Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Winfixer, 888.com and other popups - please HELP!


  • Please log in to reply

#16
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Download Pocket KillBox from here:
http://www.atribune....ads/KillBox.exe

Highlight the list below and press Ctrl+C to Copy

C:\WINDOWS\ptMpk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Update.hta


Open Pocket Killbox-> Click File-> Click Paste from Clipboard

Place a tick by Delete on Reboot-> Click the Red Circle to Delete

Click Yes to the Prompts that follow and let Killbox Reboot the PC


Restart in Safe Mode and Run each of those entries through Killbox again,one at a time.

As you paste each entry into Killbox,place a tick by these 2 selections

"Standard File Kill"
"End Explorer Shell while Killing File"


Click the Red Circle with the White X in the Middle to Delete


Open HijackThis and put a check by these but DO NOT hit the Fix Checked button yet

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchPage = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchPage = about:blank

O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\sstrs.dll (file missing)

O4 - Global Startup: Windows Update.hta

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender OnlineScanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)


O20 - Winlogon Notify: sstrs - C:\WINDOWS\System32\sstrs.dll (file missing)

Now Make sure ALL WINDOWS and BROWSERS are CLOSED and hit the Fix Checked Button


Scan once more wirth WinPfind in Safe Mode.


Restart Normal and Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post along with results of WinPFind and fresh HijackThis log.

  • 0

Advertisements


#17
alighirl

alighirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Hello again Cretemonster and thanks for your patience.
I have pasted the results you requested below. When I ran Killbox in Safe Mode (ie after I had run it in Normal Mode) and tried to delete the ptMpk file, it said the file didn't exist. The Windows Update.hta was successfully deleted. Also, in Hijack This the '04-Global Startup: Windows Update.hta' wasn't there, but I found the rest and fixed them.

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, November 27, 2005 15:42:02
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 27/11/2005
Kaspersky Anti-Virus database records: 161826
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 74581
Number of viruses found: 4
Number of infected objects: 12
Number of suspicious objects: 0
Duration of the scan process: 3546 sec

Infected Object Name - Virus Name
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E6C0000.VBN Infected: Backdoor.Win32.IRCBot.ey
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E6C0001.VBN Infected: Backdoor.Win32.IRCBot.ey
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E6C0002.VBN Infected: Backdoor.Win32.IRCBot.ey
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E6C0003.VBN Infected: Backdoor.Win32.IRCBot.ey
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E6C0004.VBN Infected: Backdoor.Win32.IRCBot.ey
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E6C0005.VBN Infected: Backdoor.Win32.IRCBot.ey
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0E6C0006.VBN Infected: Backdoor.Win32.IRCBot.ey
C:\Documents and Settings\User\Desktop\alighirl1.cab/C:/WINDOWS/System32/sstrs.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.t
C:\Documents and Settings\User\Desktop\alighirl1.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.t
C:\System Volume Information\_restore{53CA11E8-DAD2-41B2-969B-D957F085F140}\RP23\A0003820.exe Infected: not-a-virus:AdWare.Win32.SurfAccuracy.d
C:\System Volume Information\_restore{53CA11E8-DAD2-41B2-969B-D957F085F140}\RP28\A0009687.exe Infected: Trojan.Win32.StartPage.zm
C:\System Volume Information\_restore{53CA11E8-DAD2-41B2-969B-D957F085F140}\RP30\A0016252.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.t

Scan process completed.

--------------------------------------------------------------------------------------------------------------------------

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
UPX! 11/09/2005 19:14:28 3089053 C:\WINDOWS\sls_screensaver.scr
UPX! 24/06/2005 16:44:18 24064 C:\WINDOWS\Uninstall Plasma.exe

Checking %System% folder...
PEC2 31/03/2003 02:00:00 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PTech 04/11/2005 16:27:24 534280 C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2 02/11/2005 10:49:02 2368864 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 02/11/2005 10:49:02 2368864 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 04/08/2004 07:56:36 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor 04/08/2004 07:56:44 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 31/03/2003 02:00:00 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...
PTech 04/08/2004 05:41:38 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
27/11/2005 13:53:44 S 2048 C:\WINDOWS\bootstat.dat
22/11/2005 13:07:16 H 54156 C:\WINDOWS\QTFont.qfn
21/11/2005 03:11:34 H 66752 C:\WINDOWS\Minidump\Mini112105-01.dmp
21/11/2005 12:53:20 H 66752 C:\WINDOWS\Minidump\Mini112105-02.dmp
21/11/2005 13:08:58 H 66752 C:\WINDOWS\Minidump\Mini112105-03.dmp
22/11/2005 00:14:32 H 66752 C:\WINDOWS\Minidump\Mini112205-01.dmp
22/11/2005 01:14:54 H 66752 C:\WINDOWS\Minidump\Mini112205-02.dmp
23/11/2005 19:14:38 H 66752 C:\WINDOWS\Minidump\Mini112305-01.dmp
24/11/2005 10:21:38 H 66752 C:\WINDOWS\Minidump\Mini112405-01.dmp
24/11/2005 11:22:22 H 66752 C:\WINDOWS\Minidump\Mini112405-02.dmp
24/11/2005 11:41:08 H 66752 C:\WINDOWS\Minidump\Mini112405-03.dmp
25/11/2005 03:17:54 H 66752 C:\WINDOWS\Minidump\Mini112505-01.dmp
25/11/2005 03:26:52 H 66752 C:\WINDOWS\Minidump\Mini112505-02.dmp
25/11/2005 11:51:20 H 66752 C:\WINDOWS\Minidump\Mini112505-03.dmp
25/11/2005 13:30:24 H 66752 C:\WINDOWS\Minidump\Mini112505-04.dmp
25/11/2005 14:05:50 H 66752 C:\WINDOWS\Minidump\Mini112505-05.dmp
25/11/2005 14:30:34 H 66752 C:\WINDOWS\Minidump\Mini112505-06.dmp
25/11/2005 15:10:52 H 66752 C:\WINDOWS\Minidump\Mini112505-07.dmp
25/11/2005 15:41:26 H 66752 C:\WINDOWS\Minidump\Mini112505-08.dmp
26/11/2005 03:09:36 H 66752 C:\WINDOWS\Minidump\Mini112605-01.dmp
26/11/2005 13:14:32 H 66752 C:\WINDOWS\Minidump\Mini112605-03.dmp
26/11/2005 15:15:26 H 66752 C:\WINDOWS\Minidump\Mini112605-04.dmp
26/11/2005 15:32:36 H 66752 C:\WINDOWS\Minidump\Mini112605-05.dmp
20/11/2005 19:07:24 RHS 305145 C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_70.cab
20/11/2005 19:17:52 RHS 68327 C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_71.cab
05/10/2005 20:33:38 S 12849 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896424.cat
05/10/2005 01:17:40 S 21737 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896688.cat
27/11/2005 13:53:34 H 8192 C:\WINDOWS\system32\config\default.LOG
27/11/2005 13:53:56 H 1024 C:\WINDOWS\system32\config\SAM.LOG
27/11/2005 13:53:46 H 16384 C:\WINDOWS\system32\config\SECURITY.LOG
27/11/2005 14:15:08 H 196608 C:\WINDOWS\system32\config\software.LOG
27/11/2005 13:53:50 H 1060864 C:\WINDOWS\system32\config\system.LOG
24/11/2005 22:18:30 H 1024 C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
20/11/2005 19:17:56 S 558 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735
20/11/2005 19:17:56 S 144 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735
27/11/2005 13:52:38 H 6 C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 04/08/2004 07:56:58 68608 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 04/08/2004 07:56:58 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 04/08/2004 07:56:58 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 04/08/2004 07:56:58 135168 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 04/08/2004 07:56:58 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 04/08/2004 07:56:58 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 04/08/2004 07:56:58 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 04/08/2004 07:56:58 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 04/08/2004 07:56:58 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 04/08/2004 07:56:58 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems, Inc. 26/08/2005 18:14:42 49265 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 31/03/2003 02:00:00 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 04/08/2004 07:56:58 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 31/03/2003 02:00:00 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 04/08/2004 07:56:58 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 04/08/2004 07:56:58 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 31/03/2003 02:00:00 36864 C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation 04/08/2004 07:56:58 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 04/08/2004 07:56:58 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
Microsoft Corporation 04/08/2004 07:56:58 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 31/03/2003 02:00:00 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 04/08/2004 07:56:58 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 04/08/2004 07:56:58 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 26/05/2005 03:16:30 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
19/06/2003 15:08:54 HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
26/05/2004 15:04:54 1730 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
19/06/2003 08:00:30 HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
17/10/2003 15:52:22 237 C:\Documents and Settings\All Users\Application Data\hpzinstall.log

Checking files in %USERPROFILE%\Startup folder...
19/06/2003 15:08:54 HS 84 C:\Documents and Settings\User\Start Menu\Programs\Startup\desktop.ini
22/11/2005 03:15:08 1088 C:\Documents and Settings\User\Start Menu\Programs\Startup\Ubisoft register.lnk

Checking files in %USERPROFILE%\Application Data folder...
19/06/2003 08:00:30 HS 62 C:\Documents and Settings\User\Application Data\desktop.ini
12/08/2005 17:29:08 33728 C:\Documents and Settings\User\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
SV1 =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\VirusScan
{cda2863e-2497-4c49-9b89-06840e070a87} = C:\Program Files\Network Associates\VirusScan\shext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ZFAdd
{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = C:\Program Files\WinAce\arcext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\VirusScan
{cda2863e-2497-4c49-9b89-06840e070a87} = C:\Program Files\Network Associates\VirusScan\shext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\VirusScan
{cda2863e-2497-4c49-9b89-06840e070a87} = C:\Program Files\Network Associates\VirusScan\shext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ZFAdd
{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = C:\Program Files\WinAce\arcext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
= C:\PROGRA~1\SPYBOT~1\SDHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}
ST = C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
MSNToolBandBHO = C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = MSN : C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText = Messenger : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}
Search Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = MSN : C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ATIPTA C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
Display Settings C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
QT4HPOT C:\Program Files\HPQ\One-Touch\OneTouch.EXE
SynTPLpr C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HPHUPD05 c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
HPHmon05 C:\WINDOWS\System32\hphmon05.exe
Cpqset C:\Program Files\HPQ\Default Settings\cpqset.exe
RoxioEngineUtility "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
RoxioDragToDisc "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
ShStatEXE "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
McAfeeUpdaterUI "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
HP Software Update C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
SunJavaUpdateSched C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ctfmon.exe C:\WINDOWS\system32\ctfmon.exe


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
system.ini 0
win.ini 0
bootini 0
services 0
startup 0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 27/11/2005 14:22:48

-----------------------------------------------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 16:00:02, on 27/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = svrstandrew2.w-dunbarton.sch.uk:8002
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Ubisoft register.lnk = C:\Program Files\Ubisoft\Register\schedule.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
  • 0

#18
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Looks like you got it all that time.

Go ahead and manually delete

C:\Documents and Settings\User\Desktop\alighirl1.cab

C:\!Killbox

Please Install these 2 to add to the Security of the PC!

SpywareBlaster:
http://www.javacools...areblaster.html
Update Immediatly!

WinHelp2002 Hosts File
http://www.mvps.org/...2002/hosts2.htm

Disable System Restore
http://service1.syma...src=sec_doc_nam

Go ahead and Reconfigure Msconfig the way you like the PC to Startup!

Go ahead and remove any of the tools downloaded that are of no use anymore!

Post back and let me know how things are?
  • 0

#19
alighirl

alighirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Hi Cretemonster,

Everything seems to be back to normal! I have one more question, though. When I rebooted my PC, the CPU usage shot up to 100% and stayed there. I noticed that my McAfee antivirus starts a scan at startup and the Ewido has a real-time protection Guard which also activates on startup. When I cancelled the McAfee scan the CPU usage dropped to normal (about 2-5%).

Is there some kind of conflict between the two programs? Should I turn one off? I like the thought of having realtime protection from Ewido but should I always need a McAfee scan at startup?
OK, sorry, that's more than one question!
Anyway, I really can't thank you enough :tazz: . You guys are absolute heroes!
  • 0

#20
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
In all honesty,I think you can get rid of ewido whenever you like or just drop the real time protection.

Check your configurations in Mcafee and see if there are some adjustments you can make.


Go ahead and Renable System Restore and restart the PC,this will clear out all old nasty restore points and create a nice new fresh clean one for you to fall back on should you ever need it.


Read through those 3 little black links in my signature to get some extra ideas about how to avoid this in the future.


Make sure you keep your Windows Operating System up to date by visiting Windows Updates regularly to download and install any critical updates and service packs.


If you need anything else just ask away.
  • 0

#21
alighirl

alighirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Hi Cretemonster,

I don't know if I should have started a new thread, but this one still seemed to be open. I have had no more problems with popups and my computer seems to be fine, but I did an online Panda scan today and it says I have 3 types of spyware (one of them Virtumonde)!! I installed Sygate firewall (I read somewhere it's better than the Windows XP one) and it keeps giving warnings about something trying to get into my computer. When I check the details, the text says my registry is corrupted and to visit fixthereg.net. I assume it's a popup advert like the Winfixer one trying to get in. I'm not sure what to make of it all so I've pasted the Panda Active Scan result and a Hijack This log below. Thanks in advance!


Panda Active Scan Log
Incident Status Location

Adware:adware/surfaccuracy Not desinfected Windows Registry
Adware:adware/secure32 Not desinfected C:\WINDOWS\system32\drivers\etc\hosts
Spyware:spyware/virtumonde Not desinfected Windows Registry -------------------------------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 23:41:14, on 03/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\HPConfig.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = svrstandrew2.w-dunbarton.sch.uk:8002
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {B313D637-F405-4052-AC37-E2119AB3C8F8} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {5EC7C511-CD0F-42E6-830C-1BD9882F3458} -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} -
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
  • 0

#22
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Its fine to post back,thats why I leave the threads open.

Go to safe mode and scan with WinPFind once more.

Restart Normal and lets have a closer look at the Hosts File

Open HijackThis>Click Config>Click Misc Tools>Click Open Hosts File Manager>Click Open in Notepad>Copy&Paste the entire Contents of that Notepad Page to your Next Post

If you have HijackThis setup to show its normal opening page,just click the tab labeled "Open the Misc Tools Section"


Post the results of those 2 scans in the next reply.
  • 0

#23
alighirl

alighirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Thanks again for your help. Here are the logs you requested.

WinPFind

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
UPX! 24/06/2005 16:44:18 24064 C:\WINDOWS\Uninstall Plasma.exe

Checking %System% folder...
PEC2 31/03/2003 02:00:00 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PTech 04/11/2005 16:27:24 534280 C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2 02/11/2005 10:49:02 2368864 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 02/11/2005 10:49:02 2368864 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 04/08/2004 07:56:36 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor 04/08/2004 07:56:44 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 31/03/2003 02:00:00 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...
PTech 04/08/2004 05:41:38 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\HOSTS
127.0.0.1 download1.shopathomeselect.com #[ADW_SAHAGENT.A]
127.0.0.1 www.shopathomeselect.com #[Adware.SAHAgent]
127.0.0.1 web-nexus.net #[Adw.Web-Nexus.WebNexusAdServer]
127.0.0.1 dl.web-nexus.net #[eTrust.Win32.Qoologic]
127.0.0.1 dl.web-nexus.net #[eTrust.Win32.Qoologic]
127.0.0.1 stech.web-nexus.net
127.0.0.1 www.web-nexus.net
127.0.0.1 agentq.vpptechnologies.com
127.0.0.1 main.vpptechnologies.com #[IE-SpyAd]
127.0.0.1 media-0.vpptechnologies.com
127.0.0.1 media-1.vpptechnologies.com
127.0.0.1 media-4.vpptechnologies.com
127.0.0.1 media-5.vpptechnologies.com
127.0.0.1 media-6.vpptechnologies.com
127.0.0.1 media-a.vpptechnologies.com
127.0.0.1 media-b.vpptechnologies.com
127.0.0.1 media-c.vpptechnologies.com
127.0.0.1 media-d.vpptechnologies.com
127.0.0.1 media-e.vpptechnologies.com
127.0.0.1 media-f.vpptechnologies.com
127.0.0.1 msxml.vpptechnologies.com
127.0.0.1 static.vpptechnologies.com #[hotsearchbar.com]
127.0.0.1 thumbs.vpptechnologies.com
127.0.0.1 xml.vpptechnologies.com #[BlazeFind]
127.0.0.1 ad-w-a-r-e.com #[Win32.Canbede][Troj/Dloader-IG]
127.0.0.1 www.ad-w-a-r-e.com #[AdWare.Win32.Look2Me.ab]
127.0.0.1 abetterinternet.com #[Downloader.Stubby.A][Adware.Aurora]
127.0.0.1 belt.abetterinternet.com
127.0.0.1 c.abetterinternet.com #[Adware-BetterInet application]
127.0.0.1 download.abetterinternet.com #[Adware.StopPopupAdsNow]
127.0.0.1 download2.abetterinternet.com #[Parasite.Transponder]
127.0.0.1 s.abetterinternet.com
127.0.0.1 st.abetterinternet.com
127.0.0.1 static.abetterinternet.com
127.0.0.1 thinstall.abetterinternet.com
127.0.0.1 www.abetterinternet.com #[Trojan-Downloader.Win32.Stubby.d]


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
04/12/2005 17:05:02 S 2048 C:\WINDOWS\bootstat.dat
01/12/2005 23:55:36 H 54156 C:\WINDOWS\QTFont.qfn
21/11/2005 03:11:34 H 66752 C:\WINDOWS\Minidump\Mini112105-01.dmp
21/11/2005 12:53:20 H 66752 C:\WINDOWS\Minidump\Mini112105-02.dmp
21/11/2005 13:08:58 H 66752 C:\WINDOWS\Minidump\Mini112105-03.dmp
22/11/2005 00:14:32 H 66752 C:\WINDOWS\Minidump\Mini112205-01.dmp
22/11/2005 01:14:54 H 66752 C:\WINDOWS\Minidump\Mini112205-02.dmp
23/11/2005 19:14:38 H 66752 C:\WINDOWS\Minidump\Mini112305-01.dmp
24/11/2005 10:21:38 H 66752 C:\WINDOWS\Minidump\Mini112405-01.dmp
24/11/2005 11:22:22 H 66752 C:\WINDOWS\Minidump\Mini112405-02.dmp
24/11/2005 11:41:08 H 66752 C:\WINDOWS\Minidump\Mini112405-03.dmp
25/11/2005 03:17:54 H 66752 C:\WINDOWS\Minidump\Mini112505-01.dmp
25/11/2005 03:26:52 H 66752 C:\WINDOWS\Minidump\Mini112505-02.dmp
25/11/2005 11:51:20 H 66752 C:\WINDOWS\Minidump\Mini112505-03.dmp
25/11/2005 13:30:24 H 66752 C:\WINDOWS\Minidump\Mini112505-04.dmp
25/11/2005 14:05:50 H 66752 C:\WINDOWS\Minidump\Mini112505-05.dmp
25/11/2005 14:30:34 H 66752 C:\WINDOWS\Minidump\Mini112505-06.dmp
25/11/2005 15:10:52 H 66752 C:\WINDOWS\Minidump\Mini112505-07.dmp
25/11/2005 15:41:26 H 66752 C:\WINDOWS\Minidump\Mini112505-08.dmp
26/11/2005 03:09:36 H 66752 C:\WINDOWS\Minidump\Mini112605-01.dmp
26/11/2005 13:14:32 H 66752 C:\WINDOWS\Minidump\Mini112605-03.dmp
26/11/2005 15:15:26 H 66752 C:\WINDOWS\Minidump\Mini112605-04.dmp
26/11/2005 15:32:36 H 66752 C:\WINDOWS\Minidump\Mini112605-05.dmp
28/11/2005 04:19:34 H 66752 C:\WINDOWS\Minidump\Mini112805-01.dmp
28/11/2005 04:42:18 H 66752 C:\WINDOWS\Minidump\Mini112805-02.dmp
28/11/2005 12:58:02 H 66752 C:\WINDOWS\Minidump\Mini112805-03.dmp
28/11/2005 22:32:22 H 66752 C:\WINDOWS\Minidump\Mini112805-04.dmp
29/11/2005 12:13:38 H 66752 C:\WINDOWS\Minidump\Mini112905-01.dmp
30/11/2005 04:43:34 H 66752 C:\WINDOWS\Minidump\Mini113005-01.dmp
01/12/2005 00:49:02 H 66752 C:\WINDOWS\Minidump\Mini120105-01.dmp
03/12/2005 03:35:00 H 66752 C:\WINDOWS\Minidump\Mini120305-01.dmp
03/12/2005 18:35:14 H 66752 C:\WINDOWS\Minidump\Mini120305-02.dmp
04/12/2005 01:50:32 H 66752 C:\WINDOWS\Minidump\Mini120405-01.dmp
04/12/2005 02:00:16 H 66752 C:\WINDOWS\Minidump\Mini120405-02.dmp
04/12/2005 15:02:50 H 66752 C:\WINDOWS\Minidump\Mini120405-03.dmp
04/12/2005 15:44:44 H 66752 C:\WINDOWS\Minidump\Mini120405-04.dmp
20/11/2005 19:07:24 RHS 305145 C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_70.cab
20/11/2005 19:17:52 RHS 68327 C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_71.cab
05/10/2005 20:33:38 S 12849 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896424.cat
04/12/2005 17:04:50 H 8192 C:\WINDOWS\system32\config\default.LOG
04/12/2005 17:05:16 H 1024 C:\WINDOWS\system32\config\SAM.LOG
04/12/2005 17:05:04 H 16384 C:\WINDOWS\system32\config\SECURITY.LOG
04/12/2005 17:05:16 H 77824 C:\WINDOWS\system32\config\software.LOG
04/12/2005 17:05:10 H 1077248 C:\WINDOWS\system32\config\system.LOG
24/11/2005 22:18:30 H 1024 C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
02/12/2005 23:23:14 S 688 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
20/11/2005 19:17:56 S 558 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735
02/12/2005 23:23:26 S 70226 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\F482C95F83F1B59228F1B1E720F2EDF1
02/12/2005 23:23:14 S 94 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
20/11/2005 19:17:56 S 144 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735
02/12/2005 23:23:26 S 128 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\F482C95F83F1B59228F1B1E720F2EDF1
04/12/2005 17:03:56 H 6 C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 04/08/2004 07:56:58 68608 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 04/08/2004 07:56:58 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 04/08/2004 07:56:58 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 04/08/2004 07:56:58 135168 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 04/08/2004 07:56:58 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 04/08/2004 07:56:58 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 04/08/2004 07:56:58 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 04/08/2004 07:56:58 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 04/08/2004 07:56:58 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 04/08/2004 07:56:58 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems, Inc. 26/08/2005 18:14:42 49265 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 31/03/2003 02:00:00 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 04/08/2004 07:56:58 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 31/03/2003 02:00:00 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 04/08/2004 07:56:58 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 04/08/2004 07:56:58 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 31/03/2003 02:00:00 36864 C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation 04/08/2004 07:56:58 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 04/08/2004 07:56:58 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
Microsoft Corporation 04/08/2004 07:56:58 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 31/03/2003 02:00:00 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 04/08/2004 07:56:58 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 04/08/2004 07:56:58 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 26/05/2005 03:16:30 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
19/06/2003 15:08:54 HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
26/05/2004 15:04:54 1730 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
19/06/2003 08:00:30 HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
17/10/2003 15:52:22 237 C:\Documents and Settings\All Users\Application Data\hpzinstall.log

Checking files in %USERPROFILE%\Startup folder...
19/06/2003 15:08:54 HS 84 C:\Documents and Settings\User\Start Menu\Programs\Startup\desktop.ini

Checking files in %USERPROFILE%\Application Data folder...
19/06/2003 08:00:30 HS 62 C:\Documents and Settings\User\Application Data\desktop.ini
01/12/2005 14:07:40 34504 C:\Documents and Settings\User\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
SV1 =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\VirusScan
{cda2863e-2497-4c49-9b89-06840e070a87} = C:\Program Files\Network Associates\VirusScan\shext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ZFAdd
{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = C:\Program Files\WinAce\arcext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\VirusScan
{cda2863e-2497-4c49-9b89-06840e070a87} = C:\Program Files\Network Associates\VirusScan\shext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\VirusScan
{cda2863e-2497-4c49-9b89-06840e070a87} = C:\Program Files\Network Associates\VirusScan\shext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ZFAdd
{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} = C:\Program Files\WinAce\arcext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
= C:\PROGRA~1\SPYBOT~1\SDHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}
ST = C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B313D637-F405-4052-AC37-E2119AB3C8F8}
=
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
MSNToolBandBHO = C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = MSN : C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText = Messenger : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}
Search Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = MSN : C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ATIPTA C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
Display Settings C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
QT4HPOT C:\Program Files\HPQ\One-Touch\OneTouch.EXE
SynTPLpr C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HPHUPD05 c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
HPHmon05 C:\WINDOWS\System32\hphmon05.exe
Cpqset C:\Program Files\HPQ\Default Settings\cpqset.exe
RoxioEngineUtility "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
ShStatEXE "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
McAfeeUpdaterUI "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
HP Software Update C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
SunJavaUpdateSched C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

RoxioDragToDisc "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
SmcService C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
KernelFaultCheck %systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ctfmon.exe C:\WINDOWS\system32\ctfmon.exe


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^Ubisoft register.lnk
path C:\Documents and Settings\User\Start Menu\Programs\Startup\Ubisoft register.lnk
backup C:\WINDOWS\pss\Ubisoft register.lnkStartup
location Startup
command C:\PROGRA~1\Ubisoft\Register\schedule.exe /29/11/2005 03:15:05 /game=CSI-Dark Motives /language=english /country=United States /url=http://register-it.ubi.com/register.asp
item Ubisoft register

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
system.ini 0
win.ini 0
bootini 0
services 0
startup 0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 04/12/2005 17:11:18


# This MVPS HOSTS file is a free download from: #
# http://www.mvps.org/winhelp2002/ #
# #
# Notes: the browser does not read this "#" symbol #
# You can create your own notes, after the # symbol #
# This *must* be the first line: 127.0.0.1 localhost #
# ********************************************************#
# ------------------Updated: 11-26-05---------------------#
# ********************************************************#
# Entries marked with Parasite or Trojan comments should #
# be placed in the Internet Explorer Restricted Zone. #
# http://mvps.org/winh.../restricted.htm #
# #
# Entries with other comments are searchable via Google. #
# #
# Disclaimer: this file is free to use, however it is NOT #
# permitted to post on any other site without permission. #
# #
# This work is licensed under the Creative Commons #
# Attribution-NonCommercial-ShareAlike License. #
# http://creativecommo...s/by-nc-sa/2.0/ #

127.0.0.1 localhost

#start of lines added by WinHelp2002
# [Misc A - Z]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net
127.0.0.1 e.abnad.net
127.0.0.1 www.accoona.com #[Adware-Accoona][Adware.Atoolb][Panda.Accoona]
127.0.0.1 gtcc1.acecounter.com
127.0.0.1 gtp1.acecounter.com
127.0.0.1 acestats.com
127.0.0.1 www.acestats.com
127.0.0.1 data2.activshopper.com
127.0.0.1 search.activshopper.com
127.0.0.1 www.activshopper.com #[McAfee.Adware-ActivShop]
127.0.0.1 www.activesearch.com #[Adware.ActiveSearch]
127.0.0.1 actualnames.com #[Parasite.ActualNames][Spyware.ActualNames]
127.0.0.1 www.actualnames.com
127.0.0.1 ad-up.com
127.0.0.1 www.ad-up.com
127.0.0.1 adatom.com
127.0.0.1 aesp.adatom.com
127.0.0.1 adbest.com #[IE-SpyAd]
127.0.0.1 www.adcipta.net #[W32/Malware]
127.0.0.1 adserv.adbonus.com #[IE-SpyAd]
127.0.0.1 www.adbonus.com
127.0.0.1 media.adcentriconline.com #[IE-SpyAd]
127.0.0.1 ad2.adcept.net
127.0.0.1 ad3.adcept.net
127.0.0.1 www.adcept.net #[IE-SpyAd]
127.0.0.1 adcomplete.com #[IE-SpyAd]
127.0.0.1 www.adcomplete.com
127.0.0.1 www.adcopy.info
127.0.0.1 ads.adcorps.com #[verticalwebventures.com]
127.0.0.1 ads2.adcorps.com
127.0.0.1 ads.addynamix.com #[IE-SpyAd]
127.0.0.1 ad5.adecn.com #[p.mii.instacontent.net][IE-SpyAd]
127.0.0.1 www.adengage.com
127.0.0.1 pt.server1.adexit.com
127.0.0.1 www.adexit.com #[IE-SpyAd]
127.0.0.1 www.ad4ever.com #[IE-SpyAd]
127.0.0.1 www.ad-groups.com #[Ban Man Pro Banner Code]
127.0.0.1 ssl3.adhost.com #[IE-SpyAd]
127.0.0.1 www2.adhost.com
127.0.0.1 www.addme.com #[IE-SpyAd]
127.0.0.1 adsvr.adknowledge.com #[IE-SpyAd]
127.0.0.1 web.adknowledge.com
127.0.0.1 te.adlandpro.com #[IE-SpyAd]
127.0.0.1 ad.adlegend.com #[blocks Webroot Amber Alert]
127.0.0.1 media.adlegend.com
127.0.0.1 classic.adlink.de #[IE-SpyAd]
127.0.0.1 regio.adlink.de
127.0.0.1 west.adlink.de
127.0.0.1 www.adminder.com #[IE-SpyAd]
127.0.0.1 s1.ad.adocean.pl
127.0.0.1 ad01.adonspot.com #[IE-SpyAd]
127.0.0.1 ad02.adonspot.com
127.0.0.1 www.adonweb.com
127.0.0.1 adreactor.com #[IE-SpyAd]
127.0.0.1 adserver.adreactor.com #[Ad-Aware Tracking Cookie]
127.0.0.1 www.adrelevance.com #[NetRatings][IE-SpyAd]
127.0.0.1 adserver.adremedy.com #[Ad-Aware Tracking Cookie]
127.0.0.1 media.adrevolver.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 track.adrevolver.com #[IE-SpyAd]
127.0.0.1 ad.adriver.ru
127.0.0.1 serv.ad-rotator.com
127.0.0.1 166.ads8.com
127.0.0.1 ad.ads8.com
127.0.0.1 vip.ads8.com
127.0.0.1 livelines.ads365.com
127.0.0.1 www.ads365.com #[IE-SpyAd]
127.0.0.1 ad.ads.dk #[IE-SpyAd]
127.0.0.1 tdkads.ads.dk
127.0.0.1 ads.adsag.com
127.0.0.1 di.adsag.com
127.0.0.1 img.adsag.com
127.0.0.1 adsfac.net #[IE-SpyAd]
127.0.0.1 adsincontext.com #[Adware.ZioCom]
127.0.0.1 adserver.adsincontext.com #[PcTools.AdsInContext]
127.0.0.1 www.adsincontext.com #[eTrust.AdsInContext]
127.0.0.1 37.adsonar.com
127.0.0.1 ads.adsonar.com
127.0.0.1 js.adsonar.com
127.0.0.1 www.adsprve1.com #[IE-SpyAd]
127.0.0.1 adtology.com
127.0.0.1 downldcl.adtoolsinc.com
127.0.0.1 www.adtoolsinc.com #[IE-SpyAd]
127.0.0.1 www.adtrader.com #[IE-SpyAd]
127.0.0.1 survey.advantageresearch.com #[IE-SpyAd]
127.0.0.1 ad.adver.com.tw
127.0.0.1 ads.advertise.net #[IE-SpyAd]
127.0.0.1 advertisingvision.com #[IE-SpyAd]
127.0.0.1 www.advertisingvision.com #[Adware.Advision]
127.0.0.1 adpowerzone.advertserve.com
127.0.0.1 bayoubuzz.advertserve.com #[AdvertPro]
127.0.0.1 adviva.com #[IE-SpyAd]
127.0.0.1 www.adviva.com
127.0.0.1 ads.adviva.net #[IE-SpyAd]
127.0.0.1 adstats.adviva.net
127.0.0.1 tracker.affistats.com #[IE-SpyAd][msvrl.dll]
127.0.0.1 banners.affiliatefuel.com
127.0.0.1 www.affiliatefuel.com #[IE-SpyAd]
127.0.0.1 fcds.affiliatetracking.net
127.0.0.1 our.affiliatetracking.net
127.0.0.1 www.affiliatetracking.net #[IE-SpyAd]
127.0.0.1 www.affiliatetracking.com #[IE-SpyAd]
127.0.0.1 adz.afterdawn.net
127.0.0.1 aams1.aim4media.com
127.0.0.1 adcodes.aim4media.com
127.0.0.1 adserver.aim4media.com
127.0.0.1 adtest.aim4media.com
127.0.0.1 artwork.aim4media.com
127.0.0.1 pops.aim4media.com
127.0.0.1 www.aim4media.com #[IE-SpyAd]
127.0.0.1 adlik2.akavita.com
127.0.0.1 download.alexa.com #[Trackware.Alexa][SPYW_ALEXA.A]
127.0.0.1 download.china.alibaba.com #[Adware.AlibabaTB]
127.0.0.1 click.allfeeds.com #[IE-SpyAd]
127.0.0.1 tracking.allposters.com
127.0.0.1 www.allthatsearch.com #[IE-SpyAd]
127.0.0.1 v7.alwaysupdatednews.com
127.0.0.1 v8.alwaysupdatednews.com #[Trojan.Alwayup]
127.0.0.1 www.alwaysupdatednews.com #[Trojan-Downloader.Win32.Small.akz]
127.0.0.1 ads.as4x.tmcs.akadns.net #[Ticketmaster][IE-SpyAd]
127.0.0.1 bantam.ai.net #[IE-SpyAd]
127.0.0.1 fiona.ai.net
127.0.0.1 www.amazingcounters.com
127.0.0.1 ads.amazingmedia.com #[IE-SpyAd]
127.0.0.1 banner.ambercoastcasino.com #[IE-SpyAd]
127.0.0.1 adserver.ancestry.com #[RealMedia]
127.0.0.1 adserver04.ancestry.com #[RealMedia]
127.0.0.1 search.antarasystems.com #[Spyware.SearchPounder]
127.0.0.1 www.antarasystems.com
127.0.0.1 ads.antionline.com
127.0.0.1 junior.apk.net
127.0.0.1 banner.arttoday.com
127.0.0.1 asimpleinternet.com #[Parasite.SpecialOffers]
127.0.0.1 www.asimpleinternet.com #[IE-SpyAd]
127.0.0.1 ads.aspalliance.com
127.0.0.1 dist.atlas-ia.com #[ADW_ATLAST.A]
127.0.0.1 www.atlas-ia.com #[Adware.OfferAgent]
127.0.0.1 te.audiencematch.net
127.0.0.1 audiogalaxy.com
127.0.0.1 www.audiogalaxy.com
127.0.0.1 www.autosurfpro.com #[IE-SpyAd]
127.0.0.1 adserving.autotrader.com
127.0.0.1 cploving.awmhost.net #[TrojanClicker.Win32.Lopin]
127.0.0.1 www.azads.net #[IE-SpyAd]
# B
127.0.0.1 bar.baidu.com #[SPYW_BDPLUGIN.A][Sophos.JS/BDHelper-A]
127.0.0.1 www.banex.ca #[IE-SpyAd]
127.0.0.1 adserver.banneradministration.com
127.0.0.1 bannerboxes.com #[BannerBoxes Ad Code]
127.0.0.1 clicks.bannerboxes.com
127.0.0.1 feeds.bannerboxes.com
127.0.0.1 www.bannerboxes.com
127.0.0.1 ad.bannerconnect.net
127.0.0.1 ads.bannerconnect.net
127.0.0.1 www.banner-exchange.nl #[IE-SpyAd]
127.0.0.1 ad.bannerhost.ru
127.0.0.1 www.bannermanagement.nl #[IE-SpyAd]
127.0.0.1 www.bannerpromotion.it #[IE-SpyAd]
127.0.0.1 www.banner-mania.com
127.0.0.1 www.bannerspace.com #[IE-SpyAd]
127.0.0.1 www2.bannerspace.com
127.0.0.1 www3.bannerspace.com
127.0.0.1 www5.bannerspace.com
127.0.0.1 www6.bannerspace.com
127.0.0.1 www7.bannerspace.com
127.0.0.1 bannerswap.com #[IE-SpyAd]
127.0.0.1 www.bannerswap.com
127.0.0.1 bardownload.com
127.0.0.1 www.bardownload.com #[MHTMLRedir.Exploit][007installer Control]
127.0.0.1 media.baventures.com
127.0.0.1 www.besttoolbars.net #[ADW_TBARWIN32.A]
127.0.0.1 ads.betanews.com
127.0.0.1 ads.bidclix.com #[IE-SpyAd]
127.0.0.1 www.bidclix.com
127.0.0.1 bidclix.net #[IE-SpyAd]
127.0.0.1 www.bidclix.net
127.0.0.1 ads.bidvertiser.com #[IE-SpyAd]
127.0.0.1 bdv.bidvertiser.com
127.0.0.1 www.bidvertiser.com
127.0.0.1 c.bigmir.net
127.0.0.1 bigtracker.com
127.0.0.1 bighits.net #[IE-SpyAd]
127.0.0.1 bigticker.bighits.net
127.0.0.1 bounty.bighits.net
127.0.0.1 www.bighits.net
127.0.0.1 download.bigwebportal.com #[IE-SpyAd]
127.0.0.1 www.bigwebportal.com #[hotwebsearch.com]
127.0.0.1 counter.bizland.com
127.0.0.1 webads.bizservers.com
127.0.0.1 www.black-hole.co.uk
127.0.0.1 www.blacklogic.net
127.0.0.1 blacksoft.info #[Trojan-Dropper.Win32.Microjoin.b]
127.0.0.1 www.blazehits.net #[gonnasearch.com]
127.0.0.1 cluster.blingblingcontent.com
127.0.0.1 gb.blingblingcontent.com
127.0.0.1 s7.blingblingcontent.com #[HJTH.EasyWebSearch Hijacker]
127.0.0.1 blockchecker.com #[IE-SpyAd]
127.0.0.1 weblog.blogads.com
127.0.0.1 images.blogads.com
127.0.0.1 images2.blogads.com
127.0.0.1 proxy.blogads.com
127.0.0.1 www.blogads.com
127.0.0.1 blogmark.bokee.com #[Adware.BocaiToolbar]
127.0.0.1 bookedspace.com #[Parasite.BookedSpace]
127.0.0.1 www.bookedspace.com #[Adware.Bookedspace]
127.0.0.1 www.borlander.cn #[Adware.Borlan]
127.0.0.1 bans.bride.ru #[IE-SpyAd]
127.0.0.1 citi.bridgetrack.com #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 rccl.bridgetrack.com
127.0.0.1 www.browserplugin.com #[HJTH.EroticAccess][wobz.de]
127.0.0.1 install.browsertoolbar.com #[Backdoor.Autoupder][BrowserToolbar]
127.0.0.1 www2.browsertoolbar.com #[TROJ_SUA.A]
127.0.0.1 www.browsertoolbar.com #[Parasite.BrowserToolbar]
127.0.0.1 redemption.bullseye-media.net
127.0.0.1 users.bullseye-media.net
127.0.0.1 www.bullseye-media.net #[IE-SpyAd]
127.0.0.1 www.buildtraffic.com
127.0.0.1 buy-traffic.net #[searchmeup.com]
# C
127.0.0.1 cafeden.biz #[Koffix.Exploit]
127.0.0.1 images.cashfiesta.com #[AdWare.CashFiesta.a]
127.0.0.1 www.cashfiesta.com #[McAfee.Adware-CashFiesta]
127.0.0.1 www.cashventure.com
127.0.0.1 casino-on-net.com
127.0.0.1 java2.casino-on-net.com
127.0.0.1 www.casino-on-net.com
127.0.0.1 affiliate.casinorewards.com
127.0.0.1 deliver.castads.com
127.0.0.1 images.castads.com
127.0.0.1 serve.castads.com
127.0.0.1 www.care2.com #[TopMoxie]
127.0.0.1 ads.cars.com
127.0.0.1 msg.cd321.com #[Trojan.Startpage.Q]
127.0.0.1 www.cd321.com
127.0.0.1 ads.cdfreaks.com #[eTrust.Ads.cdfreaks]
127.0.0.1 cellaphone.net #[MHTMLRedir.Exploit]
127.0.0.1 www.celebritaspoglie.net #[IE-SpyAd]
127.0.0.1 mds.centrport.net #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 www.cerials.net #[C2Media/LOP variant]
127.0.0.1 abc.checkm8.com
127.0.0.1 rmm1u.checkm8.com
127.0.0.1 web.checkm8.com #[CHECKM8 AD TAGS]
127.0.0.1 ads.chellomedia.com
127.0.0.1 ad.cibleclick.com
127.0.0.1 www.cibleclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.classifieds1000.com
127.0.0.1 clearfind.com
127.0.0.1 www.clearfind.com #[IE-SpyAd]
127.0.0.1 ads.clickad.com #[eTrust.Tracking Cookie]
127.0.0.1 hits.clickandtrack.net
127.0.0.1 clickbank.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 hop.clickbank.net #[Adware.Clickbank][Adware.ClickDLoader]
127.0.0.1 zzz.clickbank.net
127.0.0.1 clickedyclick.com #[IE-SpyAd]
127.0.0.1 www.clickexchange.ru #[IE-SpyAd]
127.0.0.1 click2boost.com #[IE-SpyAd]
127.0.0.1 secure.click2boost.com
127.0.0.1 service.click2boost.com
127.0.0.1 www.click2boost.com
127.0.0.1 www.clicks2you.com #[IE-SpyAd]
127.0.0.1 clicktracks.com
127.0.0.1 stats.clicktracks.com
127.0.0.1 stats1.clicktracks.com # [eTrust.Tracking Cookie]
127.0.0.1 stats2.clicktracks.com
127.0.0.1 www.clicktracks.com #[IE-SpyAd]
127.0.0.1 www.is1.clixgalore.com
127.0.0.1 www.clixgalore.com #[IE-SpyAd]
127.0.0.1 www2.click-fr.com
127.0.0.1 www3.click-fr.com
127.0.0.1 www4.click-fr.com
127.0.0.1 www.clickhouse.com #[IE-SpyAd]
127.0.0.1 www.clicks4u.com #[IE-SpyAd]
127.0.0.1 ad1.clickhype.com #[IE-SpyAd]
127.0.0.1 cfg.clipgenie.com
127.0.0.1 download.clipgenie.com
127.0.0.1 dldw.clipgenie.com
127.0.0.1 ss.clipgenie.com
127.0.0.1 www.clipgenie.com #[Adware.ClipGenie]
127.0.0.1 banner.clubdicecasino.com
127.0.0.1 www.cnstats.com
127.0.0.1 ads.cobrad.com
127.0.0.1 comclick.com #[IE-SpyAd]
127.0.0.1 ct2.comclick.com
127.0.0.1 fl01.ct2.comclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 ihm01.ct2.comclick.com
127.0.0.1 www.comclick.com
127.0.0.1 aa.connextra.com
127.0.0.1 bb.connextra.com
127.0.0.1 cc.connextra.com
127.0.0.1 dd.connextra.com
127.0.0.1 ee.connextra.com
127.0.0.1 ff.connextra.com
127.0.0.1 data.connextra.com
127.0.0.1 consumeralertsystem.com #[Adw.ConsumerAlertSystem.CASClient]
127.0.0.1 www1.consumeralertsystem.com
127.0.0.1 www.consumeralertsystem.com #[PcTools.CasinoClient]
127.0.0.1 ads.contactmusic.com #[advertpro]
127.0.0.1 svp.contextuad.org #[IE-SpyAd]
127.0.0.1 www.thecoolbar.com #[Softomate Toolbar][Adware.Fizzle]
127.0.0.1 ads.console.net
127.0.0.1 coolshader.com
127.0.0.1 c.coolshader.com #[Win32.Harnig]
127.0.0.1 www.coolshader.com
127.0.0.1 counted.com #[IE-SpyAd]
127.0.0.1 bilbo.counted.com
127.0.0.1 www.counted.com
127.0.0.1 www.counter-gratis.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.counterguide.com
127.0.0.1 counter4u.de #[IE-SpyAd]
127.0.0.1 www.counting4free.com #[IE-SpyAd]
127.0.0.1 log1.countomat.com
127.0.0.1 connectionzone.com
127.0.0.1 count.casino-trade.com
127.0.0.1 www.couponsandoffers.com #[Adware.TopMoxie]
127.0.0.1 data.coremetrics.com #[IE-SpyAd]
127.0.0.1 test.coremetrics.com
127.0.0.1 twci.coremetrics.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 server.cpmstar.com #[ads.shizmoo.com]
127.0.0.1 cracks.am #[eTrust.Cracks.am][ADW_CRAMTB.A]
127.0.0.1 www.cracks.am #[[bleep]-portal.com][Adware.CramToolbar]
127.0.0.1 files.crackz.ws
127.0.0.1 wmw.crackz.ws
127.0.0.1 www.crackz.ws
127.0.0.1 www.crispads.com #[IE-SpyAd]
127.0.0.1 ads.crosswinds.net
127.0.0.1 megabyte.crosswinds.net
127.0.0.1 cyberbounty.com #[IE-SpyAd]
127.0.0.1 js.cybermonitor.com
127.0.0.1 stat3.cybermonitor.com
127.0.0.1 cytron.com #[DailyWinner][Cytron]
127.0.0.1 www.cytron.com
# D
127.0.0.1 ads.date.com #[IE-SpyAd]
127.0.0.1 banner.date.com
127.0.0.1 au.track.decideinteractive.com
127.0.0.1 au.link.decideinteractive.com
127.0.0.1 eu.link.decideinteractive.com
127.0.0.1 link.decideinteractive.com
127.0.0.1 www.decideinteractive.com
127.0.0.1 www.decideinteractive.co.uk
127.0.0.1 www.deepcom.com #[TrojanDropper.Win32.Small.gt]
127.0.0.1 collector.deepmetrix.com
127.0.0.1 geo.deepmetrix.com
127.0.0.1 www.deepmetrix.com
127.0.0.1 delta2378493.com #[Download.Sumina]
127.0.0.1 ads.dennisnet.co.uk
127.0.0.1 track.did-it.com #[Wired.com]
127.0.0.1 diji-realm.net #[Backdoor.Mepcod]
127.0.0.1 comm1.digits.com
127.0.0.1 counter.digits.com #[IE-SpyAd]
127.0.0.1 direct-ip.com #[Adware-DirectIP]
127.0.0.1 www.direct-ip.com #[Adware-DirectIP][Adware-CommanderNET]
127.0.0.1 stats.directnic.com
127.0.0.1 cache.directorym.com #[c2.mii.instacontent.net]
127.0.0.1 www.divago.com #[Adware.Surfairy]
127.0.0.1 track.dmipartners.com
127.0.0.1 ad.dmpi.net
127.0.0.1 ad2.dmpi.net
127.0.0.1 ad3.dmpi.net
127.0.0.1 ad4.dmpi.net
127.0.0.1 ubnm.dmpi.net
127.0.0.1 test-ware.dyndns.biz #[Trojan.Totmau]
127.0.0.1 www.dnscaching.net #[stickypops.com]
127.0.0.1 www.domamil.cz #[Trojan.Beagooz]
127.0.0.1 www.donttrip.org #[IE-SpyAd]
127.0.0.1 downloadalot.com
127.0.0.1 get.downloadalot.com
127.0.0.1 www.downloadalot.com #[IE-SpyAd]
127.0.0.1 www.downseek.com #[SunBelt.DownSeek Search]
127.0.0.1 dqmedia.net #[spam]
127.0.0.1 drmx01.net #[spam]
127.0.0.1 www.claus.drehteile-rieche.de #[Win32.Formglieder.B]
127.0.0.1 www.drinkmagik.biz #[Trojan.Spbot.C]
127.0.0.1 ads.drugs.com
127.0.0.1 www.dudu.com #[Adware.DuDuAccelerator]
127.0.0.1 www.duenow.com
127.0.0.1 gfx.dvlabs.com #[IE-SpyAd]
127.0.0.1 klipads.dvlabs.com
# E
127.0.0.1 e2give.com #[Adware-E2Give][Spyware.e2give]
127.0.0.1 www.e2give.com
127.0.0.1 eaglehousing.com #[Trojan.Tabela.B]
127.0.0.1 www.eaglehousing.com #[Trojan.Eaghouse]
127.0.0.1 www.eastworldnetwork.com
127.0.0.1 easyhitcounters.com #[IE-SpyAd]
127.0.0.1 beta.easyhitcounters.com
127.0.0.1 www.easywebsearch.nl #[Easywebinstaller Control][IE-SpyAd]
127.0.0.1 www.e-bannerx.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.easycounter.com #[IE-SpyAd]
127.0.0.1 banners.easydns.com
127.0.0.1 banner.easyspace.com #[IE-SpyAd]
127.0.0.1 adserv1.ebates.com #[WebSavings]
127.0.0.1 www.ebates.com #[Adware.MoeMoney]
127.0.0.1 c2.edapebaf.com #[IE-SpyAd]
127.0.0.1 www.efinder.cc #[StartPage-DA]
127.0.0.1 www.ek21.com #[Trojan.Chost.B]
127.0.0.1 click3.ekahfmal.com
127.0.0.1 www.elancenet.org #[Worm/Eyeveg.CH]
127.0.0.1 ad1.emediate.dk
127.0.0.1 epeople.com
127.0.0.1 errorpage404.com #[JS_TRAFFICHBAR.A]
127.0.0.1 www.errorpage404.com #[Parasite.TinyBar]
127.0.0.1 vipuk.escritorioactivo.com #[123Messenger Hijacker]
127.0.0.1 www.escorcher.com #[IE-SpyAd]
127.0.0.1 www.eshopads2.com
127.0.0.1 estat.com #[IE-SpyAd]
127.0.0.1 perso.estat.com
127.0.0.1 prof.estat.com
127.0.0.1 www.estat.com
127.0.0.1 eu-adcenter.net
127.0.0.1 thinknyc.eu-adcenter.net
127.0.0.1 ugo.eu-adcenter.net #[evidence-eliminator.com]
127.0.0.1 adopt.euroclick.com
127.0.0.1 www.euroklik.nl #[EasyBar][HJTH.SinCity Dialer]
127.0.0.1 www.euros4click.de
127.0.0.1 euro-randomizer.com #[Trojan.dropper]
127.0.0.1 engage.everyone.net
127.0.0.1 static.everyone.net #[IE-SpyAd]
127.0.0.1 www.everythingyouneed.org #[Malware Installer]
127.0.0.1 advert.exaccess.ru
127.0.0.1 dynamic.exaccess.ru #[IE-SpyAd]
127.0.0.1 www.exchangead.com #[IE-SpyAd]
127.0.0.1 exit-ad.de #[Ad-Aware.Tracking Cookie]
127.0.0.1 exitexchange.com #[IE-SpyAd]
127.0.0.1 count.exitexchange.com
127.0.0.1 images.exitexchange.com
127.0.0.1 www.exitexchange.com
127.0.0.1 www.exchangeexit.com #[HJTH.Winupie]
127.0.0.1 www.exittrade.com
127.0.0.1 www.exittraffic.net #[IE-SpyAd]
127.0.0.1 nyton.experclick.com #[p.mii.instacontent.net]
127.0.0.1 ads.expressindia.com
127.0.0.1 banners.expressindia.com
127.0.0.1 cdn.eyewonder.com #[IE-SpyAd]
127.0.0.1 www.evidence-eliminator.com
127.0.0.1 www.eyeget.com #[McAfee.Adware-EyeGet]
127.0.0.1 ezcybersearch.com #[EZCyberSearch.Surebar]
127.0.0.1 ads.ezcybersearch.com #[Adware.EZSearch.B]
127.0.0.1 ezcybersearch.mail.everyone.net
127.0.0.1 www.ezcybersearch.com #[Parasite.ezCyberSearch]
127.0.0.1 eziin.com #[Adware.Eziin]
127.0.0.1 www.eziin.com
# F
127.0.0.1 www.fast-adv.it
127.0.0.1 fast-web-search.com #[IE-SpyAd]
127.0.0.1 www.fast-web-search.com
127.0.0.1 www.fast2net.com
127.0.0.1 www.fastfind.org #[TROJ_STARTPAG.KF][Adware.Fastfind.B]
127.0.0.1 fasttrack.nu
127.0.0.1 counter.fateback.com
127.0.0.1 www.fatpickle.com #[FatPickle Toolbar][IE-SpyAd]
127.0.0.1 www.fightpopups.net #[Adware.MessStopper]
127.0.0.1 filesharingaccess.com #[MHTMLRedir.Exploit]
127.0.0.1 adserver.filefront.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.filemix.net #[Surf+][IE-SpyAd]
127.0.0.1 www.find.fm #[AdWare.SideSearch.g]
127.0.0.1 www.fineclicks.com #[IE-SpyAd]
127.0.0.1 firstname.com #[IE-SpyAd]
127.0.0.1 clicks.firstname.com
127.0.0.1 www.fish-screensaver.com #[AdWare.Win32.Gator.1008]
127.0.0.1 www.fizzlewizzle.com #[HJTH.Trojan.Downloader.VB.EU]
127.0.0.1 www.flyeagles.com #[Trojan.Drivus]
127.0.0.1 flyinads.com #[IE-SpyAd]
127.0.0.1 www.flyinads.com
127.0.0.1 cdn.flashedmail.com
127.0.0.1 tracker1.flashedmail.com #[IE-SpyAd]
127.0.0.1 adserver.fmpub.net
127.0.0.1 www.foofle.net #[Backdoor.Foobot]
127.0.0.1 js.forrestersurveys.com
127.0.0.1 securinews.free.fr #[Trojan.Hexem]
127.0.0.1 ads.freebannertrade.com #[AdNetPros Banner Code]
127.0.0.1 www.freedom850.com #[Trojan.Drivus]
127.0.0.1 www.freeloadmp3.com #[IE-SpyAd]
127.0.0.1 ad.freefind.com
127.0.0.1 www.freehistorycleaner.com #[Adware.Fapi][ADW_HISCLEAN.A]
127.0.0.1 freelogs.com
127.0.0.1 bar.freelogs.com
127.0.0.1 goo.freelogs.com
127.0.0.1 ico.freelogs.com
127.0.0.1 joe.freelogs.com
127.0.0.1 mom.freelogs.com
127.0.0.1 xyz.freelogs.com
127.0.0.1 adserver.freenet.de
127.0.0.1 free-stats.com
127.0.0.1 counters.freewebs.com
127.0.0.1 www.freewebsites.com
127.0.0.1 www.free-windows-games.com #[Parasite.GAMsys][GamHelper]
127.0.0.1 ads.ft.com
127.0.0.1 www.funbangladesh.com #[ysbweb.com][Purityscan]
# G
127.0.0.1 adserver.gadu-gadu.pl
127.0.0.1 ads.gamespy.com
127.0.0.1 adcontent.gamespy.com
127.0.0.1 ads.gamespyid.com
127.0.0.1 ad1.gamezone.com #[RealMedia]
127.0.0.1 server.gamyun.net
127.0.0.1 www.gamyun.net #[Adware.GamyunIeToolbar]
127.0.0.1 www.gebr-wachs.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 sda.geek.com #[AdvertPro]
127.0.0.1 adserver.geenstijl.nl
127.0.0.1 kassa.geenstijl.nl
127.0.0.1 gd.geobytes.com #[obtains users location]
127.0.0.1 banners.geotarget.info
127.0.0.1 www.geowhere.net #[SunBelt.GeoWhere Search]
127.0.0.1 www.getsmart.com
127.0.0.1 bp2.getredirect.com #[IE-SpyAd]
127.0.0.1 4.getredirect.com #[superlogy.com]
127.0.0.1 www.getredirect.com
127.0.0.1 getupdate.com
127.0.0.1 dlx.getupdate.com #[AdvWare.ToolBar.VB.b]
127.0.0.1 www.getupdate.com #[Adware.Getup]
127.0.0.1 gigex.com #[IE-SpyAd]
127.0.0.1 media.gigex.com #[SpeedDelivery]
127.0.0.1 oascentral.gigex.com #[RealMedia]
127.0.0.1 www.gigex.com #[download Class][eTrust.Gigex SpeedDelivery]
127.0.0.1 globesearch.com
127.0.0.1 www.globesearch.com #[IE-SpyAd][CWS]
127.0.0.1 banner.goldenpalace.com #[redirects]
127.0.0.1 www.goldfer.net #[Backdoor.Generic.OCX]
127.0.0.1 goldstats.net #[IE-SpyAd]
127.0.0.1 www.goldstats.net
127.0.0.1 www.goggle.com #[IE-SpyAd][typo squatter]
127.0.0.1 partner.gonamic.de
127.0.0.1 goodcounter.com #[IE-SpyAd]
127.0.0.1 www.goodcounter.com
127.0.0.1 adincl.gopher.com #[InfoSpace]
127.0.0.1 ads.gorillanation.com #[eTrust.GorillaNation]
127.0.0.1 adserver.gorillanation.com #[IE-SpyAd]
127.0.0.1 admonster.gorasoft.com #[TROJ_SMALL.AAL]
127.0.0.1 gostats.com #[IE-SpyAd]
127.0.0.1 as.gostats.com
127.0.0.1 c1.gostats.com
127.0.0.1 c2.gostats.com
127.0.0.1 c3.gostats.com
127.0.0.1 www.gotoo.com
127.0.0.1 webcounter.goweb.de #[IE-SpyAd]
127.0.0.1 greatstartpage.com #[IE-SpyAd]
127.0.0.1 www.greatstartpage.com
127.0.0.1 www.greasypalm.co.uk #[PcTools.GreasyPalm bar]
127.0.0.1 ads.grokads.com
127.0.0.1 grokster.com #[IE-SpyAd][P2P]
127.0.0.1 dl.grokster.com
127.0.0.1 www.grokster.com
127.0.0.1 www.groovysearchesbar.com #[IE-SpyAd]
127.0.0.1 ads.guardian.co.uk
127.0.0.1 ads.guardianunlimited.co.uk
127.0.0.1 www.g-wizzads.net
# H
127.0.0.1 hao3344.com #[Adware.Adtest]
127.0.0.1 www.hao3344.com #[eTrust.Adtest]
127.0.0.1 www.harmonyhollow.net #[Adware Bundler]
127.0.0.1 ad0.haynet.com
127.0.0.1 stats.hecklerspray.com
127.0.0.1 www.henbang.net #[Adware.Henbang][SPYW_HAP.A]
127.0.0.1 ads.hitcents.com #[IE-SpyAd]
127.0.0.1 hits-counter.com
127.0.0.1 hithopper.com #[Adware.Hithopper]
127.0.0.1 www.hithopper.com #[ADW_HITHOPPER.A]
127.0.0.1 hitkorea.co.kr #[Adware.Atlcontrol]
127.0.0.1 www.hitlogger.com
127.0.0.1 hitmodel.net
127.0.0.1 hit-now.com
127.0.0.1 hit-parade.com
127.0.0.1 loga.hit-parade.com
127.0.0.1 hitstats.net
127.0.0.1 www.hittracking.com #[IE-SpyAd]
127.0.0.1 images.hitwise.co.uk
127.0.0.1 ads.home.net
127.0.0.1 anna.homeftp.net #[W32.Linkbot.A]
127.0.0.1 www.gontijoamaral.hpg.com.br #[Adware.Diginum]
127.0.0.1 counters.honesty.com
127.0.0.1 cgi.honesty.com
127.0.0.1 horse-active.net #[Trojan.TrustedZones]
127.0.0.1 www.horse-active.net
127.0.0.1 horse-dns.net
127.0.0.1 horse-search.net
127.0.0.1 ad2.hotels.com
127.0.0.1 banners.hotlinks.net #[IE-SpyAd]
127.0.0.1 horseserver.net #[Troj/Haxdor-Fam][Trojan.Startpage.I]
127.0.0.1 www.horseserver.net #[Backdoor.Haxdoor.D]
127.0.0.1 hotsearch.com #[roar.com][IE-SpyAd]
127.0.0.1 www.hotsearch.com
127.0.0.1 www.10s.com.br #[Trojan.Cargao]
127.0.0.1 cgi.hotstat.nl #[IE-SpyAd]
127.0.0.1 viewstat.hotstat.nl
127.0.0.1 vip.huigezi.com #[Backdoor.Graybird.Q][W32.Looked.F]
127.0.0.1 hc2.humanclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.humanclick.com #[IE-SpyAd]
127.0.0.1 custom1.hurricanedigitalmedia.com
127.0.0.1 custom3.hurricanedigitalmedia.com
127.0.0.1 www.hypertracker.com #[IE-SpyAd]
# I
127.0.0.1 ads.iafrica.com
127.0.0.1 ads.iboost.com
127.0.0.1 www.i-clicks.net
127.0.0.1 hits.icdirect.com
127.0.0.1 hitctr01.icdirect.com
127.0.0.1 idolch.net #[Trojan.Idocha]
127.0.0.1 www.idonate.com #[eTrust.IDonate]
127.0.0.1 image-catcher.com
127.0.0.1 bar.iebar8.com #[Adware.Navihelper]
127.0.0.1 stats.surfaid.ihost.com #[IE-SpyAd]
127.0.0.1 gate.ilogbox.com
127.0.0.1 www.impregnable.net #[TrojanDownloader.Win32.VB.dw][Trojan.Win32.StartPage.kk]
127.0.0.1 stats.indextools.com #[IE-SpyAd][eTrust.Tracking Cookie]
127.0.0.1 adserver.indieclick.com #[server down?]
127.0.0.1 campaign.indieclick.com
127.0.0.1 adcenter.in2.com
127.0.0.1 ads.inet1.com
127.0.0.1 ads7.inet1.com
127.0.0.1 juggler.inetinteractive.com
127.0.0.1 rotator.juggler.inetinteractive.com
127.0.0.1 banners.inetfast.com
127.0.0.1 bn.inf3ct3d.info #[Backdoor.Shellbot]
127.0.0.1 images.infiads.com
127.0.0.1 www.infiads.com
127.0.0.1 reg1.info #[PWSteal.Reoxtan]
127.0.0.1 ads.infospace.com #[ADW_DEALHELPER.C]
127.0.0.1 bvads.infospace.com
127.0.0.1 xads.infospace.com
127.0.0.1 www.infotelsrl.com #[eTrust.Infotel srl]
127.0.0.1 ads.injersey.com #[RealMedia]
127.0.0.1 ads.intellicast.com
127.0.0.1 ads.intelihealth.com
127.0.0.1 strtt.interfree.it #[W32.Iberio]
127.0.0.1 ads.intermezzia.com #[IE-SpyAd]
127.0.0.1 indiads.com #[IE-SpyAd]
127.0.0.1 images.indiads.com
127.0.0.1 infostart.com #[IE-SpyAd]
127.0.0.1 popups.infostart.com #[eTrust.Popups.infostart.com]
127.0.0.1 oc.inspectorclick.com
127.0.0.1 trax.inspectorclick.com #[IE-SpyAd]
127.0.0.1 v2.inspectorclick.com
127.0.0.1 v3.inspectorclick.com
127.0.0.1 instadia.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.instadia.net
127.0.0.1 instantsearch.cc #[Panda.Adware/TheLocalSearch]
127.0.0.1 www.instantsearch.cc #[F-Secure.Small.wy]
127.0.0.1 anm.intelli-direct.com
127.0.0.1 oxfam.intelli-direct.com
127.0.0.1 www.intelli-tracker.com
127.0.0.1 newadserver.interfree.it #[Adcycle]
127.0.0.1 channels.intwined.com #[Adware/ToolBar.ISearch.c]
127.0.0.1 search.intwined.com
127.0.0.1 www.intwined.com #[McAfee.Adware-SSF!Hosts]
127.0.0.1 inqwire.com #[IE-SpyAd]
127.0.0.1 ww2.inqwire.com
127.0.0.1 www.inqwire.com
127.0.0.1 www.invinc.com #[Troj/Dloader-J]
127.0.0.1 ads.ipowerweb.com
127.0.0.1 www.ipstat.com #[IE-SpyAd]
127.0.0.1 adzones.ircspy.com
127.0.0.1 www.istats.nl #[IE-SpyAd]
127.0.0.1 adserver1.isohunt.com
127.0.0.1 ads.isoftmarketing.com
127.0.0.1 adcycle.isoftmarketing.com #[server down?]
127.0.0.1 ads1.itadnetwork.co.uk
127.0.0.1 www.itrafficstar.com #[IE-SpyAd]
# J
127.0.0.1 www.j4sb.com #[Trojan.Jasbom]
127.0.0.1 ad.jamba.net #[IE-SpyAd]
127.0.0.1 ad.jamster.com
127.0.0.1 www.japan213.com #[Trojan.Finfanse]
127.0.0.1 www.jcount.com #[IE-SpyAd]
127.0.0.1 www.jellycounter.com
127.0.0.1 app2.jkahfmal.com
127.0.0.1 jpedownload.joltid.com
127.0.0.1 www.joltid.com #[Adware.P2PNetworking][SPYW_PPNETWORK.B]
127.0.0.1 play.joyiex.com #[Trojan.Joex]
127.0.0.1 www.joyiex.com #[Trojan.Startpage.Q]
127.0.0.1 promotion.jpds.com
# K
127.0.0.1 www.k265.com #[Adware.Borlan]
127.0.0.1 kazaalite.pl
127.0.0.1 www.kazaalite.pl #[MHTMLRedir.Exploit]
127.0.0.1 adserve.kikizo.com
127.0.0.1 www1.kliks.nl #[IE-SpyAd]
127.0.0.1 www2.kliks.nl
127.0.0.1 www.kliks.nl
127.0.0.1 kt3.kliptracker.com #[IE-SpyAd]
127.0.0.1 kt4.kliptracker.com
127.0.0.1 www.kliptracker.com
127.0.0.1 www.kmindex.ru
127.0.0.1 ads.kmpads.com #[IE-SpyAd]
127.0.0.1 koolbar.net #[Adware Bundler][ADW_KOOLBAR.A]
127.0.0.1 www.koolbar.net #[eTrust.AutoSearch][IE-SpyAd]
127.0.0.1 kutsap.com #[Trojan.Anicmoo]
# L
127.0.0.1 layer-ads.de
127.0.0.1 www.leopardsearch.com
127.0.0.1 ts1.lexmark.com
127.0.0.1 www.linkads.net #[IE-SpyAd]
127.0.0.1 www.lineage0.com #[Trojan.Rohoteng]
127.0.0.1 linkbuddies.com #[IE-SpyAd]
127.0.0.1 banners.linkbuddies.com
127.0.0.1 www.linkbuddies.com
127.0.0.1 www.linkcounter.com
127.0.0.1 linkexchange.ru #[IE-SpyAd]
127.0.0.1 web.linkexchange.ru
127.0.0.1 www.linkexchange.ru
127.0.0.1 link4link.com #[IE-SpyAd]
127.0.0.1 plus.link4link.com
127.0.0.1 www.links4trade.com #[IE-SpyAd]
127.0.0.1 escati.linkopp.net #[IE-SpyAd]
127.0.0.1 www.linkopp.net
127.0.0.1 linkshelper.com #[Adware.MetaSearch]
127.0.0.1 js.livehelper.com #[IE-SpyAd]
127.0.0.1 newbrowse.livehelper.com
127.0.0.1 www.liveperson
  • 0

#24
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
All thats just as it should be.

Ill attach a zip folder with a reg file to hopefully get rid of the left over vundo stuff.

Unzip and double click vundo.reg and allow it to merge into the registry.

As for the other,I have no real way of knowing what Panda is flagging.

AdAware,Spybot or Microsoft AntiSpyware should pick up the dead reg entries.

As for why its saying that about the Hosts File is beyond me,WinHelps Hosts File is just as it should be.


If you will,post just the Hosts File log only and lets see if it fits in the reply.

Edited by Cretemonster, 04 December 2005 - 01:17 PM.

  • 0

#25
alighirl

alighirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
# This MVPS HOSTS file is a free download from: #
# http://www.mvps.org/winhelp2002/ #
# #
# Notes: the browser does not read this "#" symbol #
# You can create your own notes, after the # symbol #
# This *must* be the first line: 127.0.0.1 localhost #
# ********************************************************#
# ------------------Updated: 11-26-05---------------------#
# ********************************************************#
# Entries marked with Parasite or Trojan comments should #
# be placed in the Internet Explorer Restricted Zone. #
# http://mvps.org/winh.../restricted.htm #
# #
# Entries with other comments are searchable via Google. #
# #
# Disclaimer: this file is free to use, however it is NOT #
# permitted to post on any other site without permission. #
# #
# This work is licensed under the Creative Commons #
# Attribution-NonCommercial-ShareAlike License. #
# http://creativecommo...s/by-nc-sa/2.0/ #

127.0.0.1 localhost

#start of lines added by WinHelp2002
# [Misc A - Z]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net
127.0.0.1 e.abnad.net
127.0.0.1 www.accoona.com #[Adware-Accoona][Adware.Atoolb][Panda.Accoona]
127.0.0.1 gtcc1.acecounter.com
127.0.0.1 gtp1.acecounter.com
127.0.0.1 acestats.com
127.0.0.1 www.acestats.com
127.0.0.1 data2.activshopper.com
127.0.0.1 search.activshopper.com
127.0.0.1 www.activshopper.com #[McAfee.Adware-ActivShop]
127.0.0.1 www.activesearch.com #[Adware.ActiveSearch]
127.0.0.1 actualnames.com #[Parasite.ActualNames][Spyware.ActualNames]
127.0.0.1 www.actualnames.com
127.0.0.1 ad-up.com
127.0.0.1 www.ad-up.com
127.0.0.1 adatom.com
127.0.0.1 aesp.adatom.com
127.0.0.1 adbest.com #[IE-SpyAd]
127.0.0.1 www.adcipta.net #[W32/Malware]
127.0.0.1 adserv.adbonus.com #[IE-SpyAd]
127.0.0.1 www.adbonus.com
127.0.0.1 media.adcentriconline.com #[IE-SpyAd]
127.0.0.1 ad2.adcept.net
127.0.0.1 ad3.adcept.net
127.0.0.1 www.adcept.net #[IE-SpyAd]
127.0.0.1 adcomplete.com #[IE-SpyAd]
127.0.0.1 www.adcomplete.com
127.0.0.1 www.adcopy.info
127.0.0.1 ads.adcorps.com #[verticalwebventures.com]
127.0.0.1 ads2.adcorps.com
127.0.0.1 ads.addynamix.com #[IE-SpyAd]
127.0.0.1 ad5.adecn.com #[p.mii.instacontent.net][IE-SpyAd]
127.0.0.1 www.adengage.com
127.0.0.1 pt.server1.adexit.com
127.0.0.1 www.adexit.com #[IE-SpyAd]
127.0.0.1 www.ad4ever.com #[IE-SpyAd]
127.0.0.1 www.ad-groups.com #[Ban Man Pro Banner Code]
127.0.0.1 ssl3.adhost.com #[IE-SpyAd]
127.0.0.1 www2.adhost.com
127.0.0.1 www.addme.com #[IE-SpyAd]
127.0.0.1 adsvr.adknowledge.com #[IE-SpyAd]
127.0.0.1 web.adknowledge.com
127.0.0.1 te.adlandpro.com #[IE-SpyAd]
127.0.0.1 ad.adlegend.com #[blocks Webroot Amber Alert]
127.0.0.1 media.adlegend.com
127.0.0.1 classic.adlink.de #[IE-SpyAd]
127.0.0.1 regio.adlink.de
127.0.0.1 west.adlink.de
127.0.0.1 www.adminder.com #[IE-SpyAd]
127.0.0.1 s1.ad.adocean.pl
127.0.0.1 ad01.adonspot.com #[IE-SpyAd]
127.0.0.1 ad02.adonspot.com
127.0.0.1 www.adonweb.com
127.0.0.1 adreactor.com #[IE-SpyAd]
127.0.0.1 adserver.adreactor.com #[Ad-Aware Tracking Cookie]
127.0.0.1 www.adrelevance.com #[NetRatings][IE-SpyAd]
127.0.0.1 adserver.adremedy.com #[Ad-Aware Tracking Cookie]
127.0.0.1 media.adrevolver.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 track.adrevolver.com #[IE-SpyAd]
127.0.0.1 ad.adriver.ru
127.0.0.1 serv.ad-rotator.com
127.0.0.1 166.ads8.com
127.0.0.1 ad.ads8.com
127.0.0.1 vip.ads8.com
127.0.0.1 livelines.ads365.com
127.0.0.1 www.ads365.com #[IE-SpyAd]
127.0.0.1 ad.ads.dk #[IE-SpyAd]
127.0.0.1 tdkads.ads.dk
127.0.0.1 ads.adsag.com
127.0.0.1 di.adsag.com
127.0.0.1 img.adsag.com
127.0.0.1 adsfac.net #[IE-SpyAd]
127.0.0.1 adsincontext.com #[Adware.ZioCom]
127.0.0.1 adserver.adsincontext.com #[PcTools.AdsInContext]
127.0.0.1 www.adsincontext.com #[eTrust.AdsInContext]
127.0.0.1 37.adsonar.com
127.0.0.1 ads.adsonar.com
127.0.0.1 js.adsonar.com
127.0.0.1 www.adsprve1.com #[IE-SpyAd]
127.0.0.1 adtology.com
127.0.0.1 downldcl.adtoolsinc.com
127.0.0.1 www.adtoolsinc.com #[IE-SpyAd]
127.0.0.1 www.adtrader.com #[IE-SpyAd]
127.0.0.1 survey.advantageresearch.com #[IE-SpyAd]
127.0.0.1 ad.adver.com.tw
127.0.0.1 ads.advertise.net #[IE-SpyAd]
127.0.0.1 advertisingvision.com #[IE-SpyAd]
127.0.0.1 www.advertisingvision.com #[Adware.Advision]
127.0.0.1 adpowerzone.advertserve.com
127.0.0.1 bayoubuzz.advertserve.com #[AdvertPro]
127.0.0.1 adviva.com #[IE-SpyAd]
127.0.0.1 www.adviva.com
127.0.0.1 ads.adviva.net #[IE-SpyAd]
127.0.0.1 adstats.adviva.net
127.0.0.1 tracker.affistats.com #[IE-SpyAd][msvrl.dll]
127.0.0.1 banners.affiliatefuel.com
127.0.0.1 www.affiliatefuel.com #[IE-SpyAd]
127.0.0.1 fcds.affiliatetracking.net
127.0.0.1 our.affiliatetracking.net
127.0.0.1 www.affiliatetracking.net #[IE-SpyAd]
127.0.0.1 www.affiliatetracking.com #[IE-SpyAd]
127.0.0.1 adz.afterdawn.net
127.0.0.1 aams1.aim4media.com
127.0.0.1 adcodes.aim4media.com
127.0.0.1 adserver.aim4media.com
127.0.0.1 adtest.aim4media.com
127.0.0.1 artwork.aim4media.com
127.0.0.1 pops.aim4media.com
127.0.0.1 www.aim4media.com #[IE-SpyAd]
127.0.0.1 adlik2.akavita.com
127.0.0.1 download.alexa.com #[Trackware.Alexa][SPYW_ALEXA.A]
127.0.0.1 download.china.alibaba.com #[Adware.AlibabaTB]
127.0.0.1 click.allfeeds.com #[IE-SpyAd]
127.0.0.1 tracking.allposters.com
127.0.0.1 www.allthatsearch.com #[IE-SpyAd]
127.0.0.1 v7.alwaysupdatednews.com
127.0.0.1 v8.alwaysupdatednews.com #[Trojan.Alwayup]
127.0.0.1 www.alwaysupdatednews.com #[Trojan-Downloader.Win32.Small.akz]
127.0.0.1 ads.as4x.tmcs.akadns.net #[Ticketmaster][IE-SpyAd]
127.0.0.1 bantam.ai.net #[IE-SpyAd]
127.0.0.1 fiona.ai.net
127.0.0.1 www.amazingcounters.com
127.0.0.1 ads.amazingmedia.com #[IE-SpyAd]
127.0.0.1 banner.ambercoastcasino.com #[IE-SpyAd]
127.0.0.1 adserver.ancestry.com #[RealMedia]
127.0.0.1 adserver04.ancestry.com #[RealMedia]
127.0.0.1 search.antarasystems.com #[Spyware.SearchPounder]
127.0.0.1 www.antarasystems.com
127.0.0.1 ads.antionline.com
127.0.0.1 junior.apk.net
127.0.0.1 banner.arttoday.com
127.0.0.1 asimpleinternet.com #[Parasite.SpecialOffers]
127.0.0.1 www.asimpleinternet.com #[IE-SpyAd]
127.0.0.1 ads.aspalliance.com
127.0.0.1 dist.atlas-ia.com #[ADW_ATLAST.A]
127.0.0.1 www.atlas-ia.com #[Adware.OfferAgent]
127.0.0.1 te.audiencematch.net
127.0.0.1 audiogalaxy.com
127.0.0.1 www.audiogalaxy.com
127.0.0.1 www.autosurfpro.com #[IE-SpyAd]
127.0.0.1 adserving.autotrader.com
127.0.0.1 cploving.awmhost.net #[TrojanClicker.Win32.Lopin]
127.0.0.1 www.azads.net #[IE-SpyAd]
# B
127.0.0.1 bar.baidu.com #[SPYW_BDPLUGIN.A][Sophos.JS/BDHelper-A]
127.0.0.1 www.banex.ca #[IE-SpyAd]
127.0.0.1 adserver.banneradministration.com
127.0.0.1 bannerboxes.com #[BannerBoxes Ad Code]
127.0.0.1 clicks.bannerboxes.com
127.0.0.1 feeds.bannerboxes.com
127.0.0.1 www.bannerboxes.com
127.0.0.1 ad.bannerconnect.net
127.0.0.1 ads.bannerconnect.net
127.0.0.1 www.banner-exchange.nl #[IE-SpyAd]
127.0.0.1 ad.bannerhost.ru
127.0.0.1 www.bannermanagement.nl #[IE-SpyAd]
127.0.0.1 www.bannerpromotion.it #[IE-SpyAd]
127.0.0.1 www.banner-mania.com
127.0.0.1 www.bannerspace.com #[IE-SpyAd]
127.0.0.1 www2.bannerspace.com
127.0.0.1 www3.bannerspace.com
127.0.0.1 www5.bannerspace.com
127.0.0.1 www6.bannerspace.com
127.0.0.1 www7.bannerspace.com
127.0.0.1 bannerswap.com #[IE-SpyAd]
127.0.0.1 www.bannerswap.com
127.0.0.1 bardownload.com
127.0.0.1 www.bardownload.com #[MHTMLRedir.Exploit][007installer Control]
127.0.0.1 media.baventures.com
127.0.0.1 www.besttoolbars.net #[ADW_TBARWIN32.A]
127.0.0.1 ads.betanews.com
127.0.0.1 ads.bidclix.com #[IE-SpyAd]
127.0.0.1 www.bidclix.com
127.0.0.1 bidclix.net #[IE-SpyAd]
127.0.0.1 www.bidclix.net
127.0.0.1 ads.bidvertiser.com #[IE-SpyAd]
127.0.0.1 bdv.bidvertiser.com
127.0.0.1 www.bidvertiser.com
127.0.0.1 c.bigmir.net
127.0.0.1 bigtracker.com
127.0.0.1 bighits.net #[IE-SpyAd]
127.0.0.1 bigticker.bighits.net
127.0.0.1 bounty.bighits.net
127.0.0.1 www.bighits.net
127.0.0.1 download.bigwebportal.com #[IE-SpyAd]
127.0.0.1 www.bigwebportal.com #[hotwebsearch.com]
127.0.0.1 counter.bizland.com
127.0.0.1 webads.bizservers.com
127.0.0.1 www.black-hole.co.uk
127.0.0.1 www.blacklogic.net
127.0.0.1 blacksoft.info #[Trojan-Dropper.Win32.Microjoin.b]
127.0.0.1 www.blazehits.net #[gonnasearch.com]
127.0.0.1 cluster.blingblingcontent.com
127.0.0.1 gb.blingblingcontent.com
127.0.0.1 s7.blingblingcontent.com #[HJTH.EasyWebSearch Hijacker]
127.0.0.1 blockchecker.com #[IE-SpyAd]
127.0.0.1 weblog.blogads.com
127.0.0.1 images.blogads.com
127.0.0.1 images2.blogads.com
127.0.0.1 proxy.blogads.com
127.0.0.1 www.blogads.com
127.0.0.1 blogmark.bokee.com #[Adware.BocaiToolbar]
127.0.0.1 bookedspace.com #[Parasite.BookedSpace]
127.0.0.1 www.bookedspace.com #[Adware.Bookedspace]
127.0.0.1 www.borlander.cn #[Adware.Borlan]
127.0.0.1 bans.bride.ru #[IE-SpyAd]
127.0.0.1 citi.bridgetrack.com #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 rccl.bridgetrack.com
127.0.0.1 www.browserplugin.com #[HJTH.EroticAccess][wobz.de]
127.0.0.1 install.browsertoolbar.com #[Backdoor.Autoupder][BrowserToolbar]
127.0.0.1 www2.browsertoolbar.com #[TROJ_SUA.A]
127.0.0.1 www.browsertoolbar.com #[Parasite.BrowserToolbar]
127.0.0.1 redemption.bullseye-media.net
127.0.0.1 users.bullseye-media.net
127.0.0.1 www.bullseye-media.net #[IE-SpyAd]
127.0.0.1 www.buildtraffic.com
127.0.0.1 buy-traffic.net #[searchmeup.com]
# C
127.0.0.1 cafeden.biz #[Koffix.Exploit]
127.0.0.1 images.cashfiesta.com #[AdWare.CashFiesta.a]
127.0.0.1 www.cashfiesta.com #[McAfee.Adware-CashFiesta]
127.0.0.1 www.cashventure.com
127.0.0.1 casino-on-net.com
127.0.0.1 java2.casino-on-net.com
127.0.0.1 www.casino-on-net.com
127.0.0.1 affiliate.casinorewards.com
127.0.0.1 deliver.castads.com
127.0.0.1 images.castads.com
127.0.0.1 serve.castads.com
127.0.0.1 www.care2.com #[TopMoxie]
127.0.0.1 ads.cars.com
127.0.0.1 msg.cd321.com #[Trojan.Startpage.Q]
127.0.0.1 www.cd321.com
127.0.0.1 ads.cdfreaks.com #[eTrust.Ads.cdfreaks]
127.0.0.1 cellaphone.net #[MHTMLRedir.Exploit]
127.0.0.1 www.celebritaspoglie.net #[IE-SpyAd]
127.0.0.1 mds.centrport.net #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 www.cerials.net #[C2Media/LOP variant]
127.0.0.1 abc.checkm8.com
127.0.0.1 rmm1u.checkm8.com
127.0.0.1 web.checkm8.com #[CHECKM8 AD TAGS]
127.0.0.1 ads.chellomedia.com
127.0.0.1 ad.cibleclick.com
127.0.0.1 www.cibleclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.classifieds1000.com
127.0.0.1 clearfind.com
127.0.0.1 www.clearfind.com #[IE-SpyAd]
127.0.0.1 ads.clickad.com #[eTrust.Tracking Cookie]
127.0.0.1 hits.clickandtrack.net
127.0.0.1 clickbank.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 hop.clickbank.net #[Adware.Clickbank][Adware.ClickDLoader]
127.0.0.1 zzz.clickbank.net
127.0.0.1 clickedyclick.com #[IE-SpyAd]
127.0.0.1 www.clickexchange.ru #[IE-SpyAd]
127.0.0.1 click2boost.com #[IE-SpyAd]
127.0.0.1 secure.click2boost.com
127.0.0.1 service.click2boost.com
127.0.0.1 www.click2boost.com
127.0.0.1 www.clicks2you.com #[IE-SpyAd]
127.0.0.1 clicktracks.com
127.0.0.1 stats.clicktracks.com
127.0.0.1 stats1.clicktracks.com # [eTrust.Tracking Cookie]
127.0.0.1 stats2.clicktracks.com
127.0.0.1 www.clicktracks.com #[IE-SpyAd]
127.0.0.1 www.is1.clixgalore.com
127.0.0.1 www.clixgalore.com #[IE-SpyAd]
127.0.0.1 www2.click-fr.com
127.0.0.1 www3.click-fr.com
127.0.0.1 www4.click-fr.com
127.0.0.1 www.clickhouse.com #[IE-SpyAd]
127.0.0.1 www.clicks4u.com #[IE-SpyAd]
127.0.0.1 ad1.clickhype.com #[IE-SpyAd]
127.0.0.1 cfg.clipgenie.com
127.0.0.1 download.clipgenie.com
127.0.0.1 dldw.clipgenie.com
127.0.0.1 ss.clipgenie.com
127.0.0.1 www.clipgenie.com #[Adware.ClipGenie]
127.0.0.1 banner.clubdicecasino.com
127.0.0.1 www.cnstats.com
127.0.0.1 ads.cobrad.com
127.0.0.1 comclick.com #[IE-SpyAd]
127.0.0.1 ct2.comclick.com
127.0.0.1 fl01.ct2.comclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 ihm01.ct2.comclick.com
127.0.0.1 www.comclick.com
127.0.0.1 aa.connextra.com
127.0.0.1 bb.connextra.com
127.0.0.1 cc.connextra.com
127.0.0.1 dd.connextra.com
127.0.0.1 ee.connextra.com
127.0.0.1 ff.connextra.com
127.0.0.1 data.connextra.com
127.0.0.1 consumeralertsystem.com #[Adw.ConsumerAlertSystem.CASClient]
127.0.0.1 www1.consumeralertsystem.com
127.0.0.1 www.consumeralertsystem.com #[PcTools.CasinoClient]
127.0.0.1 ads.contactmusic.com #[advertpro]
127.0.0.1 svp.contextuad.org #[IE-SpyAd]
127.0.0.1 www.thecoolbar.com #[Softomate Toolbar][Adware.Fizzle]
127.0.0.1 ads.console.net
127.0.0.1 coolshader.com
127.0.0.1 c.coolshader.com #[Win32.Harnig]
127.0.0.1 www.coolshader.com
127.0.0.1 counted.com #[IE-SpyAd]
127.0.0.1 bilbo.counted.com
127.0.0.1 www.counted.com
127.0.0.1 www.counter-gratis.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.counterguide.com
127.0.0.1 counter4u.de #[IE-SpyAd]
127.0.0.1 www.counting4free.com #[IE-SpyAd]
127.0.0.1 log1.countomat.com
127.0.0.1 connectionzone.com
127.0.0.1 count.casino-trade.com
127.0.0.1 www.couponsandoffers.com #[Adware.TopMoxie]
127.0.0.1 data.coremetrics.com #[IE-SpyAd]
127.0.0.1 test.coremetrics.com
127.0.0.1 twci.coremetrics.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 server.cpmstar.com #[ads.shizmoo.com]
127.0.0.1 cracks.am #[eTrust.Cracks.am][ADW_CRAMTB.A]
127.0.0.1 www.cracks.am #[[bleep]-portal.com][Adware.CramToolbar]
127.0.0.1 files.crackz.ws
127.0.0.1 wmw.crackz.ws
127.0.0.1 www.crackz.ws
127.0.0.1 www.crispads.com #[IE-SpyAd]
127.0.0.1 ads.crosswinds.net
127.0.0.1 megabyte.crosswinds.net
127.0.0.1 cyberbounty.com #[IE-SpyAd]
127.0.0.1 js.cybermonitor.com
127.0.0.1 stat3.cybermonitor.com
127.0.0.1 cytron.com #[DailyWinner][Cytron]
127.0.0.1 www.cytron.com
# D
127.0.0.1 ads.date.com #[IE-SpyAd]
127.0.0.1 banner.date.com
127.0.0.1 au.track.decideinteractive.com
127.0.0.1 au.link.decideinteractive.com
127.0.0.1 eu.link.decideinteractive.com
127.0.0.1 link.decideinteractive.com
127.0.0.1 www.decideinteractive.com
127.0.0.1 www.decideinteractive.co.uk
127.0.0.1 www.deepcom.com #[TrojanDropper.Win32.Small.gt]
127.0.0.1 collector.deepmetrix.com
127.0.0.1 geo.deepmetrix.com
127.0.0.1 www.deepmetrix.com
127.0.0.1 delta2378493.com #[Download.Sumina]
127.0.0.1 ads.dennisnet.co.uk
127.0.0.1 track.did-it.com #[Wired.com]
127.0.0.1 diji-realm.net #[Backdoor.Mepcod]
127.0.0.1 comm1.digits.com
127.0.0.1 counter.digits.com #[IE-SpyAd]
127.0.0.1 direct-ip.com #[Adware-DirectIP]
127.0.0.1 www.direct-ip.com #[Adware-DirectIP][Adware-CommanderNET]
127.0.0.1 stats.directnic.com
127.0.0.1 cache.directorym.com #[c2.mii.instacontent.net]
127.0.0.1 www.divago.com #[Adware.Surfairy]
127.0.0.1 track.dmipartners.com
127.0.0.1 ad.dmpi.net
127.0.0.1 ad2.dmpi.net
127.0.0.1 ad3.dmpi.net
127.0.0.1 ad4.dmpi.net
127.0.0.1 ubnm.dmpi.net
127.0.0.1 test-ware.dyndns.biz #[Trojan.Totmau]
127.0.0.1 www.dnscaching.net #[stickypops.com]
127.0.0.1 www.domamil.cz #[Trojan.Beagooz]
127.0.0.1 www.donttrip.org #[IE-SpyAd]
127.0.0.1 downloadalot.com
127.0.0.1 get.downloadalot.com
127.0.0.1 www.downloadalot.com #[IE-SpyAd]
127.0.0.1 www.downseek.com #[SunBelt.DownSeek Search]
127.0.0.1 dqmedia.net #[spam]
127.0.0.1 drmx01.net #[spam]
127.0.0.1 www.claus.drehteile-rieche.de #[Win32.Formglieder.B]
127.0.0.1 www.drinkmagik.biz #[Trojan.Spbot.C]
127.0.0.1 ads.drugs.com
127.0.0.1 www.dudu.com #[Adware.DuDuAccelerator]
127.0.0.1 www.duenow.com
127.0.0.1 gfx.dvlabs.com #[IE-SpyAd]
127.0.0.1 klipads.dvlabs.com
# E
127.0.0.1 e2give.com #[Adware-E2Give][Spyware.e2give]
127.0.0.1 www.e2give.com
127.0.0.1 eaglehousing.com #[Trojan.Tabela.B]
127.0.0.1 www.eaglehousing.com #[Trojan.Eaghouse]
127.0.0.1 www.eastworldnetwork.com
127.0.0.1 easyhitcounters.com #[IE-SpyAd]
127.0.0.1 beta.easyhitcounters.com
127.0.0.1 www.easywebsearch.nl #[Easywebinstaller Control][IE-SpyAd]
127.0.0.1 www.e-bannerx.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.easycounter.com #[IE-SpyAd]
127.0.0.1 banners.easydns.com
127.0.0.1 banner.easyspace.com #[IE-SpyAd]
127.0.0.1 adserv1.ebates.com #[WebSavings]
127.0.0.1 www.ebates.com #[Adware.MoeMoney]
127.0.0.1 c2.edapebaf.com #[IE-SpyAd]
127.0.0.1 www.efinder.cc #[StartPage-DA]
127.0.0.1 www.ek21.com #[Trojan.Chost.B]
127.0.0.1 click3.ekahfmal.com
127.0.0.1 www.elancenet.org #[Worm/Eyeveg.CH]
127.0.0.1 ad1.emediate.dk
127.0.0.1 epeople.com
127.0.0.1 errorpage404.com #[JS_TRAFFICHBAR.A]
127.0.0.1 www.errorpage404.com #[Parasite.TinyBar]
127.0.0.1 vipuk.escritorioactivo.com #[123Messenger Hijacker]
127.0.0.1 www.escorcher.com #[IE-SpyAd]
127.0.0.1 www.eshopads2.com
127.0.0.1 estat.com #[IE-SpyAd]
127.0.0.1 perso.estat.com
127.0.0.1 prof.estat.com
127.0.0.1 www.estat.com
127.0.0.1 eu-adcenter.net
127.0.0.1 thinknyc.eu-adcenter.net
127.0.0.1 ugo.eu-adcenter.net #[evidence-eliminator.com]
127.0.0.1 adopt.euroclick.com
127.0.0.1 www.euroklik.nl #[EasyBar][HJTH.SinCity Dialer]
127.0.0.1 www.euros4click.de
127.0.0.1 euro-randomizer.com #[Trojan.dropper]
127.0.0.1 engage.everyone.net
127.0.0.1 static.everyone.net #[IE-SpyAd]
127.0.0.1 www.everythingyouneed.org #[Malware Installer]
127.0.0.1 advert.exaccess.ru
127.0.0.1 dynamic.exaccess.ru #[IE-SpyAd]
127.0.0.1 www.exchangead.com #[IE-SpyAd]
127.0.0.1 exit-ad.de #[Ad-Aware.Tracking Cookie]
127.0.0.1 exitexchange.com #[IE-SpyAd]
127.0.0.1 count.exitexchange.com
127.0.0.1 images.exitexchange.com
127.0.0.1 www.exitexchange.com
127.0.0.1 www.exchangeexit.com #[HJTH.Winupie]
127.0.0.1 www.exittrade.com
127.0.0.1 www.exittraffic.net #[IE-SpyAd]
127.0.0.1 nyton.experclick.com #[p.mii.instacontent.net]
127.0.0.1 ads.expressindia.com
127.0.0.1 banners.expressindia.com
127.0.0.1 cdn.eyewonder.com #[IE-SpyAd]
127.0.0.1 www.evidence-eliminator.com
127.0.0.1 www.eyeget.com #[McAfee.Adware-EyeGet]
127.0.0.1 ezcybersearch.com #[EZCyberSearch.Surebar]
127.0.0.1 ads.ezcybersearch.com #[Adware.EZSearch.B]
127.0.0.1 ezcybersearch.mail.everyone.net
127.0.0.1 www.ezcybersearch.com #[Parasite.ezCyberSearch]
127.0.0.1 eziin.com #[Adware.Eziin]
127.0.0.1 www.eziin.com
# F
127.0.0.1 www.fast-adv.it
127.0.0.1 fast-web-search.com #[IE-SpyAd]
127.0.0.1 www.fast-web-search.com
127.0.0.1 www.fast2net.com
127.0.0.1 www.fastfind.org #[TROJ_STARTPAG.KF][Adware.Fastfind.B]
127.0.0.1 fasttrack.nu
127.0.0.1 counter.fateback.com
127.0.0.1 www.fatpickle.com #[FatPickle Toolbar][IE-SpyAd]
127.0.0.1 www.fightpopups.net #[Adware.MessStopper]
127.0.0.1 filesharingaccess.com #[MHTMLRedir.Exploit]
127.0.0.1 adserver.filefront.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.filemix.net #[Surf+][IE-SpyAd]
127.0.0.1 www.find.fm #[AdWare.SideSearch.g]
127.0.0.1 www.fineclicks.com #[IE-SpyAd]
127.0.0.1 firstname.com #[IE-SpyAd]
127.0.0.1 clicks.firstname.com
127.0.0.1 www.fish-screensaver.com #[AdWare.Win32.Gator.1008]
127.0.0.1 www.fizzlewizzle.com #[HJTH.Trojan.Downloader.VB.EU]
127.0.0.1 www.flyeagles.com #[Trojan.Drivus]
127.0.0.1 flyinads.com #[IE-SpyAd]
127.0.0.1 www.flyinads.com
127.0.0.1 cdn.flashedmail.com
127.0.0.1 tracker1.flashedmail.com #[IE-SpyAd]
127.0.0.1 adserver.fmpub.net
127.0.0.1 www.foofle.net #[Backdoor.Foobot]
127.0.0.1 js.forrestersurveys.com
127.0.0.1 securinews.free.fr #[Trojan.Hexem]
127.0.0.1 ads.freebannertrade.com #[AdNetPros Banner Code]
127.0.0.1 www.freedom850.com #[Trojan.Drivus]
127.0.0.1 www.freeloadmp3.com #[IE-SpyAd]
127.0.0.1 ad.freefind.com
127.0.0.1 www.freehistorycleaner.com #[Adware.Fapi][ADW_HISCLEAN.A]
127.0.0.1 freelogs.com
127.0.0.1 bar.freelogs.com
127.0.0.1 goo.freelogs.com
127.0.0.1 ico.freelogs.com
127.0.0.1 joe.freelogs.com
127.0.0.1 mom.freelogs.com
127.0.0.1 xyz.freelogs.com
127.0.0.1 adserver.freenet.de
127.0.0.1 free-stats.com
127.0.0.1 counters.freewebs.com
127.0.0.1 www.freewebsites.com
127.0.0.1 www.free-windows-games.com #[Parasite.GAMsys][GamHelper]
127.0.0.1 ads.ft.com
127.0.0.1 www.funbangladesh.com #[ysbweb.com][Purityscan]
# G
127.0.0.1 adserver.gadu-gadu.pl
127.0.0.1 ads.gamespy.com
127.0.0.1 adcontent.gamespy.com
127.0.0.1 ads.gamespyid.com
127.0.0.1 ad1.gamezone.com #[RealMedia]
127.0.0.1 server.gamyun.net
127.0.0.1 www.gamyun.net #[Adware.GamyunIeToolbar]
127.0.0.1 www.gebr-wachs.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 sda.geek.com #[AdvertPro]
127.0.0.1 adserver.geenstijl.nl
127.0.0.1 kassa.geenstijl.nl
127.0.0.1 gd.geobytes.com #[obtains users location]
127.0.0.1 banners.geotarget.info
127.0.0.1 www.geowhere.net #[SunBelt.GeoWhere Search]
127.0.0.1 www.getsmart.com
127.0.0.1 bp2.getredirect.com #[IE-SpyAd]
127.0.0.1 4.getredirect.com #[superlogy.com]
127.0.0.1 www.getredirect.com
127.0.0.1 getupdate.com
127.0.0.1 dlx.getupdate.com #[AdvWare.ToolBar.VB.b]
127.0.0.1 www.getupdate.com #[Adware.Getup]
127.0.0.1 gigex.com #[IE-SpyAd]
127.0.0.1 media.gigex.com #[SpeedDelivery]
127.0.0.1 oascentral.gigex.com #[RealMedia]
127.0.0.1 www.gigex.com #[download Class][eTrust.Gigex SpeedDelivery]
127.0.0.1 globesearch.com
127.0.0.1 www.globesearch.com #[IE-SpyAd][CWS]
127.0.0.1 banner.goldenpalace.com #[redirects]
127.0.0.1 www.goldfer.net #[Backdoor.Generic.OCX]
127.0.0.1 goldstats.net #[IE-SpyAd]
127.0.0.1 www.goldstats.net
127.0.0.1 www.goggle.com #[IE-SpyAd][typo squatter]
127.0.0.1 partner.gonamic.de
127.0.0.1 goodcounter.com #[IE-SpyAd]
127.0.0.1 www.goodcounter.com
127.0.0.1 adincl.gopher.com #[InfoSpace]
127.0.0.1 ads.gorillanation.com #[eTrust.GorillaNation]
127.0.0.1 adserver.gorillanation.com #[IE-SpyAd]
127.0.0.1 admonster.gorasoft.com #[TROJ_SMALL.AAL]
127.0.0.1 gostats.com #[IE-SpyAd]
127.0.0.1 as.gostats.com
127.0.0.1 c1.gostats.com
127.0.0.1 c2.gostats.com
127.0.0.1 c3.gostats.com
127.0.0.1 www.gotoo.com
127.0.0.1 webcounter.goweb.de #[IE-SpyAd]
127.0.0.1 greatstartpage.com #[IE-SpyAd]
127.0.0.1 www.greatstartpage.com
127.0.0.1 www.greasypalm.co.uk #[PcTools.GreasyPalm bar]
127.0.0.1 ads.grokads.com
127.0.0.1 grokster.com #[IE-SpyAd][P2P]
127.0.0.1 dl.grokster.com
127.0.0.1 www.grokster.com
127.0.0.1 www.groovysearchesbar.com #[IE-SpyAd]
127.0.0.1 ads.guardian.co.uk
127.0.0.1 ads.guardianunlimited.co.uk
127.0.0.1 www.g-wizzads.net
# H
127.0.0.1 hao3344.com #[Adware.Adtest]
127.0.0.1 www.hao3344.com #[eTrust.Adtest]
127.0.0.1 www.harmonyhollow.net #[Adware Bundler]
127.0.0.1 ad0.haynet.com
127.0.0.1 stats.hecklerspray.com
127.0.0.1 www.henbang.net #[Adware.Henbang][SPYW_HAP.A]
127.0.0.1 ads.hitcents.com #[IE-SpyAd]
127.0.0.1 hits-counter.com
127.0.0.1 hithopper.com #[Adware.Hithopper]
127.0.0.1 www.hithopper.com #[ADW_HITHOPPER.A]
127.0.0.1 hitkorea.co.kr #[Adware.Atlcontrol]
127.0.0.1 www.hitlogger.com
127.0.0.1 hitmodel.net
127.0.0.1 hit-now.com
127.0.0.1 hit-parade.com
127.0.0.1 loga.hit-parade.com
127.0.0.1 hitstats.net
127.0.0.1 www.hittracking.com #[IE-SpyAd]
127.0.0.1 images.hitwise.co.uk
127.0.0.1 ads.home.net
127.0.0.1 anna.homeftp.net #[W32.Linkbot.A]
127.0.0.1 www.gontijoamaral.hpg.com.br #[Adware.Diginum]
127.0.0.1 counters.honesty.com
127.0.0.1 cgi.honesty.com
127.0.0.1 horse-active.net #[Trojan.TrustedZones]
127.0.0.1 www.horse-active.net
127.0.0.1 horse-dns.net
127.0.0.1 horse-search.net
127.0.0.1 ad2.hotels.com
127.0.0.1 banners.hotlinks.net #[IE-SpyAd]
127.0.0.1 horseserver.net #[Troj/Haxdor-Fam][Trojan.Startpage.I]
127.0.0.1 www.horseserver.net #[Backdoor.Haxdoor.D]
127.0.0.1 hotsearch.com #[roar.com][IE-SpyAd]
127.0.0.1 www.hotsearch.com
127.0.0.1 www.10s.com.br #[Trojan.Cargao]
127.0.0.1 cgi.hotstat.nl #[IE-SpyAd]
127.0.0.1 viewstat.hotstat.nl
127.0.0.1 vip.huigezi.com #[Backdoor.Graybird.Q][W32.Looked.F]
127.0.0.1 hc2.humanclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.humanclick.com #[IE-SpyAd]
127.0.0.1 custom1.hurricanedigitalmedia.com
127.0.0.1 custom3.hurricanedigitalmedia.com
127.0.0.1 www.hypertracker.com #[IE-SpyAd]
# I
127.0.0.1 ads.iafrica.com
127.0.0.1 ads.iboost.com
127.0.0.1 www.i-clicks.net
127.0.0.1 hits.icdirect.com
127.0.0.1 hitctr01.icdirect.com
127.0.0.1 idolch.net #[Trojan.Idocha]
127.0.0.1 www.idonate.com #[eTrust.IDonate]
127.0.0.1 image-catcher.com
127.0.0.1 bar.iebar8.com #[Adware.Navihelper]
127.0.0.1 stats.surfaid.ihost.com #[IE-SpyAd]
127.0.0.1 gate.ilogbox.com
127.0.0.1 www.impregnable.net #[TrojanDownloader.Win32.VB.dw][Trojan.Win32.StartPage.kk]
127.0.0.1 stats.indextools.com #[IE-SpyAd][eTrust.Tracking Cookie]
127.0.0.1 adserver.indieclick.com #[server down?]
127.0.0.1 campaign.indieclick.com
127.0.0.1 adcenter.in2.com
127.0.0.1 ads.inet1.com
127.0.0.1 ads7.inet1.com
127.0.0.1 juggler.inetinteractive.com
127.0.0.1 rotator.juggler.inetinteractive.com
127.0.0.1 banners.inetfast.com
127.0.0.1 bn.inf3ct3d.info #[Backdoor.Shellbot]
127.0.0.1 images.infiads.com
127.0.0.1 www.infiads.com
127.0.0.1 reg1.info #[PWSteal.Reoxtan]
127.0.0.1 ads.infospace.com #[ADW_DEALHELPER.C]
127.0.0.1 bvads.infospace.com
127.0.0.1 xads.infospace.com
127.0.0.1 www.infotelsrl.com #[eTrust.Infotel srl]
127.0.0.1 ads.injersey.com #[RealMedia]
127.0.0.1 ads.intellicast.com
127.0.0.1 ads.intelihealth.com
127.0.0.1 strtt.interfree.it #[W32.Iberio]
127.0.0.1 ads.intermezzia.com #[IE-SpyAd]
127.0.0.1 indiads.com #[IE-SpyAd]
127.0.0.1 images.indiads.com
127.0.0.1 infostart.com #[IE-SpyAd]
127.0.0.1 popups.infostart.com #[eTrust.Popups.infostart.com]
127.0.0.1 oc.inspectorclick.com
127.0.0.1 trax.inspectorclick.com #[IE-SpyAd]
127.0.0.1 v2.inspectorclick.com
127.0.0.1 v3.inspectorclick.com
127.0.0.1 instadia.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.instadia.net
127.0.0.1 instantsearch.cc #[Panda.Adware/TheLocalSearch]
127.0.0.1 www.instantsearch.cc #[F-Secure.Small.wy]
127.0.0.1 anm.intelli-direct.com
127.0.0.1 oxfam.intelli-direct.com
127.0.0.1 www.intelli-tracker.com
127.0.0.1 newadserver.interfree.it #[Adcycle]
127.0.0.1 channels.intwined.com #[Adware/ToolBar.ISearch.c]
127.0.0.1 search.intwined.com
127.0.0.1 www.intwined.com #[McAfee.Adware-SSF!Hosts]
127.0.0.1 inqwire.com #[IE-SpyAd]
127.0.0.1 ww2.inqwire.com
127.0.0.1 www.inqwire.com
127.0.0.1 www.invinc.com #[Troj/Dloader-J]
127.0.0.1 ads.ipowerweb.com
127.0.0.1 www.ipstat.com #[IE-SpyAd]
127.0.0.1 adzones.ircspy.com
127.0.0.1 www.istats.nl #[IE-SpyAd]
127.0.0.1 adserver1.isohunt.com
127.0.0.1 ads.isoftmarketing.com
127.0.0.1 adcycle.isoftmarketing.com #[server down?]
127.0.0.1 ads1.itadnetwork.co.uk
127.0.0.1 www.itrafficstar.com #[IE-SpyAd]
# J
127.0.0.1 www.j4sb.com #[Trojan.Jasbom]
127.0.0.1 ad.jamba.net #[IE-SpyAd]
127.0.0.1 ad.jamster.com
127.0.0.1 www.japan213.com #[Trojan.Finfanse]
127.0.0.1 www.jcount.com #[IE-SpyAd]
127.0.0.1 www.jellycounter.com
127.0.0.1 app2.jkahfmal.com
127.0.0.1 jpedownload.joltid.com
127.0.0.1 www.joltid.com #[Adware.P2PNetworking][SPYW_PPNETWORK.B]
127.0.0.1 play.joyiex.com #[Trojan.Joex]
127.0.0.1 www.joyiex.com #[Trojan.Startpage.Q]
127.0.0.1 promotion.jpds.com
# K
127.0.0.1 www.k265.com #[Adware.Borlan]
127.0.0.1 kazaalite.pl
127.0.0.1 www.kazaalite.pl #[MHTMLRedir.Exploit]
127.0.0.1 adserve.kikizo.com
127.0.0.1 www1.kliks.nl #[IE-SpyAd]
127.0.0.1 www2.kliks.nl
127.0.0.1 www.kliks.nl
127.0.0.1 kt3.kliptracker.com #[IE-SpyAd]
127.0.0.1 kt4.kliptracker.com
127.0.0.1 www.kliptracker.com
127.0.0.1 www.kmindex.ru
127.0.0.1 ads.kmpads.com #[IE-SpyAd]
127.0.0.1 koolbar.net #[Adware Bundler][ADW_KOOLBAR.A]
127.0.0.1 www.koolbar.net #[eTrust.AutoSearch][IE-SpyAd]
127.0.0.1 kutsap.com #[Trojan.Anicmoo]
# L
127.0.0.1 layer-ads.de
127.0.0.1 www.leopardsearch.com
127.0.0.1 ts1.lexmark.com
127.0.0.1 www.linkads.net #[IE-SpyAd]
127.0.0.1 www.lineage0.com #[Trojan.Rohoteng]
127.0.0.1 linkbuddies.com #[IE-SpyAd]
127.0.0.1 banners.linkbuddies.com
127.0.0.1 www.linkbuddies.com
127.0.0.1 www.linkcounter.com
127.0.0.1 linkexchange.ru #[IE-SpyAd]
127.0.0.1 web.linkexchange.ru
127.0.0.1 www.linkexchange.ru
127.0.0.1 link4link.com #[IE-SpyAd]
127.0.0.1 plus.link4link.com
127.0.0.1 www.links4trade.com #[IE-SpyAd]
127.0.0.1 escati.linkopp.net #[IE-SpyAd]
127.0.0.1 www.linkopp.net
127.0.0.1 linkshelper.com #[Adware.MetaSearch]
127.0.0.1 js.livehelper.com #[IE-SpyAd]
127.0.0.1 newbrowse.livehelper.com
127.0.0.1 www.liveperson.com
127.0.0.1 liveperson.net #[IE-SpyAd]
127.0.0.1 sales.liveperson.net
127.0.0.1 server.iad.liveperson.net #[Ad-Aware.Data Miner][HumanTag Monitor]
127.0.0.1 locators.com #[Adware.Locator]
127.0.0.1 toolbar.locators.com #[SunBelt.Locators Toolbar]
127.0.0.1 www.locators.com
127.0.0.1 www.lookde5.com #[W32.Looked]
127.0.0.1 lookoutsoft.net #[Adware Bundler]
127.0.0.1 www.lookoutsoft.net #[AdWare.Win32.WinAD.b]
127.0.0.1 www.lords-of-havoc.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 jama.lovinghost.com #[Trojan-Proxy.Win32.Agemt.ei]
127.0.0.1 exploited.lsass.cc #[Backdoor.Win32.SdBot.gen]
127.0.0.1 luckyhomepage.com #[search.targetwords.com\1stblaze.com]
127.0.0.1 www.luckyhomepage.com #[IE-SpyAd]
127.0.0.1 www.lvip.net #[McAfee.StartPage-HI]
127.0.0.1 counter.lyricsdownload.com
127.0.0.1 www.lyricspy.com #[PluginAccess]
# M
127.0.0.1 www.madoogali.com #[Madoogali][IE-SpyAd]
127.0.0.1 go.mailbits.com
127.0.0.1 mair.net #[Realtracker]
127.0.0.1 we.malresearch.org #[Backdoor.Win32.IRCBot.ay]
127.0.0.1 manwithnoname.biz #[Avira.TR/Proxy.Mitgl.DQ.1]
127.0.0.1 www.manwithnoname.biz
127.0.0.1 erotic.masterstats.com
127.0.0.1 image.masterstats.com #[IE-SpyAd]
127.0.0.1 link.masterstats.com
127.0.0.1 vw.masterstats.com
127.0.0.1 ads.affiliates.match.com
127.0.0.1 associmage.match.com #[IE-SpyAd]
127.0.0.1 adserver.matchcraft.com
127.0.0.1 ads.mcafee.com
127.0.0.1 directads.mcafee.com
127.0.0.1 ads.mdchoice.com
127.0.0.1 ads.mediaodyssey.com
127.0.0.1 acvs.mediaonenetwork.net
127.0.0.1 acvsrv.mediaonenetwork.net
127.0.0.1 ads.mediaturf.net
127.0.0.1 www.meet2k.com #[W32.Peerload.A]
127.0.0.1 exit.megago.com
127.0.0.1 www.megago.com #[typo squatter][IE-SpyAd]
127.0.0.1 www.megaseek.net #[IE-SpyAd]
127.0.0.1 megatds.com #[Panda.Adware/Megatds]
127.0.0.1 admintds.megatds.com
127.0.0.1 tds.megatds.com
127.0.0.1 www.megatds.com
127.0.0.1 adserv2.meritdesigns.com
127.0.0.1 ads.metropol.dk
127.0.0.1 pubs.mgn.net #[Grolier Network]
127.0.0.1 www.mgshareware.com #[Adware Bundler][Parasite.MySearch]
127.0.0.1 www.mini-player.com #[5MOF Mini-Player]
127.0.0.1 banner.missingkids.com
127.0.0.1 ads.mixtraffic.com #[IE-SpyAd]
127.0.0.1 smile.modchipstore.com
127.0.0.1 ads.monster.com
127.0.0.1 adserver.monster.com
127.0.0.1 adserver.a.in.monster.com
127.0.0.1 ads.monstermoving.com
127.0.0.1 cookie.monster.com
127.0.0.1 www.movieland.com #[IE-SpyAd]
127.0.0.1 mp3today.net
127.0.0.1 www.mp3yes.com #[HJTH.C2Media/LOP variant][IE-SpyAd]
127.0.0.1 mpamexit.com
127.0.0.1 www.messagetag.com #[Email tracker][IE-SpyAd]
127.0.0.1 msgtag.com
127.0.0.1 img.msgtag.com #[IE-SpyAd]
127.0.0.1 www.msgtag.com
127.0.0.1 msxpsupport.com #[Adware.SearchMaid]
127.0.0.1 www.msxpsupport.com #[Trojan.Win32.Fakespy.a]
127.0.0.1 multi1.rmuk.co.uk #[RealMedia]
127.0.0.1 musah.info #[Trojan-Downloader.Win32.Delf.h][TROJ_DLOADER.AFB]
127.0.0.1 www.musicmass.com #[HJTH.C2Media/LOP variant]
127.0.0.1 www.musicsonglyrics.com #[MVPS.Criteria]
127.0.0.1 mvtracker.com #[IE-SpyAd]
127.0.0.1 www.mvtracker.com
127.0.0.1 mvr3d.net #[NavExcel\n-CASE]
127.0.0.1 www.mvr3d.net
127.0.0.1 mvr.us #[Parasite.NavExcel]
127.0.0.1 www.mvr.us
127.0.0.1 www.myadtrack.com #[Email Tracker][IE-SpyAd]
127.0.0.1 www.myaffiliateprogram.com #[IE-SpyAd]
127.0.0.1 www.myarmory.com #[Spyware.Bazookabar]
127.0.0.1 www.myemessenger.com
127.0.0.1 noe.myftp.biz #[Backdoor.Botnachala]
127.0.0.1 www.mylinker.net #[Adware.MyLinker]
127.0.0.1 rm.myoc.com
127.0.0.1 myhitlogger.com
127.0.0.1 www.mystats.nl #[IE-SpyAd]
127.0.0.1 www2.mystats.nl
127.0.0.1 liveupdate.myim.cn #[Adware.BeSys]
# N
127.0.0.1 hit.namimedia.com #[IE-SpyAd]
127.0.0.1 ads.nandomedia.com
127.0.0.1 naupoint.com #[Parasite.Naupoint][ADW_NAUPONT.A]
127.0.0.1 feed.naupoint.com #[eTrust.Win32.Dudrev.A]
127.0.0.1 hp.naupoint.com #[NPCenter][SunBelt.NauPoint Installer]
127.0.0.1 www.naupoint.com #[TROJ_STARTPAG.X]
127.0.0.1 ads.neowin.net
127.0.0.1 banman.nepsecure.co.uk #[Ban Man Pro Banner Code]
127.0.0.1 code.netbreak.com.au
127.0.0.1 banners.netcraft.com
127.0.0.1 www.netflip.com #[IE-SpyAd]
127.0.0.1 money2.netfirms.com #[The Money Toolbar]
127.0.0.1 hints.netflame.cc #[Fireclick Web Analytics]
127.0.0.1 ssl-hints.netflame.cc
127.0.0.1 stat.netlogic.ru #[NetLogic Logger]
127.0.0.1 partner.netmechanic.com
127.0.0.1 tracker.netmechanic.com
127.0.0.1 counter.netmore.net
127.0.0.1 www.netpoll.nl
127.0.0.1 www.netpumper.com #[CounterSpy.Adware Bundler]
127.0.0.1 servedby.netshelter.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.network-tool.net #[Trojan.Magise]
127.0.0.1 www.newsh.com #[Kephyr.PUP]
127.0.0.1 ads.newsint.co.uk
127.0.0.1 adq.nextag.com
127.0.0.1 www.nlbanner.nl #[IE-SpyAd]
127.0.0.1 nowbox.com
127.0.0.1 www.nowbox.com #[Parasite.NowBox]
127.0.0.1 ad.nozonedata.com #[Ad-Aware Tracking Cookie]
127.0.0.1 ad1.nozonedata.com
127.0.0.1 ns2.iad1.nssrv.com #[IE-SpyAd]
127.0.0.1 nugget-sales.com #[ISC.Alert]
127.0.0.1 nzads.net.nz
# O
127.0.0.1 node2.ocslab.com #[TROJ_LOADER.D][TROJ_APROPO.H]
127.0.0.1 okcounter.com #[IE-SpyAd][eTrust.Tracking Cookie]
127.0.0.1 www.okww.net #[Trojan.StartPage.C]
127.0.0.1 stat.onestat.com #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 www.onestat.com
127.0.0.1 one.ru
127.0.0.1 cnt.one.ru
127.0.0.1 stats0.one.ru
127.0.0.1 stats1.one.ru
127.0.0.1 stats2.one.ru
127.0.0.1 ads.oneandonlynetwork.com
127.0.0.1 www.oneandonlynetwork.com #[Ticketmaster][IE-SpyAd]
127.0.0.1 ads.onemodelplace.com
127.0.0.1 reklama.onet.pl
127.0.0.1 online-service.cc
127.0.0.1 www.online-service.cc #[Trojan.Magise]
127.0.0.1 adserver.online-tech.com
127.0.0.1 server1.opentracker.net
127.0.0.1 ccc00.opinionlab.com
127.0.0.1 ccc01.opinionlab.com #[msn.com]
127.0.0.1 rate.opinionlab.com
127.0.0.1 www.opinionlab.com #[IE-SpyAd]
127.0.0.1 by.optimost.com
127.0.0.1 banner.orb.net
127.0.0.1 tg-images.osdn.com
127.0.0.1 otx5.otxresearch.com
127.0.0.1 otx.ifilm.com #[OTXMedia.dll]
127.0.0.1 survey.otxresearch.com #[TrojanDownloader.OTXloader.A]
127.0.0.1 www.otxresearch.com #[OTXMovie Class]
127.0.0.1 adpopper.outblaze.com #[ADW_BBINSTALL.B][bargain-buddy.net]
127.0.0.1 adp4.us4.outblaze.com
127.0.0.1 adserver.hk.outblaze.com
127.0.0.1 adserver.us.outblaze.com
127.0.0.1 download2.us4.outblaze.com #[HJTH.Bargain Buddy]
127.0.0.1 www.overpeer.com #[Trojan.Wimad]
# P
127.0.0.1 www.p2p-load.de #[W32.Peerload.A]
127.0.0.1 www.p3marketing.com #[Zapspot]
127.0.0.1 www.pantanalvip.com.br #[McAfee.Downloader-AFV]
127.0.0.1 click.payserve.com #[IE-SpyAd]
127.0.0.1 pcadprotector.cc #[McAfee.AdClicker-DI]
127.0.0.1 www.pcadprotector.cc #[Rogue/Suspect.sites]
127.0.0.1 www.pcbutts1.com #[Unauthorized Downloads]
127.0.0.1 www.pc-test.net
127.0.0.1 ad1.peel.com
127.0.0.1 ad3.peel.com
127.0.0.1 ads.peel.com
127.0.0.1 ad4.peel.com
127.0.0.1 ads5.peel.com
127.0.0.1 freeps3.peel.com
127.0.0.1 www.peel.com #[IE-SpyAd]
127.0.0.1 www.peel.net
127.0.0.1 ads.pennyweb.com #[addynamix.com]
127.0.0.1 banners.pennyweb.com #[IE-SpyAd]
127.0.0.1 www.peruvianmarket.com #[Trojan.Beagooz.D]
127.0.0.1 ads.photosight.ru
127.0.0.1 phpadsnew.com
127.0.0.1 www.phpadsnew.com
127.0.0.1 ads.planetactive.com
127.0.0.1 ads2.playnet.com
127.0.0.1 adserver.pollstar.com #[eTrust.Tracking Cookie]
127.0.0.1 popfind.net #[Adware.Ddpop]
127.0.0.1 www.pops-stop.com #[Spyware.SafeSurfing]
127.0.0.1 www.popupads.com #[IE-SpyAd]
127.0.0.1 www.popupad.net #[IE-SpyAd]
127.0.0.1 popupblockade.com #[Parasite.Httper]
127.0.0.1 www.popupblockade.com #[IE-SpyAd]
127.0.0.1 popupmoney.com #[IE-SpyAd]
127.0.0.1 server01.popupmoney.com
127.0.0.1 www.popupmoney.com
127.0.0.1 popadstop.com #[Adware.PopAdStop]
127.0.0.1 www.popadstop.com
127.0.0.1 www.popunder.info #[TROJ_CHECKIN.B]
127.0.0.1 www2.portdetective.com
127.0.0.1 www.ppctracking.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 adview.ppro.de
127.0.0.1 x0x0l.pp.ru #[BKDR_CCT.A]
127.0.0.1 www.praize.com #[Adware.Praize]
127.0.0.1 ads.primeinteractive.net
127.0.0.1 www.promarketingclub.com
127.0.0.1 www.prtracker.com
127.0.0.1 www.profitzone.com #[SunBelt.ProfitZONE Adbar]
127.0.0.1 ads.pro-market.net
127.0.0.1 pbid.pro-market.net
127.0.0.1 www.promo.com.au
127.0.0.1 www.prutect.com #[Spyware.e2give][Win32.Prutec.A]
127.0.0.1 www.protectedmedia.com #[Trojan.Wimad][Panda.WmvDown.B]
127.0.0.1 ad.prv.pl
127.0.0.1 ad.sma.punto.net
127.0.0.1 sma.punto.net
127.0.0.1 www.pureseeker.com #[C2Media/LOP variant][IE-SpyAd]
127.0.0.1 www.pwallet.com #[IE-SpyAd]
# Q
127.0.0.1 qanmqqoiw.com #[Trojan.Gamqowi]
127.0.0.1 adserv.quality-channel.de
127.0.0.1 ads-205.quarterserver.de
127.0.0.1 questionmarket.com #[IE-SpyAd]
127.0.0.1 amch.questionmarket.com
127.0.0.1 ch.questionmarket.com
127.0.0.1 survey.questionmarket.com
127.0.0.1 www.questionmarket.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 quickmetasearch.com #[ADW_SEARCHMETA.A][Adware.MetaSearch]
127.0.0.1 www.qq886.com #[Backdoor.Semes]
127.0.0.1 qqqqqq.info #[Trojan-Spy.Win32.Goldun.do][server down?]
# R
127.0.0.1 counter.rapidcounter.com
127.0.0.1 www.rapidcounter.com
127.0.0.1 www.autoraskrutka.ru #[Spyware.Acext]
127.0.0.1 www.raskrutim.ru #[Spyware.Acext]
127.0.0.1 www.realclicks.com
127.0.0.1 ads.rediff.com
127.0.0.1 adworks.rediff.com
127.0.0.1 imadworks.rediff.com
127.0.0.1 visit.referralware.com
127.0.0.1 ads.register.com
127.0.0.1 www.registrarads.com
127.0.0.1 counter.relmaxtop.com
127.0.0.1 www.relmaxtop.com
127.0.0.1 banner.relcom.ru
127.0.0.1 adservice.recon-networks.com
127.0.0.1 dae.responsetarget.com #[AutoGK][IE-SpyAd][MVPS.Criteria]
127.0.0.1 ads.revenews.com
127.0.0.1 ads.revsci.net
127.0.0.1 js.revsci.net
127.0.0.1 pix01.revsci.net
127.0.0.1 rightstats.com
127.0.0.1 www.rightstats.com
127.0.0.1 m.rmbclick.com #[IE-SpyAd]
127.0.0.1 client.roiadtracker.com #[IE-SpyAd]
127.0.0.1 hits.roitracker.com #[IE-SpyAd]
127.0.0.1 www.rgs-rostock.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 ad.ro2cn.com #[Adware.Ro2cn]
127.0.0.1 ldkiekxc.rr.nu #[Backdoor.Ryejet.B]
# S
127.0.0.1 judo.salon.com
127.0.0.1 oas.salon.com
127.0.0.1 www.savehits.com #[IE-SpyAd]
127.0.0.1 matchnet.st.sageanalyst.net
127.0.0.1 st.sageanalyst.net #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 pigmailer.scarryserv.biz #[Trojan.Mochi]
127.0.0.1 scorpionsearch.com #[W32.Adclicker.C.Trojan]
127.0.0.1 www.scorpionsearch.com #[x10.com][Trojan.Clicker.NetBuie a-b]
127.0.0.1 www.scratchindian.com #[Backdoor.Samkams]
127.0.0.1 adsremote.scripps.com
127.0.0.1 te.scripps.com
127.0.0.1 counter.search.bg #[IE-SpyAd]
127.0.0.1 searchalot.com #[IE-SpyAd]
127.0.0.1 cards.searchalot.com
127.0.0.1 mail.searchalot.com
127.0.0.1 search.searchalot.com
127.0.0.1 web.searchalot.com
127.0.0.1 www.searchalot.com #[McAfee.Adware-Tronix]
127.0.0.1 searchandclick.com
127.0.0.1 search.searchandclick.com
127.0.0.1 www.searchandclick.com #[Parasite.Browseraid][SearchAndClick]
127.0.0.1 www.searchgauge.com
127.0.0.1 searchitquick.com #[IE-SpyAd]
127.0.0.1 tb.searchitquick.com #[hotwebsearch.com][HJTH.Begin2Search Adware]
127.0.0.1 www.searchitquick.com #[SunBelt.SearchItQuick Toolbar]
127.0.0.1 www.searchlistings.biz #[IE-SpyAd]
127.0.0.1 www.searchmachine.com #[IE-SpyAd]
127.0.0.1 www.searchmagnifier.com
127.0.0.1 searchproject.net #[Trojan.Phel.A]
127.0.0.1 www.searchrelevancy.com #[Spyware.Relevancy]
127.0.0.1 www.searchresult.net #[Parasite.IgetNet]
127.0.0.1 searchtofind.net #[W32/Agent.DIR]
127.0.0.1 www.search-toolbar.com #[Trojan.Magise]
127.0.0.1 home.searchwords.com #[eTrust.AdRoad.Cpr]
127.0.0.1 www.searchwords.com #[Adware.SearchWords]
127.0.0.1 browser.secondpower.com
127.0.0.1 download.secondpower.com
127.0.0.1 www1.secondpower.com
127.0.0.1 www3.secondpower.com #[IE-SpyAd][KB320159]
127.0.0.1 www.secondpower.com #[SunBelt.SecondPower Multimedia Speedbar]
127.0.0.1 plugin.secureservicepack.com #[HJTH.GoDOTLess]
127.0.0.1 adserver.securityfocus.com #[RealMedia]
127.0.0.1 www.sedotracker.com
127.0.0.1 www.sedotracker.de #[IE-SpyAd]
127.0.0.1 www.selfsurveys.com #[IE-SpyAd]
127.0.0.1 www.seehits.com
127.0.0.1 www.seekmp3.com #[HJTH.C2Media/LOP variant]
127.0.0.1 www.send-safe.com #[Spamware]
127.0.0.1 serialkey.net #[Kephyr.PUP]
127.0.0.1 www.serialkey.net
127.0.0.1 servirc1.servebeer.com
127.0.0.1 servirc2.servebeer.com #[Backdoor.Sparta.D]
127.0.0.1 sesso.com
127.0.0.1 www.sesso.com #[VBS.Biscuit.A@mm]
127.0.0.1 www.sexyads.net
127.0.0.1 simplenter.com #[Adware.UniversalTB]
127.0.0.1 www.simplenter.com
127.0.0.1 www.simpletoolbar.com #[SunBelt.UniversalSearchToolbar]
127.0.0.1 sincooweb.com #[Backdoor.Graybird.N]
127.0.0.1 quasar.sitegauge.com
127.0.0.1 tracker.sitescout.com #[IE-SpyAd]
127.0.0.1 advertpro.sitepoint.com
127.0.0.1 www.sitestatslive.com
127.0.0.1 adserver.sharewareonline.com #[nictechnetworks.com]
127.0.0.1 ads.shizmoo.com #[IE-SpyAd][Kephyr.PUP]
127.0.0.1 www.shockcounter.com #[IE-SpyAd]
127.0.0.1 skeech.com
127.0.0.1 www.skeech.com #[IE-SpyAd]
127.0.0.1 www.smartadstats.com #[IE-SpyAd]
127.0.0.1 smart-browser.com #[eTrust.SmartBrowser]
127.0.0.1 update.smart-browser.com #[Parasite.SmartBrowser]
127.0.0.1 www.smart-browser.com #[Adware.SmartBrowser]
127.0.0.1 smartclicks.net #[IE-SpyAd]
127.0.0.1 www.smartclicks.net
127.0.0.1 smarter.com #[IE-SpyAd]
127.0.0.1 sidebar.smarter.com
127.0.0.1 www.smarter.com #[SunBelt.eBates.WebSearch]
127.0.0.1 www.smileyworld.com #[AdWare.Win32.SHBar.a][Adware.Smiley]
127.0.0.1 ads.smni.com
127.0.0.1 static.smni.com
127.0.0.1 a.softpedia.com
127.0.0.1 adserver.softwareonline.com
127.0.0.1 www1.spaex.com #[searchboss.com][IE-SpyAd]
127.0.0.1 www.spedia.net #[SunBelt.SpediaBar][IE-SpyAd]
127.0.0.1 ftp.sptr.info
127.0.0.1 www.sptr.info #[AVG.PSW.Generic.DLE][Backdoor.Zagaban]
127.0.0.1 www.spyarsenal.com #[Spyware.DesktopSpy][Spyware.FamilyKeylog]
127.0.0.1 www.spymoon.com #[Trojan.Eaghouse.B]
127.0.0.1 spyware.com #[roar.com]
127.0.0.1 ss999ss.com #[Trojan.Snines]
127.0.0.1 www.ssppyy.com #[Spyware.Ssppyy]
127.0.0.1 www.s-tracking.com
127.0.0.1 ads.starpulse.com
127.0.0.1 adsintl.starwave.com
127.0.0.1 js.statistici.ro
127.0.0.1 log.statistici.ro
127.0.0.1 s.statistici.ro #[IE-SpyAd]
127.0.0.1 www.statomatic.com #[IE-SpyAd]
127.0.0.1 statistik-gallup.net
127.0.0.1 stats4you.com #[IE-SpyAd]
127.0.0.1 reg.stats4all.com
127.0.0.1 www.stats4you.com #[IE-SpyAd]
127.0.0.1 stats4all.ws
127.0.0.1 log3.stats24.net
127.0.0.1 www.stats4all.ws
127.0.0.1 www.statsmachine.com
127.0.0.1 statswhere.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.stickypops.com #[eTrust.Stickypops][IE-SpyAd]
127.0.0.1 i.stolefrommvps.org
127.0.0.1 www.sublimemedia.net
127.0.0.1 clix.superclix.de #[IE-SpyAd]
127.0.0.1 www.superlogy.com #[AdvWare.ToolBar.VB.b]
127.0.0.1 adidm.supermedia.pl
127.0.0.1 sqwire.com #[Adware.Sqwire][Xupiter.Sqwire]
127.0.0.1 www.sqwire.com #[Parasite.Xupiter][Adware-PornKings]
127.0.0.1 www.surfassistant.com
127.0.0.1 rd1.surfernetwork.com #[SurferNETWORK Plugin]
127.0.0.1 www.surfernetwork.com
127.0.0.1 www.surveynetworks.com
127.0.0.1 www.surveysite.com
127.0.0.1 www2.survey-poll.com #[Microsoft]
127.0.0.1 www1.sweetbar.com #[ADW_SWEETBAR.A]
127.0.0.1 www.sweetbar.com #[SecurityRisk.Downldr]
127.0.0.1 www.symantic.com #[Typo Squatter][IE-SpyAd]
127.0.0.1 www.syamantec.com #[Typo Squatter]
127.0.0.1 adpick.switchboard.com
127.0.0.1 adtag.sympatico.ca
127.0.0.1 www.szadk.com #[PWSteal.Trojan]
# T
127.0.0.1 an.tacoda.net
127.0.0.1 anad.tacoda.net
127.0.0.1 te.tacoda.net
127.0.0.1 ads.tagword.com
127.0.0.1 ad.uk.tangozebra.com
127.0.0.1 srs.targetpoint.com
127.0.0.1 tat-neftbank.ru #[Backdoor.Berbew.H]
127.0.0.1 ad.gen.tbn.ru
127.0.0.1 ad.120-gen.tbn.ru
127.0.0.1 www.tenmonkey.com
127.0.0.1 www.teslaplus.com #[Rogue/Suspect.Affiliate][Psguard]
127.0.0.1 www.textads.biz
127.0.0.1 www.text-link-ads.com
127.0.0.1 a.tfag.de
127.0.0.1 ak.tfag.de
127.0.0.1 theaffiliateprogram.com
127.0.0.1 adbot.theonion.com
127.0.0.1 oascentral.theonionavclub.com
127.0.0.1 www.thepokerclub.com #[SecurityRisk.ClubPoker]
127.0.0.1 webtrends.thisis.co.uk #[Hitbox]
127.0.0.1 ads.as4x.tmcs.net
127.0.0.1 tnc4u.com #[Parasite.DownloadPlus]
127.0.0.1 new.tnc4u.com
127.0.0.1 www.tnc4u.com #[Adware.DownloadPlus]
127.0.0.1 www.toilet.com #[IE-SpyAd]
127.0.0.1 ad.tomshardware.com
127.0.0.1 topinstalls.com #[AVG.Trojan.Dropper.Agent.PP]
127.0.0.1 www.topinstalls.com #[TROJ_SMALL.AAL]
127.0.0.1 log.trafic.ro #[IE-SpyAd]
127.0.0.1 storage.trafic.ro
127.0.0.1 www.toolshack.com #[IE-SpyAd]
127.0.0.1 www.top-search.com #[Adware-SSF.dr]
127.0.0.1 ad.topstat.com
127.0.0.1 nl.topstat.com #[IE-SpyAd]
127.0.0.1 s26.topstat.com
127.0.0.1 xl.topstat.com
127.0.0.1 banners.toteme.com
127.0.0.1 cachebanners.toteme.com
127.0.0.1 ads.track-star.com
127.0.0.1 adserver.track-star.com
127.0.0.1 geo2.track-star.com
127.0.0.1 www.track-star.com
127.0.0.1 www.traffic-stock.com #[Parasite.RichFind]
127.0.0.1 tradeexit.com #[SunBelt.TradeExit]
127.0.0.1 www.tradeexit.com #[Parasite.Winupie]
127.0.0.1 ads.traderonline.com #[RealMedia]
127.0.0.1 www.trafficbeamer.nl
127.0.0.1 trafficg.com #[IE-SpyAd]
127.0.0.1 www.trafficg.com
127.0.0.1 www.trafficflame.com
127.0.0.1 trafficfile.com #[IE-SpyAd]
127.0.0.1 www.trafficfile.com
127.0.0.1 trackyourstats.com
127.0.0.1 hit.traxdb.net
127.0.0.1 media.travelzoo.com
127.0.0.1 media2.travelzoo.com
127.0.0.1 troyanov.net #[Trojan.Anicmoo]
127.0.0.1 www.troyanov.net #[nowfind.net]
127.0.0.1 trustbid.ws
127.0.0.1 www.trustbid.ws
127.0.0.1 www.trusttoolbar.com #[eTrust.Trust Toolbar]
127.0.0.1 counts.tucows.com
127.0.0.1 google.tucows.com
127.0.0.1 www.turbomemorycharger.com #[Adware.Fapi]
127.0.0.1 ads.tweakxp.com
# U
127.0.0.1 ads.ucomics.com #[RealMedia]
127.0.0.1 image.ugo.com
127.0.0.1 mediamgr.ugo.com
127.0.0.1 www.ukbanners.com #[IE-SpyAd]
127.0.0.1 ukstories.net #[Trojan-Spy.Win32.Goldun.bk][Trojan.Repsamo]
127.0.0.1 ultimatecounter.com #[IE-SpyAd]
127.0.0.1 www.ultimatecounter.com
127.0.0.1 adcontroller.unicast.com
127.0.0.1 ads.unlimitedbanners.com #[IE-SpyAd]
127.0.0.1 undertonenetworks.com #[zedo.com][IE-SpyAd]
127.0.0.1 www.undertonenetworks.com
127.0.0.1 ads1.updated.com
127.0.0.1 www.updatehq.net #[Spyware.Surfcomp]
127.0.0.1 www.updatenow.org #[IE-SpyAd]
127.0.0.1 www.upgradenow.org
127.0.0.1 www.up-the-creek.com #[MHTMLRedir.Exploit]
127.0.0.1 www.upspiral.com #[Adware.UpSpiralBar]
127.0.0.1 usachoice.net #[IE-SpyAd]
127.0.0.1 ushuistov.net #[Win32.Chisyne.F]
127.0.0.1 www.utarget.co.uk #[utarget Ad code]
# V
127.0.0.1 beacon.valeoip.com
127.0.0.1 ad.valuehost.ru #[IE-SpyAd]
127.0.0.1 counters.vendio.com
127.0.0.1 www.venus123.com #[IE-SpyAd]
127.0.0.1 www.verticlick.com
127.0.0.1 image.versiontracker.com
127.0.0.1 spinbox.versiontracker.com
127.0.0.1 ads.vesperexchange.com
127.0.0.1 www.vesperexchange.com
127.0.0.1 cinnam.vibrahost.com #[PWSteal.Revcuss.C][Win32.Revcuss.C]
127.0.0.1 vivi.vibrahost.com #[PWSteal.Revcuss.A]
127.0.0.1 yihuu.vicp.net #[Backdoor.Darkmoon.B]
127.0.0.1 oas.villagevoice.com
127.0.0.1 stat1.vipstat.com
127.0.0.1 banners.vipprofits.com
127.0.0.1 visit-link.com
127.0.0.1 www.voonda.com #[Spyware.TAFbar]
127.0.0.1 www.vstats.net #[IE-SpyAd]
127.0.0.1 ads.vnuemedia.com #[VNUAdTag]
127.0.0.1 sevenc.vze.com #[VBS.Powcox@mm]
# W
127.0.0.1 www.w3exit.com
127.0.0.1 www.want2c.com #[IE-SpyAd]
127.0.0.1 www.warezdownload.ws #[TROJ_BANKER.DC]
127.0.0.1 ng3.ads.warnerbros.com
127.0.0.1 way4find.com
127.0.0.1 www.way4find.com #[Downloader-TA.dll]
127.0.0.1 wcft.net #[Parasite.LinkReplacer]
127.0.0.1 www.wcft.net
127.0.0.1 ads.weather.com
127.0.0.1 100webads.com #[IE-SpyAd]
127.0.0.1 ads.webattack.com
127.0.0.1 webcounter.com #[IE-SpyAd]
127.0.0.1 www.webcounter.com
127.0.0.1 ads.webhosting.info
127.0.0.1 banners.webmasterplan.com
127.0.0.1 fc.webmasterpro.de
127.0.0.1 adv.webmd.com
127.0.0.1 webhits.de #[IE-SpyAd]
127.0.0.1 stat.webmedia.pl #[IE-SpyAd]
127.0.0.1 bannervip.web1000.com #[IE-SpyAd]
127.0.0.1 ads.webads360.com #[IE-SpyAd]
127.0.0.1 clickcash.webpower.com #[IE-SpyAd]
127.0.0.1 orders.webpower.com
127.0.0.1 img.webring.com
127.0.0.1 img1.webring.com
127.0.0.1 ss.webring.com
127.0.0.1 ads.webshots.com
127.0.0.1 www.webstars2000.com
127.0.0.1 www.webstat.net
127.0.0.1 fry.webtistic.com
127.0.0.1 www.webtistic.com #[IE-SpyAd]
127.0.0.1 toolbar.webtoolbars.com #[IE-SpyAd]
127.0.0.1 wefed.biz #[Win32.Bagz.D]
127.0.0.1 weirdontheweb.net
127.0.0.1 www.weirdontheweb.net #[Adware.WeirdOnTheWeb]
127.0.0.1 www.wenksdisdkjeilsow.com #[Parasite.AutoStartup][Download.Trojan]
127.0.0.1 wetrack.it #[IE-SpyAd]
127.0.0.1 st.wetrack.it
127.0.0.1 www.wgutv.com #[Adware.BuddyLinks]
127.0.0.1 partner1.whatsfind.com
127.0.0.1 www.whatsfind.com #[HTML_STARTPAGE.C]
127.0.0.1 y0.windows-center.com #[Backdoor.Shellbot]
127.0.0.1 join1.winhundred.com
127.0.0.1 www.win-update.net #[Trojan.Magise]
127.0.0.1 window1.com #[IE-SpyAd]
127.0.0.1 ads.winhelp2002.com
127.0.0.1 ads.winsite.com
127.0.0.1 winstream.com #[Parasite.Searchex]
127.0.0.1 www.winstream.com
127.0.0.1 clicktrack.wnu.com
127.0.0.1 www.wowweb.net #[Adware.WWWBar]
127.0.0.1 www.wslm.net #[REG_SEEKER.N]
# X
127.0.0.1 x0x.biz
127.0.0.1 www.x0x.biz #[Backdoor.Berbew.D]
127.0.0.1 xcounters.com
127.0.0.1 a.xcounters.com
127.0.0.1 count.xhit.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 xlonhcld.xlontech.net #[IE-SpyAd]
127.0.0.1 nedstats.xs4all.nl
127.0.0.1 hit1.xstats.com
127.0.0.1 view1.xstats.com
127.0.0.1 ads.xtra.co.nz
# Y
127.0.0.1 freegames.yaboo.dk #[W32.Guapim]
127.0.0.1 ads.yadio.com
127.0.0.1 dl.yadio.com
127.0.0.1 www.yadio.com
127.0.0.1 ad.yadro.ru #[IE-SpyAd]
127.0.0.1 counter.yadro.ru
127.0.0.1 bs.yandex.ru
127.0.0.1 www.yandex.ru
127.0.0.1 crsky2004.yeah.net #[Backdoor.Singu.B]
127.0.0.1 lb1.youbettersearch.com
127.0.0.1 ysearchus.com #[Parasite.TinyBar]
127.0.0.1 www.ysearchus.com
127.0.0.1 www.yuups.com #[Adware.Yuupsearch]
127.0.0.1 www.yyue.com #[TROJ_STARTPAG.OC]
# Z
127.0.0.1 ad.zanox.com
127.0.0.1 zanox-affiliate.de
127.0.0.1 www.zenotecnico.com #[desktoptraffic.net][Adware.ZenoSearch]
127.0.0.1 counter.zone.ee
127.0.0.1 mp3.zonebg.com #[HJTH.C2Media/LOP variant]
127.0.0.1 ads.zone-media.com #[Troj/Swizzor-CN]
127.0.0.1 ayb.zone-media.com
127.0.0.1 www.zone-media.com
127.0.0.1 bannerads.zwire.com
127.0.0.1 zxserv0.com #[Trojan.Zhopa][F-Secure.Small.wy]
# [Misc]
127.0.0.1 0cat.com #[0Cat YellowPages]
127.0.0.1 www.0cat.com #[Adware.STIEBar]
127.0.0.1 banner.0catch.com
127.0.0.1 www.0stats.com
127.0.0.1 cc.1asphost.com #[Trojan.Bansap]
127.0.0.1 123mania.com #[ADW_123MANIA.A]
127.0.0.1 www.123mania.com #[Parasite.123Mania][Adware.MatrixSearch]
127.0.0.1 123stat.com #[IE-SpyAd]
127.0.0.1 ad2.163.com
127.0.0.1 adclient.163.com
127.0.0.1 images.163.com
127.0.0.1 popme.163.com
127.0.0.1 smtp.163.com #[Trojan.PSW.Ajim_bbs]
127.0.0.1 1234.2bro.com #[Adware.Satbo]
127.0.0.1 www.241hits.com
127.0.0.1 up.isp.2ch.net #[Trojan.Upchan]
127.0.0.1 2z0o.net #[Trojan.Popper]
127.0.0.1 pop1.2z0o.net #[admarketplace.net]
127.0.0.1 pop2.2z0o.net #[TROJ_DLOADER.AGS]
127.0.0.1 req2.2z0o.net #[McAfee.Downloader-ACV]
127.0.0.1 www.3d-icons.com #[Adware bundler]
127.0.0.1 www.3find.com #[Trojan-Clicker.Win32.Small.hn]
127.0.0.1 www.3241.com #[Troj/Zikdow-B]
127.0.0.1 guannan.3322.net #[IE-SpyAd]
127.0.0.1 download.35mb.com #[impregnable.net]
127.0.0.1 static.35mb.com #[HJTH.Win32.IstBar.fa]
127.0.0.1 www.35mb.com #[HJTH.MediaTickets Installer]
127.0.0.1 ct.360i.com
127.0.0.1 ad.37.com
127.0.0.1 www.40best.com #[HJTH.C2Media/LOP variant]
127.0.0.1 41m.com #[HJTH.XXXToolbar Variant][Trojan.Clicker.BL]
127.0.0.1 cshacks.41m.com #[server down?]
127.0.0.1 msncheck.41m.com
127.0.0.1 www.41m.com
127.0.0.1 4pokertips.com
127.0.0.1 www.4pokertips.com
127.0.0.1 5sec.biz #[Backdoor.Fivsec]
127.0.0.1 5sec.info
127.0.0.1 www.5sec.info
127.0.0.1 5sec.org
127.0.0.1 www.ff.iij4u.or.jp #[Trojan.Upchan]
127.0.0.1 10000hits.net #[IE-SpyAd]
127.0.0.1 1000stars.ru #[IE-SpyAd]
127.0.0.1 7am.com
127.0.0.1 www.75558889.com #[Panda.Hupigon.BS]
127.0.0.1 www.777search.com #[C2Media/LOP]
127.0.0.1 www.7000n.com #[Adware.7000n]
127.0.0.1 ajim.delphibbs.com #[Trojan.PSW.Ajim_bbs]
127.0.0.1 banners.4d5.net
127.0.0.1 banner.50megs.com
127.0.0.1 www.53best.com #[Trojan-PSW.Win32.Lmir.gen]
127.0.0.1 banners.dot.tk
127.0.0.1 topsites.us #[Parasite.eStart]
127.0.0.1 www.9ringtone.com
# [123Banners][123Greetings.com][TROJ_NALDEM.A][Trojan.Naldem]
127.0.0.1 www.123banners.com
127.0.0.1 ftp.123banners.com
127.0.0.1 123go.com
127.0.0.1 ns1.123go.net
# [180solutions][CDT Inc][KB317714][KB320162]
127.0.0.1 180solutions.com
127.0.0.1 ads.180solutions.com
127.0.0.1 ax.180solutions.com #[HJTH.nCase Variant]
127.0.0.1 bis.180solutions.com #[nCaseInstaller Class][ADW_SOLU180.F]
127.0.0.1 bisads.180solutions.com
127.0.0.1 config.180solutions.com #[eTrust.180SearchAssistant]
127.0.0.1 cts.180solutions.com
127.0.0.1 downloads.180solutions.com
127.0.0.1 installs.180solutions.com
127.0.0.1 ping.180solutions.com
127.0.0.1 tv.180solutions.com
127.0.0.1 www.180solutions.com #[Parasite.nCase]
127.0.0.1 www.180solutions.net
127.0.0.1 infinity.180searchassistant.com #[ADW_SOLU180.H]
127.0.0.1 www.180searchassistant.com #[Adware.180Search]
127.0.0.1 blazefind.com #[IE SearchBar][Adware.CDT]
127.0.0.1 findwhatevernow.blazefind.com
127.0.0.1 omniscient.blazefind.com #[TROJ_BLAZEFIND.A]
127.0.0.1 xml.blazefind.com
127.0.0.1 www.blazefind.com #[Adware.BlazeFind.B]
127.0.0.1 www.captioncity.com
127.0.0.1 www.enterjericho.com
127.0.0.1 www.epipo.com
127.0.0.1 flingstone.com #[TROJ_WINFAVS.A][Trojan.TrustedZones]
127.0.0.1 redirect.flingstone.com
127.0.0.1 static.flingstone.com #[brdg Class]
127.0.0.1 www.flingstone.com #[Adware.WinFavorites.B]
127.0.0.1 www2.flingstone.com #[brdg Class][Win32/Bryss.Spy.Trojan]
127.0.0.1 www.fullarmorstudios.com
127.0.0.1 loudcash.com
127.0.0.1 partners.loudcash.com
127.0.0.1 www.loudcash.com
127.0.0.1 www.metricsdirect.com
127.0.0.1 n-case.com
127.0.0.1 www.n-case.com #[Panda.Adware/nCase]
127.0.0.1 www.n-case.net
127.0.0.1 page-not-found.org
127.0.0.1 www.radiopranks.com
127.0.0.1 public.searchbarcash.com #[HJTH.SearchBarCash]
127.0.0.1 www.searchbarcash.com #[Parasite.TinyBar][Downloader.Small.5.Y]
127.0.0.1 searchbrowser.com
127.0.0.1 findwhatevernow.searchbrowser.com
127.0.0.1 search.prositefinder.com #[SunBelt.bho.180Solutions.ProSiteFinder]
127.0.0.1 skoobidoo.com
127.0.0.1 www.skoobidoo.com
127.0.0.1 www2.skoobidoo.com #[Downloader.MSCache]
127.0.0.1 www.starpranks.com
127.0.0.1 winadclient.com
127.0.0.1 eula.winadclient.com
127.0.0.1 www.winadclient.com
127.0.0.1 windowssr.com
127.0.0.1 windupdates.com #[Adware.WinTaskAd][Trojan.TrustedZones]
127.0.0.1 public.windupdates.com #[Windows SyncroAd]
127.0.0.1 static.windupdates.com #[ADW_WUPD.F][ADW_WINSTATX.A]
127.0.0.1 www.windupdates.com #[AdvWare.WinAD]
127.0.0.1 counterstrike.server.us #[Downloader.CDT]
127.0.0.1 downloads.zango.com #[SunBelt.180Solutions.Zango.TVTimes]
127.0.0.1 games.zango.com #[SunBelt.Adw.Zango.Solitaire]
127.0.0.1 infinity.zango.com #[ZangoInstaller Class]
127.0.0.1 lp.zango.com
127.0.0.1 messenger.zango.com
127.0.0.1 showtimes.zango.com
127.0.0.1 www.zango.com #[Adware.ZangoSearch]
127.0.0.1 prompt.zangocash.com
127.0.0.1 static.zangocash.com
127.0.0.1 www.zangogames.com
127.0.0.1 www.zangomessenger.com
127.0.0.1 www.zangopartner.com
127.0.0.1 www.zangopartner.net
127.0.0.1 www.zangoshowtimes.com
# [3721.COM][Parasite.CnsMin][Adware.Wengs]
127.0.0.1 address.3721.com
127.0.0.1 agent.3721.com
127.0.0.1 assistant.3721.com
127.0.0.1 cns.3721.com
127.0.0.1 cnsmin.3721.com
127.0.0.1 corp.3721.com
127.0.0.1 dir.3721.com
127.0.0.1 download.3721.com
127.0.0.1 express.3721.com
127.0.0.1 img.3721.com
127.0.0.1 magic.3721.com
127.0.0.1 mark.3721.com
127.0.0.1 meta.3721.com
127.0.0.1 msearch.3721.com
127.0.0.1 sbox.3721.com
127.0.0.1 shanghai.3721.com
127.0.0.1 sina.3721.com
127.0.0.1 user.3721.com
127.0.0.1 wap.3721.com
127.0.0.1 www.3721.com #[Adware.Chinet][ADW_CNSMIN.A]
127.0.0.1 yahoo.3721.com
127.0.0.1 3721.com
127.0.0.1 download.feiyang.com
# [411 Web Directory]
127.0.0.1 ad.411web.com
127.0.0.1 adtracker.411web.com
127.0.0.1 hits.411web.com
127.0.0.1 overture.411web.com
127.0.0.1 static.411web.com
127.0.0.1 xml.411web.com
127.0.0.1 search.letssearch.com
127.0.0.1 www.letssearch.com #[BrowserAid.LetsSearch]
127.0.0.1 sidebysidesearch.com
127.0.0.1 go.sidebysidesearch.com
127.0.0.1 www.sidebysidesearch.com #[Adware.SideBySide]
# [7Search.com Networks][EMERgency 24, Inc]
127.0.0.1 7search.com #[Parasite.7FaSSt Search]
127.0.0.1 fstrack.7search.com
127.0.0.1 ia1.7search.com
127.0.0.1 mainws2.7search.com
127.0.0.1 meta.7search.com
127.0.0.1 impression.7search.com
127.0.0.1
  • 0

Advertisements


#26
alighirl

alighirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
127.0.0.1 www.7search.com #[Spyware.SevenSearch]
127.0.0.1 img.7meta.com
127.0.0.1 www.7metasearch.com
127.0.0.1 www.a1fax.com
127.0.0.1 adtactics.com #[IE-SpyAd]
127.0.0.1 bannerx.adtactics.com
127.0.0.1 www.adtactics.com
127.0.0.1 advertisingagent.com
127.0.0.1 ajokeaday.com #[IE-SpyAd]
127.0.0.1 bestsearch.com
127.0.0.1 scripts.bestsearch.com
127.0.0.1 www.bestsearch.com
127.0.0.1 browseraccelerator.com #[Spyware.BrowserAccel]
127.0.0.1 data.browseraccelerator.com
127.0.0.1 download.browseraccelerator.com
127.0.0.1 client.browseraccelerator.com
127.0.0.1 www.browseraccelerator.com #[IE-SpyAd]
127.0.0.1 www.buscamundo.com
127.0.0.1 bannersxchange.com
127.0.0.1 img.bannersxchange.com #[IE-SpyAd]
127.0.0.1 www.bannersxchange.com
127.0.0.1 internetsecurity.com
127.0.0.1 www.internetsecurity.com
127.0.0.1 www.linkstoyou.com
127.0.0.1 www.payperranking.com
127.0.0.1 www.pay-per-search.com
127.0.0.1 paypertext.com
127.0.0.1 predictivesearch.com
127.0.0.1 seal.ranking.com
127.0.0.1 www.ranking.com
127.0.0.1 tracking.roispy.com #[IE-SpyAd]
127.0.0.1 www.roispy.com
127.0.0.1 ftp.sevenmetasearch.com
127.0.0.1 www.sevenmetasearch.com
127.0.0.1 tracking.spiderbait.com
127.0.0.1 www.spiderbait.com
127.0.0.1 www.textadvertising.com
127.0.0.1 www.thetop10.com
127.0.0.1 trustgauge.com
127.0.0.1 www.trustgauge.com
127.0.0.1 seal.validatedsite.com
127.0.0.1 www.validatedsite.com
127.0.0.1 www.watch24.com
# [About.com]
127.0.0.1 clicks.about.com
127.0.0.1 f.about.com
127.0.0.1 home.about.com
127.0.0.1 js.get.about.com
127.0.0.1 images.about.com
127.0.0.1 lunafetch.about.com
127.0.0.1 pixel3.about.com
127.0.0.1 sprinks-clicks.about.com
127.0.0.1 statistics.s5.com
127.0.0.1 ad.aboutwebservices.com
# [AboveNet Communications][IE-SpyAd]
127.0.0.1 button.clickability.com
127.0.0.1 imp.clickability.com
127.0.0.1 ri.clickability.com
127.0.0.1 sftp.clickability.com
127.0.0.1 stats.clickability.com #[eTrust.Tracking Cookie]
# [Accipiter Solutions][IE-SpyAd]
127.0.0.1 ad101com.adbureau.net
127.0.0.1 ad101com-images.adbureau.net
127.0.0.1 adops.adbureau.net
127.0.0.1 bbcww.adbureau.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 capitali-images.adbureau.net
127.0.0.1 cent.adbureau.net
127.0.0.1 etype.adbureau.net
127.0.0.1 etype-images.adbureau.net
127.0.0.1 granada.adbureau.net
127.0.0.1 imediac.adbureau.net
127.0.0.1 inl.adbureau.net
127.0.0.1 studenti.adbureau.net
127.0.0.1 ttarget.adbureau.net
127.0.0.1 www.adbureau.net
# [Acez Software][Adware-NuggetSearch.dr]
127.0.0.1 www.acez.com #[AdWare.BHO.MegaSearch.b]
127.0.0.1 www.acezsoftware.com
127.0.0.1 www.searchnugget.com #[Adware.SearchNugget]
127.0.0.1 www.screengizmos.com
127.0.0.1 www.siteerror.com #[siteError.dll]
# [AD-BLASTER.COM][IE-SpyAd]
127.0.0.1 ad-blaster.com
127.0.0.1 www.ad-blaster.com
127.0.0.1 promote4profit.com
127.0.0.1 www.promote4profit.com
# [ADDFREESTATS][3DSTATS][IE-SpyAd]
127.0.0.1 www.3dstats.com
127.0.0.1 addfreestats.com
127.0.0.1 top.addfreestats.com
127.0.0.1 www.addfreestats.com
127.0.0.1 www1.addfreestats.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www2.addfreestats.com
127.0.0.1 www3.addfreestats.com
127.0.0.1 www4.addfreestats.com
127.0.0.1 www5.addfreestats.com
# [Adlogix Media Group][Orion Holtby][680180 BC LTD]
127.0.0.1 ncontext.adacuity.com
127.0.0.1 www.adacuity.com #[neededware.com]
127.0.0.1 adlogix.com #[InPop.InControl][IEEnhancer]
127.0.0.1 lasagne.adlogix.com
127.0.0.1 publisher.adlogix.com
127.0.0.1 traffic.adlogix.com #[IE-SpyAd]
127.0.0.1 trafficsource.adlogix.com
127.0.0.1 www.adlogix.com #[SunBelt.AdLogix]
127.0.0.1 servedby.adserving.us
127.0.0.1 www.adserving.us
127.0.0.1 www.creatrixads.com
127.0.0.1 www.findonpage.com
127.0.0.1 hitgo.com #[IPU][InPop.InControl]
127.0.0.1 www.hitgo.com
127.0.0.1 ncontextmedia.com
127.0.0.1 www.ncontextmedia.com
127.0.0.1 www.ncontextsearch.com #[MHTMLRedir.Exploit]
127.0.0.1 neededware.com #[Adware.NeededWare][AdWare.Winsta.a]
127.0.0.1 www.neededware.com #[Trojan.TrustedZone][eTrust.Win32.Lastad]
127.0.0.1 www.tinkopal.com
127.0.0.1 tinko-pal.com
127.0.0.1 www.tinkopal.net
127.0.0.1 r2.trafficserverstats.com
127.0.0.1 r5.trafficserverstats.com
127.0.0.1 r10.trafficserverstats.com
127.0.0.1 r18.trafficserverstats.com
127.0.0.1 r25.trafficserverstats.com
127.0.0.1 webengo.com
# [AdOrigin Corp][IE-SpyAd]
127.0.0.1 ads.adorigin.com
127.0.0.1 dev.adorigin.com
127.0.0.1 www.adorigin.com
127.0.0.1 blowsearch.com
127.0.0.1 msxml.blowsearch.com
127.0.0.1 web.blowsearch.com #[infospace.com]
127.0.0.1 www.blowsearch.com
# [ADSoft][Hot Lab][ADSoft-Development]
127.0.0.1 www.1-viagra-on-line.com
127.0.0.1 www.all-casinos.org
127.0.0.1 www.all-lyrics.org
127.0.0.1 www.best-poker.biz
127.0.0.1 www.chenjesu.com
127.0.0.1 halflemon.com #[Adware.HalfLemon][Trojan.Win32.StartPage.ya]
127.0.0.1 www.halflemon.com #[HJTH.HalfLemon Search Hijacker]
127.0.0.1 www.spycounter.net
127.0.0.1 www-start-page.com #[Adware.HalfLemon]
127.0.0.1 www.www-start-page.com #[Trojan.Win32.StartPage.ya]
127.0.0.1 www.start-page.net
127.0.0.1 www.start-page.org
127.0.0.1 the-roulette.net
127.0.0.1 www.usa-phendimetrazine.com
# [Ad-Souk AdServer]
127.0.0.1 www.ad-souk.com #[IE-SpyAd]
127.0.0.1 bilbob.com
127.0.0.1 didtal.com
127.0.0.1 quinst.com
# [Adteractive][IE-SpyAd]
127.0.0.1 cb.adprofile.net
127.0.0.1 content.adprofile.net
127.0.0.1 tx.adprofile.net
127.0.0.1 w2-ver.adprofile.net
127.0.0.1 adteractive.com
127.0.0.1 www.adteractive.com
127.0.0.1 icc.intellisrv.net
# [Adtegrity.com, Inc][IE-SpyAd]
127.0.0.1 adtegrity.com
127.0.0.1 www.adtegrity.com
127.0.0.1 webalize.com #[SearchCentrix][VisiCom.SearchCentric]
127.0.0.1 toolbar.webalize.com #[downloads.searchcentrix.com]
127.0.0.1 www.webalize.com #[Visicom Media Toolbar]
127.0.0.1 webalize.net
127.0.0.1 www.webalize.net
127.0.0.1 webalize.mygeek.com
# [Adtomi]
127.0.0.1 adtomi.com
127.0.0.1 ads.adtomi.com #[IE-SpyAd][ADW_ADTOMI.D]
127.0.0.1 www.adtomi.com #[Adware.Adtomi]
127.0.0.1 aidintime.com #[Troj/Dloader-EP]
127.0.0.1 www.aidintime.com
127.0.0.1 bascowater.com
127.0.0.1 www.bascowater.com
127.0.0.1 camberageflex.com
127.0.0.1 www.camberageflex.com
127.0.0.1 collarsaround.com
127.0.0.1 www.collarsaround.com
127.0.0.1 emorningmoss.net
127.0.0.1 www.emorningmoss.net
127.0.0.1 etightstrings.net #[Trojan.Win32.Kolweb.d]
127.0.0.1 www.etightstrings.net
127.0.0.1 logiose.com
127.0.0.1 www.logiose.com
127.0.0.1 moltenmagnet.net
127.0.0.1 www.moltenmagnet.net
127.0.0.1 netremoteline.com
127.0.0.1 www.netremoteline.com
127.0.0.1 treestompertime.net
127.0.0.1 www.treestompertime.net #[Trojan.Win32.Kolweb.a]
# [Affiliate Target]
127.0.0.1 affiliatetarget.com #[IE-SpyAd][HJTH.EScorcher Adware]
127.0.0.1 server2.affiliatetarget.com
127.0.0.1 server3.affiliatetarget.com
127.0.0.1 server4.affiliatetarget.com
127.0.0.1 server5.affiliatetarget.com
127.0.0.1 www.affiliatetarget.com #[Adware.PLook]
# [Alex Walter][Spectre][Xyfex]
127.0.0.1 install.007guard.com
127.0.0.1 download.007guard.com #[007installer Control]
127.0.0.1 www.007guard.com #[adware bundler]
127.0.0.1 2search.org #[Adware.2Search][eTrust.2Search]
127.0.0.1 www.2search.org #[clickheretofind.com]
127.0.0.1 hotmsnnames.com #[Adware bundler]
127.0.0.1 www.hotmsnnames.com
127.0.0.1 www.hottestgames.net
127.0.0.1 adserver.shizzlehost.com
127.0.0.1 www.shizzlelyrics.com
127.0.0.1 www.shizzletraffic.com
127.0.0.1 webmasterz.biz #[static.windupdates.com]
127.0.0.1 www.webmasterz.biz
127.0.0.1 www.xyfex.com #[static.windupdates.com]
# [Alset Inc][Adware.HelpExpress]
127.0.0.1 alset.com #[WIN32/HXDL AL]
127.0.0.1 www.alset.com
# [Asher Nahmias]
127.0.0.1 allcybersearch.com #[REG_STARTPAGE.A]
127.0.0.1 www.allcybersearch.com
127.0.0.1 amigeek.com
127.0.0.1 www.amigeek.com
127.0.0.1 clickyestoenter.net
127.0.0.1 www.clickyestoenter.net
127.0.0.1 www.gay50.com
127.0.0.1 gocybersearch.com
127.0.0.1 www.gocybersearch.com
127.0.0.1 www.hotelxxxcams.com
127.0.0.1 hotpopup.com
127.0.0.1 search.hotpopup.com
127.0.0.1 www.hotpopup.com
127.0.0.1 hotsearchbox.com #[JAVA_STARTPAGE.F]
127.0.0.1 www.hotsearchbox.com
127.0.0.1 i--search.com #[SunBelt.SearchUpgrade]
127.0.0.1 www.i--search.com #[StartPage-FN]
127.0.0.1 jethomepage.com #[JS.Exception.Exploit]
127.0.0.1 www.jethomepage.com #[Troj/JetHome-B]
127.0.0.1 jetseeker.com #[CWS.Bootconf]
127.0.0.1 www.jetseeker.com
127.0.0.1 search--here.info
127.0.0.1 searchxl.com #[Adware.ZeroPopUpBar]
127.0.0.1 www.searchxl.com
127.0.0.1 tinybar.com
127.0.0.1 www.tinybar.com #[Parasite.TinyBar]
127.0.0.1 topsearcher.com #[JV/Goplanet]
127.0.0.1 www.topsearcher.com #[Troj/JetHome-J]
127.0.0.1 trixscripts.com
127.0.0.1 www.trixscripts.com
127.0.0.1 zeropopup.com #[Parasite.ZeroPopUp]
127.0.0.1 www.zeropopup.com #[Tellafriend.Trojan]
127.0.0.1 znext.com #[JS_TRAFFICHBAR.A][Parasite.TinyBar]
127.0.0.1 www.znext.com #[Parasite.ZeroPopUp][App/P0P-A]
# [AD TECH AG][Adtech.de][IE-SpyAd]
127.0.0.1 adtech.de #[Ad-Aware.Tracking Cookie]
127.0.0.1 adforce.adtech.de
127.0.0.1 adserver.adtech.de #[ADTECH Group JavaScript TAG]
127.0.0.1 imageserv.adtech.de
127.0.0.1 livingnet.adtech.de
127.0.0.1 x86adserv001.adtech.de
127.0.0.1 x86adserv002.adtech.de
127.0.0.1 x86adserv003.adtech.de
127.0.0.1 x86adserv004.adtech.de
127.0.0.1 x86adserv005.adtech.de
127.0.0.1 x86adserv006.adtech.de
127.0.0.1 x86adserv007.adtech.de #[Kephyr.PUP]
127.0.0.1 x86adserv008.adtech.de
127.0.0.1 x86adserv009.adtech.de
127.0.0.1 x86adserv010.adtech.de
127.0.0.1 x86adserv011.adtech.de #[MVPS.Criteria]
127.0.0.1 x86adserv012.adtech.de
127.0.0.1 x86adserv013.adtech.de
127.0.0.1 x86adserv014.adtech.de
127.0.0.1 x86adserv015.adtech.de
127.0.0.1 x86adserv016.adtech.de
127.0.0.1 x86adserv017.adtech.de
127.0.0.1 x86adserv018.adtech.de
# [Advertising.com][AOL][IE-SpyAd]
127.0.0.1 cdn1.adsdk.com
127.0.0.1 cdn2.adsdk.com #[VirtualBouncer]
127.0.0.1 advertising.com
127.0.0.1 adserve.advertising.com
127.0.0.1 bannerfarm.ace.advertising.com
127.0.0.1 dbs.advertising.com
127.0.0.1 demo.advertising.com
127.0.0.1 opera1-servedby.advertising.com
127.0.0.1 servedby.advertising.com #[eTrust.Tracking Cookie]
127.0.0.1 rd.advertising.com
127.0.0.1 wap.advertising.com
127.0.0.1 www.advertising.com
127.0.0.1 clk4.com
127.0.0.1 www.clk4.com
127.0.0.1 www.contextualclicks.com
127.0.0.1 fastseeker.com #[Adware.FastSeek]
127.0.0.1 www.fastseeker.com
127.0.0.1 spyblast.com #[Parasite.SpyBlast]
127.0.0.1 www.spyblast.com #[SBFullInst Control]
127.0.0.1 www.thesearchster.com
# [Affiliation Networks][Tracking Service]
127.0.0.1 ads.ign.com
127.0.0.1 adserver.ign.com
127.0.0.1 t.ign.com
127.0.0.1 tracker.ign.com
127.0.0.1 adserver.snowball.com
127.0.0.1 polls.snowball.com
127.0.0.1 scripts.snowball.com
127.0.0.1 t.snowball.com
127.0.0.1 tracker.snowball.com
# [All Headline News Corp]
127.0.0.1 www.allheadlinenews.com
127.0.0.1 www.americlicks.com #[eTrust.Americlicks]
127.0.0.1 www.weatherclicks.com
# [Altnet][Adware.BDE][Adware.Topsearch.B]
127.0.0.1 altnet.com
127.0.0.1 file.altnet.com
127.0.0.1 media.altnet.com
127.0.0.1 ts.altnet.com
127.0.0.1 tss.altnet.com
127.0.0.1 pm.altnet.com
127.0.0.1 www.altnet.com #[ADW_ALTNET.A]
127.0.0.1 www.altnetp2p.com
127.0.0.1 brilliantdigital.com #[Parasite.BDE]
127.0.0.1 st.brilliantdigital.com
127.0.0.1 www.brilliantdigital.com #[TROJ_KREPPER.Y]
127.0.0.1 b3d.com
127.0.0.1 bde3d.com
127.0.0.1 www.b3d.com
# [Applied Technologies Internet][Tracking Service][IE-SpyAd]
127.0.0.1 xiti.com
127.0.0.1 loga.xiti.com
127.0.0.1 logc13.xiti.com
127.0.0.1 logi6.xiti.com
127.0.0.1 logi7.xiti.com
127.0.0.1 logv3.xiti.com
127.0.0.1 logv18.xiti.com
127.0.0.1 logv20.xiti.com
127.0.0.1 logv21.xiti.com
127.0.0.1 logv26.xiti.com
127.0.0.1 logp.xiti.com
127.0.0.1 trafic.xiti.com
127.0.0.1 www.xiti.com
# [Apropos AdIntelligence][PeopleOnPage][ADW_POPBAR.A]
127.0.0.1 adintelligence.net
127.0.0.1 acc.adintelligence.net
127.0.0.1 adchannel.adintelligence.net
127.0.0.1 creatives.adintelligence.net
127.0.0.1 download.adintelligence.net #[SysAI]
127.0.0.1 www.adintelligence.net
127.0.0.1 adchannel.contextplus.net #[Parasite.AproposMedia]
127.0.0.1 au.contextplus.net #[Trojan-Downloader.Win32.Small.ayh]
127.0.0.1 download.contextplus.net #[ADW_APROPOS.N]
127.0.0.1 dl.contextplus.net #[Trojan-Downloader.Win32.Apropo.aj]
127.0.0.1 www.contextplus.net #[TROJ_LOADER.D][Spyware.Apropos.C]
127.0.0.1 www.contextplus.com
127.0.0.1 adv.peopleonpage.com #[server down?]
127.0.0.1 app.peopleonpage.com
127.0.0.1 download.peopleonpage.com #[POP Loader]
127.0.0.1 envolo.peopleonpage.com
127.0.0.1 img.peopleonpage.com
127.0.0.1 srv.peopleonpage.com #[Spyware.Apropos.B]
127.0.0.1 www.peopleonpage.com #[PcTools.PeopleOnPage][PeopleOnPage.Apropos]
# [aQuantive Inc][Avenue A][IE-SpyAd]
127.0.0.1 www.avenuea.com
127.0.0.1 att.atdmt.com
127.0.0.1 click.atdmt.com
127.0.0.1 clk.atdmt.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 image.atdmt.com
127.0.0.1 rmd.atdmt.com
127.0.0.1 spd.atdmt.com
127.0.0.1 spe.atdmt.com
127.0.0.1 switch.atdmt.com #[AveA Action Tag]
127.0.0.1 view.atdmt.com #[eTrust.Tracking Cookie]
127.0.0.1 www.atdmt.com
127.0.0.1 atlasdmt.com
127.0.0.1 www.atlasdmt.com
127.0.0.1 www.avenueainc.com
127.0.0.1 ads.toplayerserver.com
127.0.0.1 www1.toplayerserver.com
127.0.0.1 www.toplayerserver.com
127.0.0.1 track.roiservice.com
# [Arundel Group][Harris Digital Publishing]
127.0.0.1 spyware-removal.net
127.0.0.1 www.systemdetective.com #[Rogue/Suspect]
127.0.0.1 ztrack.net #[IE-SpyAd]
# [Avenue Media]
127.0.0.1 active-alert-server.com
127.0.0.1 www.active-alert-server.com #[IE-SpyAd]
127.0.0.1 amnv.net
127.0.0.1 www.amnv.net
127.0.0.1 avenuemedia.com
127.0.0.1 www.avenuemedia.com
127.0.0.1 climaxbucks.com #[ClimaxBucks.InternetOptimizer]
127.0.0.1 cdn.climaxbucks.com
127.0.0.1 mt1.climaxbucks.com
127.0.0.1 mt23.climaxbucks.com
127.0.0.1 xbs.climaxbucks.com
127.0.0.1 www.climaxbucks.com
127.0.0.1 xbs.cocktailcash.com
127.0.0.1 cocktailcash.com
127.0.0.1 www.cocktailcash.com
127.0.0.1 internet-optimizer.com #[Downloader.Dyfcia.F]
127.0.0.1 ads.internet-optimizer.com #[Parasite.Internet Optimizer]
127.0.0.1 configure.internet-optimizer.com #[TSPY_SMALL.SN]
127.0.0.1 help.internet-optimizer.com #[ADW_SIDEFIND.L]
127.0.0.1 www.internet-optimizer.com #[Adware.NetOptimizer]
127.0.0.1 www.lunasearch.com
127.0.0.1 movies-etc.com
127.0.0.1 cdn.movies-etc.com #[ADW_DYFUCA.K]
127.0.0.1 cdn2.movies-etc.com
127.0.0.1 www.movies-etc.com
127.0.0.1 yoogee.com #[Parasite.Internet Optimizer]
127.0.0.1 www.yoogee.com #[Panda.Spyware/Dyfuca]
# [Azoogle.com INC][Impulse Leads][IE-SpyAd]
127.0.0.1 i.1100i.com
127.0.0.1 images.1100i.com
127.0.0.1 www.adroz.com #[affiliate][AIM Smileys]
127.0.0.1 c.azjmp.com
127.0.0.1 www.azjmp.com
127.0.0.1 images.azoogleads.com
127.0.0.1 images.azooimages.com
127.0.0.1 www.azoogleads.com
127.0.0.1 b.bluetime.com
127.0.0.1 b1.bluetime.com
127.0.0.1 images.bluetime.com
127.0.0.1 www.bluetime.com
127.0.0.1 www.giftfox.com
127.0.0.1 images.hostimages.net
127.0.0.1 images.imagesbyaz.com
127.0.0.1 images.imgehost.com
127.0.0.1 impulseleads.com
127.0.0.1 www.impulseleads.com
127.0.0.1 images.imgserver.net
127.0.0.1 www.merchantportal.com
127.0.0.1 www.mport.com
127.0.0.1 www.mptrack.com
127.0.0.1 www.mydishprovider.com
127.0.0.1 noadware.biz
127.0.0.1 www.noadware.biz
127.0.0.1 1.primaryads.com
127.0.0.1 c.qckjmp.com
# [Aztec Marketing][West Frontier Holdings][Offshorefleet Holdings S.A]
127.0.0.1 adblitz.biz
127.0.0.1 www.adblitz.biz
127.0.0.1 google.begin2search.com
127.0.0.1 toolbar.begin2search.com
127.0.0.1 www.begin2search.com #[Adware.Begin2search][iiittt Class]
127.0.0.1 bigtrafficnetwork.com #[PcTools.BigTrafficNetwork]
127.0.0.1 www2.bigtrafficnetwork.com
127.0.0.1 www3.bigtrafficnetwork.com
127.0.0.1 www.bigtrafficnetwork.com #[Adware.BigTrafficNet]
127.0.0.1 www2.click2begin.com
127.0.0.1 desktoptraffic.net
127.0.0.1 toolbar.desktoptraffic.net
127.0.0.1 popupsearches.com
127.0.0.1 www2.popupsearches.com
127.0.0.1 www.popupsearches.com
127.0.0.1 trafficgeneration.biz
127.0.0.1 toolbar.trafficgeneration.biz #[ADW_BEGINTO.DR]
127.0.0.1 toolbar2.trafficgeneration.biz
127.0.0.1 toolbar3.trafficgeneration.biz
127.0.0.1 toolbar4.trafficgeneration.biz
127.0.0.1 www.trafficgeneration.biz
127.0.0.1 trafficsector.com #[Adware.Webext]
127.0.0.1 new.trafficsector.com
# [Masterly International S.A.][Kitten Holding Corp]
127.0.0.1 www2.1evidencekiller.com
127.0.0.1 www2.1historyeraser.com
127.0.0.1 www2.1popupblocker.com
127.0.0.1 www.1spywarekiller.com #[Rogue/Suspect]
127.0.0.1 www2.1spywarekiller.com #[Parasite.SpywareKiller]
127.0.0.1 www3.1spywarekiller.com
127.0.0.1 www.evilmembers.com
127.0.0.1 www2.surfertools.com
127.0.0.1 www.surfertools.com
127.0.0.1 zippy-lookup.com #[Adware.ZippyLookup.BHO]
127.0.0.1 www.zippy-lookup.com
# [Actif Oiseau Alerte S.A.][Janerus, Inc]
127.0.0.1 www.eaffiliateinc.com
127.0.0.1 gpstool.globaladserver.com #[iiittt Class]
127.0.0.1 www.globaladserver.com
127.0.0.1 globalwebsearch.com #[Parasite.ILookup]
127.0.0.1 toolbar.globalwebsearch.com #[I-Lookup.GWS]
127.0.0.1 toolbar2.globalwebsearch.com #[HJTH.Lookup/GlobalWebSearch]
127.0.0.1 www.globalwebsearch.com #[Adware.ILookup]
127.0.0.1 goldmembersarea.com #[server down?]
127.0.0.1 www.goldmembersarea.com
127.0.0.1 gophersearch.com #[McAfee.Adware-WorldAnywhere]
127.0.0.1 www.gophersearch.com
127.0.0.1 www.megaadultsite.com
127.0.0.1 secure.pinkpays.com #[server down?]
127.0.0.1 www.pinkpays.com
127.0.0.1 www.toonxxxfantasies.com #[WorldAnywhere Toolbar]
127.0.0.1 vroomsearch.com
127.0.0.1 www.vroomsearch.com #[server down?]
127.0.0.1 worldanywhere.com
127.0.0.1 toolbar.worldanywhere.com
127.0.0.1 www.worldanywhere.com
# [KVM Media S. A.]
127.0.0.1 www.icannnews.com #[HJTH.Look2Me.ag][Kephyr.PUP]
127.0.0.1 kvmmedia.com
127.0.0.1 mononews.com
127.0.0.1 newsagemedia.com
# [ADP Micro]
127.0.0.1 www.alarm-works.com #[MHTMLRedir.Exploit]
127.0.0.1 www.beachtrash.com #[MHTMLRedir.Exploit]
# [Bariscloth INC][Daniel Wesley]
127.0.0.1 www.600.net
127.0.0.1 www.aimface.com #[Adware Bundler]
127.0.0.1 www.buddy-icons.us #[Kephyr.PUP]
127.0.0.1 creditloan.ws
127.0.0.1 www.creditloan.ws
127.0.0.1 www.funnyjoke.net
127.0.0.1 www.imbuddy.net #[Trojan-Dropper.Win32.ExeBundle.286]
127.0.0.1 www.ratepic.com
# [Belcaro Group][eTrust.Spyware.Belcaro GoldenRetriever]
127.0.0.1 1cat.com
127.0.0.1 i.1cat.com
127.0.0.1 www.1cat.com
127.0.0.1 gr1.cc
127.0.0.1 gr2.cc
127.0.0.1 gr3.cc #[IE-SpyAd]
127.0.0.1 gr4.cc
127.0.0.1 selectbonus.com
127.0.0.1 www.selectbonus.com
127.0.0.1 www.shopathome.com
127.0.0.1 shopathomeselect.com #[Parasite.ShopAtHomeSelect]
127.0.0.1 download1.shopathomeselect.com #[ADW_SAHAGENT.A]
127.0.0.1 downloads.shopathomeselect.com
127.0.0.1 download21.shopathomeselect.com
127.0.0.1 www.shopathomeselect.com #[Adware.SAHAgent]
# [Bell Globemedia Interactive Inc]
127.0.0.1 adcounter.theglobeandmail.com
127.0.0.1 adrates.theglobeandmail.com
127.0.0.1 ads.globeandmail.com
127.0.0.1 ads1.theglobeandmail.com
127.0.0.1 visit.theglobeandmail.com
127.0.0.1 www1.theglobeandmail.com
# [Bit Wise Publishing, LLC]
127.0.0.1 www.321search.com #[SearchAssistant.dll]
127.0.0.1 www.bitwisepublishing.com #[myglobalsearch.com]
127.0.0.1 www.free-patriotic-screensavers.com #[tafmaster.com]
127.0.0.1 www.my247eshop.com #[eShopper Search Bar]
127.0.0.1 www.scenicreflections.com #[MySearch Toolbar]
# [BLOKE.COM][IE-SpyAd]
127.0.0.1 adbot.com
127.0.0.1 w1.adbot.com
127.0.0.1 www.adbot.com
127.0.0.1 counter.bloke.com
127.0.0.1 www1.counter.bloke.com
127.0.0.1 www3.counter.bloke.com
127.0.0.1 www4.counter.bloke.com
127.0.0.1 www5.counter.bloke.com
127.0.0.1 www6.counter.bloke.com
127.0.0.1 www7.counter.bloke.com
127.0.0.1 counterbot.com
127.0.0.1 cb1.counterbot.com
# [Bluestreak][Tracking Service][IE-SpyAd]
127.0.0.1 bluestreak.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 ak.bluestreak.com
127.0.0.1 ca1.bluestreak.com
127.0.0.1 s0.bluestreak.com
127.0.0.1 s0b.bluestreak.com
127.0.0.1 s1.bluestreak.com
127.0.0.1 s2.bluestreak.com
127.0.0.1 s3.bluestreak.com
127.0.0.1 s4.bluestreak.com
127.0.0.1 s5.bluestreak.com
127.0.0.1 s6.bluestreak.com
127.0.0.1 s7.bluestreak.com
127.0.0.1 s8.bluestreak.com
127.0.0.1 www.bluestreak.com
# [Bluetide Software]
127.0.0.1 www.bluetidesoftware.com
127.0.0.1 surfsidekick.com #[ADW_SURFKICK.B]
127.0.0.1 ads.surfsidekick.com
127.0.0.1 dl.surfsidekick.com #[Parasite.TVMedia.SSK][TROJ_SMALL.AQC]
127.0.0.1 www.surfsidekick.com #[Adware.SurfSideKick]
# [Bob Jones][Tommy Davis][Adware.BlockChecker]
127.0.0.1 www.block-checker.com #[McAfee.Adclicker-DF]
127.0.0.1 www.spootie.com
127.0.0.1 www.system-processes.com #[Adware.SystemProcess]
# [Bobi Net][Parasite.WebDir]
127.0.0.1 secure.certone.com #[Adware.WebDir]
127.0.0.1 dcplusplus.info
127.0.0.1 www.filefront.net
127.0.0.1 www.gizmoyo.com #[IE-SpyAd]
127.0.0.1 www.torrentsearcher.net
127.0.0.1 www.xcode.info
127.0.0.1 files.xeol.net
127.0.0.1 pr.xeol.net
# [BONZI][Adware.Bonzi]
127.0.0.1 download.bonzi.com
127.0.0.1 images.bonzi.com
127.0.0.1 www.bonzi.com #[ADW_BONJING.A]
127.0.0.1 www.bonzibuddy.com
127.0.0.1 cdn.gms1.net
127.0.0.1 i.gms1.net #[McAfee.Adware-IEHost]
127.0.0.1 www.gms1.net
# [BraveNet][Tracking Service][IE-SpyAd]
127.0.0.1 bravenet.com
127.0.0.1 adserv.bravenet.com
127.0.0.1 images.bravenet.com
127.0.0.1 linktrack.bravenet.com
127.0.0.1 pub1.bravenet.com
127.0.0.1 pub6.bravenet.com
127.0.0.1 www.bravenet.com
# [BruggeNet][Trojan.Adclicker][WinPup]
127.0.0.1 belgiandip.com #[ITS Protocol exploit]
127.0.0.1 www.belgiandip.com
127.0.0.1 www.burlapbag.org #[IE-SpyAd]
127.0.0.1 www.illtemperedguppys.com
127.0.0.1 www.lazychestnuts.net #[Troj/StartPa-AF]
127.0.0.1 www.lugelessons.net
127.0.0.1 www.meathelmets.net
127.0.0.1 www.undergroundlair.net #[Troj/AdClick-N]
127.0.0.1 www2.undergroundlair.net
# [BUDS Inc. Ad Network][IE-SpyAd][SPYW_SOFTOMATE.A]
127.0.0.1 www.anquiro.com #[Adw.Anquiro.Toolbar][Trackware.Anquiro]
127.0.0.1 adserving.budsinc.com #[ad.yieldmanager.com]
127.0.0.1 affiliate.budsinc.com
127.0.0.1 show.budsinc.com
127.0.0.1 www.budsinc.com
127.0.0.1 www.musicfeet.com
127.0.0.1 www.iwebmusic.com
127.0.0.1 iwebtunes.com
127.0.0.1 www.iwebtunes.com
# [BurstMedia][Tracking Service][IE-SpyAd]
127.0.0.1 ads.addesktop.com
127.0.0.1 burstmedia.com
127.0.0.1 web.burstmedia.com
127.0.0.1 roscoe.burstmedia.com
127.0.0.1 ads.burstnet.com
127.0.0.1 gifs.burstnet.com
127.0.0.1 sj.burstnet.com
127.0.0.1 te.burstnet.com
127.0.0.1 text.burstnet.com
127.0.0.1 www.burstnet.com #[eTrust.Tracking Cookie]
127.0.0.1 www2.burstnet.com
127.0.0.1 www3.burstnet.com
127.0.0.1 www4.burstnet.com
127.0.0.1 www5.burstnet.com
127.0.0.1 www6.burstnet.com
127.0.0.1 www.burstnet.akadns.net
# [Casale Media][Comspec Communications][IE-SpyAd]
127.0.0.1 casalemedia.com
127.0.0.1 as.casalemedia.com
127.0.0.1 asg01.casalemedia.com
127.0.0.1 asg02.casalemedia.com
127.0.0.1 asg03.casalemedia.com
127.0.0.1 asg04.casalemedia.com
127.0.0.1 asg05.casalemedia.com
127.0.0.1 asg06.casalemedia.com
127.0.0.1 asg07.casalemedia.com
127.0.0.1 asg08.casalemedia.com
127.0.0.1 asg09.casalemedia.com
127.0.0.1 asg10.casalemedia.com
127.0.0.1 asg11.casalemedia.com
127.0.0.1 asg12.casalemedia.com
127.0.0.1 asg13.casalemedia.com
127.0.0.1 asg14.casalemedia.com
127.0.0.1 asg15.casalemedia.com
127.0.0.1 asg16.casalemedia.com
127.0.0.1 asg17.casalemedia.com
127.0.0.1 asg18.casalemedia.com
127.0.0.1 asg19.casalemedia.com
127.0.0.1 asg20.casalemedia.com
127.0.0.1 asg21.casalemedia.com
127.0.0.1 asg22.casalemedia.com
127.0.0.1 asg23.casalemedia.com
127.0.0.1 asg24.casalemedia.com
127.0.0.1 asg25.casalemedia.com
127.0.0.1 asg26.casalemedia.com
127.0.0.1 asg27.casalemedia.com
127.0.0.1 asg28.casalemedia.com
127.0.0.1 asg29.casalemedia.com
127.0.0.1 asg30.casalemedia.com
127.0.0.1 asg31.casalemedia.com
127.0.0.1 asg32.casalemedia.com
127.0.0.1 asg33.casalemedia.com
127.0.0.1 asg34.casalemedia.com
127.0.0.1 asg35.casalemedia.com
127.0.0.1 asg36.casalemedia.com
127.0.0.1 asg37.casalemedia.com
127.0.0.1 asg38.casalemedia.com
127.0.0.1 asg39.casalemedia.com
127.0.0.1 asg40.casalemedia.com
127.0.0.1 asg41.casalemedia.com
127.0.0.1 asg42.casalemedia.com
127.0.0.1 asg43.casalemedia.com
127.0.0.1 asg44.casalemedia.com
127.0.0.1 asg45.casalemedia.com
127.0.0.1 asg46.casalemedia.com
127.0.0.1 asg47.casalemedia.com
127.0.0.1 asg48.casalemedia.com
127.0.0.1 asg49.casalemedia.com
127.0.0.1 asg50.casalemedia.com
127.0.0.1 asg51.casalemedia.com
127.0.0.1 asg52.casalemedia.com
127.0.0.1 asg53.casalemedia.com
127.0.0.1 asg54.casalemedia.com
127.0.0.1 asg55.casalemedia.com
127.0.0.1 asg56.casalemedia.com
127.0.0.1 asg57.casalemedia.com
127.0.0.1 asg58.casalemedia.com
127.0.0.1 asg59.casalemedia.com
127.0.0.1 asg60.casalemedia.com
127.0.0.1 asg61.casalemedia.com
127.0.0.1 asg62.casalemedia.com
127.0.0.1 asg63.casalemedia.com
127.0.0.1 asg64.casalemedia.com
127.0.0.1 asg65.casalemedia.com
127.0.0.1 asg66.casalemedia.com
127.0.0.1 asg67.casalemedia.com
127.0.0.1 asg68.casalemedia.com
127.0.0.1 asg69.casalemedia.com
127.0.0.1 asg70.casalemedia.com
127.0.0.1 asg71.casalemedia.com
127.0.0.1 asg72.casalemedia.com
127.0.0.1 asg73.casalemedia.com
127.0.0.1 asg74.casalemedia.com
127.0.0.1 asg75.casalemedia.com
127.0.0.1 asg76.casalemedia.com
127.0.0.1 asg77.casalemedia.com
127.0.0.1 asg78.casalemedia.com
127.0.0.1 asg79.casalemedia.com
127.0.0.1 asg80.casalemedia.com
127.0.0.1 asg81.casalemedia.com
127.0.0.1 asg82.casalemedia.com
127.0.0.1 aslg01.casalemedia.com
127.0.0.1 aslg02.casalemedia.com
127.0.0.1 aslg03.casalemedia.com
127.0.0.1 aslg04.casalemedia.com
127.0.0.1 aslg05.casalemedia.com
127.0.0.1 aslg06.casalemedia.com
127.0.0.1 aslg07.casalemedia.com
127.0.0.1 aslg08.casalemedia.com
127.0.0.1 aslg09.casalemedia.com
127.0.0.1 aslg10.casalemedia.com
127.0.0.1 c.casalemedia.com
127.0.0.1 i.casalemedia.com
127.0.0.1 is.casalemedia.com
127.0.0.1 isg01.casalemedia.com
127.0.0.1 isg02.casalemedia.com
127.0.0.1 isg03.casalemedia.com
127.0.0.1 isg04.casalemedia.com
127.0.0.1 isg05.casalemedia.com
127.0.0.1 isg06.casalemedia.com
127.0.0.1 isg07.casalemedia.com
127.0.0.1 isg08.casalemedia.com
127.0.0.1 isg09.casalemedia.com
127.0.0.1 isg10.casalemedia.com
127.0.0.1 lb01.casalemedia.com
127.0.0.1 r.casalemedia.com
127.0.0.1 www.casalemedia.com
127.0.0.1 www.errorguard.com #[PcTools.ErrorGuard][eTrust.ErrorGuard]
127.0.0.1 spywarestormer.com #[Rogue/Suspect]
127.0.0.1 www.spywarestormer.com #[CInstall Class][Zoombar Object]
127.0.0.1 www.oofun.com
127.0.0.1 00fun.com
127.0.0.1 www.00fun.com
# [c2 Media Ltd][Download.Adware.Lop][C2.lop]
127.0.0.1 aavc.com
127.0.0.1 active-max.com
127.0.0.1 search.active-max.com
127.0.0.1 www.active-max.com
127.0.0.1 allaboutsearching.com
127.0.0.1 www.allaboutsearching.com
127.0.0.1 amazingautossearch.com
127.0.0.1 www.amazingautossearch.com
127.0.0.1 contexualsearch.com
127.0.0.1 www.contexualsearch.com
127.0.0.1 www.dialup2.com
127.0.0.1 ecpm.com #[ADW_BADBITOR.A]
127.0.0.1 www.ecpm.com
127.0.0.1 find-quick.com
127.0.0.1 www.find-quick.com
127.0.0.1 look-today.com
127.0.0.1 www.look-today.com
127.0.0.1 lop.com
127.0.0.1 ao.lop.com
127.0.0.1 ayb.lop.com
127.0.0.1 bins.lop.com
127.0.0.1 k17177.bins.lop.com
127.0.0.1 img.lop.com
127.0.0.1 sue.lop.com
127.0.0.1 srch.lop.com #[Parasite.LOP]
127.0.0.1 www1.lop.com
127.0.0.1 www.lop.com
127.0.0.1 maxexp.com
127.0.0.1 www.mp3search.com
127.0.0.1 mysearchnow.com
127.0.0.1 search200.com #[eTrust.Search200 Toolbar]
127.0.0.1 www.search200.com #[ADW_BADBITOR.A]
127.0.0.1 search.mysearchnow.com
127.0.0.1 www.mysearchnow.com
127.0.0.1 netsearchsoft.com
127.0.0.1 www.netsearchsoft.com
127.0.0.1 omegasearch.com
127.0.0.1 www.omegasearch.com
127.0.0.1 prosearching.com
127.0.0.1 www.prosearching.com
127.0.0.1 search.rub.to #[Adware.Trinity]
127.0.0.1 www.rub.to
127.0.0.1 sbvr.com
127.0.0.1 www.sbvr.com
127.0.0.1 searchexe.com
127.0.0.1 www.searchexe.com
127.0.0.1 searchweb2.com
127.0.0.1 www.searchweb2.com
127.0.0.1 spawnet.com
127.0.0.1 www.spawnet.com
127.0.0.1 tdmy.com #[TrojanDownloader.Win32.Swizzor.h]
127.0.0.1 tefs.com
127.0.0.1 tfil.com
127.0.0.1 www.tfil.com
127.0.0.1 tdko.com
127.0.0.1 www.tdko.com
127.0.0.1 wfix.com #[super-spider.com]
# [CA Web Designs][Tracking Service][IE-SpyAd]
127.0.0.1 clickxchange.com
127.0.0.1 caweb1.clickxchange.com
127.0.0.1 caweb2.clickxchange.com
127.0.0.1 www.clickxchange.com
# [Chunkybreakfast][Robert Davidson]
127.0.0.1 elitemediagroup.net #[Trojan.TrustedZone]
127.0.0.1 bins.elitemediagroup.net
127.0.0.1 cabs.elitemediagroup.net #[elitectl.DemoCtl]
127.0.0.1 logs.elitemediagroup.net
127.0.0.1 mmm.elitemediagroup.net
127.0.0.1 www.elitemediagroup.net
127.0.0.1 alerts.imgiant.com
127.0.0.1 blog.imgiant.com
127.0.0.1 www.imgiant.com #[McAfee.imGiant]
127.0.0.1 cabs.imgiant.net
127.0.0.1 mmm.imgiant.net
127.0.0.1 www.imgiant.net #[IMGiant Instant Messenger]
127.0.0.1 www.media-motor.com
127.0.0.1 bins.media-motor.net #[ADW_MOTOR.A]
127.0.0.1 bins2.media-motor.net #[TROJ_VB.DO]
127.0.0.1 cabs.media-motor.net #[IObjSafety.DemoCtl]
127.0.0.1 logs.media-motor.net
127.0.0.1 mmm.media-motor.net #[Adware.Popuppers]
127.0.0.1 mmm1.media-motor.net #[mmm.roings.com]
127.0.0.1 www.media-motor.net #[ADW_MEDIAMOT.B]
127.0.0.1 pokahaus.com
127.0.0.1 ran.popuppers.com
127.0.0.1 tar.popuppers.com #[Adware.Medload]
127.0.0.1 www.popuppers.com #[Adware.Roimoi][SULoads.popuppers]
127.0.0.1 bins.roings.com #[jimmyloader.jimmyform]
127.0.0.1 cabs.roings.com #[IObjSafety.DemoCtl]
127.0.0.1 logs.roings.com
127.0.0.1 mmm.roings.com #[limmyloding.limmyform][SunBelt.JimmyHelp]
127.0.0.1 www.roings.com #[Roings Search Enhancment]
127.0.0.1 www.uskyonline.com #[IE-SpyAd]
# [Media-Motor][ERG][Joystick Networks]
127.0.0.1 www.alienicons.com
127.0.0.1 www.blingblingicons.com #[media-motor.net]
127.0.0.1 www.celebsoncrack.com #[media-motor.net]
127.0.0.1 www.diamonddollz.com
127.0.0.1 www.iconarmy.com
127.0.0.1 www.jenkyicons.com
127.0.0.1 www.joystickaudio.com
127.0.0.1 www.joystickball.com
127.0.0.1 www.joystickcheats.com #[AdWare.MediaMotor.a]
127.0.0.1 www.joystickflash.com
127.0.0.1 www.joystickmovies.com
127.0.0.1 cheats.joysticknetworks.com
127.0.0.1 icons.joysticknetworks.com #[AdWare.MediaMotor.a]
127.0.0.1 music.joysticknetworks.com
127.0.0.1 savers.joysticknetworks.com #[eTrust.JoyURLs19]
127.0.0.1 www.joysticknetworks.com #[Trojan.JoystickNetworks.DesktopIcons]
127.0.0.1 www.joysticknews.com
127.0.0.1 www.joysticksavers.com
127.0.0.1 www.joystickwar.com #[Kephyr.PUP]
# [Chitika]
127.0.0.1 ads.chitika.net #[IE-SpyAd]
127.0.0.1 ads1.chitika.net
127.0.0.1 blogads.chitika.net
127.0.0.1 ca.chitika.net
127.0.0.1 mm.chitika.net
127.0.0.1 scripts.chitika.net
# [CJB Management][Backdoor.Ptsnoop]
127.0.0.1 bannerexchange.cjb.net
127.0.0.1 coder3862004.cjb.net #[Trojan.Bansap]
127.0.0.1 dialer.cjb.net #[TIBSLoader Class]
127.0.0.1 crashtest.cjb.net #[IE-SpyAd]
127.0.0.1 searchwww.com
127.0.0.1 search.searchwww.com #[Parasite.SearchWWW]
127.0.0.1 vbs.searchwww.com
127.0.0.1 www.searchwww.com
# [Claria Corporation][GAIN Publishing][Parasite.Gator]
127.0.0.1 www.behaviorlink.com #[IE-SpyAd]
127.0.0.1 ath.belnk.com
127.0.0.1 art.ath.belnk.com
127.0.0.1 dist.belnk.com #[HJTH.Gator Variant]
127.0.0.1 content.dashbar.com
127.0.0.1 results.dashbar.com #[Adware.DashBar][SPYW_DASHBAR.300]
127.0.0.1 www.dashbar.com #[eTrust.Spyware.Claria.Dashbar]
127.0.0.1 www.date-manager.com #[SunBelt.Claria.DateManager][Adware.DateManager]
127.0.0.1 www.entrypass.com
127.0.0.1 www.gainpublishing.com
127.0.0.1 www.gatorcorporation.com
127.0.0.1 www.gatoradvertisinginformationnetwork.com
127.0.0.1 gator.com #[SPYW_GATOR.F]
127.0.0.1 bannerserver.gator.com
127.0.0.1 bc2.gator.com #[SPYW_GATOR.B]
127.0.0.1 bg.gator.com
127.0.0.1 bg2.gator.com
127.0.0.1 bi.gator.com
127.0.0.1 coupons.gator.com
127.0.0.1 gator29.gator.com
127.0.0.1 gatorcme.gator.com
127.0.0.1 gatortime.gator.com
127.0.0.1 gbs.gator.com
127.0.0.1 gi.gator.com
127.0.0.1 gs.gator.com
127.0.0.1 gt.gator.com
127.0.0.1 images.gator.com
127.0.0.1 map.gator.com
127.0.0.1 papps.gator.com
127.0.0.1 patchserver.gator.com
127.0.0.1 patchserver2.gator.com
127.0.0.1 regserver.gator.com
127.0.0.1 rs.gator.com
127.0.0.1 scriptserver.gator.com
127.0.0.1 search.gator.com
127.0.0.1 ss.gator.com
127.0.0.1 ssbackup.gator.com
127.0.0.1 ts.gator.com
127.0.0.1 trickle.gator.com
127.0.0.1 updateserver.gator.com
127.0.0.1 weather.gator.com
127.0.0.1 web.balance.gator.com
127.0.0.1 webpdp.gator.com #[DFRun Class][HDPluginCtrl Class]
127.0.0.1 xmlsearch.gator.com
127.0.0.1 xmlsearch.balance.gator.com
127.0.0.1 www.gator.com #[Adware.GatorEWallet][ADW_GAIN.A]
127.0.0.1 www.gotsmiley.com #[Adware.GotSmiley][PcTools.GotSmily]
127.0.0.1 www.offercompanion.com #[eTrust.Offer Companion]
127.0.0.1 www.precision-time.com #[Adware.PrecisionTime]
127.0.0.1 www.screenscenes.com #[Adware.ScreenScenes]
127.0.0.1 content.searchscout.com
127.0.0.1 results.searchscout.com
127.0.0.1 www.searchscout.com #[Adware.SearchScout]
127.0.0.1 www.tgcsearch.com #[IE-SpyAd]
127.0.0.1 www.weatherscope.com #[SunBelt.Claria.WeatherScope]
127.0.0.1 www.websecurealert.com #[Adware.WebSecureAlert][ADW_WSECALERT.A]
# [Click Enterprises]
127.0.0.1 dafinder.com
127.0.0.1 www3.dafinder.com
127.0.0.1 ourlinklist.com
127.0.0.1 searchaccurate.com #[Parasite.TinyBar]
127.0.0.1 www.searchaccurate.com
# [CNN/Time Warner/AOL]
127.0.0.1 ads.web.aol.com
127.0.0.1 affiliate.aol.com
127.0.0.1 aim.aol.com
127.0.0.1 dynamic.aol.com
127.0.0.1 free.aol.com
127.0.0.1 ar.atwola.com #[causes problems at netscape.com?]
127.0.0.1 ar1.atwola.com
127.0.0.1 ar7.atwola.com
127.0.0.1 pr.atwola.com
127.0.0.1 ads.newline.aol.com
127.0.0.1 adremote.pathfinder.com
127.0.0.1 adremote.timeinc.net
127.0.0.1 aolwpnscom.112.2o7.net
127.0.0.1 aolwpnswhatsnew.112.2o7.net
127.0.0.1 timecom.112.2o7.net
# [CNET Networks]
127.0.0.1 a.adstome.com
127.0.0.1 newads.cmpnet.com
127.0.0.1 datapop.cmpnet.com
127.0.0.1 cookies.cmpnet.com
127.0.0.1 adimg.cnet.com
127.0.0.1 c10-ad-xw1.cnet.com
127.0.0.1 mads.cnet.com
127.0.0.1 remotead-internal.cnet.com
127.0.0.1 remotead.cnet.com
127.0.0.1 ads.com.com
127.0.0.1 adimg.com.com
127.0.0.1 adlog.com.com
127.0.0.1 mads.com.com
127.0.0.1 ads.techtv.com
127.0.0.1 ads.zdnet.com
127.0.0.1 adimg.zdnet.com
127.0.0.1 mads.zdnet.com
# [CommonName Limited][Adware.CommonName][Parasite.CommonName]
127.0.0.1 commonname.com
127.0.0.1 www.commonname.com #[AdWare.CommonName.l]
127.0.0.1 commonnames.com
127.0.0.1 www.commonnames.com
127.0.0.1 g3ads.com
127.0.0.1 www.g3ads.com
127.0.0.1 www.kpsn.com
127.0.0.1 trafficexplorer.com
127.0.0.1 www.trafficexplorer.com #[AdWare.CommonName.g]
127.0.0.1 xpsn.com
127.0.0.1 www.xpsn.com
# [Conducive]
127.0.0.1 ad.admarketplace.net
127.0.0.1 ads.admarketplace.net
127.0.0.1 ads.cc214142.com #[Kephyr.PUP]
# [Contextu Ads]
127.0.0.1 tag.contextweb.com
127.0.0.1 www1.contextweb.com
127.0.0.1 www2.contextweb.com
127.0.0.1 www3.contextweb.com
127.0.0.1 www4.contextweb.com
127.0.0.1 www5.contextweb.com
127.0.0.1 www6.contextweb.com
127.0.0.1 www7.contextweb.com
127.0.0.1 www8.contextweb.com
127.0.0.1 www.contextuads.com #[F-Secure.ContextuAd][IE-SpyAd]
127.0.0.1 www.nicheseek.com
127.0.0.1 www2.nicheseek.com
# [Coolsavings, Inc][Conducent TimeSink][Coolsavings Coupon Manager]
127.0.0.1 img10.coolsavings.com
127.0.0.1 mn104.coolsavings.com
127.0.0.1 www101.coolsavings.com
127.0.0.1 www102.coolsavings.com #[IE-SpyAd][ADW_COOLSAVE.500]
127.0.0.1 www105.coolsavings.com
127.0.0.1 www109.coolsavings.com
127.0.0.1 www112.coolsavings.com #[CMV5 Class]
# [Coolwebsearch.com and affiliates]
# [InterWeb Solutions][IE-SpyAd]
127.0.0.1 coolwebsearch.com #[Trojan.TrustedZones]
127.0.0.1 php.coolwebsearch.com
127.0.0.1 search_fd.php.coolwebsearch.com
127.0.0.1 stats.coolwebsearch.com
127.0.0.1 www.coolwebsearch.com #[CWS/IEFeats]
# [CWS related and Major Affiliates]
127.0.0.1 1-se.com #[CWS.Aboutblank][W32.Tuoba.Trojan]
127.0.0.1 www.1-se.com #[VBS.Startpage.C]
127.0.0.1 www.212-229-05.com
127.0.0.1 www.31234.com #[CWS.Msconfig]
127.0.0.1 a7search.com
127.0.0.1 www.a7search.com
127.0.0.1 www.a-137.com #[runsearch.com]
127.0.0.1 dl.ad-ware.cc # #[MHTMLRedir.Exploit][topx.cc]
127.0.0.1 acc.count-all.com #[CWS.Tapicfg]
127.0.0.1 allneedsearch.com #[TROJ_STARTPAGE.B][find-itnow.com]
127.0.0.1 alfaportal.com
127.0.0.1 approvedlinks.com #[super-spider.com]
127.0.0.1 asdbiz.biz #[searchmeup.com][Trojan.TrustedZone]
127.0.0.1 www.asdbiz.biz #[Trojan-Downloader.Win32.Small.biq]
127.0.0.1 autosearch.cc
127.0.0.1 bestsearch.cc #[PcTools.Trojan.Startpage.CF]
127.0.0.1 bestwebslinks.com #[Troj/Puper-D][SmithFraud.c]
127.0.0.1 www.bestwebslinks.com
127.0.0.1 bettersearch.biz #[ADW_COOLSEARCH.A][Trojan.TrustedZone]
127.0.0.1 www.bettersearch.biz #[CWS.CoolSearchA]
127.0.0.1 www.coolfreehost.com
127.0.0.1 coolsearcher.net #[Troj/DownLdr-FC]
127.0.0.1 cool-search.cc
127.0.0.1 defaultsearching.com #[CWS.Sounddrv][searchmeup.com]
127.0.0.1 dnserror.cc
127.0.0.1 drusearch.com #[Download.Ject.B][VBS/StartPa-DN]
127.0.0.1 allways.drusearch.com #[Adware.Drusearch]
127.0.0.1 www.drusearch.com
127.0.0.1 enjoysearch.info #[CWS.Xxxvideo]
127.0.0.1 www.enjoysearch.info
127.0.0.1 e-plus.cc #[Adware.WorldSearch]
127.0.0.1 www.e-plus.cc
127.0.0.1 fastboxhosting.com #[Kephyr.PUP][Suspended]
127.0.0.1 prx.freecj.com #[MHTMLRedir.Exploit]
127.0.0.1 www.findin.org
127.0.0.1 findloss.com #[umaxsearch.com]
127.0.0.1 www.findloss.com
127.0.0.1 firstbookmark.com #[Parasite.ClientMan]
127.0.0.1 www.firstbookmark.com
127.0.0.1 freepage.ws
127.0.0.1 www.getaflick.biz #[MHTMLRedir.Exploit]
127.0.0.1 globe-finder.net #[clearsearch.net]
127.0.0.1 www.globe-finder.net
127.0.0.1 global-finder.com #[CWS.Msinfo]
127.0.0.1 www.global-finder.com
127.0.0.1 idgsearch.com #[GoogleMS Search Helper][CWS.Googlems]
127.0.0.1 www.idgsearch.com #[Trojan.Digits]
127.0.0.1 icansearch.net
127.0.0.1 www.icansearch.net
127.0.0.1 www.internet-search.info
127.0.0.1 itseasy.us #[Galorion][McAfee.Startpage-YBM]
127.0.0.1 justload.com #[MHTMLRedir.Exploit]
127.0.0.1 luckysearch.net #[CWS.Tapicfg]
127.0.0.1 www.luckysearch.net
127.0.0.1 lustler.com
127.0.0.1 www.lustler.com
127.0.0.1 makechoice.com #[McAfee.QlowZones-25]
127.0.0.1 www.makechoice.com #[MHTMLRedir.Exploit]
127.0.0.1 myexexex.com #[CWS.Jsconsole]
127.0.0.1 www.myexexex.com #[StartPage-EC]
127.0.0.1 www.myhandysearch.com
127.0.0.1 www.mywebsearch.net
127.0.0.1 ne-ebu.com #[search-system.com][topsearch10.com]
127.0.0.1 othersearch.com #[Parasite.Tubby]
127.0.0.1 www.othersearch.com
127.0.0.1 payfortraffic.net #[CWS.Dnsrelay.3][CWS.Msole]
127.0.0.1 www.payfortraffic.net
127.0.0.1 www.placeforsearch.com
127.0.0.1 power-search.info #[Trojan.Bookmarker.G]
127.0.0.1 www.power-search.info #[Adware.Olehelp]
127.0.0.1 pro-websearch.info
127.0.0.1 www.pro-websearch.info #[dating-live.net]
127.0.0.1 richfind.com #[vipse.org]
127.0.0.1 www.richfind.com
127.0.0.1 rdposters.com #[Trojan.Win32.Adex.a]
127.0.0.1 runsearch.com #[CWS.Mupdate]
127.0.0.1 www.runsearch.com
127.0.0.1 www.searchadv.com #[Trojan.GuestBook][umaxlogin.com]
127.0.0.1 searchanyway.com
127.0.0.1 feed.searchanyway.com #[coolwebsearch.com]
127.0.0.1 go.searchanyway.com
127.0.0.1 www.searchanyway.com
127.0.0.1 searchbar.us #[Spyware.IEToolbar]
127.0.0.1 searchcentral.cc
127.0.0.1 searchdesire.com
127.0.0.1 searchfind.info #[Parasite.RichFind]
127.0.0.1 search-more.net #[McAfee.Adware-SearchMore]
127.0.0.1 www.search-more.net
127.0.0.1 search-network.cc #[CoolWebSearch.XPlugin]
127.0.0.1 search-system.com #[SunBelt.Search-SystemPlugin]
127.0.0.1 www.search-system.com #[topsearch10.com]
127.0.0.1 searchtm.cc #[W32/DLoader.GQ]
127.0.0.1 searchzoomer.com
127.0.0.1 www.searchzoomer.com
127.0.0.1 security-updater.com #[Win32.Wintrim.AG]
127.0.0.1 www.security-updater.com
127.0.0.1 shop.sexplorer.it
127.0.0.1 www.sexplorer.it
127.0.0.1 sitsearch.com #[morwillsearch.com]
127.0.0.1 spyantivirus.info #[umaxlogin.com]
127.0.0.1 sutra.spyantivirus.info
127.0.0.1 www.spyantivirus.info
127.0.0.1 startsearches.com
127.0.0.1 www.startsearches.com
127.0.0.1 supersearch.com
127.0.0.1 www.supersearch.com #[CWS.Msoffice.3]
127.0.0.1 super-spider.com #[CWS.Control][TROJ_KREPPER.I]
127.0.0.1 t.rack.cc #[TROJ_SEEKER.B]
127.0.0.1 roquvp.t.rack.cc
127.0.0.1 teen-biz.com #[Trojan.Win32.StartPage.bh]
127.0.0.1 temasearch.com #[coolwebsearch.com]
127.0.0.1 www.temasearch.com
127.0.0.1 the-exit.com
127.0.0.1 www.the-exit.com
127.0.0.1 www.the-huns-yellow-pages.com
127.0.0.1 topfivesearch.com #[TROJ_DLOADER.VR]
127.0.0.1 xml.topfivesearch.com #[VPP Technologies]
127.0.0.1 www.topfivesearch.com #[eTrust.TopFiveSearch]
127.0.0.1 toteen.com #[Trojan.Bookmarker.G]
127.0.0.1 out.true-counter.com #[Trojan.Bootconf][CWS.Msinfo]
127.0.0.1 true-counter.com #[Trojan.Slog]
127.0.0.1 www.true-counter.com
127.0.0.1 umaxsearch.biz
127.0.0.1 www.umaxsearch.biz
127.0.0.1 updatesearches.com
127.0.0.1 www.updatesearches.com #[eTrust.Puper.UpdateSearches]
127.0.0.1 v73.us #[Adware.CWSConyc]
127.0.0.1 www.v73.us
127.0.0.1 warlog.info
127.0.0.1 webtracer.cc
127.0.0.1 rl.webtracer.cc #[globe-finder.cc][Troj/StartPa-FZ]
127.0.0.1 www.wholeworldmarket.com #[CWS.Systeminit.2]
127.0.0.1 www.wow-access.com
127.0.0.1 www-search.cc
127.0.0.1 www.xyesearch.com
127.0.0.1 yellow-pages.ws #[searchmeup.com]
127.0.0.1 adult.yellow-pages.ws
127.0.0.1 search.yellow-pages.ws
127.0.0.1 www.youfindall.com #[CWS.Aff.Winshow]
127.0.0.1 youfindall.net
127.0.0.1 www.youfindall.net
127.0.0.1 yoursearch.ws
# [Adult 24]
127.0.0.1 www.add-to-favorites.net #[IE-SpyAd]
127.0.0.1 crdrcr.com #[Win32.Holax.A]
127.0.0.1 find-it-easy.org #[Parasite.CoolWebSearch.InetDoor]
127.0.0.1 findtop.net
# [Afer Sanches]
127.0.0.1 2004search.cc #[searchanyway.com]
127.0.0.1 33search.cc
127.0.0.1 all-search.cc
127.0.0.1 searchinwww.cc #[searchanyway.com]
127.0.0.1 wwwsearch.cc
127.0.0.1 yufgd43w.cc #[TROJ_ESEPOR.AB]
# [Anatoliy Petrenko]
127.0.0.1 cool-partner.com
127.0.0.1 bad.cool-partner.com
127.0.0.1 coolmegasearch.com
127.0.0.1 netmegasearch.com #[IE-SpyAd]
# [asdbiz.biz][Vasiliy Ivanov]
127.0.0.1 allstarsearch.net #[Webhelper4u.SearchTerror]
127.0.0.1 craftsmensearch.com #[MHTMLRedir.Exploit]
127.0.0.1 fogsearch.net #[MHTMLRedir.Exploit]
127.0.0.1 powdersearch.com
127.0.0.1 rimssearch.com #[via 66.246.209.224]
127.0.0.1 searchterror.com
# [Atlantics Cons S/A]
127.0.0.1 clicksearchclick.com #[yeahsearch.net]
127.0.0.1 www.clicksearchclick.com #[kklik2.php]
127.0.0.1 daoclick.com
127.0.0.1 www.daoclick.com
127.0.0.1 ipassist.biz #[MHTMLRedir.Exploit]
127.0.0.1 www.ipassist.biz #[clicksearchclick.com]
127.0.0.1 ipcons.biz #[mwsfeed.php]
127.0.0.1 adderall.ipcons.biz
127.0.0.1 www.ipcons.biz
127.0.0.1 web-free-hosting.net #[MHTMLRedir.Exploit]
127.0.0.1 www.web-free-hosting.net
# [Chabad Lubavitch][Kreoman Boduin]
127.0.0.1 a-search.biz
127.0.0.1 k-search.biz
127.0.0.1 www.k-search.biz
127.0.0.1 mysearchpage.biz
127.0.0.1 ssearch.biz #[StartPage-EH]
127.0.0.1 xysearch.biz
# [Danyelle Christian][Trojan.TrustedZones]
127.0.0.1 69sexsearch.com #[TROJ_DLOADER.W][TROJ_DROPPER.T]
127.0.0.1 www.69sexsearch.com
127.0.0.1 aflashcounter.com #[Trojan.Moo.B]
127.0.0.1 gen.aflashcounter.com
127.0.0.1 xyz.aflashcounter.com #[MHTMLRedir.Exploit]
127.0.0.1 yxz.aflashcounter.com
127.0.0.1 realsearch.cc
127.0.0.1 spyware-spyware.org #[razespyware.com]
127.0.0.1 www.spyware-spyware.org
# [Denn Dillmark]
127.0.0.1 hitscount.net #[MHTMLRedir.Exploit]
127.0.0.1 searchforfree.info
127.0.0.1 trytofind.info
# [Conyc][Trojan.ByteVerify]
127.0.0.1 0websearch.com
127.0.0.1 bestsearcher.info
127.0.0.1 ren.bestsearcher.info
127.0.0.1 www.bestsearcher.info
127.0.0.1 giga-search.info #[morwillsearch.com]
127.0.0.1 maxysearch.info
127.0.0.1 wm.maxysearch.info #[McAfee.Spam-Maxy]
127.0.0.1 www.maxysearch.info #[mwsfeed]
127.0.0.1 on-search.com
127.0.0.1 www.on-search.com
127.0.0.1 searcheverywhere.info #[morwillsearch.com]
127.0.0.1 search-daily.com #[TROJ_CLICKER.E]
127.0.0.1 www.search-daily.com
127.0.0.1 search-paga.com
127.0.0.1 www.search-paga.com
127.0.0.1 www.seekeveryday.info
127.0.0.1 traff-store.com
# [DMC MEDIA GROUP]
127.0.0.1 ie-search.com #[CWS.Loadbat][umaxsearch.com]
127.0.0.1 www.ie-search.com
# [FlatHousing-Group][makeat.net]
127.0.0.1 adextension.com #[MHTMLRedir.Exploit][MediaTickets]
127.0.0.1 www.bitreactor.net
127.0.0.1 www.ddload.net
127.0.0.1 toolbar.dworx.org #[MHTMLRedir.Exploit][MediaTickets]
127.0.0.1 edonkey2000.at
127.0.0.1 elitegate.de #[HJTH.Win32.IstBar.fa]
127.0.0.1 www.elitegate.de
127.0.0.1 www.flathousing.net
127.0.0.1 www.providersms.com
127.0.0.1 snipernet.biz
127.0.0.1 snipernet.us #[MHTMLRedir.Exploit][paretologic.com]
127.0.0.1 sxload.com #[Troj/Dloader-QG][Trojan.TrustedZone]
127.0.0.1 bar.sxload.com #[MHTMLRedir.Exploit]
127.0.0.1 www.sxload.com
127.0.0.1 tgp-devil.com #[MHTMLRedir.Exploit]
127.0.0.1 tgp-devil.net
127.0.0.1 www.tgp-devil.net
127.0.0.1 xxsware.com #[SunBelt.Xware]
# [Galina Charmandjieva]
127.0.0.1 count.cc #[TROJ_STRTPAG.AC][TROJ_STARTPAG.AG]
127.0.0.1 js.count.cc
127.0.0.1 oz.msie.tv #[Parasite.CoolWebSearch.BlankFilter]
127.0.0.1 th.msie.tv
127.0.0.1 vn.msie.tv
127.0.0.1 ewizard.cc #[Troj/AdClick-AH][TROJ_STARTPAG.LC]
127.0.0.1 c1dcon.ewizard.cc
127.0.0.1 cldcon.ewizard.cc
127.0.0.1 s12ds1.ewizard.cc #[Win32.Startpage.NS]
127.0.0.1 s13ds.ewizard.cc
127.0.0.1 s1di.ewizard.cc
127.0.0.1 searchx.cc #[CWS.Searchx][Trojan.Win32.StartPage.fw]
# [Geo Global Solutions]
127.0.0.1 allaboutvirgins.com #[hotoffers.info]
127.0.0.1 allxxxteen.com #[searchmeup.com]
127.0.0.1 www.enlargeyourpockets.com #[globolook.com]
127.0.0.1 neverseen.freeandexclusive.com #[server down?]
127.0.0.1 www.freeandexclusive.com
127.0.0.1 fullhqgalleries.com
127.0.0.1 teen.fullhqgalleries.com #[server down?]
127.0.0.1 globolook.com
127.0.0.1 adult.globolook.com
127.0.0.1 antispy.globolook.com
127.0.0.1 www.globolook.com #[MHTMLRedir.Exploit]
127.0.0.1 hotoffers.info #[MHTMLRedir.Exploit][SPYW_COOLWEB.G]
127.0.0.1 www.hotoffers.info #[Trojan.Desktophijack][TROJ_PUPER.AT]
127.0.0.1 www.loosingvirginity.com
127.0.0.1 www.lostvirginitypics.com
127.0.0.1 lust-mature.com #[server down?]
127.0.0.1 www.neverseenvirgins.com
127.0.0.1 adult.newgenlook.info #[globolook.com]
127.0.0.1 antispy.newgenlook.info #[eTrust.Win32.Warspy]
127.0.0.1 pharma.newgenlook.info
127.0.0.1 pharmacy.newgenlook.info
127.0.0.1 www.newgenlook.info #[Troj/Warspy-G]
127.0.0.1 onedayoffer.biz #[MHTMLRedir.Exploit]
127.0.0.1 www.onedayoffer.biz
127.0.0.1 www.rarevirginspics.com
127.0.0.1 specialgoods.info
127.0.0.1 adult.specialgoods.info
127.0.0.1 antispy.specialgoods.info #[Troj/Warspy-G]
127.0.0.1 pharma.specialgoods.info
127.0.0.1 pharmacy.specialgoods.info
127.0.0.1 www.specialgoods.info #[globolook.com]
127.0.0.1 wearehosters.com
127.0.0.1 www.wearehosters.com #[MHTMLRedir.Exploit]
# [GSM]
127.0.0.1 alfa-search.com #[CWS.Alfasearch]
127.0.0.1 www.alfa-search.com #[Adware.CWSAlfaSearch]
127.0.0.1 www.mommypic.com
# [huevo K]
127.0.0.1 4-counter.com #[CWS.Winproc32][Troj/StarPa-CV]
127.0.0.1 crue.4-counter.com
127.0.0.1 icanfindit.net
127.0.0.1 www.icanfindit.net #[CWS.Winproc32]
# [Henry Bison][CoolWebSearch.olehelp][TROJ_STARTPAG.BQ]
127.0.0.1 abcsearch4u.com #[PcTools.AbcSearch4u]
127.0.0.1 www.abcsearch4u.com
127.0.0.1 any-find.com
127.0.0.1 www.any-find.com
127.0.0.1 bestfind4u.com #[Trojan.StartPage.N]
127.0.0.1 www.bestfind4u.com
127.0.0.1 bizonio.com
127.0.0.1 www.bizonio.com
127.0.0.1 dorkodrom.com #[Troj/StartPa-HE]
127.0.0.1 www.dorkodrom.com
127.0.0.1 drsearch4u.com
127.0.0.1 www.drsearch4u.com
127.0.0.1 dubolom.com
127.0.0.1 www.dubolom.com
127.0.0.1 find4u.net #[CWS.IEengine]
127.0.0.1 www.find4u.net
127.0.0.1 free-spy-cam.net #[McAfee.QlowZones-25]
127.0.0.1 getthis4free.com
127.0.0.1 www.getthis4free.com
127.0.0.1 terra.hbison.com
127.0.0.1 hcworld.com
127.0.0.1 free.hcworld.com
127.0.0.1 terra.hcworld.com #[McAfee.QlowZones-25]
127.0.0.1 hotsearch4u.com
127.0.0.1 www.hotsearch4u.com
127.0.0.1 ie-searchengine.com
127.0.0.1 www.ie-searchengine.com
127.0.0.1 iesearchengine.com
127.0.0.1 www.iesearchengine.com
127.0.0.1 kloun.com
127.0.0.1 klounada.com
127.0.0.1 www.klounada.com
127.0.0.1 msfind4u.com
127.0.0.1 www.msfind4u.com
127.0.0.1 ms-find.com
127.0.0.1 my-find.com
127.0.0.1 www.my-find.com
127.0.0.1 my-finder.com #[Trojan.Regger.A]
127.0.0.1 www.my-finder.com
127.0.0.1 myfind4u.com
127.0.0.1 my-find4u.com
127.0.0.1 my-searcher.com
127.0.0.1 mssearch4u.com
127.0.0.1 mypoisk.com
127.0.0.1 mypoiskovik.com
127.0.0.1 www.mypoiskovik.com
127.0.0.1 my-search4u.com
127.0.0.1 www.my-search4u.com
127.0.0.1 partokrat.com
127.0.0.1 quick-searcher.com
127.0.0.1 top-find4u.com
127.0.0.1 www.top-find4u.com
127.0.0.1 topsearch4u.com
127.0.0.1 www.topsearch4u.com
127.0.0.1 topotun.com #[Adware.Topotun]
127.0.0.1 www.topotun.com
127.0.0.1 tropotun.com
127.0.0.1 web-cams-chat.com
127.0.0.1 w-find.com
127.0.0.1 www.w-find.com
127.0.0.1 w-find4u.com
127.0.0.1 www.w-find4u.com
127.0.0.1 wind-find.com
127.0.0.1 www.wind-find.com
127.0.0.1 wind-find4u.com
127.0.0.1 www.wind-find4u.com
127.0.0.1 windfind4u.com
127.0.0.1 www.windfind4u.com
127.0.0.1 window-find.com
127.0.0.1 www.window-find.com
127.0.0.1 windows-find.com
127.0.0.1 www.windows-find.com
127.0.0.1 windows-find4u.com #[MHTMLRedir.Exploit]
127.0.0.1 www.windows-find4u.com
127.0.0.1 windows-searchengine.com
127.0.0.1 www.windows-searchengine.com
127.0.0.1 windowssearchengine.com
127.0.0.1 www.windowssearchengine.com
127.0.0.1 your-find.com
127.0.0.1 www.your-find.com
127.0.0.1 your-finder.com
127.0.0.1 yourpoiskovik.com
127.0.0.1 www.yourpoiskovik.com
127.0.0.1 your-searcher.com #[CWS.IEengine][StartPage-DQ]
127.0.0.1 youriskalka.com
127.0.0.1 yoursearcher.com
# [Vasia Pupkin]
127.0.0.1 rapefreepics.com
127.0.0.1 www.rapefreepics.com
127.0.0.1 prolivation.com #[IE-SpyAd]
127.0.0.1 www.prolivation.com
127.0.0.1 sexyque.com
127.0.0.1 www.sexyque.com
# [Vasiliy Pupkin][Trojan.TrustedZones]
127.0.0.1 iframedollars.biz #[Trojan.Moo.B]
# [Haldex][Ivan Demidov]
127.0.0.1 2pursuit.com #[Trojan-Downloader.Win32.Delf.lh]
127.0.0.1 www.2pursuit.com #[Trojan.Stwoyle]
127.0.0.1 www2.2pursuit.com
127.0.0.1 areuhorny.com
127.0.0.1 relevantsites.net #[IE-SpyAd]
127.0.0.1 x-pearl.com
# [Hot Bookmark Ink]
127.0.0.1 0-2u.com
127.0.0.1 0-days.net
127.0.0.1 000info.com
127.0.0.1 go-advertising.com
127.0.0.1 get-access.com
127.0.0.1 go-acct.com
127.0.0.1 go-all.com
127.0.0.1 hotbookmark.com #[Troj/IEStart-F]
127.0.0.1 www.hotbookmark.com
127.0.0.1 winlink.biz
# [ICommerce Solutions][MK Digital Media][IMPRO CORPORATION]
127.0.0.1 61.131.54.618.cc #[dsmanager.dll][PcTools.Phony Search Redirector]
127.0.0.1 www.adwaredelete.com #[Downloader-ACZ][Rogue/Suspect]
127.0.0.1 antivirus-gold.com #[Trojan.Win32.TopAntiSpyware.l]
127.0.0.1 support.antivirus-gold.com
127.0.0.1 www.antivirus-gold.com #[Troj/Spyre-C][Rogue/Suspect]
127.0.0.1 becomers.com
127.0.0.1 imgs.becomers.com
127.0.0.1 www.becomers.com
127.0.0.1 best-web-search.com
127.0.0.1 www.best-web-search.com
127.0.0.1 www.bigwebfind.com
127.0.0.1 www.boom-search.com #[klikfind.com]
127.0.0.1 cameup.com #[MHTMLRedir.Exploit]
127.0.0.1 www.cameup.com
127.0.0.1 www.cannotfind.net #[Adult Search bar]
127.0.0.1 www.chart20.com #[find-help.org]
127.0.0.1 civiv.info #[itsoktosearch.net]
127.0.0.1 drugwebsearch.com
127.0.0.1 www.digimedia.com #[Wishbone.com]
127.0.0.1 ez-finder.com
127.0.0.1 www.ez-finder.com
127.0.0.1 find-help.org #[McAfee.Adware-Tolbar.dll]
127.0.0.1 www.find-help.org
127.0.0.1 f3search.com
127.0.0.1 findfreegoods.com
127.0.0.1 firstxxxsearch.com #[digimedia.com]
127.0.0.1 www.icommerce.ws #[MHTMLRedir.Exploit]
127.0.0.1 iehelp.net #[Trojan.Domcom][MHTMLRedir.Exploit]
127.0.0.1 www.iehelp.net
127.0.0.1 inet-casino.com #[becomers.com]
127.0.0.1 intelligence-search.com
127.0.0.1 imgs.itsoktosearch.net
127.0.0.1 www.itsoktosearch.net #[klikfind.com]
127.0.0.1 iwantsearch.com #[TROJ_AGENT.EX][SPYW_STARTPAGE.A]
127.0.0.1 www.iwantsearch.com #[Adware.Iwantsearch]
127.0.0.1 www.klikcash.com
127.0.0.1 klikfeed.com
127.0.0.1 xml.klikfeed.com
127.0.0.1 www.klikfeed.com
127.0.0.1 klikfind.com #[PcTools.Klikfind]
127.0.0.1 imgs.klikfind.com
127.0.0.1 www.klikfind.com
127.0.0.1 www.klikrevenue.com
127.0.0.1 www.kliksearch.com #[CWS.Aff.Toolband]
127.0.0.1 www.kliksoftware.com
127.0.0.1 look1.net
127.0.0.1 www.look1.net
127.0.0.1 www.madsearches.com #[klikfind.com]
127.0.0.1 www.mk-digital.com
127.0.0.1 manga2.com
127.0.0.1 www.manga2.com
127.0.0.1 satiristlist.com
127.0.0.1 search-com.biz
127.0.0.1 www.search-com.biz
127.0.0.1 searchemup.info
127.0.0.1 searchservices.info
127.0.0.1 www.searchservices.info
127.0.0.1 uni--search.com
127.0.0.1 www.uni--search.com
127.0.0.1 web--search.com #[McAfee.Adware-SBSoft]
127.0.0.1 yeahsearch.net
127.0.0.1 www.yeahsearch.net
127.0.0.1 www.web--search.com
# [Independet]
127.0.0.1 www.600pics.com #[Panda.SpamNet.A]
127.0.0.1 all-tgp.org
127.0.0.1 www.all-tgp.org
127.0.0.1 sex-pics.biz
# [Jan Gefferson]
127.0.0.1 evker.com #[Dropper.Agent.5.BD]
127.0.0.1 www.evker.com
# [JRC Group][Anchor Group Ltd][IDEASFORHOST.COM]
127.0.0.1 www.adult-dvdmovie.com #[JS/Relink-B][JS_RELINK.A]
127.0.0.1 www.crooder.com #[umaxsearch.com]
127.0.0.1 e-finder.cc
127.0.0.1 www.e-finder.cc #[CWS.Addclass.2][StartPage-DA]
127.0.0.1 eager-search.cc
127.0.0.1 ehttp.cc #[CWS.Addclass][TROJ_STARTPAGE.D][Spyware.CWSAddClass]
127.0.0.1 fast-look.com
127.0.0.1 www.fast-look.com
127.0.0.1 www.firecruiser.com
127.0.0.1 locator.cc #[CoolWebSearch.DOMPeek]
127.0.0.1 www.locator.cc
127.0.0.1 www.lucky-finder.com
127.0.0.1 rightfinder.net #[CWS.Addclass.2]
127.0.0.1 www.rightfinder.net #[Troj/StartPg-AY]
127.0.0.1 securitycenter.cc #[Trojan.StartPage.K]
127.0.0.1 www.securitycenter.cc
127.0.0.1 security-look.cc
127.0.0.1 www.security-look.cc #[Trojan.StartPage.F]
127.0.0.1 spyware-locator.cc
127.0.0.1 www.spyware-locator.cc
127.0.0.1 swift-look.com #[phishing exploit]
127.0.0.1 www.swift-look.com
127.0.0.1 tadstore.cc #[CWS.Addclass.2][rightfinder.net]
127.0.0.1 webcruiser.cc #[TROJ_SMALL.AFG]
127.0.0.1 www.webcruiser.cc #[Trojan.Startpage.O]
# [Maria Cossich][Guatemala]
127.0.0.1 4klm.com #[searchx.cc]
127.0.0.1 allneedsearch.net #[toolbar.cc]
127.0.0.1 cameup.net #[searchx.cc]
127.0.0.1 cannotfind.biz
127.0.0.1 fasion.biz
127.0.0.1 find-online.biz
127.0.0.1 fined.biz
127.0.0.1 himen.biz
127.0.0.1 infoglobus.info #[kklik2][searchx.cc]
127.0.0.1 praw.biz #[searchx.cc]
127.0.0.1 search-portal.biz
127.0.0.1 searchtheall.net
127.0.0.1 separtner.net
127.0.0.1 sintet.info
127.0.0.1 spetialsearch.com
127.0.0.1 testme.biz
127.0.0.1 testus.info
127.0.0.1 try4search.com
# [Pan Koudelka]
127.0.0.1 vv1.s12.dupx.cc
127.0.0.1 vv2.s12.dupx.cc
127.0.0.1 vv3.s12.dupx.cc
127.0.0.1 vv6.s12.dupx.cc
127.0.0.1 aflcub.t.muxa.cc #[vv6.i1.topx.cc][various sub-domains]
127.0.0.1 bjvvhk.t.muxa.cc #[Adware.Raxums]
127.0.0.1 cpzlcc.t.muxa.cc #[vv2.i1.topx.cc]
127.0.0.1 fzkdvi.t.muxa.cc #[vv3.i1.topx.cc]
127.0.0.1 mzyzlu.t.muxa.cc #[Troj/StartPa-CB]
127.0.0.1 pcwlrh.t.muxa.cc #[REG_STARTPAGE.R]
127.0.0.1 s13.tempx.cc
127.0.0.1 uk.s13.tempx.cc
127.0.0.1 vv1.s13.tempx.cc
127.0.0.1 vv2.s13.tempx.cc
127.0.0.1 vv3.s13.tempx.cc
127.0.0.1 vv6.s13.tempx.cc
127.0.0.1 enter.topx.cc
127.0.0.1 vv2.i1.topx.cc
127.0.0.1 vv3.i1.topx.cc
127.0.0.1 vv6.i1.topx.cc
127.0.0.1 vv2.s13.topx.cc
127.0.0.1 vv3.s13.topx.cc
127.0.0.1 vv6.s13.topx.cc
127.0.0.1 t.swapx.cc
127.0.0.1 bin.wordsx.cc #[TROJ_SAMLLAMB.A]
# [Rasta Community][Wildcard DNS]
127.0.0.1 directwebsearch.net #[TROJ_STARTPAG.IG]
127.0.0.1 dka.directwebsearch.net #[Troj/StartPa-BR]
127.0.0.1 mega.directwebsearch.net #[PcTools.WinSearchIE32]
127.0.0.1 weba.directwebsearch.net #[Parasite.CoolWebSearch/WinUpd]
127.0.0.1 www.directwebsearch.net
127.0.0.1 nakurka.org
127.0.0.1 search.smokaz.com
# [Vadim Fedorov]
127.0.0.1 www.100mature.net #[IE-SpyAd]
127.0.0.1 adult-friends-finder.net
127.0.0.1 coolsearcher.info #[CoolSearcher ToolBar]
127.0.0.1 www.coolsearcher.info
127.0.0.1 www.coolwebsearch.org
127.0.0.1 searchcomplete.com #[Adware.YellowPages]
127.0.0.1 www.searchcomplete.com
127.0.0.1 searchforge.com
127.0.0.1 www.searchforge.com
# [Ivan Leselidze]
127.0.0.1 6o9.com #[Win32.Winshow.N]
127.0.0.1 www.6o9.com
  • 0

#27
alighirl

alighirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
I'm still only about 1/4 way down the page - should I post the rest? Should I send the text file as an attachment?
  • 0

#28
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
WOW! :tazz:

Lets try this,the Hosts File log that HijackThis created,try attaching it to this post as a text file.
  • 0

#29
alighirl

alighirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
I hope I've done this properly! :tazz: Attached File  HJThosts.txt   357.68KB   307 downloads
  • 0

#30
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Completely Normal!

Ill try to contact WinHelp and Panda and get this resolved.

Just wanted to be sure there wasnt anything fishy.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP