127.0.0.1 enbay.it
127.0.0.1 www.endcodec.com
127.0.0.1 www.energy-factor.com
127.0.0.1 energy-factor.com
127.0.0.1 www.engineplay.com
127.0.0.1 engineplay.com
127.0.0.1 www.engine-ticket.com
127.0.0.1 engine-ticket.com
127.0.0.1 enhance.com
127.0.0.1 www.enhancevideos.com
127.0.0.1 enhancevideos.com
127.0.0.1 enitinvest.net
127.0.0.1 www.entertainsite.net
127.0.0.1 entertainsite.net
127.0.0.1 enterthesearch.com
127.0.0.1 www.entirexxx.com
127.0.0.1 entirexxx.com
127.0.0.1 envolo.peopleonpage.com
127.0.0.1 e-plus.cc
127.0.0.1 epornsex.com
127.0.0.1 www.eprotectpage.com
127.0.0.1 eprotectpage.com
127.0.0.1 www.erbay.it
127.0.0.1 erbay.it
127.0.0.1 www.erepubblica.it
127.0.0.1 erepubblica.it
127.0.0.1 ergosites.com
127.0.0.1 www.erossoalice.it
127.0.0.1 erossoalice.it
127.0.0.1 www.errari.it
127.0.0.1 errari.it
127.0.0.1 errclean.com
127.0.0.1 www.error404site.com
127.0.0.1 error404site.com
127.0.0.1 www.error404site.net
127.0.0.1 error404site.net
127.0.0.1 www.errorfri.com
127.0.0.1 errorfri.com
127.0.0.1 www.errorout.com
127.0.0.1 errorout.com
127.0.0.1 www.errorsdns.com
127.0.0.1 errorsdns.com
127.0.0.1 www.errorskydd.com
127.0.0.1 errorskydd.com
127.0.0.1 www.errorsoshi.com
127.0.0.1 errorsoshi.com
127.0.0.1 errorsweeper.com
127.0.0.1 ert0003.e76.163ns.com
127.0.0.1 ert47.a1.wrs.mcboo.com
127.0.0.1 www.ertikadeswiokinganfujas.com
127.0.0.1 ertikadeswiokinganfujas.com
127.0.0.1 es0-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es1-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es2-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es3-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es4-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es5-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es6-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es7-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es8-www.5zgmu7o20kt5d8yq.com
127.0.0.1 es9-www.5zgmu7o20kt5d8yq.com
127.0.0.1 www.esafetypage.com
127.0.0.1 esafetypage.com
127.0.0.1 www.esbay.it
127.0.0.1 esbay.it
127.0.0.1 esearch2005.com
127.0.0.1 www.esecuritypage.com
127.0.0.1 esecuritypage.com
127.0.0.1 www.esupereva.it
127.0.0.1 esupereva.it
127.0.0.1 www.etomi.all-downloads-now.com
127.0.0.1 etomi.all-downloads-now.com
127.0.0.1 www.eupdatepage.com
127.0.0.1 eupdatepage.com
127.0.0.1 euuu.com
127.0.0.1 www.evbay.it
127.0.0.1 evbay.it
127.0.0.1 evidence-detector.biz
127.0.0.1 evilspidercomics.com
127.0.0.1 www.evko.biz
127.0.0.1 evko.biz
127.0.0.1 www.ewbay.it
127.0.0.1 ewbay.it
127.0.0.1 ewebsearch.net
127.0.0.1 e-websitesolutions.com
127.0.0.1 www.exaccess.ru
127.0.0.1 exaccess.ru
127.0.0.1 excellentsckin.com
127.0.0.1 www.exclusivexxxclips.com
127.0.0.1 exclusivexxxclips.com
127.0.0.1 www.exeupdate.com
127.0.0.1 exeupdate.com
127.0.0.1 www.exflow.org
127.0.0.1 exflow.org
127.0.0.1 www.expandvideo.com
127.0.0.1 expandvideo.com
127.0.0.1 www.exportplay.com
127.0.0.1 exportplay.com
127.0.0.1 www.extremepaidsurveys.com
127.0.0.1 extremepaidsurveys.com
127.0.0.1 extremeseek.net
127.0.0.1 www.ezcybersearch.com
127.0.0.1 ezcybersearch.com
127.0.0.1 www.ezdvdx.com
127.0.0.1 ezdvdx.com
127.0.0.1 ez-searching.com
127.0.0.1 ezwebsearching.com
127.0.0.1 www.ezycontract.com
127.0.0.1 ezycontract.com
127.0.0.1 f0.thezirius.com
127.0.0.1 f1.bestmanage.org
127.0.0.1 f1.thezirius.com
127.0.0.1 f1.truth-is-out-there.org
127.0.0.1 www.f1organizer.com
127.0.0.1 f1organizer.com
127.0.0.1 f2.bestmanage.org
127.0.0.1 f2.thezirius.com
127.0.0.1 f3.bestmanage.org
127.0.0.1 f3.thezirius.com
127.0.0.1 f3.truth-is-out-there.org
127.0.0.1 f4.bestmanage.org
127.0.0.1 f4.thezirius.com
127.0.0.1 f4.truth-is-out-there.org
127.0.0.1 f5.bestmanage.org
127.0.0.1 f5.thezirius.com
127.0.0.1 f5.truth-is-out-there.org
127.0.0.1 f6.bestmanage.org
127.0.0.1 f6.thezirius.com
127.0.0.1 f7.bestmanage.org
127.0.0.1 f7.thezirius.com
127.0.0.1 f7.truth-is-out-there.org
127.0.0.1 f8.bestmanage.org
127.0.0.1 f8.thezirius.com
127.0.0.1 f8.truth-is-out-there.org
127.0.0.1 f9.bestmanage.org
127.0.0.1 f9.thezirius.com
127.0.0.1 f9.truth-is-out-there.org
127.0.0.1 www.fairsearcher.com
127.0.0.1 fairsearcher.com
127.0.0.1 faithstevens.com
127.0.0.1 fantasiewelten.com
127.0.0.1 farmacept32.phpnet.us
127.0.0.1 farmsteadbandb.com
127.0.0.1 farse.com
127.0.0.1 fartpost.com
127.0.0.1 fastfreedownload.com
127.0.0.1 www.fastmetasearch.com
127.0.0.1 fastmetasearch.com
127.0.0.1 www.fastmp.net
127.0.0.1 fastmp.net
127.0.0.1 www.fastpspdownloads.com
127.0.0.1 fastpspdownloads.com
127.0.0.1 www.fastssearch.com
127.0.0.1 fastssearch.com
127.0.0.1 www.fasttvdownloads.com
127.0.0.1 fasttvdownloads.com
127.0.0.1 fastwebfinder.com
127.0.0.1 faxporn.com
127.0.0.1 www.fazzetta.it
127.0.0.1 fazzetta.it
127.0.0.1 www.fcorriere.it
127.0.0.1 fcorriere.it
127.0.0.1 featured-results.com
127.0.0.1 www.febay.it
127.0.0.1 febay.it
127.0.0.1 feed.dedsearch.com
127.0.0.1 www.feeds.2search.com
127.0.0.1 feeds.2search.com
127.0.0.1 www.feeds2.2search.org
127.0.0.1 www.ferraeri.it
127.0.0.1 ferraeri.it
127.0.0.1 www.ferrai.it
127.0.0.1 ferrai.it
127.0.0.1 www.ferrarei.it
127.0.0.1 ferrarei.it
127.0.0.1 www.ferrarti.it
127.0.0.1 ferrarti.it
127.0.0.1 www.ferrasri.it
127.0.0.1 ferrasri.it
127.0.0.1 www.ferratri.it
127.0.0.1 ferratri.it
127.0.0.1 www.ferreari.it
127.0.0.1 ferreari.it
127.0.0.1 www.ferrri.it
127.0.0.1 ferrri.it
127.0.0.1 www.ferrsari.it
127.0.0.1 ferrsari.it
127.0.0.1 www.ferrtari.it
127.0.0.1 ferrtari.it
127.0.0.1 www.fetrrari.it
127.0.0.1 fetrrari.it
127.0.0.1 www.fgazzetta.it
127.0.0.1 fgazzetta.it
127.0.0.1 www.fgoogle.it
127.0.0.1 fgoogle.it
127.0.0.1 fhg.panet.org
127.0.0.1 www.fhgate.com
127.0.0.1 fhgate.com
127.0.0.1 fickenisgeil.de
127.0.0.1 www.fidoproblems.com
127.0.0.1 fidoproblems.com
127.0.0.1 www.fiksfeil.com
127.0.0.1 fiksfeil.com
127.0.0.1 file.qqhelper.com
127.0.0.1 file.unionsms.net
127.0.0.1 file0.qqhelper.com
127.0.0.1 file1.qqhelper.com
127.0.0.1 file2.qqhelper.com
127.0.0.1 file3.qqhelper.com
127.0.0.1 file4.qqhelper.com
127.0.0.1 file5.qqhelper.com
127.0.0.1 file6.qqhelper.com
127.0.0.1 file7.qqhelper.com
127.0.0.1 file8.qqhelper.com
127.0.0.1 file9.qqhelper.com
127.0.0.1 fileprotector.com
127.0.0.1 www.filesharing-downloads.com
127.0.0.1 filesharing-downloads.com
127.0.0.1 www.filetretporn.com
127.0.0.1 filetretporn.com
127.0.0.1 www.filevoom.com
127.0.0.1 filevoom.com
127.0.0.1 www.Filtrodetrojan.com
127.0.0.1 Filtrodetrojan.com
127.0.0.1 www.finalfantasyactionfigures.com
127.0.0.1 finalfantasyactionfigures.com
127.0.0.1 finance-loans.com
127.0.0.1 find4u.net
127.0.0.1 www.find-52.com
127.0.0.1 find-52.com
127.0.0.1 www.findanyshow.org
127.0.0.1 findanyshow.org
127.0.0.1 www.find-find-777.net
127.0.0.1 find-find-777.net
127.0.0.1 find-itnow.com
127.0.0.1 findit-now.com
127.0.0.1 www.finditquick.com
127.0.0.1 finditquick.com
127.0.0.1 findthesite.com
127.0.0.1 find-uk-health.co.uk
127.0.0.1 www.findwapsite.org
127.0.0.1 findwapsite.org
127.0.0.1 fined.biz
127.0.0.1 fionasteel.com
127.0.0.1 www.firefoxdownload-now.com
127.0.0.1 firefoxdownload-now.com
127.0.0.1 www.firehunt.com
127.0.0.1 firehunt.com
127.0.0.1 www.firewallgold.com
127.0.0.1 firewallgold.com
127.0.0.1 www.firewallprotectionpro.com
127.0.0.1 firewallprotectionpro.com
127.0.0.1 www.firewallprotectionsite.com
127.0.0.1 firewallprotectionsite.com
127.0.0.1 www.firewallprotector.com
127.0.0.1 firewallprotector.com
127.0.0.1 www.firgilio.it
127.0.0.1 firgilio.it
127.0.0.1 firstbookmark.net
127.0.0.1 firstgoodsearch.com
127.0.0.1 fitness-free.com
127.0.0.1 www.fixerantispy.com
127.0.0.1 fixerantispy.com
127.0.0.1 www.fjsynebcod.com
127.0.0.1 fjsynebcod.com
127.0.0.1 flashflashmx.3322.org
127.0.0.1 www.floorsovertexas.com
127.0.0.1 floorsovertexas.com
127.0.0.1 www.floproject.com
127.0.0.1 floproject.com
127.0.0.1 flrxtools.greatnuke.com
127.0.0.1 www.flrx-tools.net
127.0.0.1 flrx-tools.net
127.0.0.1 www.fn777.greatbahamas.com
127.0.0.1 fn777.greatbahamas.com
127.0.0.1 foodvacations.net
127.0.0.1 forex.jps.ru
127.0.0.1 forexcredit.com
127.0.0.1 forexcredit.ru
127.0.0.1 formingfusions.com
127.0.0.1 www.forseo.com
127.0.0.1 forseo.com
127.0.0.1 forsythfire.net
127.0.0.1 forthline.com
127.0.0.1 www.foxmin.com
127.0.0.1 foxmin.com
127.0.0.1 fp.outerinfo.net
127.0.0.1 www.fr.drivecleaner.com
127.0.0.1 fr.drivecleaner.com
127.0.0.1 fr.winfixer.com
127.0.0.1 frame.crazywinnings.com
127.0.0.1 www.free3xclips.com
127.0.0.1 free3xclips.com
127.0.0.1 free4porno.net
127.0.0.1 free64all.com
127.0.0.1 www.free-adobe-download-support.com
127.0.0.1 free-adobe-download-support.com
127.0.0.1 www.free-avg.org
127.0.0.1 free-avg.org
127.0.0.1 www.free-avg-download.com
127.0.0.1 free-avg-download.com
127.0.0.1 www.free-bearshares.com
127.0.0.1 free-bearshares.com
127.0.0.1 freebookmark.net
127.0.0.1 freebookmarks.net
127.0.0.1 www.freecat.biz
127.0.0.1 freecat.biz
127.0.0.1 freecategories.com
127.0.0.1 free-chipes.com
127.0.0.1 freecj.com
127.0.0.1 www.freeclipoftheday.com
127.0.0.1 freeclipoftheday.com
127.0.0.1 freecoolhost.com
127.0.0.1 freedownloadhq.com
127.0.0.1 www.freedownloadpage.com
127.0.0.1 freedownloadpage.com
127.0.0.1 www.free-download-place.com
127.0.0.1 free-download-place.com
127.0.0.1 www.free-download-support.com
127.0.0.1 free-download-support.com
127.0.0.1 www.freedownloadzone.com
127.0.0.1 freedownloadzone.com
127.0.0.1 www.free[bleep]movs.com
127.0.0.1 free[bleep]movs.com
127.0.0.1 free-hit.com
127.0.0.1 freehqmovies.com
127.0.0.1 www.freeimageheaven.com
127.0.0.1 freeimageheaven.com
127.0.0.1 www.freemp3access.com
127.0.0.1 freemp3access.com
127.0.0.1 www.free-music-network.com
127.0.0.1 free-music-network.com
127.0.0.1 free-pics-and-movies.com
127.0.0.1 www.free-popup-killer.com
127.0.0.1 free-popup-killer.com
127.0.0.1 www.free-program-download.com
127.0.0.1 free-program-download.com
127.0.0.1 freerbhost.com
127.0.0.1 freescratchandwin.com
127.0.0.1 free-sex-movie-clips.net
127.0.0.1 freeshemalepics.net
127.0.0.1 www.free-software-center.com
127.0.0.1 free-software-center.com
127.0.0.1 www.free-spybot.com
127.0.0.1 free-spybot.com
127.0.0.1 www.freeunlimitedskype.com
127.0.0.1 freeunlimitedskype.com
127.0.0.1 freeyaho.com
127.0.0.1 fregat.drocherway.com
127.0.0.1 www.frepubblica.it
127.0.0.1 frepubblica.it
127.0.0.1 freshseek.com
127.0.0.1 freshteensite.com
127.0.0.1 fric.cn
127.0.0.1 www.frostwire.click-new-download.com
127.0.0.1 frostwire.click-new-download.com
127.0.0.1 www.frrari.it
127.0.0.1 frrari.it
127.0.0.1 www.frrrari.it
127.0.0.1 frrrari.it
127.0.0.1 www.ftiscali.it
127.0.0.1 ftiscali.it
127.0.0.1 www.ftrenitalia.it
127.0.0.1 ftrenitalia.it
127.0.0.1 www.ftuttogratis.it
127.0.0.1 ftuttogratis.it
127.0.0.1 www.fullmusicdownload.com
127.0.0.1 fullmusicdownload.com
127.0.0.1 www.fullpaidsurveys.com
127.0.0.1 fullpaidsurveys.com
127.0.0.1 www.fullsoftwarecenter.com
127.0.0.1 fullsoftwarecenter.com
127.0.0.1 www.fullsoftwaredownloadz.com
127.0.0.1 fullsoftwaredownloadz.com
127.0.0.1 full-tgp.net
127.0.0.1 www.fulltimevideos.com
127.0.0.1 fulltimevideos.com
127.0.0.1 www.fulltvdownloading.com
127.0.0.1 fulltvdownloading.com
127.0.0.1 www.funcodec.com
127.0.0.1 funcodec.com
127.0.0.1 funny-girls.com
127.0.0.1 www.funnysuperxxx.com
127.0.0.1 funnysuperxxx.com
127.0.0.1 www.fun-photo.com
127.0.0.1 fun-photo.com
127.0.0.1 www.fvirgilio.it
127.0.0.1 fvirgilio.it
127.0.0.1 www.fwrrari.it
127.0.0.1 fwrrari.it
127.0.0.1 www.g0oogle.it
127.0.0.1 g0oogle.it
127.0.0.1 www.g9oogle.it
127.0.0.1 g9oogle.it
127.0.0.1 ga31.com
127.0.0.1 www.gaazzetta.it
127.0.0.1 gaazzetta.it
127.0.0.1 gabrielscott.com
127.0.0.1 gad-network.com
127.0.0.1 galpostgirls.com
127.0.0.1 gals-for-free.com
127.0.0.1 gambling-online4you.com
127.0.0.1 www.game4all.biz
127.0.0.1 game4all.biz
127.0.0.1 www.games.de.ag
127.0.0.1 games-desktop.com
127.0.0.1 gameterror.net
127.0.0.1 www.gaqzzetta.it
127.0.0.1 gaqzzetta.it
127.0.0.1 www.gaszzetta.it
127.0.0.1 gaszzetta.it
127.0.0.1 www.gaxzetta.it
127.0.0.1 gaxzetta.it
127.0.0.1 www.gaxzzetta.it
127.0.0.1 gaxzzetta.it
127.0.0.1 gay50.com
127.0.0.1 gay-clan.com
127.0.0.1 www.gayspornmag.com
127.0.0.1 gayspornmag.com
127.0.0.1 www.gaystogay.com
127.0.0.1 gaystogay.com
127.0.0.1 www.gazxetta.it
127.0.0.1 gazxetta.it
127.0.0.1 www.gazxzetta.it
127.0.0.1 gazxzetta.it
127.0.0.1 www.gazzaetta.it
127.0.0.1 gazzaetta.it
127.0.0.1 www.gazzdetta.it
127.0.0.1 gazzdetta.it
127.0.0.1 www.gazzedtta.it
127.0.0.1 gazzedtta.it
127.0.0.1 www.gazzeetta.it
127.0.0.1 gazzeetta.it
127.0.0.1 www.gazzeftta.it
127.0.0.1 gazzeftta.it
127.0.0.1 www.gazzegtta.it
127.0.0.1 gazzegtta.it
127.0.0.1 www.gazzehtta.it
127.0.0.1 gazzehtta.it
127.0.0.1 www.gazzerta.it
127.0.0.1 gazzerta.it
127.0.0.1 www.gazzertta.it
127.0.0.1 gazzertta.it
127.0.0.1 www.gazzestta.it
127.0.0.1 gazzestta.it
127.0.0.1 www.gazzetra.it
127.0.0.1 gazzetra.it
127.0.0.1 www.gazzett.it
127.0.0.1 gazzett.it
127.0.0.1 www.gazzettaa.it
127.0.0.1 gazzettaa.it
127.0.0.1 www.gazzettaq.it
127.0.0.1 gazzettaq.it
127.0.0.1 www.gazzettas.it
127.0.0.1 gazzettas.it
127.0.0.1 www.gazzettaz.it
127.0.0.1 gazzettaz.it
127.0.0.1 www.gazzettfa.it
127.0.0.1 gazzettfa.it
127.0.0.1 www.gazzettga.it
127.0.0.1 gazzettga.it
127.0.0.1 www.gazzettha.it
127.0.0.1 gazzettha.it
127.0.0.1 www.gazzettqa.it
127.0.0.1 gazzettqa.it
127.0.0.1 www.gazzettra.it
127.0.0.1 gazzettra.it
127.0.0.1 www.gazzetts.it
127.0.0.1 gazzetts.it
127.0.0.1 www.gazzettsa.it
127.0.0.1 gazzettsa.it
127.0.0.1 www.gazzettya.it
127.0.0.1 gazzettya.it
127.0.0.1 www.gazzettza.it
127.0.0.1 gazzettza.it
127.0.0.1 www.gazzetya.it
127.0.0.1 gazzetya.it
127.0.0.1 www.gazzetyta.it
127.0.0.1 gazzetyta.it
127.0.0.1 www.gazzeyta.it
127.0.0.1 gazzeyta.it
127.0.0.1 www.gazzeytta.it
127.0.0.1 gazzeytta.it
127.0.0.1 www.gazzfetta.it
127.0.0.1 gazzfetta.it
127.0.0.1 www.gazzretta.it
127.0.0.1 gazzretta.it
127.0.0.1 www.gazzrtta.it
127.0.0.1 gazzrtta.it
127.0.0.1 www.gazzsetta.it
127.0.0.1 gazzsetta.it
127.0.0.1 www.gazztta.it
127.0.0.1 gazztta.it
127.0.0.1 www.gazzwetta.it
127.0.0.1 gazzwetta.it
127.0.0.1 www.gazzwtta.it
127.0.0.1 gazzwtta.it
127.0.0.1 www.gazzxetta.it
127.0.0.1 gazzxetta.it
127.0.0.1 www.gbazzetta.it
127.0.0.1 gbazzetta.it
127.0.0.1 www.gboogle.it
127.0.0.1 gboogle.it
127.0.0.1 www.ge.net
127.0.0.1 ge.net
127.0.0.1 www.geil-de.info
127.0.0.1 geil-de.info
127.0.0.1 generalsmeltingofcanada.com
127.0.0.1 www.generateskey.com
127.0.0.1 generateskey.com
127.0.0.1 germany.rub.to
127.0.0.1 www.gerrari.it
127.0.0.1 gerrari.it
127.0.0.1 www.get-access.host.sk
127.0.0.1 www.getanysoftware.com
127.0.0.1 getanysoftware.com
127.0.0.1 www.getbestloanrate.info
127.0.0.1 getbestloanrate.info
127.0.0.1 www.getdailyimages.com
127.0.0.1 getdailyimages.com
127.0.0.1 www.getdvdshrink2007.com
127.0.0.1 getdvdshrink2007.com
127.0.0.1 geteens.com
127.0.0.1 www.getfreepornvideo.com
127.0.0.1 getfreepornvideo.com
127.0.0.1 www.getimageactivex.com
127.0.0.1 getimageactivex.com
127.0.0.1 www.get-ipod-music.com
127.0.0.1 get-ipod-music.com
127.0.0.1 getmirar.com
127.0.0.1 www.get-mp3-onlined.com
127.0.0.1 get-mp3-onlined.com
127.0.0.1 www.getpatytoday.info
127.0.0.1 getpatytoday.info
127.0.0.1 www.getpcmusic.com
127.0.0.1 getpcmusic.com
127.0.0.1 www.getphotosets.com
127.0.0.1 getphotosets.com
127.0.0.1 getpicshere.com
127.0.0.1 www.getpornmag.com
127.0.0.1 getpornmag.com
127.0.0.1 www.getpornvideoz.com
127.0.0.1 getpornvideoz.com
127.0.0.1 www.get-realplayer.com
127.0.0.1 get-realplayer.com
127.0.0.1 www.get-spybot.com
127.0.0.1 get-spybot.com
127.0.0.1 www.getvaxobject.com
127.0.0.1 getvaxobject.com
127.0.0.1 www.getvideosource.com
127.0.0.1 getvideosource.com
127.0.0.1 www.get-winrar.com
127.0.0.1 get-winrar.com
127.0.0.1 www.getxmovies.com
127.0.0.1 getxmovies.com
127.0.0.1 www.get-zune.com
127.0.0.1 get-zune.com
127.0.0.1 www.gfazzetta.it
127.0.0.1 gfazzetta.it
127.0.0.1 www.gfoogle.it
127.0.0.1 gfoogle.it
127.0.0.1 www.gfxgraphics.net
127.0.0.1 gfxgraphics.net
127.0.0.1 www.ggazzetta.it
127.0.0.1 ggazzetta.it
127.0.0.1 www.ghazzetta.it
127.0.0.1 ghazzetta.it
127.0.0.1 www.ghktoolkit.com
127.0.0.1 ghktoolkit.com
127.0.0.1 www.ghoogle.it
127.0.0.1 ghoogle.it
127.0.0.1 www.giangho.biz
127.0.0.1 giangho.biz
127.0.0.1 www.gigacodec.net
127.0.0.1 gigacodec.net
127.0.0.1 www.gigaz.info
127.0.0.1 gigaz.info
127.0.0.1 gimmezamore.com
127.0.0.1 gimnasiaer.com
127.0.0.1 www.giogle.it
127.0.0.1 giogle.it
127.0.0.1 www.gioogle.it
127.0.0.1 gioogle.it
127.0.0.1 www.girgilio.it
127.0.0.1 girgilio.it
127.0.0.1 girls-porn-life.com
127.0.0.1 www.giscali.it
127.0.0.1 giscali.it
127.0.0.1 www.givecnt.info
127.0.0.1 givecnt.info
127.0.0.1 www.gkoogle.it
127.0.0.1 gkoogle.it
127.0.0.1 www.gl.secdep.info
127.0.0.1 gl.secdep.info
127.0.0.1 glbdf.org
127.0.0.1 globalefinder.com
127.0.0.1 global-finder.com
127.0.0.1 globe-finder.cc
127.0.0.1 globe-finder.com
127.0.0.1 www.globesearch.com
127.0.0.1 globesearch.com
127.0.0.1 www.glogle.it
127.0.0.1 glogle.it
127.0.0.1 www.gneprogram.com
127.0.0.1 gneprogram.com
127.0.0.1 go.errorsafe.com
127.0.0.1 www.go0ogle.it
127.0.0.1 go0ogle.it
127.0.0.1 go2realsearch.com
127.0.0.1 www.go9ogle.it
127.0.0.1 go9ogle.it
127.0.0.1 www.gocodec.com
127.0.0.1 gocodec.com
127.0.0.1 www.gocybersearch.com
127.0.0.1 gocybersearch.com
127.0.0.1 www.goigle.it
127.0.0.1 goigle.it
127.0.0.1 www.goiogle.it
127.0.0.1 goiogle.it
127.0.0.1 www.gokogle.it
127.0.0.1 gokogle.it
127.0.0.1 goldbaccarat.info
127.0.0.1 www.goldcodec.com
127.0.0.1 goldcodec.com
127.0.0.1 www.gold-craps.info
127.0.0.1 gold-craps.info
127.0.0.1 www.goldenfreehost.com
127.0.0.1 goldenfreehost.com
127.0.0.1 goldengr.hypermart.net
127.0.0.1 www.goldensurvey.com
127.0.0.1 goldensurvey.com
127.0.0.1 golftennis.net
127.0.0.1 www.golgle.it
127.0.0.1 golgle.it
127.0.0.1 www.gologle.it
127.0.0.1 gologle.it
127.0.0.1 Gomusic.com
127.0.0.1 www.gomyron.com
127.0.0.1 www.goo0gle.it
127.0.0.1 goo0gle.it
127.0.0.1 www.goo9gle.it
127.0.0.1 goo9gle.it
127.0.0.1 www.goobgle.it
127.0.0.1 goobgle.it
127.0.0.1 www.gooble.it
127.0.0.1 gooble.it
127.0.0.1 www.good-casino.net
127.0.0.1 good-casino.net
127.0.0.1 good-mortgages.net
127.0.0.1 good-mortgages-calculator.com
127.0.0.1 www.goodmovielaugh.com
127.0.0.1 goodmovielaugh.com
127.0.0.1 good-movie-play.com
127.0.0.1 goodsexs.com
127.0.0.1 www.goofgle.it
127.0.0.1 goofgle.it
127.0.0.1 www.googble.it
127.0.0.1 googble.it
127.0.0.1 www.googel.it
127.0.0.1 googel.it
127.0.0.1 www.googfle.it
127.0.0.1 googfle.it
127.0.0.1 www.googhle.it
127.0.0.1 googhle.it
127.0.0.1 www.googkle.it
127.0.0.1 googkle.it
127.0.0.1 www.googl3e.it
127.0.0.1 googl3e.it
127.0.0.1 www.googl4e.it
127.0.0.1 googl4e.it
127.0.0.1 www.googld.it
127.0.0.1 googld.it
127.0.0.1 www.googlde.it
127.0.0.1 googlde.it
127.0.0.1 google.panet.org
127.0.0.1 google123.web1000.com
127.0.0.1 www.google3.it
127.0.0.1 google3.it
127.0.0.1 www.google4.it
127.0.0.1 google4.it
127.0.0.1 googlebar.jps.ru
127.0.0.1 www.googled.it
127.0.0.1 googled.it
127.0.0.1 www.googlef.it
127.0.0.1 googlef.it
127.0.0.1 www.googler.it
127.0.0.1 googler.it
127.0.0.1 www.googles.it
127.0.0.1 googles.it
127.0.0.1 www.googlew.it
127.0.0.1 googlew.it
127.0.0.1 googlf.com
127.0.0.1 www.googlf.it
127.0.0.1 googlf.it
127.0.0.1 www.googlfe.it
127.0.0.1 googlfe.it
127.0.0.1 www.googlke.it
127.0.0.1 googlke.it
127.0.0.1 www.googloe.it
127.0.0.1 googloe.it
127.0.0.1 www.googlpe.it
127.0.0.1 googlpe.it
127.0.0.1 www.googlre.it
127.0.0.1 googlre.it
127.0.0.1 www.googlse.it
127.0.0.1 googlse.it
127.0.0.1 www.googlus.com
127.0.0.1 www.googlwe.it
127.0.0.1 googlwe.it
127.0.0.1 www.googole.it
127.0.0.1 googole.it
127.0.0.1 www.googple.it
127.0.0.1 googple.it
127.0.0.1 www.googtle.it
127.0.0.1 googtle.it
127.0.0.1 www.googvle.it
127.0.0.1 googvle.it
127.0.0.1 www.googyle.it
127.0.0.1 googyle.it
127.0.0.1 www.goohgle.it
127.0.0.1 goohgle.it
127.0.0.1 www.goohle.it
127.0.0.1 goohle.it
127.0.0.1 www.gooigle.it
127.0.0.1 gooigle.it
127.0.0.1 www.gookgle.it
127.0.0.1 gookgle.it
127.0.0.1 www.gooogle.bz
127.0.0.1 gooogle.bz
127.0.0.1 www.goopgle.it
127.0.0.1 goopgle.it
127.0.0.1 www.gootgle.it
127.0.0.1 gootgle.it
127.0.0.1 www.gootle.it
127.0.0.1 gootle.it
127.0.0.1 www.goovgle.it
127.0.0.1 goovgle.it
127.0.0.1 www.goovle.it
127.0.0.1 goovle.it
127.0.0.1 www.gooygle.it
127.0.0.1 gooygle.it
127.0.0.1 www.gopgle.it
127.0.0.1 gopgle.it
127.0.0.1 www.gopogle.it
127.0.0.1 gopogle.it
127.0.0.1 gorecord.com
127.0.0.1 Go-turf.com
127.0.0.1 www.gpogle.it
127.0.0.1 gpogle.it
127.0.0.1 www.gpoogle.it
127.0.0.1 gpoogle.it
127.0.0.1 www.gqazzetta.it
127.0.0.1 gqazzetta.it
127.0.0.1 grab-it-today.net
127.0.0.1 www.graceinthedesert.org
127.0.0.1 graceinthedesert.org
127.0.0.1 gradforum.org
127.0.0.1 gratisdownloads.nl
127.0.0.1 gratis-porn-movie.com
127.0.0.1 gratis-pornopics.com
127.0.0.1 www.greatbahamas.com
127.0.0.1 greatbahamas.com
127.0.0.1 www.greatcodec.com
127.0.0.1 greatcodec.com
127.0.0.1 www.great-ticket.net
127.0.0.1 great-ticket.net
127.0.0.1 www.greencardspouse.com
127.0.0.1 greencardspouse.com
127.0.0.1 greg-search.com
127.0.0.1 greg-tut.com
127.0.0.1 www.grepubblica.it
127.0.0.1 grepubblica.it
127.0.0.1 www.gsazzetta.it
127.0.0.1 gsazzetta.it
127.0.0.1 www.gszzetta.it
127.0.0.1 gszzetta.it
127.0.0.1 gtawarehouse.com
127.0.0.1 www.gtazzetta.it
127.0.0.1 gtazzetta.it
127.0.0.1 www.gtiscali.it
127.0.0.1 gtiscali.it
127.0.0.1 www.gtoogle.it
127.0.0.1 gtoogle.it
127.0.0.1 www.gtrenitalia.it
127.0.0.1 gtrenitalia.it
127.0.0.1 www.gtuttogratis.it
127.0.0.1 gtuttogratis.it
127.0.0.1 www.gueb.com
127.0.0.1 gueb.com
127.0.0.1 www.guyvsgirl.com
127.0.0.1 guyvsgirl.com
127.0.0.1 guzzycats.com
127.0.0.1 www.gvazzetta.it
127.0.0.1 gvazzetta.it
127.0.0.1 www.gvirgilio.it
127.0.0.1 gvirgilio.it
127.0.0.1 www.gvoogle.it
127.0.0.1 gvoogle.it
127.0.0.1 www.gyoogle.it
127.0.0.1 gyoogle.it
127.0.0.1 www.gzazzetta.it
127.0.0.1 gzazzetta.it
127.0.0.1 gzphoenix.com
127.0.0.1 www.gzzetta.it
127.0.0.1 gzzetta.it
127.0.0.1 H24413.tfil.com
127.0.0.1 www.hachimitsu-lemon.com
127.0.0.1 hachimitsu-lemon.com
127.0.0.1 www.hacker.com.cn
127.0.0.1 hacker.com.cn
127.0.0.1 hadesunharuikeya.com
127.0.0.1 hallnetaccolade.com
127.0.0.1 hand-book.com
127.0.0.1 happyanal.com
127.0.0.1 hardbodytgp.com
127.0.0.1 www.hardcorefantasyland.com
127.0.0.1 hardcorefantasyland.com
127.0.0.1 hardcoreover.com
127.0.0.1 www.hardcorepornmag.com
127.0.0.1 hardcorepornmag.com
127.0.0.1 www.harddrevvagt.com
127.0.0.1 harddrevvagt.com
127.0.0.1 hardfootballbabes.com
127.0.0.1 hard-gals.com
127.0.0.1 hardloved.com
127.0.0.1 hardwareseek.net
127.0.0.1 harukaigawa.com
127.0.0.1 www.hastalavista.com
127.0.0.1 hastalavista.com
127.0.0.1 havy.biz
127.0.0.1 www.hazzetta.it
127.0.0.1 hazzetta.it
127.0.0.1 hccsolanonapa.org
127.0.0.1 www.headlinesandnews.com
127.0.0.1 headlinesandnews.com
127.0.0.1 health-protein.com
127.0.0.1 www.helpcodec.com
127.0.0.1 helpcodec.com
127.0.0.1 helpyoursearch.com
127.0.0.1 hentai4u.net
127.0.0.1 www.here4search.biz
127.0.0.1 here4search.com
127.0.0.1 www.herramientadereparacion.com
127.0.0.1 herramientadereparacion.com
127.0.0.1 www.hervam.com
127.0.0.1 hervam.com
127.0.0.1 heyrichy.com
127.0.0.1 www.hgazzetta.it
127.0.0.1 hgazzetta.it
127.0.0.1 www.hgoogle.it
127.0.0.1 hgoogle.it
127.0.0.1 www.hi.studioaperto.net
127.0.0.1 hi.studioaperto.net
127.0.0.1 www.hiboss.com
127.0.0.1 hiboss.com
127.0.0.1 hiddenguides.com
127.0.0.1 www.hijack-this.net
127.0.0.1 hijack-this.net
127.0.0.1 himen.biz
127.0.0.1 www.hiscali.it
127.0.0.1 hiscali.it
127.0.0.1 hi-search.com
127.0.0.1 hitlistlyrics.com
127.0.0.1 hitscount.net
127.0.0.1 hitsdriving.com
127.0.0.1 hitvirus.com
127.0.0.1 www.hityou.com
127.0.0.1 hityou.com
127.0.0.1 www.hobbypesca.com.br
127.0.0.1 hobbypesca.com.br
127.0.0.1 www.hoetechnology.com
127.0.0.1 hoetechnology.com
127.0.0.1 holidayautostr.com
127.0.0.1 www.homelandnetwork.COM
127.0.0.1 homelandnetwork.COM
127.0.0.1 homemortage.ws
127.0.0.1 www.hoogle.it
127.0.0.1 hoogle.it
127.0.0.1 host.sk
127.0.0.1 www.hostance.net
127.0.0.1 hostance.net
127.0.0.1 www.host-codec.com
127.0.0.1 host-codec.com
127.0.0.1 hostssp.com
127.0.0.1 www.hostthesky.com
127.0.0.1 hostthesky.com
127.0.0.1 hotbookmark.com
127.0.0.1 hot-cartoon-sex.anime.american-teens.net
127.0.0.1 www.hotcodec.net
127.0.0.1 hotcodec.net
127.0.0.1 www.hotelcodec.com
127.0.0.1 hotelcodec.com
127.0.0.1 hotels-list.net
127.0.0.1 hotelxxxcams.com
127.0.0.1 www.hotfreebies.com
127.0.0.1 hotfreebies.com
127.0.0.1 hotlolitas.underagehost.com
127.0.0.1 www.hotmp3download.com
127.0.0.1 hotmp3download.com
127.0.0.1 www.hotmp3music.com
127.0.0.1 hotmp3music.com
127.0.0.1 www.hotmp3now.com
127.0.0.1 hotmp3now.com
127.0.0.1 www.hotnchilly.com
127.0.0.1 hotnchilly.com
127.0.0.1 hotpopup.com
127.0.0.1 hotsearchbox.com
127.0.0.1 hotsex-series.com
127.0.0.1 hotstartpage.com
127.0.0.1 Hot-tv.com
127.0.0.1 www.hotwinupdates.com
127.0.0.1 hotwinupdates.com
127.0.0.1 www.hqadultvideos.com
127.0.0.1 hqadultvideos.com
127.0.0.1 www.hqcodectime.net
127.0.0.1 hqcodectime.net
127.0.0.1 www.hq-downloads.com
127.0.0.1 hq-downloads.com
127.0.0.1 www.hqexplicitvids.com
127.0.0.1 hqexplicitvids.com
127.0.0.1 hqsex.biz
127.0.0.1 www.hqthefilmsxxx.com
127.0.0.1 hqthefilmsxxx.com
127.0.0.1 www.htiscali.it
127.0.0.1 htiscali.it
127.0.0.1 www.httpwwwads.com
127.0.0.1 httpwwwads.com
127.0.0.1 hu15.ru
127.0.0.1 www.hugefreevids.com
127.0.0.1 hugefreevids.com
127.0.0.1 www.hugeinvention.com
127.0.0.1 hugeinvention.com
127.0.0.1 hugeporn4u.net
127.0.0.1 www.hugevideoszone.com
127.0.0.1 hugevideoszone.com
127.0.0.1 www.hukommelsesbeskytter.com
127.0.0.1 hukommelsesbeskytter.com
127.0.0.1 hunacsa.com
127.0.0.1 www.huntbar.com
127.0.0.1 huntbar.com
127.0.0.1 www.huoche.com.cn
127.0.0.1 huoche.com.cn
127.0.0.1 hupacasath.com
127.0.0.1 www.hushware.com
127.0.0.1 hushware.com
127.0.0.1 hut1.ru
127.0.0.1 www.hwgate.com
127.0.0.1 hwgate.com
127.0.0.1 www.hypoteches.com
127.0.0.1 hypoteches.com
127.0.0.1 hzsx.com
127.0.0.1 www.iaxobjectdownload.com
127.0.0.1 iaxobjectdownload.com
127.0.0.1 www.ibankis.org
127.0.0.1 ibankis.org
127.0.0.1 ibm.dmcast.com
127.0.0.1 ibmx.com
127.0.0.1 www.ibsprogram.com
127.0.0.1 ibsprogram.com
127.0.0.1 icansearch.net
127.0.0.1 www.iconfessonline.com
127.0.0.1 iconfessonline.com
127.0.0.1 www.iconnectyou.biz
127.0.0.1 iconnectyou.biz
127.0.0.1 www.ictmanufacture.com
127.0.0.1 ictmanufacture.com
127.0.0.1 www.ictprivate.com
127.0.0.1 ictprivate.com
127.0.0.1 icwb.com
127.0.0.1 icwo.com
127.0.0.1 icwp.com
127.0.0.1 www.idblg.com
127.0.0.1 idblg.com
127.0.0.1 iddh.com
127.0.0.1 idgsearch.com
127.0.0.1 idhh.com
127.0.0.1 www.idnserror.com
127.0.0.1 idnserror.com
127.0.0.1 www.idolikemovies.com
127.0.0.1 idolikemovies.com
127.0.0.1 idownload.com
127.0.0.1 ie.marketdart.com
127.0.0.1 www.iednserror.com
127.0.0.1 iednserror.com
127.0.0.1 www.iesafetypage.com
127.0.0.1 iesafetypage.com
127.0.0.1 www.iesecurepage.com
127.0.0.1 iesecurepage.com
127.0.0.1 www.iesecuritybar.com
127.0.0.1 iesecuritybar.com
127.0.0.1 www.ifeelyou.info
127.0.0.1 ifeelyou.info
127.0.0.1 www.i-femdom.com
127.0.0.1 i-femdom.com
127.0.0.1 ifiz.com
127.0.0.1 iframe.biz
127.0.0.1 www.iframebiz.com
127.0.0.1 iframebiz.com
127.0.0.1 www.igetnet.com
127.0.0.1 igetnet.com
127.0.0.1 www.ignphrases.com
127.0.0.1 ignphrases.com
127.0.0.1 iguu.com
127.0.0.1 www.ikataweb.it
127.0.0.1 ikataweb.it
127.0.0.1 www.ilbero.it
127.0.0.1 ilbero.it
127.0.0.1 i-lookup.com
127.0.0.1 www.imageactivexsolution.com
127.0.0.1 imageactivexsolution.com
127.0.0.1 www.imageaxaccesssoft.com
127.0.0.1 imageaxaccesssoft.com
127.0.0.1 www.imagemediaax.com
127.0.0.1 imagemediaax.com
127.0.0.1 www.imagescontrol.com
127.0.0.1 imagescontrol.com
127.0.0.1 www.imagesezine.com
127.0.0.1 imagesezine.com
127.0.0.1 www.imagespecials.com
127.0.0.1 imagespecials.com
127.0.0.1 www.imcodec.com
127.0.0.1 imcodec.com
127.0.0.1 www.imediacodec.com
127.0.0.1 imediacodec.com
127.0.0.1 www.imergeyou.com
127.0.0.1 imergeyou.com
127.0.0.1 www.imesh.click-new-download.com
127.0.0.1 imesh.click-new-download.com
127.0.0.1 imiserver.com
127.0.0.1 www.imp3download.com
127.0.0.1 imrworldwide.com
127.0.0.1 www.imusicadvance.com
127.0.0.1 imusicadvance.com
127.0.0.1 in.hushware.com
127.0.0.1 in.popupblocker.com
127.0.0.1 in.spywareavenger.com
127.0.0.1 www.inc-codec.com
127.0.0.1 inc-codec.com
127.0.0.1 incest-host.com
127.0.0.1 incestporngate.com
127.0.0.1 www.incredimail-download-now.com
127.0.0.1 incredimail-download-now.com
127.0.0.1 www.incredimail-hq.com
127.0.0.1 incredimail-hq.com
127.0.0.1 www.incredimailpro.com
127.0.0.1 incredimailpro.com
127.0.0.1 www.infectedkernel.com
127.0.0.1 infectedkernel.com
127.0.0.1 infodigger.net
127.0.0.1 infoglobus.com
127.0.0.1 infport.com
127.0.0.1 inherhole.com
127.0.0.1 www.inibo.it
127.0.0.1 inibo.it
127.0.0.1 innovagest2000.com
127.0.0.1 insertthiscock.com
127.0.0.1 www.install.007guard.com
127.0.0.1 install.searchtab.net
127.0.0.1 www.installmoviepro.com
127.0.0.1 installmoviepro.com
127.0.0.1 www.installobject.com
127.0.0.1 installobject.com
127.0.0.1 installs.180solutions.com
127.0.0.1 www.installvaxobject.com
127.0.0.1 installvaxobject.com
127.0.0.1 www.instantpsp.com
127.0.0.1 instantpsp.com
127.0.0.1 instlog.errorsafe.com
127.0.0.1 instlog.winfixer.com
127.0.0.1 insuranceall.net
127.0.0.1 insurance-flood.net
127.0.0.1 www.intcodec.com
127.0.0.1 intcodec.com
127.0.0.1 interactivebrands.com
127.0.0.1 www.internationalmarketingfirm.com
127.0.0.1 internationalmarketingfirm.com
127.0.0.1 www.i-nt-e-r-n-e-t.com
127.0.0.1 i-nt-e-r-n-e-t.com
127.0.0.1 Internetgamebox.com
127.0.0.1 www.Internet-media-download.com
127.0.0.1 Internet-media-download.com
127.0.0.1 www.internet-optimizer.com
127.0.0.1 internet-optimizer.com
127.0.0.1 internetsearch.ru
127.0.0.1 ionichost.com
127.0.0.1 ionomist.com
127.0.0.1 www.ipo.net
127.0.0.1 ipo.net
127.0.0.1 www.ipoddownloadingpro.com
127.0.0.1 ipoddownloadingpro.com
127.0.0.1 www.ipod-itunes-download-now.com
127.0.0.1 ipod-itunes-download-now.com
127.0.0.1 www.ipod-music-store.com
127.0.0.1 ipod-music-store.com
127.0.0.1 www.ipod-tunes-download.com
127.0.0.1 ipod-tunes-download.com
127.0.0.1 www.ipod-wiz.com
127.0.0.1 ipod-wiz.com
127.0.0.1 www.ipointyou.hk
127.0.0.1 ipointyou.hk
127.0.0.1 ipsex.net
127.0.0.1 www.ipspdownload.com
127.0.0.1 ipspdownload.com
127.0.0.1 iqsearch.net
127.0.0.1 www.ireit.com
127.0.0.1 ireit.com
127.0.0.1 www.irfanview-center.com
127.0.0.1 irfanview-center.com
127.0.0.1 www.irfanview-download-now.com
127.0.0.1 irfanview-download-now.com
127.0.0.1 www.irfanview-stop.com
127.0.0.1 irfanview-stop.com
127.0.0.1 ironcarteam.com
127.0.0.1 is-best.com
127.0.0.1 www.iscali.it
127.0.0.1 iscali.it
127.0.0.1 www.ishowbao.com
127.0.0.1 ishowbao.com
127.0.0.1 www.israilq.com
127.0.0.1 israilq.com
127.0.0.1 istarthere.com
127.0.0.1 www.itfindout.org
127.0.0.1 itfindout.org
127.0.0.1 www.itknown.net
127.0.0.1 itknown.net
127.0.0.1 itsanal.com
127.0.0.1 www.itunesandipods.com
127.0.0.1 itunesandipods.com
127.0.0.1 www.itunesfreebies.com
127.0.0.1 itunesfreebies.com
127.0.0.1 www.itvdownload.com
127.0.0.1 itvdownload.com
127.0.0.1 www.iugate.com
127.0.0.1 www.iunibo.it
127.0.0.1 iunibo.it
127.0.0.1 www.iunige.it
127.0.0.1 iunige.it
127.0.0.1 www.iunimi.it
127.0.0.1 iunimi.it
127.0.0.1 www.iunipd.it
127.0.0.1 iunipd.it
127.0.0.1 www.iunipg.it
127.0.0.1 iunipg.it
127.0.0.1 www.iunipv.it
127.0.0.1 iunipv.it
127.0.0.1 www.iunito.it
127.0.0.1 iunito.it
127.0.0.1 i-used.cc
127.0.0.1 www.ivideocodec.com
127.0.0.1 ivideocodec.com
127.0.0.1 www.iwantsearch.net
127.0.0.1 iwantsearch.net
127.0.0.1 iweb-commerce.com
127.0.0.1 iwebland.com
127.0.0.1 iwon.com
127.0.0.1 www.ixcodec.com
127.0.0.1 j10.wrs.mcboo.com
127.0.0.1 www.jackpot-advertising.info
127.0.0.1 jackpot-advertising.info
127.0.0.1 www.jackpotcheck.info
127.0.0.1 jackpotcheck.info
127.0.0.1 jeannineoldfield.com
127.0.0.1 www.jerrynews.com
127.0.0.1 jerrynews.com
127.0.0.1 www.jetcodec.com
127.0.0.1 jethomepage.com
127.0.0.1 www.jethomepage.com
127.0.0.1 jetseeker.com
127.0.0.1 jhzjyj.bigwww.com
127.0.0.1 www.jinkinyunhdefunkasderun.com
127.0.0.1 jinkinyunhdefunkasderun.com
127.0.0.1 www.jkataweb.it
127.0.0.1 jkataweb.it
127.0.0.1 jmhgallery.org
127.0.0.1 www.jmsn.it
127.0.0.1 jmsn.it
127.0.0.1 joannelatham.com
127.0.0.1 js.megalocast.net
127.0.0.1 judin.ru
127.0.0.1 jumptothat.com
127.0.0.1 junkysex.com
127.0.0.1 www.jupitersatellites.biz
127.0.0.1 jupitersatellites.biz
127.0.0.1 www.justcount.net
127.0.0.1 justcount.net
127.0.0.1 www.juyatinjesaza.com
127.0.0.1 juyatinjesaza.com
127.0.0.1 k8l.info
127.0.0.1 www.k9instructor.com
127.0.0.1 k9instructor.com
127.0.0.1 www.kaaweb.it
127.0.0.1 kaaweb.it
127.0.0.1 www.kabex.com
127.0.0.1 kabex.com
127.0.0.1 www.kaftaweb.it
127.0.0.1 kaftaweb.it
127.0.0.1 www.kagtaweb.it
127.0.0.1 kagtaweb.it
127.0.0.1 www.kahtaweb.it
127.0.0.1 kahtaweb.it
127.0.0.1 kalmarte.zapto.org
127.0.0.1 kannylizaciya.info
127.0.0.1 www.kaqtaweb.it
127.0.0.1 kaqtaweb.it
127.0.0.1 www.karachun.biz
127.0.0.1 karachun.biz
127.0.0.1 www.karaweb.it
127.0.0.1 karaweb.it
127.0.0.1 karleyt.narod.ru
127.0.0.1 www.kartaweb.it
127.0.0.1 kartaweb.it
127.0.0.1 www.kastaweb.it
127.0.0.1 kastaweb.it
127.0.0.1 www.kataaweb.it
127.0.0.1 kataaweb.it
127.0.0.1 www.katadweb.it
127.0.0.1 katadweb.it
127.0.0.1 www.kataeb.it
127.0.0.1 kataeb.it
127.0.0.1 www.kataeeb.it
127.0.0.1 kataeeb.it
127.0.0.1 www.kataewb.it
127.0.0.1 kataewb.it
127.0.0.1 www.kataeweb.it
127.0.0.1 kataeweb.it
127.0.0.1 www.kataqeb.it
127.0.0.1 kataqeb.it
127.0.0.1 www.kataqweb.it
127.0.0.1 kataqweb.it
127.0.0.1 www.katasearch.com
127.0.0.1 katasearch.com
127.0.0.1 www.katasweb.it
127.0.0.1 katasweb.it
127.0.0.1 www.katawaeb.it
127.0.0.1 katawaeb.it
127.0.0.1 www.katawb.it
127.0.0.1 katawb.it
127.0.0.1 www.katawdeb.it
127.0.0.1 katawdeb.it
127.0.0.1 www.katawe.it
127.0.0.1 katawe.it
127.0.0.1 www.katawebb.it
127.0.0.1 katawebb.it
127.0.0.1 www.katawebg.it
127.0.0.1 katawebg.it
127.0.0.1 www.katawebh.it
127.0.0.1 katawebh.it
127.0.0.1 www.katawebn.it
127.0.0.1 katawebn.it
127.0.0.1 www.katawebv.it
127.0.0.1 katawebv.it
127.0.0.1 www.katawedb.it
127.0.0.1 katawedb.it
127.0.0.1 www.kataweeb.it
127.0.0.1 kataweeb.it
127.0.0.1 www.katawefb.it
127.0.0.1 katawefb.it
127.0.0.1 www.katawegb.it
127.0.0.1 katawegb.it
127.0.0.1 www.katawehb.it
127.0.0.1 katawehb.it
127.0.0.1 www.katawenb.it
127.0.0.1 katawenb.it
127.0.0.1 www.katawerb.it
127.0.0.1 katawerb.it
127.0.0.1 www.katawesb.it
127.0.0.1 katawesb.it
127.0.0.1 www.katawev.it
127.0.0.1 katawev.it
127.0.0.1 www.katawevb.it
127.0.0.1 katawevb.it
127.0.0.1 www.katawfeb.it
127.0.0.1 katawfeb.it
127.0.0.1 www.katawqeb.it
127.0.0.1 katawqeb.it
127.0.0.1 www.katawrb.it
127.0.0.1 katawrb.it
127.0.0.1 www.katawreb.it
127.0.0.1 katawreb.it
127.0.0.1 www.katawseb.it
127.0.0.1 katawseb.it
127.0.0.1 www.katawwb.it
127.0.0.1 katawwb.it
127.0.0.1 www.katawweb.it
127.0.0.1 katawweb.it
127.0.0.1 www.katazweb.it
127.0.0.1 katazweb.it
127.0.0.1 www.katfaweb.it
127.0.0.1 katfaweb.it
127.0.0.1 www.katgaweb.it
127.0.0.1 katgaweb.it
127.0.0.1 www.kathaweb.it
127.0.0.1 kathaweb.it
127.0.0.1 kathisomers.com
127.0.0.1 www.katqaweb.it
127.0.0.1 katqaweb.it
127.0.0.1 www.katraweb.it
127.0.0.1 katraweb.it
127.0.0.1 www.katsaweb.it
127.0.0.1 katsaweb.it
127.0.0.1 www.katsweb.it
127.0.0.1 katsweb.it
127.0.0.1 www.kattaweb.it
127.0.0.1 kattaweb.it
127.0.0.1 www.katweb.it
127.0.0.1 katweb.it
127.0.0.1 www.katzaweb.it
127.0.0.1 katzaweb.it
127.0.0.1 www.kayaweb.it
127.0.0.1 kayaweb.it
127.0.0.1 kazaa-lite.ws
127.0.0.1 www.kaztaweb.it
127.0.0.1 kaztaweb.it
127.0.0.1 www.Keinegefahr.com
127.0.0.1 Keinegefahr.com
127.0.0.1 keithgreenpro.com
127.0.0.1 kenmccaul.com
127.0.0.1 www.keratomir.biz
127.0.0.1 www.keratomir2.biz
127.0.0.1 keratomir2.biz
127.0.0.1 www.keycodec.com
127.0.0.1 keycodec.com
127.0.0.1 www.key-codec.com
127.0.0.1 key-codec.com
127.0.0.1 www.keygenguru.com
127.0.0.1 keygenguru.com
127.0.0.1 www.key-ticket.com
127.0.0.1 key-ticket.com
127.0.0.1 www.khcbaym.com
127.0.0.1 khcbaym.com
127.0.0.1 www.kiataweb.it
127.0.0.1 kiataweb.it
127.0.0.1 www.kibero.it
127.0.0.1 kibero.it
127.0.0.1 killerpornstars.com
127.0.0.1 kilosex.com
127.0.0.1 kimhines.com
127.0.0.1 www.kimsoftware.com
127.0.0.1 kimsoftware.com
127.0.0.1 kinoru.com
127.0.0.1 www.kintunhdefunhganmdesun.com
127.0.0.1 kintunhdefunhganmdesun.com
127.0.0.1 www.kitehosting.com
127.0.0.1 kitehosting.com
127.0.0.1 www.kjataweb.it
127.0.0.1 kjataweb.it
127.0.0.1 www.kkataweb.it
127.0.0.1 kkataweb.it
127.0.0.1 www.klataweb.it
127.0.0.1 klataweb.it
127.0.0.1 www.klibero.it
127.0.0.1 klibero.it
127.0.0.1 www.klikadvertising.com
127.0.0.1 kliksearch.com
127.0.0.1 k-lined.com
127.0.0.1 www.klitegeneration.com
127.0.0.1 klitegeneration.com
127.0.0.1 k-litegold.com
127.0.0.1 www.k-litegold.com
127.0.0.1 k-litegold.com
127.0.0.1 klitepro.com
127.0.0.1 www.klitepro.com
127.0.0.1 klitepro.com
127.0.0.1 www.k-litepro.com
127.0.0.1 k-litepro.com
127.0.0.1 k-litetk.com
127.0.0.1 www.k-litetk.com
127.0.0.1 k-litetk.com
127.0.0.1 www.kmataweb.it
127.0.0.1 kmataweb.it
127.0.0.1 www.kmpads.com
127.0.0.1 kmpads.com
127.0.0.1 www.kmsn.it
127.0.0.1 kmsn.it
127.0.0.1 www.koataweb.it
127.0.0.1 koataweb.it
127.0.0.1 www.komforochka.info
127.0.0.1 komforochka.info
127.0.0.1 www.kqataweb.it
127.0.0.1 kqataweb.it
127.0.0.1 www.kr62.com
127.0.0.1 kr62.com
127.0.0.1 www.krankin.com
127.0.0.1 krankin.com
127.0.0.1 www.ksataweb.it
127.0.0.1 ksataweb.it
127.0.0.1 ksdspups.org
127.0.0.1 www.kstaweb.it
127.0.0.1 kstaweb.it
127.0.0.1 www.ktaweb.it
127.0.0.1 ktaweb.it
127.0.0.1 www.kuturoisus.com
127.0.0.1 kuturoisus.com
127.0.0.1 www.kyoishusei.com
127.0.0.1 kyoishusei.com
127.0.0.1 www.kzataweb.it
127.0.0.1 kzataweb.it
127.0.0.1 www.kzdh.com
127.0.0.1 kzdh.com
127.0.0.1 l.mezzicodec.net
127.0.0.1 www.l8bero.it
127.0.0.1 l8bero.it
127.0.0.1 www.l8ibero.it
127.0.0.1 l8ibero.it
127.0.0.1 www.l9bero.it
127.0.0.1 l9bero.it
127.0.0.1 www.l9ibero.it
127.0.0.1 l9ibero.it
127.0.0.1 landrape.com
127.0.0.1 Lastsoftwares.com
127.0.0.1 www.laughnetwork.com
127.0.0.1 laughnetwork.com
127.0.0.1 lauraroebuck.com
127.0.0.1 www.lavasoftupdate.com
127.0.0.1 lavasoftupdate.com
127.0.0.1 www.lavl-vicky.com
127.0.0.1 lavl-vicky.com
127.0.0.1 www.lbero.it
127.0.0.1 lbero.it
127.0.0.1 www.lbiero.it
127.0.0.1 lbiero.it
127.0.0.1 leannalovelace.com
127.0.0.1 www.lebenstest.de
127.0.0.1 lebenstest.de
127.0.0.1 www.lerunjinkfeunhadesun.com
127.0.0.1 lerunjinkfeunhadesun.com
127.0.0.1 www.lesbianpornmag.com
127.0.0.1 lesbianpornmag.com
127.0.0.1 www.lesbianspornmag.com
127.0.0.1 lesbianspornmag.com
127.0.0.1 lesobank.ru
127.0.0.1 www.lets-get-it.info
127.0.0.1 lets-get-it.info
127.0.0.1 lets-get-it.net
127.0.0.1 www.lets-get-it.org
127.0.0.1 lets-get-it.org
127.0.0.1 www.lfxmsc.gov.cn
127.0.0.1 lfxmsc.gov.cn
127.0.0.1 www.li8bero.it
127.0.0.1 li8bero.it
127.0.0.1 www.li9bero.it
127.0.0.1 li9bero.it
127.0.0.1 www.lib3ero.it
127.0.0.1 lib3ero.it
127.0.0.1 www.lib3ro.it
127.0.0.1 lib3ro.it
127.0.0.1 www.lib4ero.it
127.0.0.1 lib4ero.it
127.0.0.1 www.lib4ro.it
127.0.0.1 lib4ro.it
127.0.0.1 www.libdero.it
127.0.0.1 libdero.it
127.0.0.1 www.libdro.it
127.0.0.1 libdro.it
127.0.0.1 www.libe3ro.it
127.0.0.1 libe3ro.it
127.0.0.1 www.libe4o.it
127.0.0.1 libe4o.it
127.0.0.1 www.libe4ro.it
127.0.0.1 libe4ro.it
127.0.0.1 www.libe5o.it
127.0.0.1 libe5o.it
127.0.0.1 www.libe5ro.it
127.0.0.1 libe5ro.it
127.0.0.1 www.libedro.it
127.0.0.1 libedro.it
127.0.0.1 www.libeeo.it
127.0.0.1 libeeo.it
127.0.0.1 www.libeero.it
127.0.0.1 libeero.it
127.0.0.1 www.libefro.it
127.0.0.1 libefro.it
127.0.0.1 www.libegro.it
127.0.0.1 libegro.it
127.0.0.1 www.liber0.it
127.0.0.1 liber0.it
127.0.0.1 www.liber0o.it
127.0.0.1 liber0o.it
127.0.0.1 www.liber4o.it
127.0.0.1 liber4o.it
127.0.0.1 www.liber5o.it
127.0.0.1 liber5o.it
127.0.0.1 www.liber9.it
127.0.0.1 liber9.it
127.0.0.1 www.liberdo.it
127.0.0.1 liberdo.it
127.0.0.1 www.libereo.it
127.0.0.1 libereo.it
127.0.0.1 www.liberfo.it
127.0.0.1 liberfo.it
127.0.0.1 www.libergo.it
127.0.0.1 libergo.it
127.0.0.1 www.liberko.it
127.0.0.1 liberko.it
127.0.0.1 www.liberl.it
127.0.0.1 liberl.it
127.0.0.1 www.liberlo.it
127.0.0.1 liberlo.it
127.0.0.1 www.libero0.it
127.0.0.1 libero0.it
127.0.0.1 www.libero9.it
127.0.0.1 libero9.it
127.0.0.1 www.liberoi.it
127.0.0.1 liberoi.it
127.0.0.1 www.liberok.it
127.0.0.1 liberok.it
127.0.0.1 www.liberol.it
127.0.0.1 liberol.it
127.0.0.1 www.liberop.it
127.0.0.1 liberop.it
127.0.0.1 www.liberpo.it
127.0.0.1 liberpo.it
127.0.0.1 www.liberro.it
127.0.0.1 liberro.it
127.0.0.1 libertyonlinehosting.com
127.0.0.1 www.libesro.it
127.0.0.1 libesro.it
127.0.0.1 www.libetro.it
127.0.0.1 libetro.it
127.0.0.1 www.libewro.it
127.0.0.1 libewro.it
127.0.0.1 www.libfero.it
127.0.0.1 libfero.it
127.0.0.1 www.libfro.it
127.0.0.1 libfro.it
127.0.0.1 www.libgero.it
127.0.0.1 libgero.it
127.0.0.1 www.libhero.it
127.0.0.1 libhero.it
127.0.0.1 www.libnero.it
127.0.0.1 libnero.it
127.0.0.1 www.libreo.it
127.0.0.1 libreo.it
127.0.0.1 www.librero.it
127.0.0.1 librero.it
127.0.0.1 www.libsero.it
127.0.0.1 libsero.it
127.0.0.1 www.libsro.it
127.0.0.1 libsro.it
127.0.0.1 www.libvero.it
127.0.0.1 libvero.it
127.0.0.1 www.libwero.it
127.0.0.1 libwero.it
127.0.0.1 www.libwro.it
  • 0

#8
Kizzy

Kizzy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
The DSs extra.txt report did not open and I tried it 3 times. Here is the DSS main.txt report.

Deckard's System Scanner v20071014.68
Run by Kirsten on 2008-02-29 19:39:22
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 254 MiB (512 MiB recommended).


-- HijackThis (run as Kirsten.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:39:45 PM, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Kirsten\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Kirsten.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec....000030.0000010e
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2f...earch.html?p=KL
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.co...ALStreaming.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1172946596421
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...224/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O21 - SSODL: bdmanager - {DC027BDA-0C73-459B-A461-C984940276F1} - C:\WINDOWS\bdmanager.dll (file missing)
O21 - SSODL: bxlrvps - {E32133B8-BFB6-4DF5-A308-51AF9F0E1C47} - C:\WINDOWS\bxlrvps.dll (file missing)
O21 - SSODL: alofkmn - {840C24E6-87BB-4FDB-9F13-408A22B512D0} - C:\WINDOWS\alofkmn.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 11266 bytes

-- Files created between 2008-01-29 and 2008-02-29 -----------------------------

2008-02-28 18:53:45 8576 --a------ C:\WINDOWS\system32\drivers\grjtxmrodgbg.sys <Not Verified; Panda Software International; RKPavProc Driver>
2008-02-28 18:29:15 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-02-28 09:43:54 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-02-28 09:43:53 0 d-------- C:\Documents and Settings\Kirsten\Application Data\SUPERAntiSpyware.com
2008-02-28 09:43:16 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 18:32:29 0 d-------- C:\Documents and Settings\Kirsten\Application Data\Grisoft
2008-02-10 22:59:06 0 d-------- C:\Program Files\SpywareBlaster
2008-02-10 22:29:28 0 d-------- C:\Program Files\SpywareGuard
2008-02-10 10:26:25 4214 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-10 10:24:43 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-10 10:24:43 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-02-10 10:24:43 85504 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-02-10 10:24:43 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-02-10 10:24:43 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-02-10 10:24:43 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-02-10 10:24:43 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-06 19:48:26 0 d-------- C:\Program Files\Alwil Software
2008-02-06 16:37:17 0 d-------- C:\WINDOWS\McAfee.com
2008-02-05 17:35:41 0 d-------- C:\Documents and Settings\Guest\Application Data\ultra
2008-02-03 21:17:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-02 14:34:36 0 d-------- C:\Program Files\Common Files\Java
2008-02-02 13:40:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-30 22:21:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-30 09:49:41 0 d-------- C:\Documents and Settings\Guest\Application Data\Grisoft
2008-01-29 23:38:46 0 d-------- C:\Program Files\Trend Micro


-- Find3M Report ---------------------------------------------------------------

2008-02-29 13:06:09 4060 --a----c- C:\Documents and Settings\Kirsten\Application Data\wklnhst.dat
2008-02-28 18:52:56 0 d-------- C:\Program Files\iTunes
2008-02-28 18:52:32 0 d-------- C:\Program Files\DellSupport
2008-02-28 18:51:35 0 d-------- C:\Program Files\Digital Line Detect
2008-02-28 09:43:16 0 d-------- C:\Program Files\Common Files
2008-02-12 12:52:28 0 d-------- C:\Program Files\QuickTime
2008-02-03 23:33:24 0 d-------- C:\Program Files\Google
2008-02-02 14:37:29 0 d-------- C:\Program Files\Java
2008-01-31 00:36:35 0 d-------- C:\Program Files\America Online 9.0
2008-01-28 10:18:07 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-01-27 05:34:10 0 d-------- C:\Program Files\iPod
2008-01-26 06:21:53 0 d-------- C:\Program Files\Dell Support Center
2008-01-26 06:21:19 0 d-------- C:\Program Files\Common Files\supportsoft
2008-01-04 23:22:08 2984 --a------ C:\cc_20080104_2321.reg
2008-01-04 22:58:37 8772 --a------ C:\cc_20080104_2258.reg
2008-01-04 22:58:08 266458 --a------ C:\cc_20080104_2257.reg
2008-01-04 22:03:07 0 d-------- C:\Program Files\Citrix
2008-01-04 14:20:58 3072 --a----c- C:\Documents and Settings\Kirsten\Application Data\dvd.bmk
2008-01-01 12:25:57 0 d-------- C:\Documents and Settings\Kirsten\Application Data\GRETECH
2008-01-01 12:25:20 0 d-------- C:\Program Files\GRETECH
2008-01-01 03:32:50 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-01 01:59:52 0 d-------- C:\Documents and Settings\Kirsten\Application Data\CyberLink
2007-12-31 23:36:40 0 d-------- C:\Documents and Settings\Kirsten\Application Data\WinRAR
2007-12-11 12:15:40 47360 --a------ C:\Documents and Settings\Kirsten\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2007-12-11 12:15:40 55 --a------ C:\Documents and Settings\Kirsten\Application Data\pcouffin.log
2007-12-11 12:15:40 1144 --a------ C:\Documents and Settings\Kirsten\Application Data\pcouffin.inf
2007-12-11 12:15:40 7887 --a------ C:\Documents and Settings\Kirsten\Application Data\pcouffin.cat
2007-12-10 21:47:41 3350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-12-10 21:47:23 88 -r-hs---- C:\WINDOWS\system32\9B8DD435AC.sys


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [07/21/2006 04:19 PM]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [10/26/2007 03:42 PM]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [10/14/2003 10:22 AM]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [04/14/2004 02:46 PM]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [04/14/2004 03:04 PM]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe" [05/25/2004 09:16 AM]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [07/20/2004 09:34 AM]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [10/14/2004 06:42 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 09:44 AM]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [06/10/2005 09:44 AM]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [10/05/2005 02:12 AM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 09:24 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [01/15/2008 03:22 AM]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 AM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [12/04/2007 07:00 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [01/31/2008 11:13 PM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 03:25 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 10:09 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:00 AM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 10:24 AM]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [11/15/2007 09:23 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [02/03/2008 09:17 PM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/27/2007 11:39 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
@=C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec....000030.0000010e
"FlashPlayerUpdate"=C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe

C:\Documents and Settings\Kirsten\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 7:05:35 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [8/2/2006 7:09:24 PM]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2/3/2008 9:17:29 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 12:01:04 AM]
Status Monitor.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1/19/2007 7:27:14 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdmanager"= {DC027BDA-0C73-459B-A461-C984940276F1} - C:\WINDOWS\bdmanager.dll [ ]
"bxlrvps"= {E32133B8-BFB6-4DF5-A308-51AF9F0E1C47} - C:\WINDOWS\bxlrvps.dll [ ]
"alofkmn"= {840C24E6-87BB-4FDB-9F13-408A22B512D0} - C:\WINDOWS\alofkmn.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 02/27/2007 11:39 AM 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll 01/04/2008 10:02 PM 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)




-- End of Deckard's System Scanner: finished at 2008-02-29 19:40:34 ------------
  • 0

#9
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Hi Kizzy

.......because my post was too long and I had to break them up.

yep, it was a long one!

The DSs extra.txt report did not open and I tried it 3 times. Here is the DSS main.txt report.

we will run a full report later, i guess you have run DSS before.

in this post we will restore your hosts file, clear away the malware traces, flush your temp folders and do a couple of scans to see what else is on your machine.

the scans will likely take over 2 hours, so just let them run

firstly:
While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.


====STEP 1====
Download the HostsXpert 4.2 - Hosts File Manager.
  • Unzip HostsXpert 4.2 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.2 - Hosts File Manager
  • Run HostsXpert 4.2 - Hosts File Manager from its new home
  • Click on "File Handling".
  • Click on "Restore MS Hosts File".
  • Click OK on the Confirmation box.
  • Click on "Make Read Only?"
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

====STEP 2====
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O21 - SSODL: bdmanager - {DC027BDA-0C73-459B-A461-C984940276F1} - C:\WINDOWS\bdmanager.dll (file missing)
O21 - SSODL: bxlrvps - {E32133B8-BFB6-4DF5-A308-51AF9F0E1C47} - C:\WINDOWS\bxlrvps.dll (file missing)
O21 - SSODL: alofkmn - {840C24E6-87BB-4FDB-9F13-408A22B512D0} - C:\WINDOWS\alofkmn.dll (file missing)

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.


====STEP 3====
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


====STEP 4====
i see you already have SUPERantispyware on your machine, therefore:

Double-click the SUPERantispyware icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.


====STEP 5====
Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


In your next reply could i see:
1. the SUPERantispyware log
2. the kaspersky scan log
3. a new hijackthis log

there may be a lot of information to post, so you may have to post it over more than one reply to ensure it is all posted.

andrewuk
  • 0

#10
Kizzy

Kizzy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Hi andrewuk, Here are my reports

SUPERAntiSpyware Scan Log
Generated 03/01/2008 at 12:52 PM

Application Version : 3.6.1000

Core Rules Database Version : 3412
Trace Rules Database Version: 1404

Scan type : Complete Scan
Total Scan Time : 01:28:44

Memory items scanned : 549
Memory threats detected : 0
Registry items scanned : 6007
Registry threats detected : 0
File items scanned : 61153
File threats detected : 2

Adware.SXGAdvisor
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP32\A0008926.DLL

Trojan.Smitfraud Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP32\A0008929.DLL

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, March 01, 2008 2:49:08 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 1/03/2008
Kaspersky Anti-Virus database records: 592387
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 62327
Number of viruses found: 3
Number of infected objects: 10
Number of suspicious objects: 0
Duration of the scan process: 00:59:43

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SupportSoft\DellSupportCenter\SYSTEM\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\Kirsten\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Kirsten\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Documents and Settings\Kirsten\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Documents and Settings\Kirsten\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Documents and Settings\Kirsten\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\Kirsten\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Kirsten\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Kirsten\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Kirsten\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Kirsten\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Kirsten\Local Settings\Application Data\ApplicationHistory\sprtcmd.exe.63e7480d.ini.inuse Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Application Data\SupportSoft\DellSupportCenter\Kirsten\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\History\History.IE5\MSHist012008030120080302\index.dat Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Temp\Perflib_Perfdata_ac0.dat Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Temp\~DF15FB.tmp Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Temp\~DF4DBA.tmp Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Temp\~DF9299.tmp Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Kirsten\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kirsten\ntuser.dat Object is locked skipped
C:\Documents and Settings\Kirsten\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0008825.exe Infected: Trojan-Downloader.Win32.Zlob.ijy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0008850.exe Infected: Trojan-Downloader.Win32.Zlob.ijy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0008869.exe Infected: Trojan-Downloader.Win32.Zlob.ijy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0008903.exe Infected: Trojan-Downloader.Win32.Zlob.ijy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP32\A0008923.exe Infected: Trojan-Downloader.Win32.Zlob.ijy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP33\A0009051.dll Infected: Trojan-Downloader.Win32.Agent.jnw skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP33\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{9FF29387-A03B-49C8-A2DD-003E5F6DDF63}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\Perflib_Perfdata_5bc.dat Object is locked skipped
C:\WINDOWS\TEMP\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:51:27 PM, on 3/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec....000030.0000010e
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2f...earch.html?p=KL
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.co...ALStreaming.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1172946596421
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...224/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 10929 bytes
  • 0

Advertisements


#11
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
your logs are looking much better

the scans did not find anything that was not already quarantined or in a restore point (we will clear those at the end).

in this post i just want to do a final quick scan and get a full Deckard Systam Scan report before i give the all clear.

====STEP 1====
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


====STEP 2====
click on Start, click on Run
copy and paste the following in bold in the open window and then click OK
"%userprofile%\desktop\dss.exe" /config
This will open up DSS configuration
click on Check All
click Scan
DSS will now run again when finished
Please post back both logs that open in notepad
Main txt and extra txt


In your next reply could i see:
1. the malwarebytes log
2. the 2 DSS logs
3. some idea of how your machine is running now

there may be a lot of information to post, so you may have to post it over more than one reply to ensure it is all posted.

andrewuk
  • 0

#12
Kizzy

Kizzy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Hello andrewuk,
My computer is working better now. No pop ups or anything. :)
Here are my logs

Malwarebytes' Anti-Malware 1.05
Database version: 436

Scan type: Quick Scan
Objects scanned: 32130
Time elapsed: 12 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 18
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\emotigt.btsg (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\emotigt.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{049104e8-61e2-4a8c-9740-0189ea316d3f} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e00993b6-ae8d-40d8-9c52-68ced46ae659} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{6ef2961d-c224-4745-8b7b-3936988427a6} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ekvgsnw.bdxp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ekvgsnw.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{60570909-486a-4609-b7ae-cbcaa3831168} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{004400ef-1efb-4d04-953e-a33c8cac377b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{84adc82a-618e-4391-a720-4771efff5da2} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{2d303d62-6320-4aa8-8140-9a424d5cc1e1} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2125299c-378e-4065-a925-17fae942cba9} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{5d8d43c8-6331-4207-bb5e-8e3e9f5f2cd6} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\emotigt.btsg (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\emotigt.ToolBar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ekvgsnw.bdxp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ekvgsnw.ToolBar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Guest\Application Data\ultra (Rogue.Multiple) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)

extra.txt
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Celeron® CPU 2.53GHz
Percentage of Memory in Use: 76%
Physical Memory (total/avail): 253.98 MiB / 58.67 MiB
Pagefile Memory (total/avail): 3640.93 MiB / 3111.55 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1922.21 MiB

C: is Fixed (NTFS) - 52.7 GiB total, 30.38 GiB free.
D: is Fixed (NTFS) - 18.05 GiB total, 17.98 GiB free.
E: is CDROM (No Media)
F: is Removable (No Media)

\\.\PHYSICALDRIVE0 - HDS728080PLAT20 - 74.5 GiB - 4 partitions
\PARTITION0 - Unknown - 39.19 MiB
\PARTITION1 (bootable) - Installable File System - 52.7 GiB - C:
\PARTITION2 - Installable File System - 18.05 GiB - D:
\PARTITION3 - Unknown - 3.71 GiB

\\.\PHYSICALDRIVE1 - Brother MFC-210C USB Device



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

AV: avast! antivirus 4.7.1098 [VPS 080301-0] v4.7.1098 (ALWIL Software)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Kirsten\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_04\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=DAVISFAMILY
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Kirsten
LOGONSERVER=\\DAVISFAMILY
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\QuickTime\QTSystem;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0409
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_04\lib\ext\QTJava.zip
SESSIONNAME=Console
SonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Kirsten\LOCALS~1\Temp
TMP=C:\DOCUME~1\Kirsten\LOCALS~1\Temp
USERDOMAIN=DAVISFAMILY
USERNAME=Kirsten
USERPROFILE=C:\Documents and Settings\Kirsten
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Kirsten (admin)
Administrator (admin)
Guest (guest)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\PROGRA~1\Yahoo!\Common\unyt.exe
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
--> MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
--> MsiExec.exe /I{8A42F680-2DD6-11D4-9A8C-0040F6982C20}
--> MsiExec.exe /I{A2529672-574A-4A99-86A5-C1770A0E31FE}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
America Online (Choose which version to remove) --> C:\Program Files\Common Files\aolshare\Aolunins_us.exe
AOL Coach Version 1.0(Build:20040229.1 en) --> C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe
AOL Connectivity Services --> C:\PROGRA~1\COMMON~1\AOL\ACS\AcsUninstall.exe /c
AOLIcon --> MsiExec.exe /I{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}
Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
AT&T Yahoo! Applications --> C:\PROGRA~1\Yahoo!\common\uninstall.exe
avast! Antivirus --> rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup
AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
Banctec Service Agreement --> MsiExec.exe /X{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}
Brother MFL-Pro Suite --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40A6C96D-808E-41DD-8716-617AB6B0F1F1}\Setup.exe" -l0x9 Brunin03.dllBrunin03.dll
CleanUp! --> C:\Program Files\CleanUp!\uninstall.exe
Conexant D850 56K V.9x DFVc Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE -U -Idel200fk.inf
Corel Photo Album 6 --> MsiExec.exe /X{8A9B8148-DDD7-448F-BD6C-358386D32354}
Dell CinePlayer --> MsiExec.exe /I{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}
Dell Digital Jukebox Driver --> C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Driver Reset Tool --> MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
Dell Game Console --> "C:\Program Files\WildTangent\Apps\Dell Game Console\Uninstall.exe"
Dell Support Center --> MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
DellConnect --> MsiExec.exe /X{52D56C42-8C69-4882-A661-39695537C9CF}
DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
Digital Content Portal --> MsiExec.exe /I{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}
Digital Line Detect --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
Documentation & Support Launcher --> MsiExec.exe /X{B0DF58A2-40DF-4465-AA56-38623EC9938C}
EducateU --> MsiExec.exe /I{A683A2C0-821C-486F-858C-FA634DB5E864}
ELIcon --> MsiExec.exe /I{4667B940-BB01-428B-986E-A0CC46497BF7}
Games, Music, & Photos Launcher --> MsiExec.exe /X{B6884A07-0305-47AE-9969-8F26FADC17DE}
Get High Speed Internet! --> MsiExec.exe /I{7A3F0566-5E05-4919-9C98-456F6B5CF831}
GOM Player --> "C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
GoToAssist 8.0.0.480 --> C:\Program Files\Citrix\GoToAssist\480\G2AUninstaller.exe /uninstall
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Intel® Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
Intel® PRO Network Adapters and Drivers --> Prounstl.exe
Intel® PROSet for Wired Connections --> MsiExec.exe /I{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}
iTunes --> MsiExec.exe /I{B85C4D19-6CEB-48CF-BD98-C887AC8C6F94}
Java™ 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Kaspersky Online Scanner --> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
LimeWire 4.14.10 --> "C:\Program Files\LimeWire\uninstall.exe"
Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MCU --> MsiExec.exe /I{D2988E9B-C73F-422C-AD4B-A66EBE257120}
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Digital Image Standard 2006 --> "C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=PREM VERSION=11
Microsoft Encarta Encyclopedia Standard 2006 --> MsiExec.exe /I{06040048-3E21-46D6-9A91-D927BA08F41D}
Microsoft Money 2006 --> "C:\Program Files\Microsoft Money 2006\MNYCoreFiles\Setup\uninst.exe" /s:120
Microsoft Plus! Digital Media Edition Installer --> MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Plus! Photo Story 2 LE --> MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
Microsoft Streets & Trips 2006 --> MsiExec.exe /I{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Word 2002 --> MsiExec.exe /I{911B0409-6000-11D3-8CFE-0050048383C9}
Microsoft Works --> MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
Microsoft Works Suite 2006 Setup Launcher --> C:\Program Files\Microsoft Works Suite 2006\Setup\Launcher.exe /ARP E:\
Microsoft Works Suite Add-in for Microsoft Word --> MsiExec.exe /I{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}
Modem Helper --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Move Networks Player for Internet Explorer --> "C:\Documents and Settings\Kirsten\Application Data\Move Networks\ie_bin\unins000.exe"
MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
Musicmatch® Jukebox --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst
NetWaiting --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
PaperPort --> MsiExec.exe /I{A17EABB6-D0C6-44E5-820C-72DC7F495064}
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Roxio DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Roxio RecordNow Audio --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Roxio RecordNow Copy --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Roxio RecordNow Data --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Search Assist --> MsiExec.exe /X{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Sonic Activation Module --> MsiExec.exe /I{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}
Sonic Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster v3.5.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 --> "C:\Program Files\SpywareGuard\unins000.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Talking Typing Teacher --> C:\WINDOWS\uninst.exe -f"C:\Program Files\Cosmi\Talking Typing Teacher\DeIsL1.isu" -c"C:\Program Files\Cosmi\Talking Typing Teacher\_ISREG32.DLL"
URL Assistant --> regsvr32 /u /s "C:\Program Files\BAE\BAE.dll"
WebCyberCoach 3.2 Dell --> "C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type15366 / Error
Event Submitted/Written: 02/29/2008 07:40:11 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The specified server cannot perform the requested operation.

Event Record #/Type15365 / Error
Event Submitted/Written: 02/29/2008 07:40:11 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The specified server cannot perform the requested operation.

Event Record #/Type15364 / Error
Event Submitted/Written: 02/29/2008 07:40:10 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The specified server cannot perform the requested operation.

Event Record #/Type15363 / Error
Event Submitted/Written: 02/29/2008 07:40:10 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The specified server cannot perform the requested operation.

Event Record #/Type15362 / Error
Event Submitted/Written: 02/29/2008 07:40:10 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: The specified server cannot perform the requested operation.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type37652 / Error
Event Submitted/Written: 03/01/2008 04:29:44 PM
Event ID/Source: 7016 / Service Control Manager
Event Description:
The BrSplService service has reported an invalid current state 0.

Event Record #/Type37650 / Error
Event Submitted/Written: 03/01/2008 03:29:08 PM
Event ID/Source: 6161 / Print
Event Description:
The document http://www.carmax.co...p...eet&bPrint= owned by Kirsten failed to print on printer Brother MFC-210C USB Printer. Data type: NT EMF 1.008. Size of the spool file in bytes: 12908288. Number of bytes printed: 835936. Total number of pages in the document: 3. Number of pages printed: 0. Client machine: \\DAVISFAMILY. Win32 error code returned by the print processor: http://www.carmax.co...p...et&bPrint=0. http://www.carmax.co...p...et&bPrint=1

Event Record #/Type37649 / Error
Event Submitted/Written: 03/01/2008 03:25:59 PM
Event ID/Source: 6161 / Print
Event Description:
The document http://www.carmax.co...p...eet&bPrint= owned by Kirsten failed to print on printer Brother MFC-210C USB Printer. Data type: NT EMF 1.008. Size of the spool file in bytes: 15529728. Number of bytes printed: 7542624. Total number of pages in the document: 3. Number of pages printed: 0. Client machine: \\DAVISFAMILY. Win32 error code returned by the print processor: http://www.carmax.co...p...et&bPrint=0. http://www.carmax.co...p...et&bPrint=1

Event Record #/Type37648 / Warning
Event Submitted/Written: 03/01/2008 03:24:48 PM
Event ID/Source: 8 / Print
Event Description:
Printer Brother MFC-210C USB Printer was purged.

Event Record #/Type37647 / Warning
Event Submitted/Written: 03/01/2008 03:24:11 PM
Event ID/Source: 8 / Print
Event Description:
Printer Brother MFC-210C USB Printer was purged.



-- End of Deckard's System Scanner: finished at 2008-03-01 16:31:27 ------------

main.txt
Deckard's System Scanner v20071014.68
Run by Kirsten on 2008-03-01 16:28:30
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
5: 2008-03-01 22:28:44 UTC - RP35 - Deckard's System Scanner Restore Point
4: 2008-03-01 20:29:40 UTC - RP34 - System Checkpoint
3: 2008-02-29 20:23:24 UTC - RP33 - System Checkpoint
2: 2008-02-28 15:43:49 UTC - RP32 - Installed SUPERAntiSpyware Free Edition
1: 2008-02-28 00:16:47 UTC - RP31 - New Geeks to go restore point


Performed disk cleanup.

Percentage of Memory in Use: 90% (more than 75%).
Total Physical Memory: 254 MiB (512 MiB recommended).


-- HijackThis (run as Kirsten.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:29:11 PM, on 3/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Kirsten\desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Kirsten.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec....000030.0000010e
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2f...earch.html?p=KL
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.co...ALStreaming.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1172946596421
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...224/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 10934 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080203-161709-168 O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
backup-20080203-161709-250 O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
backup-20080203-161709-947 O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
backup-20080301-111648-333 O21 - SSODL: bdmanager - {DC027BDA-0C73-459B-A461-C984940276F1} - C:\WINDOWS\bdmanager.dll (file missing)
backup-20080301-111649-452 O21 - SSODL: bxlrvps - {E32133B8-BFB6-4DF5-A308-51AF9F0E1C47} - C:\WINDOWS\bxlrvps.dll (file missing)
backup-20080301-111649-920 O21 - SSODL: alofkmn - {840C24E6-87BB-4FDB-9F13-408A22B512D0} - C:\WINDOWS\alofkmn.dll (file missing)

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
R3 DSproct - c:\program files\dellsupport\gtaction\triggers\dsproct.sys <Not Verified; Gteko Ltd.; processt>
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>

S3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
S3 SDTHOOK - c:\windows\system32\drivers\sdthook.sys <Not Verified; Panda Software; Panda® Antivirus>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 sprtsvc_dellsupportcenter (SupportSoft Sprocket Service (dellsupportcenter)) - c:\program files\dell support center\bin\sprtsvc.exe /service /p dellsupportcenter

S3 YPCService - c:\windows\system32\ypcser~1.exe <Not Verified; Yahoo! Inc.; YPCService Module>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Process Modules -------------------------------------------------------------

C:\WINDOWS\system32\winlogon.exe (pid 632)
2007-02-27 11:39:26 282624 --a------ C:\Program Files\SUPERAntiSpyware\SASWINLO.dll <Not Verified; SUPERAntiSpyware.com; SUPERAntiSpyware WinLogon Processor>

C:\WINDOWS\explorer.exe (pid 1328)
2006-12-20 12:55:48 77824 --a------ C:\Program Files\SUPERAntiSpyware\SASSEH.DLL <Not Verified; SuperAdBlocker.com; SuperAntiSpyware>


-- Scheduled Tasks -------------------------------------------------------------

2008-02-29 10:16:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-02-18 20:00:00 626 --a------ C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Kirsten.job


-- Files created between 2008-02-01 and 2008-03-01 -----------------------------

2008-03-01 15:55:59 0 d-------- C:\Documents and Settings\Kirsten\Application Data\Malwarebytes
2008-03-01 15:55:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-01 15:55:45 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-01 13:27:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-01 13:27:24 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-01 13:27:21 0 d-------- C:\WINDOWS\LastGood
2008-02-28 18:53:45 8576 --a------ C:\WINDOWS\system32\drivers\grjtxmrodgbg.sys <Not Verified; Panda Software International; RKPavProc Driver>
2008-02-28 18:29:15 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-02-28 09:43:54 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-02-28 09:43:53 0 d-------- C:\Documents and Settings\Kirsten\Application Data\SUPERAntiSpyware.com
2008-02-28 09:43:16 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 18:32:29 0 d-------- C:\Documents and Settings\Kirsten\Application Data\Grisoft
2008-02-10 22:59:06 0 d-------- C:\Program Files\SpywareBlaster
2008-02-10 22:29:28 0 d-------- C:\Program Files\SpywareGuard
2008-02-10 10:26:25 4214 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-10 10:24:43 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-10 10:24:43 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-02-10 10:24:43 85504 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-02-10 10:24:43 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-02-10 10:24:43 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-02-10 10:24:43 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-02-10 10:24:43 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-06 19:48:26 0 d-------- C:\Program Files\Alwil Software
2008-02-06 16:37:17 0 d-------- C:\WINDOWS\McAfee.com
2008-02-03 21:17:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-02 14:34:36 0 d-------- C:\Program Files\Common Files\Java
2008-02-02 13:40:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7


-- Find3M Report ---------------------------------------------------------------

2008-03-01 16:09:45 0 d-------- C:\Program Files\Common Files
2008-02-29 13:06:09 4060 --a----c- C:\Documents and Settings\Kirsten\Application Data\wklnhst.dat
2008-02-28 18:52:56 0 d-------- C:\Program Files\iTunes
2008-02-28 18:52:32 0 d-------- C:\Program Files\DellSupport
2008-02-28 18:51:35 0 d-------- C:\Program Files\Digital Line Detect
2008-02-12 12:52:28 0 d-------- C:\Program Files\QuickTime
2008-02-03 23:33:24 0 d-------- C:\Program Files\Google
2008-02-02 14:37:29 0 d-------- C:\Program Files\Java
2008-01-31 00:36:35 0 d-------- C:\Program Files\America Online 9.0
2008-01-29 23:38:46 0 d-------- C:\Program Files\Trend Micro
2008-01-28 10:18:07 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-01-27 05:34:10 0 d-------- C:\Program Files\iPod
2008-01-26 06:21:53 0 d-------- C:\Program Files\Dell Support Center
2008-01-26 06:21:19 0 d-------- C:\Program Files\Common Files\supportsoft
2008-01-04 23:22:08 2984 --a------ C:\cc_20080104_2321.reg
2008-01-04 22:58:37 8772 --a------ C:\cc_20080104_2258.reg
2008-01-04 22:58:08 266458 --a------ C:\cc_20080104_2257.reg
2008-01-04 22:03:07 0 d-------- C:\Program Files\Citrix
2008-01-04 14:20:58 3072 --a----c- C:\Documents and Settings\Kirsten\Application Data\dvd.bmk
2008-01-01 12:25:57 0 d-------- C:\Documents and Settings\Kirsten\Application Data\GRETECH
2008-01-01 12:25:20 0 d-------- C:\Program Files\GRETECH
2008-01-01 03:32:50 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-01 01:59:52 0 d-------- C:\Documents and Settings\Kirsten\Application Data\CyberLink
2007-12-11 12:15:40 47360 --a------ C:\Documents and Settings\Kirsten\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2007-12-11 12:15:40 55 --a------ C:\Documents and Settings\Kirsten\Application Data\pcouffin.log
2007-12-11 12:15:40 1144 --a------ C:\Documents and Settings\Kirsten\Application Data\pcouffin.inf
2007-12-11 12:15:40 7887 --a------ C:\Documents and Settings\Kirsten\Application Data\pcouffin.cat
2007-12-10 21:47:41 3350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-12-10 21:47:23 88 -r-hs---- C:\WINDOWS\system32\9B8DD435AC.sys


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [07/21/2006 04:19 PM]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [10/26/2007 03:42 PM]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [10/14/2003 10:22 AM]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [04/14/2004 02:46 PM]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [04/14/2004 03:04 PM]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe" [05/25/2004 09:16 AM]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [07/20/2004 09:34 AM]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [10/14/2004 06:42 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 09:44 AM]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [06/10/2005 09:44 AM]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [10/05/2005 02:12 AM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 09:24 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [01/15/2008 03:22 AM]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 AM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [12/04/2007 07:00 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [01/31/2008 11:13 PM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 03:25 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 10:09 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:00 AM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 10:24 AM]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [11/15/2007 09:23 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [02/03/2008 09:17 PM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/27/2007 11:39 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
@=C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec....000030.0000010e

C:\Documents and Settings\Kirsten\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 7:05:35 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [8/2/2006 7:09:24 PM]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2/3/2008 9:17:29 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 12:01:04 AM]
Status Monitor.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1/19/2007 7:27:14 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 02/27/2007 11:39 AM 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll 01/04/2008 10:02 PM 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)




-- End of Deckard's System Scanner: finished at 2008-03-01 16:31:27 ------------
  • 0

#13
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Hi Kizzy

congratulations, your files are clean :)

in this post we will reset your restore points and i will leave you with some ideas on how to enhance the protection of your machine against future infection.

you can delete all the tools we used in the fix.

====STEP 1====
To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

Instructions with screenshots to help is http://www.f-secure..../sfc_dis1.shtml

(Windows XP)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

How to Turn On and Turn Off System Restore in Windows XP
http://support.microsoft.com/kb/310405


====AND FINALLY====
The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  • Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
  • AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  • SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  • SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  • IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
  • Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein


andrewuk
  • 0

#14
Kizzy

Kizzy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Ok I followed your instructions and turned off system restore, reboot my computer and turned it on again. My computer is working much better now. Thank you for your help! :)
Is it ok to have Spybot Search & Destroy, AdAware, SpywareBlaster, and SpywareGuard on my computer all at once? Can too much Spyware protection be harmful to my computer? I also have Avast Antivirus Software. Is this a good antivirus software?

Edited by Kizzy, 01 March 2008 - 05:54 PM.

  • 0

#15
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts

Is it ok to have Spybot Search & Destroy, AdAware, SpywareBlaster, and SpywareGuard on my computer all at once? Can too much Spyware protection be harmful to my computer? I also have Avast Antivirus Software. Is this a good antivirus software?

yes. Spybot Search & Destroy and AdAware are on-demand protection. SpywareBlaster and SpywareGuard work well together.

Avast antivirus is as good as any in my mind :)

andrewuk
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP