Computer Hope

Software => Computer viruses and spyware => Virus and spyware removal => Topic started by: omgzzitsash on July 31, 2010, 03:24:32 AM

Title: trojan horse dropper.generic2.aema in AVGfree
Post by: omgzzitsash on July 31, 2010, 03:24:32 AM
AVG scanned and told me i had two threats (both said the same thing)
thanks ahead of time for your time and assistance

logs are as follows:


superantispyware:


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/31/2010 at 02:05 AM

Application Version : 4.41.1000

Core Rules Database Version : 5286
Trace Rules Database Version: 3098

Scan type       : Complete Scan
Total Scan Time : 02:15:14

Memory items scanned      : 674
Memory threats detected   : 0
Registry items scanned    : 7243
Registry threats detected : 3
File items scanned        : 122721
File threats detected     : 886

Adware.Zango/SmartShopper
   HKU\S-1-5-21-1663112170-2198310755-3143026997-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E}
   HKCR\CLSID\{4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E}

Adware.AdRotator
   HKLM\SOFTWARE\Classes\AppID\{7B6A2552-E65B-4a9e-ADD4-C45577FFD8FD}

Adware.Tracking Cookie
   .doubleclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adinterax.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .qnsr.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .qnsr.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .qnsr.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.qsstats.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.qsstats.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediaplex.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .avgtechnologies.112.2o7.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .trafficmp.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atwola.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ar.atwola.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .at.atwola.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.googleadservices.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .server.cpmstar.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .eaeacom.112.2o7.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .bannertgt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .bannertgt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .bannertgt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .content.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   adserver.adreactor.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .apmebf.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstnet.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .www.burstnet.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.burstbeacon.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstbeacon.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adserver.adtechus.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   dc.tremormedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .doubleclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adecn.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   metroleap.rotator.hadj7.adjuggler.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   metroleap.rotator.hadj7.adjuggler.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   metroleap.rotator.hadj7.adjuggler.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .videoegg.adbureau.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .imrworldwide.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .imrworldwide.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cracked.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cracked.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .dmtracker.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .yieldmanager.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .247realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.cracked.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .edgeadx.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .lucidmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .lucidmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .lucidmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .questionmarket.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .kontera.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tacoda.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .msnbc.112.2o7.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .at.atwola.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .at.atwola.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .bluestreak.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atwola.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .collective-media.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ru4.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ru4.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ru4.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .burstnet.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.burstnet.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .insightexpressai.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .lfstmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .lfstmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .lfstmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .myap.liveperson.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   wizard.liveperson.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .liveperson.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cracked.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cracked.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cracked.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cracked.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .a1.interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .a1.interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .a1.interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediadakine.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cracked.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .network.realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .casalemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   d.mediadakine.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   d.mediadakine.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   d.mediadakine.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   d.mediadakine.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   d.mediadakine.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   d.mediadakine.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .trafficmp.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .trafficmp.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .atdmt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adinterax.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .pro-market.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .pro-market.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .pro-market.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .revsci.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   5.k.i.cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   k.b.i.cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .zedo.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   0.q.i.cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .banners.socialflirt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .banners.socialflirt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .banners.socialflirt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .banners.socialflirt.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   p.g.i.cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .oasn04.247realmedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   n.v.i.cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cltomedia.info [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads7.hermoment.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads7.hermoment.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads7.hermoment.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .server.cpmstar.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adlegend.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adlegend.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ads8.hermoment.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ads7.hermoment.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .server.cpmstar.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .myroitracking.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   fidelity.rotator.hadj7.adjuggler.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   fidelity.rotator.hadj7.adjuggler.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   fidelity.rotator.hadj7.adjuggler.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   rotator.adjuggler.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   rotator.adjuggler.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   rotator.adjuggler.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .webmasterplan.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .webmasterplan.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .webmasterplan.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .bs.serving-sys.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .serving-sys.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .traffictrack.de [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adfarm1.adition.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tradedoubler.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   track.adform.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   track.adform.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ad.adnet.biz [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   eas.apm.emediate.eu [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   eas.apm.emediate.eu [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   adserver2.clipkit.de [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   eas.apm.emediate.eu [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .server.cpmstar.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .clicksor.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .xiti.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .smartadserver.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .questionmarket.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .questionmarket.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .a1.interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .a1.interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .a1.interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .a1.interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .interclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   srv.clickfuse.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .fastclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .advertising.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .mediaplex.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   optimize.indieclick.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .statcounter.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   www.googleadservices.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .adbrite.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .specificclick.net [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .media6degrees.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .content.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .invitemedia.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   .tribalfusion.com [ C:\Users\ash\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
   optimize.indieclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .mediaplex.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .mediaplex.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .doubleclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .advertising.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .advertising.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .advertising.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .advertising.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .bs.serving-sys.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .burstnet.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .advertising.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .advertising.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .at.atwola.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .247realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .247realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .iacas.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .imrworldwide.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .imrworldwide.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .chitika.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .doubleclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .dmtracker.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .iacas.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .burstnet.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .kontera.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .kontera.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .cracked.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .cracked.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adserver.adtechus.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .at.atwola.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .iacas.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .iacas.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .iacas.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .iacas.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .247realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .burstnet.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ads.bridgetrack.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .247realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .mediaplex.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .iacas.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .mediaplex.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .kontera.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .atwola.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2mdn.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .sixapart.112.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .network.realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .network.realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   optimize.indieclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .afe.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .view.atdmt.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .overture.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .overture.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   dc.tremormedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .247realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.specificmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .lfstmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .lfstmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adlegend.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .mediaforgews.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   www.cracked.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .eyewonder.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .eyewonder.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .yieldmanager.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .pro-market.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fineartteens.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .msnportal.112.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .azjmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   www8.addfreestats.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   statse.webtrendslive.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   stat.onestat.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   stat.onestat.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   stat.onestat.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   stat.onestat.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .clicksor.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-foxnewsnetworkllc.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .foxnews.112.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   adserver.adreactor.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   metroleap.rotator.hadj7.adjuggler.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   metroleap.rotator.hadj7.adjuggler.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .videoegg.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ads.bnmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .sol.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   server.iad.liveperson.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   server.iad.liveperson.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trafficmp.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgo
Title: i didn't realize that they didn't all post.
Post by: omgzzitsash on July 31, 2010, 09:11:16 PM
i didn't notice that the logs didn't post, sorry.

[recovering disk space - old attachment deleted by admin]
Title: rest of superantispyware log
Post by: omgzzitsash on August 01, 2010, 01:17:09 AM
.care2.112.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-nestleusainc.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-nestleusainc.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-nestleusainc.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   rotator.adjuggler.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   rotator.adjuggler.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   sales.liveperson.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   sales.liveperson.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   www.3dstats.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   www9.addfreestats.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   eas.apm.emediate.eu [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .timeinc.122.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   findarticles.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .findarticles.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .findarticles.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ads5.hermoment.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .server.cpmstar.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trvlnet.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trvlnet.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trvlnet.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .trvlnet.adbureau.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   eas.apm.emediate.eu [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fb-friend-stats.appspot.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fb-friend-stats.appspot.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fb-friend-stats2.appspot.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fb-friend-stats2.appspot.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .s.clickability.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .s.clickability.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-akronbeacon.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   d.mediadakine.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .mediadakine.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   d.mediadakine.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .hearstmagazines.112.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-viacom.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-viacom.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-viacom.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .lockedonmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .usnews.122.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .smartadserver.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ext-us.bestofmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .xiti.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revenue.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   optimize.indieclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adinterax.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adinterax.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .clickyoutubedownload.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .tribalfusion.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   breakmedia.checkm8.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   breakmedia.checkm8.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   breakmedia.checkm8.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   breakmedia.checkm8.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   breakmedia.checkm8.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   breakmedia.checkm8.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adecn.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adlegend.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.zanox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .afaservice.122.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .host-d.oddcast.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .host-d.oddcast.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .lfstmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .myap.liveperson.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   wizard.liveperson.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   myap.liveperson.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ehg-viacom.hitbox.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .tacoda.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .at.atwola.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .crackle.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .crackle.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .crackle.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .crackle.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .crackle.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .crackle.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .redorbit.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .redorbit.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .www.burstnet.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .burstnet.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   www.burstnet.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   www.burstbeacon.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .burstbeacon.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .oasn04.247realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .bluestreak.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .oasn04.247realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   cdn4.specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .advertising.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   gr.burstnet.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   www.cracked.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .cracked.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .cracked.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .cracked.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .edgeadx.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   data.coremetrics.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adxpose.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.doubleclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media.contextweb.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .media.contextweb.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   d.mediadakine.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.harrenmedianetwork.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.harrenmedianetwork.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.harrenmedianetwork.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .xm.xtendmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ads2.weblogssl.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   metrics.hirebridge.com.re.getclicky.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   in.getclicky.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .247realmedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   fuckyouverymuch.dk [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .fuckyouverymuch.dk [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .server.cpmstar.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .legolas-media.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .legolas-media.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .legolas-media.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .server.cpmstar.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .mtvn.112.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .intermundomedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .intermundomedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .intermundomedia.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adtechus.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .myroitracking.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .f2network.112.2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .atwola.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .2o7.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .revsci.net [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .liveperson.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   click2go.org [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .zedo.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   rev.remnantmedianetwork.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .ru4.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   *Blocked Russian URL* [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .bannertgt.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .bannertgt.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   .bannertgt.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
   www.googleadservices.com [ C:\Users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\cookies.sqlite ]
Title: MBAM log
Post by: omgzzitsash on August 01, 2010, 01:18:00 AM
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4373

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

7/31/2010 4:06:23 AM
mbam-log-2010-07-31 (04-06-23).txt

Scan type: Quick scan
Objects scanned: 127541
Time elapsed: 11 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\cscrptxt.cscrptxt (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bec0} (Adware.SmartShopper) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
C:\Program Files\ezLife\ezLife (Adware.EzLife) -> Quarantined and deleted successfully.
C:\Program Files\ezLife\ezLife\1.6.2.0 (Adware.EzLife) -> Quarantined and deleted successfully.
C:\Program Files\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
C:\Program Files\Smart-Ads-Solutions\SmartAds (Adware.SmartAds) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\ezLife\ezLife\1.6.2.0\uninstall.exe (Adware.EzLife) -> Quarantined and deleted successfully.
Title: HJT log
Post by: omgzzitsash on August 01, 2010, 01:18:37 AM
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:28:05 AM, on 7/31/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18470)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Toshiba\IVP\ISM\pinger.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Users\ash\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ash\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ash\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ash\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://apps.facebook.com/frontierville/?crt&aff=bookmarks&src=bookmark&newUser&sendkey&ref=bookmarks
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Emsisoft\Online Armor\OAui.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Google Update] "C:\Users\ash\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files\Emsisoft\Online Armor\OAcat.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Emsisoft\Online Armor\oasrv.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 9299 bytes
Title: Re: trojan horse dropper.generic2.aema in AVGfree
Post by: SuperDave on August 08, 2010, 05:30:40 PM
Hello and welcome to Computer Hope Forum. My name is Dave. Sorry for being so late in getting to your post. Everyone is especially busy. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript


Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

====================================

Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1 (http://screen317.spywareinfoforum.org/SecurityCheck.exe)
Link 2 (http://screen317.changelog.fr/SecurityCheck.exe)

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

===================================

Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

link # 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link # 2 (http://subs.geekstogo.com/ComboFix.exe)

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of security programs that should be disabled and how to disable them.

Right-click combofix.exe and select Run as Administrator and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.

Title: Re: trojan horse dropper.generic2.aema in AVGfree
Post by: omgzzitsash on August 09, 2010, 03:41:30 AM
NOTE: combo fix discovered that McAffee was still running, but i don't have McAffee on my computer to the best of my knowledge. it wasn't in the toolbar, and i looked in program files and even add/remove programs and it was nowhere to be found.


 Results of screen317's Security Check version 0.99.5 
 Windows Vista Service Pack 1 (UAC is enabled)
 Out of date service pack!! (http://support.microsoft.com/kb/935791)[/b]
 Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Disabled! 
 AVG Free 9.0   
 Online Armor 4.0   
 Antivirus up to date! 
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 CCleaner (remove only)   
 Java(TM) 6 Update 21 
 Java(TM) SE Runtime Environment 6
 Adobe Flash Player 10.0.32.18 
Adobe Reader 7.1.0
Out of date Adobe Reader installed!
 Mozilla Firefox (3.6.8)
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 AVG avgwdsvc.exe
 AVG avgtray.exe
 AVG avgrsx.exe
 AVG avgnsx.exe
 AVG avgemc.exe
 Tall Emu Online Armor OAcat.exe
````````````````````````````````
DNS Vulnerability Check:

 GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````







ComboFix 10-08-08.01 - ash 08/09/2010   4:32.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.2037.1241 [GMT -5:00]
Running from: c:\users\ash\Downloads\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
 * Created a new restore point
.

(((((((((((((((((((((((((   Files Created from 2010-07-09 to 2010-08-09  )))))))))))))))))))))))))))))))
.

2010-08-09 09:44 . 2010-08-09 09:44   --------   d-----w-   c:\users\Default\AppData\Local\temp
2010-07-31 20:26 . 2010-07-31 20:26   921440   ----a-w-   c:\programdata\avg9\update\backup\avgemc.exe
2010-07-31 20:26 . 2010-07-31 20:26   1615200   ----a-w-   c:\programdata\avg9\update\backup\avgssie.dll
2010-07-31 20:26 . 2010-07-31 20:26   1373536   ----a-w-   c:\programdata\avg9\update\backup\avgssff.dll
2010-07-31 20:26 . 2010-07-31 20:26   1107296   ----a-w-   c:\programdata\avg9\update\backup\avgxpl.dll
2010-07-31 20:26 . 2010-07-31 20:26   4368224   ----a-w-   c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-31 09:24 . 2010-07-31 09:24   388096   ----a-r-   c:\users\ash\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-31 09:18 . 2010-07-31 09:17   423656   ----a-w-   c:\windows\system32\deployJava1.dll
2010-07-31 08:53 . 2010-07-31 08:53   --------   d-----w-   c:\users\ash\AppData\Roaming\Malwarebytes
2010-07-31 08:53 . 2010-04-29 20:39   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-31 08:53 . 2010-07-31 08:53   --------   d-----w-   c:\programdata\Malwarebytes
2010-07-31 08:53 . 2010-04-29 20:39   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
2010-07-31 08:53 . 2010-07-31 08:53   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2010-07-31 08:23 . 2010-07-31 08:23   --------   d-----w-   c:\programdata\OnlineArmor
2010-07-31 08:23 . 2010-07-31 08:23   --------   d-----w-   c:\users\ash\AppData\Roaming\OnlineArmor
2010-07-31 04:34 . 2010-07-07 17:25   22600   ----a-w-   c:\windows\system32\drivers\OAmon.sys
2010-07-31 04:34 . 2010-07-07 17:25   29256   ----a-w-   c:\windows\system32\drivers\OAnet.sys
2010-07-31 04:34 . 2010-07-07 17:25   236104   ----a-w-   c:\windows\system32\drivers\OADriver.sys
2010-07-31 04:34 . 2010-07-31 04:34   --------   d-----w-   c:\program files\Emsisoft
2010-07-31 04:26 . 2010-07-31 04:48   63488   ----a-w-   c:\users\ash\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-31 04:26 . 2010-07-31 04:26   52224   ----a-w-   c:\users\ash\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-31 04:26 . 2010-07-31 04:47   117760   ----a-w-   c:\users\ash\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-31 04:26 . 2010-07-31 04:26   --------   d-----w-   c:\users\ash\AppData\Roaming\SUPERAntiSpyware.com
2010-07-31 04:26 . 2010-07-31 04:26   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2010-07-31 04:25 . 2010-07-31 04:26   --------   d-----w-   c:\program files\SUPERAntiSpyware
2010-07-31 04:05 . 2010-07-31 04:05   --------   d-----w-   C:\$AVG
2010-07-31 03:04 . 2010-07-31 03:04   12536   ----a-w-   c:\windows\system32\avgrsstx.dll
2010-07-31 03:04 . 2010-07-31 03:04   243024   ----a-w-   c:\windows\system32\drivers\avgtdix.sys
2010-07-31 03:04 . 2010-07-31 03:04   216400   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
2010-07-31 03:04 . 2010-07-31 03:04   29584   ----a-w-   c:\windows\system32\drivers\avgmfx86.sys
2010-07-31 03:04 . 2010-08-09 08:34   --------   d-----w-   c:\windows\system32\drivers\Avg
2010-07-30 22:53 . 2010-07-30 23:19   --------   d-----w-   c:\programdata\Electronic Arts
2010-07-30 21:40 . 2010-07-30 21:40   10134   ----a-r-   c:\users\ash\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2010-07-30 21:40 . 2010-07-30 21:40   --------   d-----w-   c:\program files\Microsoft WSE
2010-07-30 21:39 . 2006-09-28 21:05   2414360   ----a-w-   c:\windows\system32\d3dx9_31.dll
2010-07-30 21:23 . 2010-07-30 23:20   --------   d-----w-   c:\program files\Electronic Arts
2010-07-30 21:08 . 2010-07-30 21:10   --------   d-----w-   c:\program files\MagicDisc
2010-07-30 21:08 . 2009-02-24 23:42   116736   ----a-w-   c:\windows\system32\drivers\mcdbus.sys
2010-07-29 07:50 . 2010-07-29 07:50   --------   d-----w-   c:\program files\AVG
2010-07-29 07:49 . 2010-07-31 02:57   --------   d-----w-   c:\programdata\avg9
2010-07-29 07:45 . 2010-07-29 07:45   --------   d-----w-   c:\programdata\AIM
2010-07-29 07:45 . 2010-07-29 07:45   --------   d-----w-   c:\program files\AIM
2010-07-29 07:45 . 2010-07-29 07:45   --------   d-----w-   c:\program files\Common Files\Software Update Utility
2010-07-29 06:34 . 2010-07-30 22:13   --------   d-----w-   c:\users\ash\AppData\Roaming\BitTorrent
2010-07-29 06:34 . 2010-07-29 06:34   --------   d-----w-   c:\program files\BitTorrent
2010-07-26 08:04 . 2009-11-08 15:55   99176   ----a-w-   c:\windows\system32\PresentationHostProxy.dll
2010-07-26 08:04 . 2009-11-08 15:55   49472   ----a-w-   c:\windows\system32\netfxperf.dll
2010-07-26 08:04 . 2009-11-08 15:55   297808   ----a-w-   c:\windows\system32\mscoree.dll
2010-07-26 08:04 . 2009-11-08 15:55   295264   ----a-w-   c:\windows\system32\PresentationHost.exe
2010-07-26 08:04 . 2009-11-08 15:55   1130824   ----a-w-   c:\windows\system32\dfshim.dll
2010-07-26 08:02 . 2010-02-20 23:39   24064   ----a-w-   c:\windows\system32\nshhttp.dll
2010-07-26 08:02 . 2010-02-20 23:37   31232   ----a-w-   c:\windows\system32\httpapi.dll
2010-07-26 08:02 . 2010-02-20 21:18   411136   ----a-w-   c:\windows\system32\drivers\http.sys
2010-07-25 22:55 . 2009-12-11 12:07   301568   ----a-w-   c:\windows\system32\drivers\srv.sys
2010-07-25 22:55 . 2009-12-11 12:07   98304   ----a-w-   c:\windows\system32\drivers\srvnet.sys
2010-07-25 22:55 . 2010-01-29 16:21   738304   ----a-w-   c:\windows\system32\inetcomm.dll
2010-07-25 22:55 . 2010-02-23 11:32   212992   ----a-w-   c:\windows\system32\drivers\mrxsmb10.sys
2010-07-25 22:55 . 2010-02-23 11:32   105984   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
2010-07-25 22:55 . 2010-02-23 11:32   78848   ----a-w-   c:\windows\system32\drivers\mrxsmb20.sys
2010-07-25 22:55 . 2010-02-18 14:49   3598216   ----a-w-   c:\windows\system32\ntkrnlpa.exe
2010-07-25 22:55 . 2010-02-18 14:49   3545992   ----a-w-   c:\windows\system32\ntoskrnl.exe
2010-07-25 22:55 . 2010-04-05 16:07   67072   ----a-w-   c:\windows\system32\asycfilt.dll
2010-07-25 22:55 . 2010-03-04 18:54   430080   ----a-w-   c:\windows\system32\vbscript.dll
2010-07-25 22:33 . 2009-12-23 12:43   171520   ----a-w-   c:\windows\system32\wintrust.dll
2010-07-25 22:32 . 2010-01-15 00:04   98304   ----a-w-   c:\windows\system32\cabview.dll
2010-07-25 02:52 . 2010-07-25 02:52   --------   d-----w-   c:\users\ash\AppData\Local\BuildAGadget Content

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-06 10:18 . 2008-09-29 18:07   3220   ----a-w-   c:\users\ash\AppData\Roaming\wklnhst.dat
2010-07-31 09:19 . 2006-12-01 00:46   --------   d-----w-   c:\program files\Common Files\Java
2010-07-31 09:17 . 2006-12-01 00:46   --------   d-----w-   c:\program files\Java
2010-07-30 23:43 . 2006-12-01 00:18   --------   d--h--w-   c:\program files\InstallShield Installation Information
2010-07-29 07:44 . 2008-11-28 06:36   --------   d-----w-   c:\programdata\AOL Downloads
2010-07-29 06:02 . 2008-06-07 23:25   --------   d-----w-   c:\programdata\Viewpoint
2010-07-27 08:21 . 2009-04-14 23:06   --------   d-----w-   c:\program files\MySpace
2010-07-27 08:16 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2010-07-25 02:48 . 2009-04-11 06:35   --------   d-----w-   c:\program files\Yawcam
2010-07-25 02:44 . 2009-05-14 03:08   --------   d-----w-   c:\programdata\Skype
2010-07-25 02:31 . 2006-12-01 00:37   --------   d-----w-   c:\program files\TOSHIBA Games
2010-07-25 02:29 . 2008-09-24 15:26   --------   d-----w-   c:\program files\Canon
2010-07-25 02:29 . 2009-03-17 00:01   --------   d-----w-   c:\users\ash\AppData\Roaming\Canon
2010-07-25 02:27 . 2009-04-22 07:44   --------   d-----w-   c:\program files\Audacity
2010-07-25 02:27 . 2009-10-01 00:00   --------   d-----w-   c:\users\ash\AppData\Roaming\Amazon
2010-05-26 16:16 . 2010-07-25 22:54   34304   ----a-w-   c:\windows\system32\atmlib.dll
2010-05-26 14:25 . 2010-07-25 22:54   289792   ----a-w-   c:\windows\system32\atmfd.dll
2010-05-21 19:14 . 2009-10-02 15:45   221568   ------w-   c:\windows\system32\MpSigStub.exe
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2006-11-10 417792]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Google Update"="c:\users\ash\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-07-29 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-03 1045800]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-12-16 188416]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 413696]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-01-19 421888]
"PINGER"="c:\toshiba\IVP\ISM\pinger.exe" [2006-07-20 151552]
"NDSTray.exe"="NDSTray.exe" [BU]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 3784704]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-11-23 409264]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-11-28 52912]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2006-11-20 446128]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2006-11-29 523952]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-31 2065760]
"@OnlineArmor GUI"="c:\program files\Emsisoft\Online Armor\OAui.exe" [2010-07-07 6854984]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\users\ash\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-7-30 576000]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-7 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\Emsisoft\ONLINE~1\oaevent.dll" [2010-07-07 924488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

R2 SvcOnlineArmor;Online Armor;c:\program files\Emsisoft\Online Armor\oasrv.exe [2010-07-07 3364680]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-07-31 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-07-31 243024]
S1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2010-07-07 236104]
S1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2010-07-07 22600]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-31 921952]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-31 308136]
S2 OAcat;Online Armor Helper Service;c:\program files\Emsisoft\Online Armor\OAcat.exe [2010-07-07 1283400]
S3 OAnet;OnlineArmor Service;c:\windows\system32\DRIVERS\oanet.sys [2010-07-07 29256]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile   REG_MULTI_SZ      wcescomm rapimgr
LocalServiceRestricted   REG_MULTI_SZ      WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder

2010-08-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1663112170-2198310755-3143026997-1000Core.job
- c:\users\ash\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-29 06:47]

2010-08-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1663112170-2198310755-3143026997-1000UA.job
- c:\users\ash\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-29 06:47]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://apps.facebook.com/frontierville/?crt&aff=bookmarks&src=bookmark&newUser&sendkey&ref=bookmarks
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\ash\AppData\Roaming\Mozilla\Firefox\Profiles\zgzkgoiw.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\users\ash\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\ash\AppData\Roaming\Move Networks\plugins\npqmp071503000010.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size",  4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
HKCU-Run-ares - c:\program files\Ares\Ares.exe
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-09 04:44
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i???????2b????????8???p?????????

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-08-09  04:49:04
ComboFix-quarantined-files.txt  2010-08-09 09:48

Pre-Run: 19,909,775,360 bytes free
Post-Run: 19,019,239,424 bytes free

- - End Of File - - E6DBEBFB3CB3D40A0702480B2228DC52
Title: Re: trojan horse dropper.generic2.aema in AVGfree
Post by: SuperDave on August 09, 2010, 05:26:09 PM
Download the McAfee Consumer Product Removal Tool (http://www.majorgeeks.com/McAfee_Consumer_Product_Removal_Tool_d5420.html) to your Desktop.

Using McAfee Consumer Product Removal tool:

* Double click the MCPR.exe
* A Command Line window will be displayed, and then close automatically.
* Wait for a second Command Line window to be displayed.

Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.

* After the second window appears, the program will begin the cleanup.
* Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n]
* Press Y on the keyboard.
* Wait for the computer to restart.
* All McAfee products are now removed from your computer.
===================================

Please download the newest version of Adobe Acrobat Reader from Adobe.com (http://www.adobe.com/products/acrobat/readstep2.html)

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

==================================

P2P - I see you have P2P software installed on your machine (BitTorrent
)
. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

=====================================

You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

More information:

* ViewMgr.exe - Useless (http://www.greatis.com/appdata/u/v/viewmgr.exe.htm)
* Viewpoint to Plunge Into Adware (http://www.clickz.com/news/article.php/3561546/)

It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

* Viewpoint
* Viewpoint Manager
* Viewpoint Media Player
* Viewpoint Toolbar
* Viewpoint Experience Technology


================================

* Download the following tool: RootRepeal - Rootkit Detector (http://rootrepeal.googlepages.com/)
* Direct download link is here: RootRepeal.zip (http://rootrepeal.googlepages.com/RootRepeal.zip)

* Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
* Click this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of such programs and how to disable them.

* Extract the program file to a new folder such as C:\RootRepeal
* Run the program RootRepeal.exe and go to the REPORT tab and click on the Scan button.
* Select ALL of the checkboxes and then click OK and it will start scanning your system.
* If you have multiple drives you only need to check the C: drive or the one Windows is installed on.
* When done, click on Save Report
* Save it to the same location where you ran it from, such as C:RootRepeal
* Save it as rootrepeal.txt
* Then open that log and select all and copy/paste it back on your next reply please.
* Close RootRepeal.