HitmanPro 3.6.2.173
www.hitmanpro.com
Computer name . . . . : WINDOWS7-PC
Windows . . . . . . . : 6.1.1.7601.X86/2
User name . . . . . . : Windows7-PC\Windows 7
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (30 days left)
Scan date . . . . . . : 2012-11-08 19:33:43
Scan mode . . . . . . : Normal
Scan duration . . . . : 14m 22s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 3
Traces . . . . . . . : 126
Objects scanned . . . : 1.899.716
Files scanned . . . . : 80.069
Remnants scanned . . : 849.943 files / 969.704 keys
Malware _____________________________________________________________________
C:\Users\Windows 7\Downloads\CYPE 2012 I\CYPE 2012 I\Dlls\document.dll -> Quarantined
Size . . . . . . . : 745.472 bytes
Age . . . . . . . : 7.1 days (2012-11-01 17:27:52)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 226637A4F52BEBF78603AA89394A9397E77AF6B36C632DDEBD286C183CFC985D
> Ikarus . . . . . . : Trojan-Downloader.Win32.Delf!IK
Fuzzy . . . . . . : 107.0
C:\Users\Windows 7\Games\Unreal Tournament 3\EXTRAS\Trainer+8\Unreal Tournament 3 Trainer.exe -> Deleted
Size . . . . . . . : 444.928 bytes
Age . . . . . . . : 330.2 days (2011-12-14 14:04:32)
Entropy . . . . . : 7.8
SHA-256 . . . . . : B054DB7D4C9195440239756EC68724BA86E8476DD792252795470A250E7E32F5
Product . . . . . : Unreal Tournament Trainer 1.3
Publisher . . . . : CheatHappens
Version . . . . . : 1.3
> G Data . . . . . . : Trojan.Generic.4743412 (Engine-A)
> Ikarus . . . . . . : Virus.Win32.Trojan!IK
Fuzzy . . . . . . : 108.0
Suspicious files ____________________________________________________________
C:\Users\Windows 7\AppData\Local\PunkBuster\COD4\pb\dll\wc002258.dll
Size . . . . . . . : 956.558 bytes
Age . . . . . . . : 253.0 days (2012-02-29 18:55:22)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 567AB086A18F5447AB036192A40837C4FB9679BDB54BE2DCF99F90F4BA83BCC9
Fuzzy . . . . . . : 29.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
C:\Users\Windows 7\AppData\Local\PunkBuster\COD4\pb\dll\wc002301.dll
Size . . . . . . . : 967.213 bytes
Age . . . . . . . : 177.3 days (2012-05-15 12:35:10)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 4BD30C84D354E3B8B5236F48F62718D6E4F2A6DAA303365B6DFCE45D21DFE853
Fuzzy . . . . . . : 29.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
C:\Users\Windows 7\AppData\Local\PunkBuster\COD4\pb\dll\wc002318.dll
Size . . . . . . . : 967.165 bytes
Age . . . . . . . : 45.2 days (2012-09-24 13:47:56)
Entropy . . . . . : 7.6
SHA-256 . . . . . : B1B32990F47ED2E39EB18AEA0839D9521B87E9ED18C0BCA8E2C6873FBA9D6494
Fuzzy . . . . . . : 29.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
C:\Users\Windows 7\AppData\Local\PunkBuster\COD4\pb\pbcl.dll
Size . . . . . . . : 967.165 bytes
Age . . . . . . . : 35.9 days (2012-10-03 20:51:40)
Entropy . . . . . : 7.6
SHA-256 . . . . . : B1B32990F47ED2E39EB18AEA0839D9521B87E9ED18C0BCA8E2C6873FBA9D6494
Fuzzy . . . . . . : 29.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
C:\Users\Windows 7\AppData\Local\PunkBuster\COD4\pb\pbclold.dll
Size . . . . . . . : 967.165 bytes
Age . . . . . . . : 253.8 days (2012-02-28 23:41:18)
Entropy . . . . . : 7.6
SHA-256 . . . . . : B1B32990F47ED2E39EB18AEA0839D9521B87E9ED18C0BCA8E2C6873FBA9D6494
Fuzzy . . . . . . : 29.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
C:\Users\Windows 7\AppData\Local\PunkBuster\UNCO\pb\pbcl.dll
Size . . . . . . . : 833.236 bytes
Age . . . . . . . : 132.1 days (2012-06-29 16:34:29)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 224E58B68FE38C7B9DE702D8E970158B3DB6B0CAE3429B4903DAFC68AE60C83C
Fuzzy . . . . . . : 29.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\places.sqlite-shm
Size . . . . . . . : 6.656 bytes
Age . . . . . . . : -0.0 days (2012-11-08 19:37:23)
Entropy . . . . . : 4.4
SHA-256 . . . . . : FAECDC0DCB6EACE8130B278E2FB84B9523AB10329A00B24043B9C76867B917F0
Product . . . . . : StarForce Protection System
Publisher . . . . : Protection Technology
Description . . . : StarForce Protection Helper Driver
Version . . . . . : 2.3
Copyright . . . . : (c) Protection Technology, 2000-2005
Fuzzy . . . . . . : 50.0
The file is hidden from Windows API. This is typical for malware.
The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
Time indicates that the file appeared recently on this computer.
The file name extension of this program is not common.
The file is in use by one or more active processes.
The file is a device driver. Device drivers run as trusted (highly privileged) code.
C:\Users\Windows 7\AppData\Roaming\PnkBstrK.sys
Size . . . . . . . : 138.904 bytes
Age . . . . . . . : 253.8 days (2012-02-28 23:23:43)
Entropy . . . . . : 7.8
SHA-256 . . . . . : DA71664514D8ED17F9D550E28258F75D771B17BFD367101007F06A611E9BBF28
RSA Key Size . . . : 2048
Authenticode . . . : Valid
Fuzzy . . . . . . : 22.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program contains PE structure anomalies. This is not typical for most programs.
The file is a device driver. Device drivers run as trusted (highly privileged) code.
Program is code signed with a valid Authenticode certificate.
Malware remnants ____________________________________________________________
HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\ (Adware.MyWebSearch) -> Deleted
Potential Unwanted Programs _________________________________________________
HKU\S-1-5-21-4262662125-357226519-1601362764-1001\Software\Softonic\ (Softonic)
Cookies _____________________________________________________________________
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ad.360yield.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ad.adserver01.de
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ad.estradasdeportugal.pt
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ad.yieldmanager.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ad.zanox.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:adbrite.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:adinterax.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.ad4game.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.adk2.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.bsplayer.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.clix.pt
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.crakmedia.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.footballmedia.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.glispa.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.lzjl.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.mail3x.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.opensubtitles.org
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.pornerbros.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.pubmatic.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.trafficjunky.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.undertone.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ads.yvmads.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:adserver.zwame.pt
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:adtech.de
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:adultadworld.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:adultfriendfinder.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:advertising.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:advertstream.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:alotporn.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:apmebf.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:at.atwola.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:atdmt.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:atwola.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:bmwportugal.solution.weborama.fr
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:br.rk.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:bs.serving-sys.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:c.atdmt.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:c1.atdmt.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:casalemedia.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:clicksor.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:cnt.proporn.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:collective-media.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:content.yieldmanager.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:crazyhomesex.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:daimlerag.122.2o7.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:doubleclick.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:eaeacom.112.2o7.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:engine.phn.doublepimp.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ero-advertising.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:exoclick.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:fastclick.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:gsk.solution.weborama.fr
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:h.atdmt.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:h2porn.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:hellporno.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:hqpornlinks.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:invitemedia.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:live-cams-1.livejasmin.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:livejasmin.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:loboporno.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:media6degrees.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:mediaplex.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:microsoftsto.112.2o7.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:mm.chitika.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:msn.sexy.webcams.pt
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:myroitracking.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:new.livejasmin.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:partypoker.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:pornbongo.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:pornerbros.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:pornicom.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:pornup.me
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:proporn.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ptsexotube.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ptsexotube.sexy.easyencontro.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:revsci.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:rexona.solution.weborama.fr
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:rts.phn.doublepimp.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:ru4.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:samsung4.solution.weborama.fr
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:server.cpmstar.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:serving-sys.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:sexad.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:sexfinder.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:sexoverdose.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:smartadserver.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:specificclick.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:statcounter.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:statse.webtrendslive.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:streamate.doublepimp.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:track.adform.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:tradedoubler.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:tribalfusion.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:uniceraguasgasaguaspedras.solution.weborama.fr
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:userporn.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:viciadosnosexo.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:vodafonegroup.122.2o7.net
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:weborama.fr
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.etracker.de
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.googleadservices.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.hqpornlinks.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.pornerbros.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.pornup.me
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.proporn.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.ptsexotube.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.sexo69.org
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:www.viciadosnosexo.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:xiti.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:xxxbunker.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:yadro.ru
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:zedo.com
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:zontvcabozonnetcabo.solution.weborama.fr
C:\Users\Windows 7\AppData\Roaming\Mozilla\Firefox\Profiles\7waq89sn.default\cookies.sqlite:zontvcabozontvcabo.solution.weborama.fr