PDA

View Full Version : ad.yieldmanager



gatoramanda
2007-04-10, 22:47
Hello - I am having a fairly specific problem. I use myspace and when I view other friends profiles, my page does a reload and sends me to a google/dell search screen with the message that it cannot find page "ad.yieldmanager.com followed by some additional symbols... This is very frustrating and I have run every program that I can find. Ad-aware, spybot, ewido, panda, etc, etc... from my research I understand that this is a cookie problem...I have deleted all cookies, temp files, browser history and still have this problem...below are my logs:

Hijack this Log:

Logfile of HijackThis v1.99.1
Scan saved at 3:37:46 PM, on 4/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\regscan.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Brad%20and%20Amanda/Desktop/B/website_files/Homepage/homepage1.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://rmlsfl.MLXchange.com
O16 - DPF: {0D859AF0-C75E-11D4-B760-00E0B81077E8} (FileCruiser Class) - http://rmlsfl.mlxchange.com/Control/FileCruiser.cab
O16 - DPF: {16FD824B-8E7B-11D2-9855-00802962956C} (Specfile Control) - http://rmlsfl.mlxchange.com/Control/Specfile.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {284DAE3C-A691-11D3-AD58-00E0B8107A24} (SISCtrl Class) - http://rmlsfl.mlxchange.com/Control/SISC.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://rairc.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145971389593
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.kw.com/listings/includes/ImageUploader4.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLS Client Utils) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/MLSClientUtils.cab
O16 - DPF: {78523E50-56EB-11D3-B739-CAA1986A452F} (LiteGridCtl Class) - http://rmlsfl.mlxchange.com/Control/LiteGrid.cab
O16 - DPF: {7A7537FC-5988-11D3-8B33-00104B9E5A4A} (IRCWwwPrint Class) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCWebPrint.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCSharc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F060A272-A18A-11D3-B75B-00E0B81077E8} (DropList Class) - http://rmlsfl.mlxchange.com/Control/AspCustomCtrls.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54GSSVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe" "WMP54GSv1_1.exe (file missing)

Panda Online Log:


Incident Status Location

Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt[.azjmp.com/]
Thank you for your time...I hope I did all that you request correctly...Amanda

pskelley
2007-04-11, 01:29
Welcome to the forum, I am sorry to be the bearer of bad news, but you have a nasty trojan onboard that has no doubt severely compromised your security. Have a look:
C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
http://www.sophos.com/virusinfo/analyses/w32rbotha.html
Allows others to access the computer
Steals information
Records keystrokes
Installs itself in the Registry
Exploits system or software vulnerabilities
Used in DOS attacks

For your benefit I need to provide you with this information:
A Backdoor is a software program that gives an attacker unauthorized access to a machine and the means for remotely controlling the machine without the user's knowledge. A Backdoor compromises system integrity by making changes to the system that allow it to by used by the attacker for malicious purposes unknown to the user.

One or more of the identified infections is a backdoor trojan.
This allows hackers to remotely control your computer, steal critical system information and Download and Execute files
I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
http://www.dslreports.com/faq/10451

When Should I Format, How Should I Reinstall
http://www.dslreports.com/faq/10063

Please let us know what you have decided to do in your next post.

Thanks

gatoramanda
2007-04-11, 05:33
I downloaded sophos...but am still have the page reloading problem when i log into myspace...it is specific to that website and all the myspace pages....it seems as though I have removed the regscan.exe...but i know you stated this is not the best way to get rid of...please let me know what you think...i appreciate your help...amanda

Logfile of HijackThis v1.99.1
Scan saved at 10:22:17 PM, on 4/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
c:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Brad%20and%20Amanda/Desktop/B/website_files/Homepage/homepage1.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://rmlsfl.MLXchange.com
O16 - DPF: {0D859AF0-C75E-11D4-B760-00E0B81077E8} (FileCruiser Class) - http://rmlsfl.mlxchange.com/Control/FileCruiser.cab
O16 - DPF: {16FD824B-8E7B-11D2-9855-00802962956C} (Specfile Control) - http://rmlsfl.mlxchange.com/Control/Specfile.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {284DAE3C-A691-11D3-AD58-00E0B8107A24} (SISCtrl Class) - http://rmlsfl.mlxchange.com/Control/SISC.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://rairc.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145971389593
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.kw.com/listings/includes/ImageUploader4.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLS Client Utils) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/MLSClientUtils.cab
O16 - DPF: {78523E50-56EB-11D3-B739-CAA1986A452F} (LiteGridCtl Class) - http://rmlsfl.mlxchange.com/Control/LiteGrid.cab
O16 - DPF: {7A7537FC-5988-11D3-8B33-00104B9E5A4A} (IRCWwwPrint Class) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCWebPrint.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCSharc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F060A272-A18A-11D3-B75B-00E0B81077E8} (DropList Class) - http://rmlsfl.mlxchange.com/Control/AspCustomCtrls.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - c:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54GSSVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe" "WMP54GSv1_1.exe (file missing)

gatoramanda
2007-04-11, 06:14
I may have spoken too soon on the last post....I ran sophos anti-virus again and once again it found 2 problems (one not a major...just adware, but still I cleaned it)....the other was the trojan....well, i cleaned it again and as of right now am not having problems on the myspace site with the reloading of pages...

So...I am running sophos again just to triple check everything...just wondering if you would advise me to continue and do the reformat and reinstall....

gatoramanda
2007-04-11, 06:39
Sorry for the multiple posts...just ran sophos for the third time and came up clean...not having problems surfing on myspace....few questions:

1) should I reformat/reinstall?
2) what antivirus should i use for future?
3) where did this problem come from? was myspace the root of all evil??

I really appreciate your help and look forward to your response..
To bed ...finally!

pskelley
2007-04-11, 13:35
Hello Amanda, let me give you a little information.

1) I provided a link to information about this backdoor trojan, I could have removed it for you but I believed you needed to be aware of what the trojan was capable of. By whatever means you used to remove it, nothing changes the fact that it was there and that is why I provided you with information. The decision as to what to do about it remains yours.

2) You have Windows Live Care running on your computer, and it is supposed to provide antivirus, firewall and spyware protection, see this information:
You are running two antivirus programs at the same time and this is not a good thing. They conflict with each other and you will be less safe than if you ran one good program and maintained it properly. Uninstall one, update the one you keep and run a complete system scan, post for me any item that can't be removed, the complete name and pathway.
http://service1.symantec.com/SUPPORT/nav.nsf/docid/2000031316555206
"Microsoft recommends that you have only one anti-virus program installed on your computer."
http://www.washingtonpost.com/wp-dyn/content/article/2005/12/03/AR2005120300087.html

If you have any doubts about running two anti-virus programs I suggest you contact: http://support.microsoft.com/ for advice.

3) I suggest you review this information: http://www.pcworld.com/article/id,129933-c,onlinesecurity/articlehtml
http://www.google.com/search?hl=en&q=myspace+security+problems&btnG=Search

4)
what antivirus should i use for future? I personally only suggest freeware products, but here is the google for you:
http://www.google.com/search?hl=en&q=review+antivirus+programs&btnG=Google+Search

5) The trojan appears to have been removed, I do see some junk I believe should be removed and I think this computer also needs a good cleaning. If you wish me to proceed, resolve the issue of two anti-virus programs by uninstalling one and post to let me know that is what you want me to do. Post a new HJT log and any comments you think will help.

Thanks...Phil

gatoramanda
2007-04-11, 15:11
Hi Phil - thanks for all the great help. I have removed both windows live care and sophos. I have installed AVG free (what I had running when I got the bug...erg!) But I suppose it is the best thing out there. I have had it for years...but it didn't find this virus....which does concern me...any suggestions on that front?

Another question - I have not updated to IE7 because the program I use for my business has not fully supported it yet and it has slowed down my work...would updating to 7 have helped in not having this issue?

I appreciate your help in assisting me to continue to clean up my computer...I will be back in a couple of hours ...thanks! Any suggestions will be very helpful...

Here is my Hijack this log from this am....

Logfile of HijackThis v1.99.1
Scan saved at 8:04:17 AM, on 4/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\1137215138\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\1137215138\ee\aolsoftware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\Program Files\Grisoft\AVG7\avgw.exe
C:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Brad%20and%20Amanda/Desktop/B/website_files/Homepage/homepage1.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://rmlsfl.MLXchange.com
O16 - DPF: {0D859AF0-C75E-11D4-B760-00E0B81077E8} (FileCruiser Class) - http://rmlsfl.mlxchange.com/Control/FileCruiser.cab
O16 - DPF: {16FD824B-8E7B-11D2-9855-00802962956C} (Specfile Control) - http://rmlsfl.mlxchange.com/Control/Specfile.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {284DAE3C-A691-11D3-AD58-00E0B8107A24} (SISCtrl Class) - http://rmlsfl.mlxchange.com/Control/SISC.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://rairc.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145971389593
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.kw.com/listings/includes/ImageUploader4.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLS Client Utils) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/MLSClientUtils.cab
O16 - DPF: {78523E50-56EB-11D3-B739-CAA1986A452F} (LiteGridCtl Class) - http://rmlsfl.mlxchange.com/Control/LiteGrid.cab
O16 - DPF: {7A7537FC-5988-11D3-8B33-00104B9E5A4A} (IRCWwwPrint Class) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCWebPrint.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCSharc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F060A272-A18A-11D3-B75B-00E0B81077E8} (DropList Class) - http://rmlsfl.mlxchange.com/Control/AspCustomCtrls.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54GSSVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe" "WMP54GSv1_1.exe (file missing)

pskelley
2007-04-11, 19:59
Thanks for the feedback, I will post information before we are done from experts to help, but I strongly suggest you read all information under all tabs in the link about this trojan I posted for you. There is little chance that item came through your antivirus, they don't call them backdoors for nothing. Like all evil, it seeks the weakest point in your security to exploit. Since organized crime got involved because of the vast amounts of money, it become more and more important to leave no weaknesses, it is as easy of making a mistake and going to a bad site and waving the mouse over a banner, nothing else is necessary.

http://www.microsoft.com/windows/ie/ie6/using/howto/customizing/prsonalizehmpg.mspx
I also suggest you consider installing Internet Explorer 7 for the additional protection it affords.

You also need to update your Java program:
http://forums.spybot.info/showpost.php?p=12880&postcount=2
Then uninsall all old version in Add Remove Programs.

Let's do this for now and then you tell me how the computer is running.

Please download ATF Cleaner by Atribune
http://www.atribune.org/content/view/25/2/
Save it to your Desktop. We will use this later.

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

(unless you set the first item, check and remove it, and use the information to set your homepage, you have http://www.dell.com set right now, if you do not want that, check and remove it and set what you wish)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Brad%20and%20Amanda/Desktop/B/website_files/Homepage/homepage1.htm
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
(if you know why this is in the TZ, leave it, if not, remove it)
O15 - Trusted Zone: http://rmlsfl.MLXchange.com
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab

(you may remove any 016 item you wish, you would be prompted to install them again if you ever go to the site)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Follow the instructions in this link to download, install, update and run AVG Anti-Spyware, make sure you delete or at least quarantine anything it finds and save the scan report to post.
http://forums.security-central.us/showthread.php?t=3165

Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Restart the computer and post the scan report from AVG Anti-Spyware, a new HJT log and any comments you think will help.

Thanks

gatoramanda
2007-04-11, 22:10
my avg results came back clean - but i am having trouble providing you with a copy of that....

I am having a situation after I turn on my computer where I have a windows message state "access violation at address 00426059 in module 'WMP54GSv1_1.exe' Read of address 00000368" - I know this has to do with my wireless router...but other than that, I have no clue what to do.

I have updated IE7, Java, and followed all of the other steps...below is my HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 3:09:51 PM, on 4/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Brad%20and%20Amanda/Desktop/B/website_files/Homepage/homepage1.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0D859AF0-C75E-11D4-B760-00E0B81077E8} (FileCruiser Class) - http://rmlsfl.mlxchange.com/Control/FileCruiser.cab
O16 - DPF: {16FD824B-8E7B-11D2-9855-00802962956C} (Specfile Control) - http://rmlsfl.mlxchange.com/Control/Specfile.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {284DAE3C-A691-11D3-AD58-00E0B8107A24} (SISCtrl Class) - http://rmlsfl.mlxchange.com/Control/SISC.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://rairc.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145971389593
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.kw.com/listings/includes/ImageUploader4.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLS Client Utils) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/MLSClientUtils.cab
O16 - DPF: {78523E50-56EB-11D3-B739-CAA1986A452F} (LiteGridCtl Class) - http://rmlsfl.mlxchange.com/Control/LiteGrid.cab
O16 - DPF: {7A7537FC-5988-11D3-8B33-00104B9E5A4A} (IRCWwwPrint Class) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCWebPrint.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCSharc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F060A272-A18A-11D3-B75B-00E0B81077E8} (DropList Class) - http://rmlsfl.mlxchange.com/Control/AspCustomCtrls.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54GSSVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe" "WMP54GSv1_1.exe (file missing)

Thanks again...amanda :)

gatoramanda
2007-04-11, 22:18
I just logged onto myspace using IE7 and was redirected back to that google/dell search page with the following response:
Sorry, we couldn't find http://ad.yieldmanager.com/imp%3Fz. Here are some related websites:

pskelley
2007-04-11, 22:34
Hi Amanda, a couple of things I can see.

1) This is still in the HJT log so I assume you know why it is there:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Brad%20and%20Amanda/Desktop/B/website_files/Homepage/homepage1.htm

2) Next...I see nothing of the AVG Anti-Spyware program in this last HJT Log? You are not confusing it with your Anti-Virus program which is completely different?

3)
I am having a situation after I turn on my computer where I have a windows message state "access violation at address 00426059 in module 'WMP54GSv1_1.exe' Read of address 00000368" - I know this has to do with my wireless router...but other than that, I have no clue what to do.See this: http://forums.linksys.com/rss/message?board.id=Wireless_Routers&message.id=31020
There are three links there you can click on to see how the issue is addressed at Linksys Community Forums.
All I can suggest is you contact technical support for Linksys:
http://www.linksys.com/servlet/Satellite?c=L_CASupport_C1&childpagename=US%2FLayout&cid=1166859677881&pagename=Linksys%2FCommon%2FVisitorWrapper

Keep me posted...thanks

pskelley
2007-04-11, 22:46
Did you take the time to read all of the problems MySpace is having right now?
3) I suggest you review this information:
http://www.pcworld.com/article/id,129933-c,onlinesecurity/articlehtml
http://www.google.com/search?hl=en&q=myspace+security+problems&btnG=Search

What do you have set for your default search page?
What is this? R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Brad%20and%20Amanda/Desktop/B/website_files/Homepage/homepage1.htm

http://www.microsoft.com/windows/ie/community/columns/ie7_basics.mspx

gatoramanda
2007-04-11, 23:35
Hi Phil - my homepage is a self-designed page with links that I use often that are bolded....just a file I have on my computer....

I have read all the info on myspace - is there a way to prevent these issues other than continually running avg? Will avg even prevent these? Life is so unfair :)

Here is the AVG Anti Spyware log:

-------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 4:31:40 PM 4/11/2007

+ Scan result:



:mozilla.6:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.10:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.11:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.8:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.9:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.12:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.13:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.14:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.15:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.16:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.60:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.61:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.62:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.63:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.64:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.70:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.71:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.72:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.73:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.74:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.75:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.76:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.77:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.78:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.82:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.83:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.84:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.85:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.86:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.87:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.88:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.89:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.90:C:\Documents and Settings\Brad and Amanda\Application Data\Mozilla\Firefox\Profiles\i8upf8pd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end



New HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 4:33:43 PM, on 4/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Brad%20and%20Amanda/Desktop/B/website_files/Homepage/homepage1.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0D859AF0-C75E-11D4-B760-00E0B81077E8} (FileCruiser Class) - http://rmlsfl.mlxchange.com/Control/FileCruiser.cab
O16 - DPF: {16FD824B-8E7B-11D2-9855-00802962956C} (Specfile Control) - http://rmlsfl.mlxchange.com/Control/Specfile.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {284DAE3C-A691-11D3-AD58-00E0B8107A24} (SISCtrl Class) - http://rmlsfl.mlxchange.com/Control/SISC.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://rairc.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145971389593
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.kw.com/listings/includes/ImageUploader4.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLS Client Utils) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/MLSClientUtils.cab
O16 - DPF: {78523E50-56EB-11D3-B739-CAA1986A452F} (LiteGridCtl Class) - http://rmlsfl.mlxchange.com/Control/LiteGrid.cab
O16 - DPF: {7A7537FC-5988-11D3-8B33-00104B9E5A4A} (IRCWwwPrint Class) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCWebPrint.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://rmlsfl.mlxchange.com/3.0.01.46/Control/IRCSharc.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F060A272-A18A-11D3-B75B-00E0B81077E8} (DropList Class) - http://rmlsfl.mlxchange.com/Control/AspCustomCtrls.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54GSSVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe" "WMP54GSv1_1.exe (file missing)

pskelley
2007-04-12, 00:10
Hello Amanda, Thanks for the information about your homepage, so I can leave you alone about it:laugh:

I have read all the info on myspace - is there a way to prevent these issues other than continually running avg? Will avg even prevent these? Life is so unfair That is a question I can not answer. I have my own MySpace and I never go there because I know how compromised the site it. It is a shame but it has turned into a hunting ground for hackers. There is much $$ involved and these Russians (Ukrainians probably), Brazilians and more and more the Chinese hackers will do anything for it. I see no solution myself but to avoid the site, until and unless the site developers find a way to assure folks safety there and when Microsoft can't assure that there Operating Systems are safe, I doubt that is going to occur anytime soon.

AVG Anti-Spyware cleaned a lot of cookies and nothing else, here is some information to help contol those if you wish:
http://privacy.getnetwise.org/browsing/tools/firefox1/ffdisablecookies
http://www.mozilla.org/projects/security/pki/psm/help_21/using_priv_help.html

Your HJT log looks to be clean of malware, I suggest you do this:
System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?Open&src=sec_doc_nam

If I can do more, please let me know:)

AVG Anti-Spyware is a good program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

gatoramanda
2007-04-12, 06:48
I think I found my problem...what the heck is google afe? I deleted it and now my problems with the redirect seem to be gone right now. I also noticed this program was only on my desktop (where the problem was) and not on my laptop (clean as a whistle...hopefully!)....well, we shall see, i would like to monitor for a few more days and continue to receive your input...I really appeciate it Phil!

pskelley
2007-04-12, 14:40
Hi Amanda, anytime you have a question, always reach for your Google: http://www.google.com/
http://www.google.com/search?hl=en&q=google+afe&btnG=Google+Search
________________________________________________________

Let's have a look at your Hosts file, like this:
To view the Hosts file:
Start -> Run -> Copy the following to the box and hit enter:
C:\WINDOWS\System32\drivers\etc\HOSTS <<< copy/paste

A window opens, choose Notepad from the list and hit OK.

A notepad document opens, copy the contents to here

__________________________________________________________

I would appreciate it if you would post exactly what you did to remove that item, and anything else you think others could use. When others Google a similiar issues, they will benefit from your learning experience.

Thanks...Phil

gatoramanda
2007-04-12, 18:34
Phil - here is part 1 of my hosts file:

# This MVPS HOSTS file is a free download from: #
# http://www.mvps.org/winhelp2002/ #
# #
# Notes: the browser does not read this "#" symbol #
# You can create your own notes, after the # symbol #
# This *must* be the first line: 127.0.0.1 localhost #
# ********************************************************#
# ------------------Updated: 04-08-07---------------------#
# ********************************************************#
# Entries marked with Parasite or Trojan comments should #
# be placed in the Internet Explorer Restricted Zone. #
# http://mvps.org/winhelp2002/restricted.htm #
# #
# Entries with other comments are searchable via Google. #
# #
# Disclaimer: this file is free to use, however it is NOT #
# permitted to post on any other site without permission. #
# #
# This work is licensed under the Creative Commons #
# Attribution-NonCommercial-ShareAlike License. #
# http://creativecommons.org/licenses/by-nc-sa/2.0/ #

127.0.0.1 localhost

#start of lines added by WinHelp2002
# [Misc A - Z]
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 www.abcsearcher.com #[Spamdexing][Microsoft.Strider]
127.0.0.1 abc-search.info
127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net
127.0.0.1 b.abnad.net
127.0.0.1 c.abnad.net #[IE-SpyAd]
127.0.0.1 d.abnad.net
127.0.0.1 e.abnad.net
127.0.0.1 t.abnad.net
127.0.0.1 adv.abv.bg
127.0.0.1 bimg.abv.bg
127.0.0.1 accuserveadsystem.com
127.0.0.1 www.accuserveadsystem.com
127.0.0.1 gtcc1.acecounter.com
127.0.0.1 gtp1.acecounter.com
127.0.0.1 acestats.com
127.0.0.1 www.acestats.com
127.0.0.1 ads.active.com
127.0.0.1 am1.activemeter.com
127.0.0.1 www.activemeter.com
127.0.0.1 ads.activepower.net #[server down?]
127.0.0.1 at.ad2click.nl
127.0.0.1 cms.ad2click.nl
127.0.0.1 banner.ad.nu
127.0.0.1 ad-up.com
127.0.0.1 www.ad-up.com
127.0.0.1 adbest.com #[IE-SpyAd]
127.0.0.1 ad.adbest.com
127.0.0.1 ad.pop1.adbn.ru
127.0.0.1 www.adcipta.net #[Norman.W32/Malware]
127.0.0.1 adserv.adbonus.com #[IE-SpyAd]
127.0.0.1 www.adbonus.com
127.0.0.1 james.adbutler.de #[Tenebril.TrackingCookie]
127.0.0.1 www.adbutler.de #[SunBelt.AdButler.de]
127.0.0.1 adcp.adcentriconline.com
127.0.0.1 bell.adcentriconline.com #[Wildcard DNS]
127.0.0.1 media.adcentriconline.com #[IE-SpyAd]
127.0.0.1 adcomplete.com #[IE-SpyAd]
127.0.0.1 www.adcomplete.com
127.0.0.1 www.adcopy.info
127.0.0.1 axa.addcontrol.net #[Ewido.TrackingCookie.Addcontrol]
127.0.0.1 ads.addynamix.com #[IE-SpyAd][SpySweeper.Spy.Cookie]
127.0.0.1 e13.media.addynamix.com
127.0.0.1 ad2.adecn.com
127.0.0.1 cds.adecn.com #[p.mii.instacontent.net]
127.0.0.1 ad5.adecn.com #[SpySweeper.Spy.Cookie][IE-SpyAd]
127.0.0.1 www.adeos.eu
127.0.0.1 adcode.adengage.com
127.0.0.1 stats2.adengage.com
127.0.0.1 www.adengage.com
127.0.0.1 pt.server1.adexit.com
127.0.0.1 www.adexit.com #[IE-SpyAd]
127.0.0.1 www.ad4ever.com #[IE-SpyAd]
127.0.0.1 track.adform.net
127.0.0.1 harvest.adgardener.com
127.0.0.1 seeds.adgardener.com
127.0.0.1 www.adgroups.net
127.0.0.1 www.ad-groups.com #[Ban Man Pro Banner Code]
127.0.0.1 www.adgauge.com
127.0.0.1 host1.adhese.be #[Adhese Datamine Tag]
127.0.0.1 host2.adhese.be
127.0.0.1 host3.adhese.be #[ad.be.doubleclick.net]
127.0.0.1 host4.adhese.be
127.0.0.1 ssl3.adhost.com #[IE-SpyAd]
127.0.0.1 www2.adhost.com
127.0.0.1 ads.adhostingsolutions.com
127.0.0.1 www.adimpact.com
127.0.0.1 adfarm1.adition.com
127.0.0.1 imagesrv.adition.com
127.0.0.1 adsearch.adkontekst.pl
127.0.0.1 community.adlandpro.com #[Ad-Aware Tracking Cookie]
127.0.0.1 pk.adlandpro.com
127.0.0.1 te.adlandpro.com #[IE-SpyAd]
127.0.0.1 trafficex.adlandpro.com
127.0.0.1 www.adlandpro.com #[Ad-Aware Tracking Cookie]
127.0.0.1 engine.adland.ru
127.0.0.1 publicidad.adlead.com
127.0.0.1 ad.adlegend.com #[blocks Webroot Amber Alert]
127.0.0.1 media.adlegend.com
127.0.0.1 www.adlimg03.com
127.0.0.1 classic.adlink.de #[IE-SpyAd]
127.0.0.1 regio.adlink.de
127.0.0.1 west.adlink.de
127.0.0.1 www.adminder.com #[IE-SpyAd][SpySweeper.Spy.Cookie]
127.0.0.1 rms.admeta.com #[admeta.basefarm.net]
127.0.0.1 ad.adnet.biz
127.0.0.1 engine.adnet.ru
127.0.0.1 ad2.adnetinteractive.com
127.0.0.1 ad.adnetwork.com.br
127.0.0.1 www.adnetworkonline.com
127.0.0.1 s1.ad.adocean.pl #[Ewido.Spyware.Cookie.Adocean]
127.0.0.1 s2.ad.adocean.pl
127.0.0.1 ad01.adonspot.com #[IE-SpyAd]
127.0.0.1 ad02.adonspot.com
127.0.0.1 isohunt.adonspot.com
127.0.0.1 ab.adpro.com.ua
127.0.0.1 ac.adpro.com.ua
127.0.0.1 system.adquick.nl
127.0.0.1 www.adquest.nl
127.0.0.1 adreactor.com #[IE-SpyAd]
127.0.0.1 adserver.adreactor.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 adx.adrenaline.cz
127.0.0.1 www.adrelevance.com #[NetRatings][IE-SpyAd]
127.0.0.1 www.adsforindians.com
127.0.0.1 www.adreporting.com #[SunBelt.Adreporting.com]
127.0.0.1 gambling911.adrevolver.com
127.0.0.1 media.adrevolver.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 track.adrevolver.com #[IE-SpyAd][McAfee.Cookie-Adrevolver]
127.0.0.1 cntr.adrime.com
127.0.0.1 images.adrime.com
127.0.0.1 ad.adriver.ru
127.0.0.1 www.adrotate.net
127.0.0.1 serv.ad-rotator.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ad.ads8.com
127.0.0.1 vip.ads8.com
127.0.0.1 livelines.ads365.com #[a478.g.akamai.net]
127.0.0.1 www.ads365.com #[IE-SpyAd]
127.0.0.1 antevenio.flux.ads-click.com
127.0.0.1 ad.ads.dk #[IE-SpyAd]
127.0.0.1 tdkads.ads.dk
127.0.0.1 ads.adsag.com #[SpySweeper.Spy.Cookie]
127.0.0.1 di.adsag.com
127.0.0.1 img.adsag.com
127.0.0.1 adservercentral.com
127.0.0.1 banners.adservercentral.com
127.0.0.1 www.adservercentral.com #[SunBelt.adservercentral.com]
127.0.0.1 adservicedomain.info
127.0.0.1 adsfac.net #[Facilitate Tracking Code][IE-SpyAd]
127.0.0.1 ad-soft.net #[regfreeze.net][IE-SpyAd]
127.0.0.1 adsaway.com #[HTML/TrojanDownloader.Agent.BP trojan]
127.0.0.1 www.adsaway.com #[Google Warning]
127.0.0.1 allchix.adsmax.com
127.0.0.1 www2.adsmax.com
127.0.0.1 www.adsodainteractive.com
127.0.0.1 37.adsonar.com
127.0.0.1 ads.adsonar.com
127.0.0.1 foxnews.adsonar.com
127.0.0.1 js.adsonar.com
127.0.0.1 redir.adsonar.com
127.0.0.1 www.adspace.be
127.0.0.1 serv.adspeed.com
127.0.0.1 ads.adsponse.de
127.0.0.1 www.adsprve1.com #[IE-SpyAd]
127.0.0.1 creative.adsrevenue.net
127.0.0.1 popunder.adsrevenue.net
127.0.0.1 adserve.adster.com
127.0.0.1 images.adster.com
127.0.0.1 www.adtiger.de
127.0.0.1 adtology.com #[server down?]
127.0.0.1 adtology2.com
127.0.0.1 ad.adtoma.com
127.0.0.1 downldcl.adtoolsinc.com
127.0.0.1 www.adtoolsinc.com #[IE-SpyAd]
127.0.0.1 www.adtrade.net
127.0.0.1 www.adtrader.com #[IE-SpyAd]
127.0.0.1 netshelter.adtrix.com
127.0.0.1 advancedfind.net #[Spamdexing]
127.0.0.1 ads.advancedpcmedia.com
127.0.0.1 survey.advantageresearch.com #[IE-SpyAd]
127.0.0.1 ad.adver.com.tw
127.0.0.1 www.adventideas.com #[Adcycle]
127.0.0.1 www.adversal.com
127.0.0.1 www.adversalservers.com
127.0.0.1 austria1.adverserve.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 ads.advertise.net #[IE-SpyAd]
127.0.0.1 www.advertisingstats.com #[IE-SpyAd]
127.0.0.1 advertisingpurchase.com
127.0.0.1 ads.advertisingz.com
127.0.0.1 ad.advertstream.com
127.0.0.1 adviva.com #[IE-SpyAd]
127.0.0.1 www.adviva.com
127.0.0.1 ads.adviva.net #[IE-SpyAd]
127.0.0.1 adstats.adviva.net
127.0.0.1 ad.adworx.at
127.0.0.1 www.ad-z.de
127.0.0.1 banners.adzones.com
127.0.0.1 clicks.adzones.com
127.0.0.1 feeds.adzones.com
127.0.0.1 www.adzones.com
127.0.0.1 aeoworld.de
127.0.0.1 www.aeoworld.de #[W32/WMF-exploit]
127.0.0.1 tracker.affistats.com #[IE-SpyAd][msvrl.dll]
127.0.0.1 adz.afterdawn.net
127.0.0.1 ad.aftonbladet.se #[RealMedia]
127.0.0.1 ad.afy11.net
127.0.0.1 stats.agent.co.il
127.0.0.1 rmbannerserver.agestado.com.br
127.0.0.1 stats.agentinteractive.com
127.0.0.1 api.aggregateknowledge.com
127.0.0.1 aams1.aim4media.com
127.0.0.1 adcodes.aim4media.com
127.0.0.1 adserver.aim4media.com #[SunBelt.Adserver.aim4media]
127.0.0.1 artwork.aim4media.com
127.0.0.1 pops.aim4media.com
127.0.0.1 www.aim4media.com #[IE-SpyAd]
127.0.0.1 adlik.akavita.com
127.0.0.1 adlik2.akavita.com
127.0.0.1 adserver.akqa.net #[Ad-Aware Tracking Cookie]
127.0.0.1 download.alexa.com #[Trackware.Alexa][SPYW_ALEXA.A]
127.0.0.1 download.china.alibaba.com #[Adware.AlibabaTB][AdWare.ToolBar.Alibabar.b]
127.0.0.1 tracking.allposters.com
127.0.0.1 www.almondnetworks.com
127.0.0.1 www.almoso3h.com #[Trojan-PSW.Win32.VB.cl]
127.0.0.1 www.alsaloumainvestment.com #[Win32/SpamTool.Gadina]
127.0.0.1 ads3.alternate-url-ads.com
127.0.0.1 ad.altervista.org
127.0.0.1 marx2.altervista.org
127.0.0.1 pqwaker.altervista.org
127.0.0.1 ads.as4x.tmcs.akadns.net #[Ticketmaster][IE-SpyAd]
127.0.0.1 bantam.ai.net #[IE-SpyAd]
127.0.0.1 fiona.ai.net
127.0.0.1 adimg.alice.it
127.0.0.1 adv.alice.it
127.0.0.1 www.alldep.com #[Spamdexing]
127.0.0.1 adserver.alt.com
127.0.0.1 c0.amazingcounters.com
127.0.0.1 c1.amazingcounters.com
127.0.0.1 c2.amazingcounters.com
127.0.0.1 c3.amazingcounters.com
127.0.0.1 c4.amazingcounters.com
127.0.0.1 c5.amazingcounters.com
127.0.0.1 c6.amazingcounters.com
127.0.0.1 c7.amazingcounters.com
127.0.0.1 www.amazingcounters.com
127.0.0.1 ads.amazingmedia.com #[IE-SpyAd]
127.0.0.1 banner.ambercoastcasino.com #[IE-SpyAd]
127.0.0.1 ads.amdmb.com
127.0.0.1 advert.ananzi.co.za
127.0.0.1 advert2.ananzi.co.za
127.0.0.1 adserver.ancestry.com #[RealMedia]
127.0.0.1 adserver04.ancestry.com #[RealMedia]
127.0.0.1 www.antarasystems.com
127.0.0.1 www.anticlown.com
127.0.0.1 ads.antionline.com
127.0.0.1 junior.apk.net
127.0.0.1 www.arcadebanners.com
127.0.0.1 www.arcadebannerexchange.com
127.0.0.1 ard114.info #[Spamdexing]
127.0.0.1 demiurge.arstechnica.com
127.0.0.1 banner.arttoday.com
127.0.0.1 ads.asia1.com.sg
127.0.0.1 asimpleinternet.com #[Parasite.SpecialOffers]
127.0.0.1 www.asimpleinternet.com #[IE-SpyAd]
127.0.0.1 ads.ask.com #[sv-click.looksmart.com]
127.0.0.1 www.askyaya.com #[SunBelt.AskYaya]
127.0.0.1 ads.aspalliance.com
127.0.0.1 dist.atlas-ia.com #[ADW_ATLAST.A]
127.0.0.1 www.atlas-ia.com #[Adware.OfferAgent][Adware-Atlas]
127.0.0.1 elitegaming.ath.cx #[Adware.AdSupport]
127.0.0.1 www.elitegaming.ath.cx
127.0.0.1 audiogalaxy.com
127.0.0.1 www.audiogalaxy.com
127.0.0.1 auto-search.org #[VicMan Search]
127.0.0.1 ads.auctioncity.co.nz
127.0.0.1 www.autosurfpro.com #[IE-SpyAd]
127.0.0.1 ads.autotrader.co.za
127.0.0.1 adserving.autotrader.com #[SunBelt.AdServing.AutoTrader.com]
127.0.0.1 www.axill.com
127.0.0.1 images.axill.in
127.0.0.1 www.axill.in
127.0.0.1 axload.to #[Adware.Webprefix][Trojan.Downloader.6588.E]
127.0.0.1 valid.axload.to
127.0.0.1 www.azads.net #[IE-SpyAd]
127.0.0.1 azresults.com #[Spamdexing]
127.0.0.1 www.azresults.com
127.0.0.1 azsearch.org
# [B]
127.0.0.1 babla.info #[Spamdexing]
127.0.0.1 adserver1.backbeatmedia.com
127.0.0.1 adserver1-images.backbeatmedia.com
127.0.0.1 bullseye.backbeatmedia.com
127.0.0.1 ads.badische-zeitung.de
127.0.0.1 bar.baidu.com #[SPYW_BDPLUGIN.A][Sophos.JS/BDHelper-A]
127.0.0.1 ad.baiso.com.cn #[Trojan.Baiso][ADSPY/BaiduBar.P]
127.0.0.1 www.baltictop.com
127.0.0.1 www.banex.ca #[IE-SpyAd]
127.0.0.1 adsrv.bankrate.com
127.0.0.1 adserver.banneradministration.com
127.0.0.1 bannerboxes.com #[BannerBoxes Ad Code]
127.0.0.1 clicks.bannerboxes.com
127.0.0.1 feeds.bannerboxes.com
127.0.0.1 www.bannerboxes.com
127.0.0.1 bannerbg.com
127.0.0.1 www.banner-exchange.nl #[IE-SpyAd]
127.0.0.1 ad.bannerhost.ru
127.0.0.1 banner-ge.com
127.0.0.1 www.bannermanagement.nl #[IE-SpyAd]
127.0.0.1 www.bannerout.com
127.0.0.1 www.banneroverdrive.com
127.0.0.1 www.bannerpromotion.it #[IE-SpyAd]
127.0.0.1 www.banner-mania.com
127.0.0.1 www.bannerspace.com #[IE-SpyAd]
127.0.0.1 www3.bannerspace.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www5.bannerspace.com
127.0.0.1 www6.bannerspace.com
127.0.0.1 www7.bannerspace.com #[Tenebril.Tracking Cookie]
127.0.0.1 www.bannerswap.ca
127.0.0.1 bardownload.com
127.0.0.1 www.bardownload.com #[MHTMLRedir.Exploit][SiteAdvisor.bardownload.com]
127.0.0.1 ads.vg.basefarm.net #[RealMedia]
127.0.0.1 media.baventures.com
127.0.0.1 ads.baz.ch
127.0.0.1 www.beachtrash.com #[MHTMLRedir.Exploit]
127.0.0.1 www.belstat.be
127.0.0.1 www.belstat.com
127.0.0.1 www.belstat.nl
127.0.0.1 bestfour.com
127.0.0.1 webtrends.besite.be
127.0.0.1 www.besttoolbars.net #[ADW_TBARWIN32.A]
127.0.0.1 ads.betanews.com
127.0.0.1 download.baigoo.com #[AdWare.Win32.Baigoo.a][Trackware.Baigoo]
127.0.0.1 ads.bidclix.com #[IE-SpyAd]
127.0.0.1 www.bidclix.com
127.0.0.1 bidclix.net #[IE-SpyAd]
127.0.0.1 www.bidclix.net
127.0.0.1 ads.bidvertiser.com #[IE-SpyAd]
127.0.0.1 bdv.bidvertiser.com
127.0.0.1 www.bidvertiser.com
127.0.0.1 ad0.bigmir.net
127.0.0.1 ad1.bigmir.net
127.0.0.1 ad4.bigmir.net
127.0.0.1 ad5.bigmir.net
127.0.0.1 ad6.bigmir.net
127.0.0.1 ad7.bigmir.net
127.0.0.1 adi.bigmir.net
127.0.0.1 c.bigmir.net #[SecuritySpace.WebBug]
127.0.0.1 i.bigmir.net
127.0.0.1 bigtracker.com
127.0.0.1 bighits.net #[IE-SpyAd]
127.0.0.1 bigticker.bighits.net
127.0.0.1 bounty.bighits.net
127.0.0.1 www.bighits.net
127.0.0.1 counter.bigli.ru
127.0.0.1 download.bigwebportal.com #[IE-SpyAd]
127.0.0.1 www.bigwebportal.com #[hotwebsearch.com]
127.0.0.1 banex.bikers-engine.com
127.0.0.1 adserver.bizhat.com
127.0.0.1 counter.bizland.com
127.0.0.1 webads.bizservers.com
127.0.0.1 www.black-hole.co.uk
127.0.0.1 ads2.blastro.com
127.0.0.1 ads3.blastro.com
127.0.0.1 ads4.blastro.com
127.0.0.1 ads.blick.ch
127.0.0.1 b.blogads.com
127.0.0.1 banners.blogads.com
127.0.0.1 banners2.blogads.com
127.0.0.1 cache.blogads.com
127.0.0.1 images.blogads.com #[server down?]
127.0.0.1 images2.blogads.com
127.0.0.1 proxy.blogads.com
127.0.0.1 lg.proxy.blogads.com
127.0.0.1 stat.blogads.com #[Web Bug]
127.0.0.1 weblog.blogads.com
127.0.0.1 www.blogads.com
127.0.0.1 blogadswap.com
127.0.0.1 tracker.blogbeat.net
127.0.0.1 ads.blogdrive.com
127.0.0.1 counter.blogexplosion.com
127.0.0.1 blogtextlinks.blogexplosion.com
127.0.0.1 rentblog.blogexplosion.com
127.0.0.1 mapstats.blogflux.com
127.0.0.1 www.blogpatrol.com
127.0.0.1 pcbutts1-therealtruth.blogspot.com
127.0.0.1 blogmark.bokee.com #[Adware.BocaiToolbar]
127.0.0.1 count.blogscout.de
127.0.0.1 track.blogcounter.de
127.0.0.1 www.blogcounter.de
127.0.0.1 adserver.bluewin.ch
127.0.0.1 images.bmnq.com
127.0.0.1 ads.boardtracker.com
127.0.0.1 ranks.boardtracker.com
127.0.0.1 ad.bol.bg
127.0.0.1 adv.bol.bg
127.0.0.1 ads.bomis.com
127.0.0.1 err.boom.ru
127.0.0.1 www.borlander.cn #[Adware.Borlan]
127.0.0.1 www.borlander.com.cn #[ADSPY/Boran.X.19.C]
127.0.0.1 astalavista.box.sk #[SiteAdvisor.astalavista.box.sk]
127.0.0.1 download.bravesentry.com #[McAfee.BraveSentry]
127.0.0.1 support.bravesentry.com
127.0.0.1 www.bravesentry.com #[NOD32.Win32/Adware.SpySheriff.variant]
127.0.0.1 bans.bride.ru #[IE-SpyAd]
127.0.0.1 cc.bridgetrack.com
127.0.0.1 citi.bridgetrack.com #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 citi.bridgetrack.com.edgesuite.net
127.0.0.1 rccl.bridgetrack.com #[MVPS.Criteria]
127.0.0.1 stats.broadbandpublisher.com
127.0.0.1 admanager2.broadbandpublisher.com
127.0.0.1 banners.broadwayworld.com
127.0.0.1 www.browserplugin.com #[HJTH.EroticAccess][wobz.de]
127.0.0.1 btbilgisayarkursu.com #[Win32/TrojanDownloader.Small.AWA]
127.0.0.1 www.btbilgisayarkursu.com #[Win32/TrojanDownloader.Small.AWA]
127.0.0.1 buheradesunme.com #[Email-Worm:W32/Warezov.MG]
127.0.0.1 133.buheradesunme.com #[Win32/Stration.YK][server down?]
127.0.0.1 2849.buheradesunme.com
127.0.0.1 www.bulletads.com
127.0.0.1 redemption.bullseye-media.net
127.0.0.1 users.bullseye-media.net
127.0.0.1 www.bullseye-media.net #[IE-SpyAd]
127.0.0.1 bunnezone.com #[Win32/Jep.Russ]
127.0.0.1 www.burn4free.com #[Navexcel]
127.0.0.1 burnsrecyclinginc.com #[Win32/TrojanDropper.Agent.NBX]
127.0.0.1 www.burnsrecyclinginc.com
127.0.0.1 ad1.bustcash.com
127.0.0.1 www.buy404s.com
127.0.0.1 www.buzzclick.com

gatoramanda
2007-04-12, 18:36
# [C]
127.0.0.1 images.cashfiesta.com #[AdWare.CashFiesta.a]
127.0.0.1 www.cashfiesta.com #[McAfee.Adware-CashFiesta]
127.0.0.1 www.cashfiesta.net
127.0.0.1 www.cashventure.com
127.0.0.1 ads.casino.com
127.0.0.1 out.catchonlife.com #[lootseek.com]
127.0.0.1 ad.caradisiac.com
127.0.0.1 ads.cars.com
127.0.0.1 www.cd321.com
127.0.0.1 ads.cdfreaks.com #[eTrust.Ads.cdfreaks]
127.0.0.1 ads.cdrinfo.com
127.0.0.1 stats.cdrinfo.com #[WebBug]
127.0.0.1 www.celebritypicturesarchive.com #[Trojan-Downloader.Win32.IstBar.nn]
127.0.0.1 www.celebrity-pictures-world.com #[Trojan-Downloader.Win32.IstBar.nn]
127.0.0.1 mds.centrport.net #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 adserver.cducinema.com
127.0.0.1 tracker.cgiworld.net
127.0.0.1 abc.checkm8.com
127.0.0.1 rmm1u.checkm8.com
127.0.0.1 web.checkm8.com #[CHECKM8 AD TAGS]
127.0.0.1 ads.checkm8.co.za
127.0.0.1 ads.chellomedia.com
127.0.0.1 www.china-abc.cn #[TR/Proxy.VB.W]
127.0.0.1 ad.chip.de
127.0.0.1 www.chsniper.com #[Downloader.Sniper]
127.0.0.1 ad.cibleclick.com #[eTrust.Cibleclick]
127.0.0.1 www.cibleclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 board.classifieds1000.com
127.0.0.1 xp.classifieds1000.com
127.0.0.1 www.classifieds1000.com #[SiteAdvisor.classifieds1000.com]
127.0.0.1 images.clckm.com
127.0.0.1 pics.clckm.com #[Parking Service]
127.0.0.1 cleansearch.info #[Spamdexing]
127.0.0.1 clearfind.com
127.0.0.1 www.clearfind.com #[IE-SpyAd]
127.0.0.1 ads.clickad.com #[eTrust.Tracking Cookie]
127.0.0.1 clickbank.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 hop.clickbank.net #[Adware.Clickbank][Adware.ClickDLoader]
127.0.0.1 ssl.clickbank.net
127.0.0.1 zzz.clickbank.net #[Ewido.TrackingCookie.Clickbank]
127.0.0.1 publishers.clickbooth.com #[directleads.com]
127.0.0.1 clickboothlnk.com
127.0.0.1 www.clickboothlnk.com
127.0.0.1 j.clickdensity.com
127.0.0.1 r.clickdensity.com
127.0.0.1 dsml.clickexperts.net
127.0.0.1 www.clicks2you.com #[IE-SpyAd]
127.0.0.1 clicktopsite.com #[Spamdexing][server down?]
127.0.0.1 clicktracks.com #[McAfee.Cookie-Clicktracks]
127.0.0.1 stats.clicktracks.com #[Tenebril.Tracking Cookie]
127.0.0.1 stats1.clicktracks.com # [eTrust.Tracking Cookie]
127.0.0.1 stats2.clicktracks.com #[SpySweeper.Spy.Cookie]
127.0.0.1 stats3.clicktracks.com
127.0.0.1 stats4.clicktracks.com
127.0.0.1 www.clicktracks.com #[IE-SpyAd][SunBelt.ClickTracks]
127.0.0.1 www.is1.clixgalore.com
127.0.0.1 www.clixgalore.com #[IE-SpyAd]
127.0.0.1 www2.click-fr.com
127.0.0.1 www3.click-fr.com
127.0.0.1 www4.click-fr.com
127.0.0.1 www.clickhouse.com #[IE-SpyAd][SunBelt.ClickHouse]
127.0.0.1 www.click-power.com #[Win32/TrojanDownloader.VB.JL][Win32.Virtumonde.by]
127.0.0.1 www.clicks4u.com #[IE-SpyAd]
127.0.0.1 www.clicksbroker.com
127.0.0.1 ad1.clickhype.com #[IE-SpyAd][Ewido.TrackingCookie.Clickhype]
127.0.0.1 redirect.clickshield.net
127.0.0.1 clickthru.net
127.0.0.1 ads.clickthru.net
127.0.0.1 icon.clickthru.net
127.0.0.1 clicktorrent.info
127.0.0.1 static.clicktorrent.info
127.0.0.1 www.clicktorrent.info #[phpAds]
127.0.0.1 www1.clicktorrent.info
127.0.0.1 norbert_sirot.club.fr #[Trojan-Spy.Win32.Banker.anv]
127.0.0.1 banner.clubdicecasino.com
127.0.0.1 adserver.clix.pt
127.0.0.1 www.cnstats.com
127.0.0.1 s12.cnzz.com
127.0.0.1 ads.cobrad.com
127.0.0.1 admanager3.collegepublisher.com
127.0.0.1 localads.collegepublisher.com
127.0.0.1 www.combimedia.nl
127.0.0.1 bdx.comclick.com
127.0.0.1 br.comclick.com
127.0.0.1 ct2.comclick.com #[Tenebril.Tracking Cookie]
127.0.0.1 fl01.ct2.comclick.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 ihm01.ct2.comclick.com
127.0.0.1 www.comclick.com #[Ewido.TrackingCookie.Comclick]
127.0.0.1 aa.connextra.com
127.0.0.1 bb.connextra.com #[a22.g.akamai.net]
127.0.0.1 cc.connextra.com
127.0.0.1 dd.connextra.com
127.0.0.1 ee.connextra.com
127.0.0.1 ff.connextra.com #[a22.g.akamai.net]
127.0.0.1 data.connextra.com
127.0.0.1 linkexchange.consoleunderground.com
127.0.0.1 www.consoleunderground.com #[Adware.Begin2search]
127.0.0.1 ads.consumeraffairs.com
127.0.0.1 ads.contactmusic.com #[advertpro]
127.0.0.1 svp.contextuad.org #[IE-SpyAd]
127.0.0.1 www.contextualclick.com #[Dynamic keywords analyser]
127.0.0.1 ads.console.net
127.0.0.1 banners.copyscape.com
127.0.0.1 www.countit.ch
127.0.0.1 www.counter-gratis.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.countercentral.com
127.0.0.1 www.counterguide.com
127.0.0.1 counter4u.de #[IE-SpyAd]
127.0.0.1 www.counting4free.com #[IE-SpyAd]
127.0.0.1 www.countmypage.com
127.0.0.1 log1.countomat.com #[IE-SpyAd]
127.0.0.1 connectionzone.com
127.0.0.1 www.couponsandoffers.com #[Adware.TopMoxie]
127.0.0.1 data.coremetrics.com #[IE-SpyAd]
127.0.0.1 test.coremetrics.com #[SpySweeper.Spy.Cookie]
127.0.0.1 twci.coremetrics.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 banner.coza.com
127.0.0.1 server.cpmstar.com #[ads.shizmoo.com]
127.0.0.1 1.cq158.cn #[Win32/Agent.NAW]
127.0.0.1 cracks.am #[eTrust.Cracks.am][ADW_CRAMTB.A]
127.0.0.1 www.cracks.am #[fuck-portal.com][Adware.CramToolbar]
127.0.0.1 ads.cracked.com
127.0.0.1 track.cracked.com
127.0.0.1 www.crackserver.com #[StopBadware.Report]
127.0.0.1 new.crashextads.co.uk
127.0.0.1 crawl.ws
127.0.0.1 cont.crawl.ws #[AdWare.Win32.MegaKiss.b]
127.0.0.1 www.crawl.ws
127.0.0.1 counter.credo.ru
127.0.0.1 www.cridem.org #[Win32/Spy.Banker.AHY]
127.0.0.1 www.crispads.com #[IE-SpyAd]
127.0.0.1 ads.crosswinds.net
127.0.0.1 megabyte.crosswinds.net
127.0.0.1 ads.crucialparadigm.com
127.0.0.1 www.cucush.info #[Spamdexing][server down?]
127.0.0.1 cyberbounty.com #[IE-SpyAd]
127.0.0.1 js.cybermonitor.com #[McAfee.Cookie-Cybermonitor]
127.0.0.1 stat3.cybermonitor.com
127.0.0.1 banner.cybertechdev.com
127.0.0.1 search.cygo.net
127.0.0.1 www.cygo.net #[McAfee.Adware-Cygo]
127.0.0.1 cytron.com #[DailyWinner][eTrust.Cytron]
127.0.0.1 www.cytron.com
# [D]
127.0.0.1 mm.dalumm.com #[Win32/TrojanDownloader.Small.TZ]
127.0.0.1 www.data-jpn.com #[Trojan.Pajatan]
127.0.0.1 banner.date.com #[Tenebril.Tracking Cookie]
127.0.0.1 www.dateclix.com #[DateClix.com Banner Exchange Code]
127.0.0.1 datingbanners.net
127.0.0.1 ads.datinggold.com
127.0.0.1 ad.db3nf.com
127.0.0.1 deansplanet.com #[Zango]
127.0.0.1 au.track.decideinteractive.com
127.0.0.1 au.link.decideinteractive.com
127.0.0.1 eu.link.decideinteractive.com
127.0.0.1 link.decideinteractive.com
127.0.0.1 www.decideinteractive.com
127.0.0.1 www.decideinteractive.co.uk
127.0.0.1 deepcom.com #[SiteAdvisor.deepcom.com]
127.0.0.1 www.deepcom.com #[TrojanDropper.Win32.Small.gt]
127.0.0.1 collector.deepmetrix.com
127.0.0.1 geo.deepmetrix.com
127.0.0.1 www.deepmetrix.com #[Microsoft]
127.0.0.1 ads.dennisnet.co.uk
127.0.0.1 ad.detik.com
127.0.0.1 desire-search.com #[Spamdexing]
127.0.0.1 ads.deviantart.com
127.0.0.1 phpadsnew.devstart.com
127.0.0.1 dgdg567.com #[Win32/PSW.Legendmir]
127.0.0.1 banners.diariodelaltoaragon.es
127.0.0.1 track.did-it.com #[Panda.Spyware:Cookie/did-it]
127.0.0.1 www.digink.com #[PcTools.SysCheckBop32]
127.0.0.1 ads.digitalpoint.com
127.0.0.1 geo.digitalpoint.com
127.0.0.1 hk.digitaltrends.com
127.0.0.1 comm1.digits.com
127.0.0.1 counter.digits.com #[IE-SpyAd]
127.0.0.1 ads.dir.bg
127.0.0.1 banners.dir.bg
127.0.0.1 direct-ip.com #[Adware-DirectIP][SecurityRisk.DirectIP]
127.0.0.1 www.direct-ip.com #[Adware-DirectIP][Adware-CommanderNET]
127.0.0.1 ad.directconnect.se
127.0.0.1 banners.directnic.com #[SecuritySpace.WebBug][MVPS.Criteria]
127.0.0.1 dnads.directnic.com
127.0.0.1 parked.directnic.com
127.0.0.1 stats.directnic.com
127.0.0.1 www.directnicparking.com
127.0.0.1 www.directoryofads.com
127.0.0.1 cache.directorym.com #[c2.mii.instacontent.net]
127.0.0.1 ads.directnetadvertising.net
127.0.0.1 www.directnetadvertising.net #[Ad-Aware Tracking Cookie]
127.0.0.1 ad.displayadsmedia.com
127.0.0.1 agentq.ditto.com
127.0.0.1 js.ditto.com
127.0.0.1 matrix.ditto.com
127.0.0.1 media.ditto.com #[a232.x.akamai.net]
127.0.0.1 www.ditto.com #[AdWare.Win32.Softomate.c]
127.0.0.1 dcww.dmcast.com #[Adware-DesktopMedia]
127.0.0.1 dmdl.dmcast.com
127.0.0.1 install.dmcast.com #[Adware-DesktopMedia.dr]
127.0.0.1 track.dmipartners.com
127.0.0.1 ads.dmnews.com
127.0.0.1 ad.dmpi.net
127.0.0.1 ad2.dmpi.net
127.0.0.1 ad3.dmpi.net
127.0.0.1 ad4.dmpi.net
127.0.0.1 ubnm.dmpi.net
127.0.0.1 www.dnscaching.net #[stickypops.com]
127.0.0.1 www.domamil.cz #[Trojan.Beagooz]
127.0.0.1 www.dodostats.com
127.0.0.1 doorgen.com #[Spamdexing]
127.0.0.1 www.doorgen.com
127.0.0.1 ads.dotomi.com
127.0.0.1 www.donotchangeme.com
127.0.0.1 www.download-services.com #[VBA32.Trojan-Downloader.Agent.26]
127.0.0.1 www.downseek.com #[SunBelt.DownSeek Search]
127.0.0.1 banners.dpnet.com.br
127.0.0.1 drmx01.net #[spam]
127.0.0.1 counter.dreamhost.com
127.0.0.1 www.claus.drehteile-rieche.de #[Win32.Formglieder.B]
127.0.0.1 www.dreamadvert.com #[SunBelt.Dreamadvert]
127.0.0.1 www.dropthehammer.com #[Win32/Spy.Banker.AHY]
127.0.0.1 ads.drugs.com
127.0.0.1 b.ds1.nl
127.0.0.1 ddd.dudu.com #[Tenebril.DuDu Accelerator]
127.0.0.1 ulink4.dudu.com #[Adware.DDDClient][SunBelt.DuDuAccelerator]
127.0.0.1 ulink13.dudu.com #[Win32/Adware.DM]
127.0.0.1 www.dudu.com #[McAfee.Downloader-AVV]
127.0.0.1 www.duenow.com
127.0.0.1 www.dutty.de #[W32.Peerload.A]
127.0.0.1 gfx.dvlabs.com #[IE-SpyAd]
127.0.0.1 klipads.dvlabs.com
# [E]
127.0.0.1 e2give.com #[Adware-E2Give][Spyware.e2give]
127.0.0.1 www.e2give.com
127.0.0.1 hits.e.cl
127.0.0.1 blogads.ebanner.nl
127.0.0.1 www.e-bannerx.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.earncashontheinternet.com #[SunBelt.OpinionBar]
127.0.0.1 www.eash.info #[Spamdexing][Microsoft.Strider]
127.0.0.1 click.easilyfound.com #[Tenebril.AdTraffic]
127.0.0.1 www.easilyfound.com
127.0.0.1 www.eastworldnetwork.com
127.0.0.1 www.easycounter.com #[IE-SpyAd]
127.0.0.1 banners.easydns.com
127.0.0.1 easyerror.info #[Trojan-Downloader.Win32.Delf.agw]
127.0.0.1 easyhitcounters.com #[IE-SpyAd]
127.0.0.1 beta.easyhitcounters.com
127.0.0.1 banner.easyspace.com #[IE-SpyAd]
127.0.0.1 easy-web-stats.com
127.0.0.1 adserv1.ebates.com #[WebSavings]
127.0.0.1 mailer.ebates.com
127.0.0.1 www.ebates.com #[Adware.MoeMoney]
127.0.0.1 ads.eccentrix.com
127.0.0.1 ads.ecrush.com #[AdvertPro]
127.0.0.1 www.eden21.net #[Win32/Haxdoor][TR/Dldr.Botol.D.1]
127.0.0.1 c6.edgesuite.net #[RealMedia]
127.0.0.1 ads.edirectme.com
127.0.0.1 www.ejmx.com #[Adware.ElectroJMX]
127.0.0.1 www.ek21.com #[Trojan.Chost.B]
127.0.0.1 www.elancenet.org #[Worm/Eyeveg.CH]
127.0.0.1 now.eloqua.com #[WebBug]
127.0.0.1 ads.eluniversal.com.mx
127.0.0.1 hits.eluniversal.com.mx
127.0.0.1 publicidad.eluniversal.com.mx
127.0.0.1 ad1.emediate.dk
127.0.0.1 www.emoinstaller.com #[Win32/Adware.NdotNet][SiteAdvisor.emoinstaller.com]
127.0.0.1 www.emusic.com #[McAfee.Adware-eMusic][F-Secure.Adware.eMusic]
127.0.0.1 dotnet.endai.com
127.0.0.1 entk.net
127.0.0.1 ads.eog.com
127.0.0.1 ads.e-planning.net
127.0.0.1 ads.us.e-planning.net
127.0.0.1 adserving00.epi.es
127.0.0.1 adserving02.epi.es
127.0.0.1 adserving03.epi.es
127.0.0.1 launcheruk.escritorioactivo.com
127.0.0.1 vipuk.escritorioactivo.com #[HJTH.123Messenger Hijacker]
127.0.0.1 www.escorcher.com #[IE-SpyAd]
127.0.0.1 www.eshopads2.com
127.0.0.1 estat.com #[IE-SpyAd]
127.0.0.1 perso.estat.com #[Ewido.Spyware.Cookie.Estat]
127.0.0.1 prof.estat.com #[SecuritySpace.WebBug]
127.0.0.1 www.estat.com
127.0.0.1 gtb.etology.com
127.0.0.1 pages.etology.com
127.0.0.1 www.etracker.de
127.0.0.1 www.etxh.com #[Win32/Prosti.C]
127.0.0.1 ads.ero-advertising.com
127.0.0.1 adopt.euroclick.com #[Ewido.TrackingCookie.Euroclick]
127.0.0.1 cdn.euroclick.com
127.0.0.1 www.euroklik.nl #[EasyBar][HJTH.SinCity Dialer]
127.0.0.1 advert.eurotip.cz
127.0.0.1 www.euros4click.de
127.0.0.1 ad.eurosport.com #[oas.eurosport.com]
127.0.0.1 www.eurowebstats.com
127.0.0.1 www.everestpoker.com #[AdWare.Win32.Casino.t]
127.0.0.1 engage.everyone.net
127.0.0.1 ezcybersearch.mail.everyone.net
127.0.0.1 advert.exaccess.ru
127.0.0.1 dynamic.exaccess.ru #[IE-SpyAd]
127.0.0.1 static.exaccess.ru
127.0.0.1 www.exchangead.com #[IE-SpyAd]
127.0.0.1 exchange.bg
127.0.0.1 www.exchange.bg
127.0.0.1 exit-ad.de #[Ad-Aware.Tracking Cookie]
127.0.0.1 exitexchange.com #[IE-SpyAd][SiteAdvisor.exitexchange.com]
127.0.0.1 count.exitexchange.com #[McAfee.Cookie-Exitexchange]
127.0.0.1 images.exitexchange.com
127.0.0.1 www.exitexchange.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.exittrade.com
127.0.0.1 www.exittraffic.net #[IE-SpyAd]
127.0.0.1 syndication.exoclick.com
127.0.0.1 nyton.experclick.com #[p.mii.instacontent.net]
127.0.0.1 www.experclick.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ads.expressindia.com
127.0.0.1 banners.expressindia.com
127.0.0.1 cdn.eyewonder.com #[IE-SpyAd][SunBelt.EyeWonder]
127.0.0.1 pixel1097.everesttech.net
127.0.0.1 pixel1370.everesttech.net
127.0.0.1 www.evidence-eliminator.com
127.0.0.1 www.eyeget.com #[McAfee.Adware-EyeGet]
127.0.0.1 ads.ezboard.com
127.0.0.1 eziin.com #[Adware.Eziin][server down?]
127.0.0.1 www.eziin.com
127.0.0.1 www.ezurl.co.kr #[Spyware.Ezurl]

gatoramanda
2007-04-12, 18:38
# [F]
127.0.0.1 ads.facebook.com #[facebook-ads.vo.llnwd.net]
127.0.0.1 www.factorygames.com #[SiteAdvisor.factorygames.com]
127.0.0.1 www.fast-adv.it
127.0.0.1 www.fast2net.com
127.0.0.1 www.fastfind.org #[TROJ_STARTPAG.KF][Win32/Adware.MediaBack]
127.0.0.1 fastonlineusers.com
127.0.0.1 ads.fastpay.ro
127.0.0.1 fasttrack.nu
127.0.0.1 fastwebcounter.com
127.0.0.1 counter.fateback.com
127.0.0.1 www.fatpickle.com #[FatPickle Toolbar][IE-SpyAd]
127.0.0.1 alex.fileburst.com #[Win32/TrojanDropper.Agent.NBT]
127.0.0.1 adserver.filefront.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 findover.org #[Spamdexing]
127.0.0.1 search.findscout.com
127.0.0.1 www.findscout.com #[W32/Delf.KPZ]
127.0.0.1 ai.p.findology.com
127.0.0.1 banner.finn.no
127.0.0.1 ads.firingsquad.com
127.0.0.1 ads2.firingsquad.com
127.0.0.1 ads.firstgrand.com
127.0.0.1 firstname.com #[IE-SpyAd]
127.0.0.1 clicks.firstname.com
127.0.0.1 firstwolf.org #[Downloader-BAC]
127.0.0.1 fishclix.com
127.0.0.1 www.fishclix.com
127.0.0.1 www.fish-screensaver.com #[AdWare.Win32.Gator.1008]
127.0.0.1 www.fjordbergen.com #[Win32/Spy.Banker.BIG]
127.0.0.1 www.fjjyjy.net #[Win32/Hipigon][W32.Fijjy]
127.0.0.1 flyinads.com #[IE-SpyAd]
127.0.0.1 www.flyinads.com
127.0.0.1 cdn.flashedmail.com #[Parked?]
127.0.0.1 tracker1.flashedmail.com #[IE-SpyAd]
127.0.0.1 adserver.fmpub.net
127.0.0.1 dynamic.fmpub.net
127.0.0.1 static.fmpub.net
127.0.0.1 www.foofle.net #[Backdoor.Foobot]
127.0.0.1 adcycle.footymad.net
127.0.0.1 js.forrestersurveys.com
127.0.0.1 socratos.forrestersurveys.com
127.0.0.1 akcr.free.fr #[Win32/Spy.Bancos.U]
127.0.0.1 ad.freecity.de
127.0.0.1 ads05.freecity.de
127.0.0.1 freecounters.xp.tl
127.0.0.1 www.freecounter.it
127.0.0.1 securinews.free.fr #[Trojan.Hexem]
127.0.0.1 www.freedownloadhq.com #[SiteAdvisor.freedownloadhq.com]
127.0.0.1 ad.freefind.com
127.0.0.1 www.freehitwebcounters.com
127.0.0.1 adverts.freeloader.com
127.0.0.1 freelogs.com
127.0.0.1 bar.freelogs.com
127.0.0.1 goo.freelogs.com
127.0.0.1 htm.freelogs.com
127.0.0.1 ico.freelogs.com
127.0.0.1 joe.freelogs.com
127.0.0.1 mom.freelogs.com
127.0.0.1 xyz.freelogs.com
127.0.0.1 adserver.freenet.de
127.0.0.1 freeonlineusers.com
127.0.0.1 free-stats.com
127.0.0.1 insurancejournal.freestats.com
127.0.0.1 www.freestat.ws
127.0.0.1 www.freestats.ws
127.0.0.1 banners.freett.com
127.0.0.1 count.freett.com
127.0.0.1 counters.freewebs.com
127.0.0.1 ads.freeonlinegames.com
127.0.0.1 stats.freeonlinegames.com
127.0.0.1 error.freewebsites.com
127.0.0.1 www.freewebsites.com
127.0.0.1 media.ftv-publicite.fr #[RealMedia]
127.0.0.1 full-search.biz #[McAfee.StartPage-FC][MHTMLRedir.Exploit]
127.0.0.1 www.fullddl.com #[HTML/TrojanDownloader.XXXToolbar]
127.0.0.1 funppc.com #[IE-SpyAd]
127.0.0.1 www.funppc.com
127.0.0.1 ads.futurenetworkusa.com
# [G]
127.0.0.1 adserver.gadu-gadu.pl
127.0.0.1 www.gamersbanner.com
127.0.0.1 gamesbanner.net
127.0.0.1 www.gamesbanner.net
127.0.0.1 ads.gameservers.com
127.0.0.1 ads.gamespy.com #[SpySweeper.Spy.Cookie]
127.0.0.1 adcontent.gamespy.com
127.0.0.1 ads.gamespyid.com
127.0.0.1 server.gamyun.net
127.0.0.1 www.gamyun.net #[Adware.GamyunIeToolbar]
127.0.0.1 ads.gather.com
127.0.0.1 js.gbeb.cc #[Javascript.Exploit]
127.0.0.1 haymarket-adserver.gcnpublishing.com
127.0.0.1 www.gebr-wachs.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 sda.geek.com #[AdvertPro]
127.0.0.1 adserver.geenstijl.nl
127.0.0.1 kassa.geenstijl.nl
127.0.0.1 gd.geobytes.com #[obtains users location]
127.0.0.1 geotarget.info #[Whois.Blacklisted]
127.0.0.1 banners.geotarget.info
127.0.0.1 www.geotarget.info
127.0.0.1 www.geowhere.net #[SunBelt.GeoWhere Search]
127.0.0.1 get-access.host.sk #[McAfee.StartPage-IR]
127.0.0.1 getclicky.com
127.0.0.1 www.getmusicvideocodes.com #[Zango]
127.0.0.1 www.getsmart.com
127.0.0.1 dlx.getupdate.com #[AdvWare.ToolBar.VB.b][Adware.Getup]
127.0.0.1 banner.giantvegas.com
127.0.0.1 truehits1.gits.net.th
127.0.0.1 ads.globo.com
127.0.0.1 duke.gocomics.com #[ads.uclick.com]
127.0.0.1 www.god74.com #[Trojan.Huanux]
127.0.0.1 www.godesktop.com #[SiteAdvisor.godesktop.com]
127.0.0.1 adserver2.goals365.com
127.0.0.1 www.go-and-search.com #[Spamdexing]
127.0.0.1 goglee.biz
127.0.0.1 www.goglee.biz
127.0.0.1 golden-keys.net #[Spamdexing]
127.0.0.1 banner.goldenpalace.com #[Tenebril.Tracking Cookie]
127.0.0.1 stage.goldkey.com #[Parking Service]
127.0.0.1 goldstats.net #[IE-SpyAd]
127.0.0.1 www.goldstats.net
127.0.0.1 www.goodhealth-search.com #[Spamdexing]
127.0.0.1 www.qooqlesearch.com #[Spamdexing]
127.0.0.1 www.goggle.com #[IE-SpyAd][typo squatter]
127.0.0.1 show.googleadsenseagent.com #[Adware.Roogoo]
127.0.0.1 google-pharmacy.com #[Spamdexing]
127.0.0.1 goooglegulp.com #[Spamdexing]
127.0.0.1 www.gogogo.com #[PremiumTraffic.Parking Service]
127.0.0.1 partner.gonamic.de
127.0.0.1 www.goodsearchnow.com #[Trojan.Jakposh]
127.0.0.1 googlelink.us #[Win32/PSW.LegendMir]
127.0.0.1 adincl.gopher.com #[InfoSpace]
127.0.0.1 go-pic.com #[Trojan-Downloader.Win32.Delf.arx]
127.0.0.1 goserv.com #[Koffix Blocker][MHTMLRedir.Exploit]
127.0.0.1 stat.org.gosite.ws
127.0.0.1 gostats.com #[IE-SpyAd]
127.0.0.1 as.gostats.com
127.0.0.1 c1.gostats.com
127.0.0.1 c2.gostats.com #[SpySweeper.Spy.Cookie]
127.0.0.1 c3.gostats.com
127.0.0.1 c4.gostats.com #[Panda.Spyware:Cookie/GoStats]
127.0.0.1 ded.gostats.com
127.0.0.1 monster.gostats.com
127.0.0.1 webcounter.goweb.de #[IE-SpyAd]
127.0.0.1 ads.goyk.com
127.0.0.1 www.graffitifonts.com #[Zango]
127.0.0.1 graficastrigo.com #[Trojan.Tabela.E]
127.0.0.1 www.gratis-toplist.de
127.0.0.1 greatstartpage.com #[IE-SpyAd]
127.0.0.1 www.greatstartpage.com
127.0.0.1 www.greasypalm.co.uk #[PcTools.GreasyPalm bar]
127.0.0.1 grepblogs.net
127.0.0.1 adserver.gruprc.ro
127.0.0.1 publi.grupocorreo.es #[RealMedia]
127.0.0.1 ads.guardian.co.uk
127.0.0.1 ads.guru3d.com
127.0.0.1 www.g-wizzads.net #[adbureau.net]
# [H]
127.0.0.1 ads2.haber3.com
127.0.0.1 www.handyarchive.com #[SiteAdvisor.handyarchive.com]
127.0.0.1 streamit.hardwarezone.com
127.0.0.1 ad1.hardware.no #[AdvertPro]
127.0.0.1 adserver.hardwareanalysis.com
127.0.0.1 www.harmonyhollow.net #[Adware Bundler]
127.0.0.1 ads.harpers.org
127.0.0.1 hartim.com
127.0.0.1 ad0.haynet.com
127.0.0.1 ad.hbv.de
127.0.0.1 www.hehe911.com #[Win32/PSW.QQPass.GZ]
127.0.0.1 www.henbang.net #[Adware.Henbang][SPYW_HAP.A]
127.0.0.1 www.hentaibanners.com
127.0.0.1 www.hentaicashmachine.com
127.0.0.1 www.hentaicounter.com
127.0.0.1 www.hentaipop.com #[Electronic Group Dialer]
127.0.0.1 www.hentaiseeker.com
127.0.0.1 www.hentaitoonami.com
127.0.0.1 ads.herbalsmokeshop.com
127.0.0.1 www.herbalsmokeshops.com
127.0.0.1 www2.hermoment.com
127.0.0.1 www3.hermoment.com #[Realmedia]
127.0.0.1 www.hermoment.com
127.0.0.1 www.hey.lt
127.0.0.1 hicuernavaca.com #[WMF-exploit][server down?]
127.0.0.1 pubs.hiddennetwork.com
127.0.0.1 www.hiperstat.com
127.0.0.1 adserver.hispanoclick.com
127.0.0.1 ads.hitcents.com #[IE-SpyAd]
127.0.0.1 hits-counter.com
127.0.0.1 www.hits-counter.com
127.0.0.1 www.hit-counter-download.com
127.0.0.1 hithopper.com #[Adware.Hithopper]
127.0.0.1 www.hithopper.com #[ADW_HITHOPPER.A]
127.0.0.1 www.hitlogger.com
127.0.0.1 hitmodel.net
127.0.0.1 www.hit-counts.com
127.0.0.1 hit-now.com
127.0.0.1 www.hitscreamer.com #[server down?]
127.0.0.1 hitslog.com
127.0.0.1 h1.hitslog.com
127.0.0.1 s4.histats.com
127.0.0.1 s10.histats.com
127.0.0.1 s11.histats.com
127.0.0.1 www.hitstats.co.uk
127.0.0.1 hitstats.net
127.0.0.1 www.hittracking.com #[IE-SpyAd]
127.0.0.1 images.hitwise.co.uk
127.0.0.1 anna.homeftp.net #[W32.Linkbot.A]
127.0.0.1 adserver.hostfinderguy.com
127.0.0.1 ads.hothardware.com
127.0.0.1 www.gontijoamaral.hpg.com.br #[Adware.Diginum]
127.0.0.1 www.adserver.home.pl
127.0.0.1 www.homeoffun.com #[SiteAdvisor.homeoffun.com]
127.0.0.1 counters.honesty.com
127.0.0.1 cgi.honesty.com #[MVPS.Criteria]
127.0.0.1 ad.hosting.pl
127.0.0.1 ad2.hotels.com
127.0.0.1 www.hot-lindsay.com #[Zango][Parked?]
127.0.0.1 www.10s.com.br #[Trojan.Cargao]
127.0.0.1 cgi.hotstat.nl #[IE-SpyAd]
127.0.0.1 viewstat.hotstat.nl
127.0.0.1 ad.howstuffworks.com #[RealMedia][SpySweeper.Spy.Cookie]
127.0.0.1 hpod.com
127.0.0.1 www.htmate2.com #[Cursor.MySpace]
127.0.0.1 adserver.html.it
127.0.0.1 vip.huigezi.com #[Backdoor.Graybird.Q][W32.Looked.F]
127.0.0.1 www.huxley-online.net #[Win32/Spy.Elite.10.A]
127.0.0.1 www.hypertracker.com #[IE-SpyAd][SpySweeper.Spy.Cookie]
# [I]
127.0.0.1 ads.iafrica.com
127.0.0.1 www.i-clicks.net
127.0.0.1 hits.icdirect.com #[SunBelt.ICDirect.com]
127.0.0.1 hitctr01.icdirect.com
127.0.0.1 tracker.icerocket.com
127.0.0.1 ads.idgnow.com.br
127.0.0.1 banners.idg.com.br
127.0.0.1 adidm07.idmnet.pl
127.0.0.1 ad.ifrance.com
127.0.0.1 image-catcher.com
127.0.0.1 bar.iebar8.com #[Adware.Navihelper]
127.0.0.1 stats.surfaid.ihost.com #[IE-SpyAd]
127.0.0.1 adserver.ig.com.br
127.0.0.1 gate.ilogbox.com
127.0.0.1 bbn.img.com.ua
127.0.0.1 content-ads.impactengine.com
127.0.0.1 www.impregnable.net #[TrojanDownloader.Win32.VB.dw][Trojan.Win32.StartPage.kk]
127.0.0.1 ads.ims.nl
127.0.0.1 s201.indexstats.com
127.0.0.1 stats.indexstats.com #[Analytics Tracking Code]
127.0.0.1 stats.indextools.com #[IE-SpyAd][eTrust.Tracking Cookie]
127.0.0.1 campaign.indieclick.com
127.0.0.1 adcenter.in2.com
127.0.0.1 get.inetbar.com #[SunBelt.INetBar]
127.0.0.1 juggler.inetinteractive.com
127.0.0.1 rotator.juggler.inetinteractive.com
127.0.0.1 banners.inetfast.com
127.0.0.1 adserving.infinite-ads.com
127.0.0.1 www.infineo.de #[Win32/Spy.Banker.AWA]
127.0.0.1 infospot.infocious.com
127.0.0.1 ads.infospace.com #[ADW_DEALHELPER.C]
127.0.0.1 msxml.infospace.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.infotelsrl.com #[eTrust.Infotel srl]
127.0.0.1 ads.injersey.com #[RealMedia]
127.0.0.1 bimonline.insites.be
127.0.0.1 ads.intellicast.com #[weather.com]
127.0.0.1 strtt.interfree.it #[W32.Iberio]
127.0.0.1 counter.internet.ge
127.0.0.1 indiads.com #[IE-SpyAd]
127.0.0.1 images.indiads.com
127.0.0.1 servedby.indiads.com #[RealMedia]
127.0.0.1 infoshops.info #[Spamdexing]
127.0.0.1 popups.infostart.com #[eTrust.Popups.infostart.com]
127.0.0.1 ad1.iframeuploads.org #[W32.Timeserv@mm]
127.0.0.1 www.imiclk.com
127.0.0.1 oc.inspectorclick.com
127.0.0.1 trax.inspectorclick.com #[IE-SpyAd]
127.0.0.1 v2.inspectorclick.com
127.0.0.1 v3.inspectorclick.com
127.0.0.1 www.instantattention.com #[adimpact.com][server down?]
127.0.0.1 instantbuzz.com #[NOD32.Win32/Adware.InstantBuzz]
127.0.0.1 www2.instantbuzz.com
127.0.0.1 www.instantbuzz.com #[Adware.ToolBar.InstantBuzz.a]
127.0.0.1 media.intelia.it
127.0.0.1 anm.intelli-direct.com #[IntelliTracker]
127.0.0.1 info.intelli-direct.com
127.0.0.1 oxfam.intelli-direct.com
127.0.0.1 tui.intelli-direct.com
127.0.0.1 www.intelli-tracker.com
127.0.0.1 newadserver.interfree.it #[Adcycle]
127.0.0.1 www.interstats.nl
127.0.0.1 www.intrastats.com
127.0.0.1 channels.intwined.com #[Adware/ToolBar.ISearch.c]
127.0.0.1 search.intwined.com
127.0.0.1 www.intwined.com #[McAfee.Adware-SSF!Hosts]
127.0.0.1 www.invinc.com #[Troj/Dloader-J]
127.0.0.1 www.ipcounter.de
127.0.0.1 ad2.ip.ro
127.0.0.1 ads.ipowerweb.com
127.0.0.1 www.ipqwe.com #[Exploit.ANI]
127.0.0.1 content.ipro.com #[WebBug]
127.0.0.1 www.ipstat.com #[IE-SpyAd]
127.0.0.1 adzones.ircspy.com
127.0.0.1 isecurepages.net #[Google Warning]
127.0.0.1 www.isecurepages.net #[IFrame.Exploit]
127.0.0.1 www.istats.nl #[IE-SpyAd]
127.0.0.1 a.isohunt.com
127.0.0.1 adserver1.isohunt.com
127.0.0.1 ads.isoftmarketing.com
127.0.0.1 banman.isoftmarketing.com
127.0.0.1 ads1.itadnetwork.co.uk
127.0.0.1 www.itemgame.net #[W32/HLLP.Philis.ar]
127.0.0.1 itisbest.info #[Spamdexing]
127.0.0.1 www.itrackpages.com
127.0.0.1 www.itrafficstar.com #[IE-SpyAd]
127.0.0.1 ilead.itrack.it
127.0.0.1 adserver.itsfogo.com
127.0.0.1 partnerfeed.itsfogo.com
127.0.0.1 ads.itv.com #[adbureau.net]
127.0.0.1 www.iwebmusic.com
127.0.0.1 iwebtunes.com #[FTC Action]
127.0.0.1 www.iwebtunes.com
# [J]
127.0.0.1 ad.jamba.net #[IE-SpyAd]
127.0.0.1 www.jamming.cn #[Win32/Spy.Banker.AHY][server down?]
127.0.0.1 ad.jamster.com
127.0.0.1 www.jcount.com #[IE-SpyAd]
127.0.0.1 www.jellycounter.com
127.0.0.1 www.jethit.com
127.0.0.1 t1.jfglass.net #[Trojan.Booha]
127.0.0.1 dl.jiangmin.com #[Adware-BDSearch.dr]
127.0.0.1 jimmybuttons.com #[eTrust.Win32/Nirbot]
127.0.0.1 www.jm-my.com #[BackDoor-CXI]
127.0.0.1 ad.joetec.net
127.0.0.1 ads.jokaroo.com
127.0.0.1 jpedownload.joltid.com
127.0.0.1 ads.jossip.com
127.0.0.1 pastorale.jpn.org #[Win32/Spy.Banker.AHY]
127.0.0.1 www.joltid.com #[Adware.P2PNetworking][SPYW_PPNETWORK.B]
127.0.0.1 promotion.jpds.com
127.0.0.1 ads.jt.org
127.0.0.1 www.justfreegames.com #[AdWare.Win32.Relevant.a]
# [K]
127.0.0.1 www.k265.com #[Adware.Borlan]
127.0.0.1 stat.katalysatormedia.no
127.0.0.1 kazantip-top.com
127.0.0.1 www.kazantip-top.com #[HTML/Exploit.VMLFill]
127.0.0.1 ads.webfever.kadserver.com
127.0.0.1 ads.deblok.net.kadserver.com
127.0.0.1 ads.zebest-3000.net.kadserver.com
127.0.0.1 countus.get.kadserver.com
127.0.0.1 geo113prod.kadserver.com
127.0.0.1 get.kadserver.com
127.0.0.1 kazaalite.pl
127.0.0.1 www.kazaalite.pl #[MHTMLRedir.Exploit]
127.0.0.1 gavzad.keenspot.com
127.0.0.1 ad.kewlbox.com
127.0.0.1 banner.kiev.ua
127.0.0.1 adserve.kikizo.com
127.0.0.1 kjsc.org #[Win32/Spy.Banker.ANV]
127.0.0.1 ads.kleinman.com #[Adcycle]
127.0.0.1 www.klikvipresources.com #[Spamdexing]
127.0.0.1 gfx.klipmart.com #[gfx.dvlabs.com]
127.0.0.1 kt3.kliptracker.com #[IE-SpyAd]
127.0.0.1 kt4.kliptracker.com
127.0.0.1 www.kliptracker.com
127.0.0.1 ads.klixxx.com
127.0.0.1 www.km-nyc.com #[W32.Lecna.A]
127.0.0.1 click.kmindex.ru
127.0.0.1 counter.kmindex.ru
127.0.0.1 counting.kmindex.ru
127.0.0.1 www.kmindex.ru
127.0.0.1 www.knacads.com
127.0.0.1 ads.komli.com
127.0.0.1 www.kompass-intl.com #[Win32/Adware.Toolbar.PowerSearch]
127.0.0.1 de.komtrack.com
127.0.0.1 koolbar.net #[Adware Bundler][ADW_KOOLBAR.A]
127.0.0.1 www.koolbar.net #[eTrust.AutoSearch][IE-SpyAd]
127.0.0.1 sitestat.kpn-is.nl
127.0.0.1 kuaiso.com #[AdWare.Win32.Kuaiso.a]
127.0.0.1 toolsbar.kuaiso.com #[Adware.Kuaiso]
127.0.0.1 www.kuaiso.com
127.0.0.1 www.kusik-tusik-traff.com #[Javascript.Exploit]
127.0.0.1 kustusch.com #[Javascript.Exploit]

gatoramanda
2007-04-12, 18:39
# [L]
127.0.0.1 alwaysforfriend.land.ru #[Trojan-Downloader.Win32.Banload.bdp]
127.0.0.1 www.animacoes.land.ru #[Downloader.Swif.B]
127.0.0.1 www.latinbusca.com #[Adware-CommanderNET]
127.0.0.1 ads.lawnsite.com
127.0.0.1 layer-ads.de
127.0.0.1 www.layer-ads.de
127.0.0.1 banner.lbs.km.ru
127.0.0.1 iframe.leadacceptor.com
127.0.0.1 leakedcelebvideos.com #[Win32/TrojanDownloader.Agent.BCZ]
127.0.0.1 www.leakedcelebvideos.com
127.0.0.1 pubs.lemonde.fr
127.0.0.1 www.leopardsearch.com
127.0.0.1 ads.letemps.ch
127.0.0.1 ts1.lexmark.com
127.0.0.1 www.leythosthestalker.com
127.0.0.1 adserver.libero.it
127.0.0.1 adv-banner.libero.it
127.0.0.1 stats.lightningcast.net
127.0.0.1 stats2.lightningcast.net
127.0.0.1 phpads.lime.com
127.0.0.1 link.ru
127.0.0.1 link.link.ru
127.0.0.1 www.linkads.net #[IE-SpyAd]
127.0.0.1 ads.linki.nl
127.0.0.1 lindr.net
127.0.0.1 www.lindr.net #[RelatedSearch][Adware.Uptofind]
127.0.0.1 www.linkads.de
127.0.0.1 linkbuddies.com #[IE-SpyAd]
127.0.0.1 banners.linkbuddies.com
127.0.0.1 www.linkbuddies.com
127.0.0.1 www.linkcounter.com
127.0.0.1 linksexchange.net
127.0.0.1 linkexchange.ru #[IE-SpyAd]
127.0.0.1 web.linkexchange.ru
127.0.0.1 www.linkexchange.ru
127.0.0.1 link4link.com #[IE-SpyAd]
127.0.0.1 plus.link4link.com
127.0.0.1 www.links4trade.com #[IE-SpyAd]
127.0.0.1 escati.linkopp.net #[IE-SpyAd]
127.0.0.1 www.linkopp.net
127.0.0.1 click.linkstattrack.com #[SiteAdvisor.linkstattrack.com]
127.0.0.1 ads.linuxjournal.com
127.0.0.1 www.ligue13.com #[Win32/Spy.Banker.BIG]
127.0.0.1 livecounter.net
127.0.0.1 www.livecounter.net
127.0.0.1 js.livehelper.com #[IE-SpyAd]
127.0.0.1 newbrowse.livehelper.com
127.0.0.1 ads.livescore.com
127.0.0.1 traffic.livevideo.com
127.0.0.1 omnituretrack.local.com
127.0.0.1 www.lojastal.com.br #[Win32/Spy.Banker.ANV]
127.0.0.1 lol.to #[HTML/Exploit.Mht]
127.0.0.1 err.lolipop.jp
127.0.0.1 www.lookde5.com #[W32.Looked]
127.0.0.1 lookoutsoft.net #[SiteAdvisor.lookoutsoft.net]
127.0.0.1 screensavers.lookoutsoft.net
127.0.0.1 www.lookoutsoft.net #[AdWare.Win32.WinAD.b]
127.0.0.1 www.lords-of-havoc.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 lolteens.in #[Haxdoor.Exploit]
127.0.0.1 lottery-news.info #[HTML/TrojanDownloader.Agent.NAB]
127.0.0.1 hexusads.fluent.ltd.uk
127.0.0.1 luckyhomepage.com #[search.targetwords.com\1stblaze.com]
127.0.0.1 www.luckyhomepage.com #[IE-SpyAd]
127.0.0.1 ads-apsa.lvz-online.de
127.0.0.1 counter.lyricsdownload.com
127.0.0.1 www.lyricspy.com #[PluginAccess]
127.0.0.1 666.lyzh.com #[Trojan-PSW.Win32.Lineage.aec][TSPY_LINEAGE.WK]
# [M]
127.0.0.1 m2k.ru
127.0.0.1 ad.m-adx.com
127.0.0.1 media.m-adx.com
127.0.0.1 www.madoogali.com #[Madoogali][IE-SpyAd]
127.0.0.1 www.madrascements.com #[Win32/Spy.Banker.Big]
127.0.0.1 msn-sexoweb.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 humortadela.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 www.novogerador.mail15.com
127.0.0.1 www.uolcard.mail15.com #[Trojan-Spy.Win32.Banker.ark]
127.0.0.1 voegol.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 humortadela0.mail333.com #[Win32/Spy.Banker.AHY]
127.0.0.1 destino-gol.mail333.com #[Win32/Spy.Banker.BCK]
127.0.0.1 www.messengerbeta.mail333.com #[Win32/Spy.Banker.BCK]
127.0.0.1 mair.net #[Realtracker]
127.0.0.1 marketing-know-how.com #[TR/Dldr.iBill.V]
127.0.0.1 aw.masterstats.com
127.0.0.1 erotic.masterstats.com
127.0.0.1 image.masterstats.com #[IE-SpyAd]
127.0.0.1 link.masterstats.com
127.0.0.1 vw.masterstats.com #[Ewido.TrackingCookie.Masterstats]
127.0.0.1 ads.affiliates.match.com
127.0.0.1 associmage.match.com #[IE-SpyAd]
127.0.0.1 adserver.matchcraft.com
127.0.0.1 www.maxi-music.fr #[Win32/Spy.Banker.ANV]
127.0.0.1 ads.maxivip.fr
127.0.0.1 ads.mcafee.com
127.0.0.1 directads.mcafee.com #[Tenebril.Tracking Cookie]
127.0.0.1 up.medbod.com #[Backdoor.Win32.Medbot.k]
127.0.0.1 www.media-codec.net #[Win32/TrojanDownloader.Zlob.US]
127.0.0.1 mcmads.mediacapital.pt #[DoubleClick]
127.0.0.1 matrix.mediavantage.de
127.0.0.1 adland.medialand.ru
127.0.0.1 adnet.medialand.ru
127.0.0.1 content.medialand.ru
127.0.0.1 ads.mediaodyssey.com
127.0.0.1 acvs.mediaonenetwork.net
127.0.0.1 acvsrv.mediaonenetwork.net
127.0.0.1 ads1.mediaops.com.br
127.0.0.1 ad2.pl.mediainter.net
127.0.0.1 servedby.mediaplace.tv #[ad.firstadsolution.com]
127.0.0.1 media-servers.net
127.0.0.1 ads.mediaturf.net #[McAfee.Cookie-Mediaturf]
127.0.0.1 adv.medscape.com #[ads.webmd.com]
127.0.0.1 megabablo.info
127.0.0.1 www.megastats.com
127.0.0.1 exit.megago.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.megago.com #[typo squatter][IE-SpyAd]
127.0.0.1 megaswaiter.info #[server down?]
127.0.0.1 www.megaseek.net #[IE-SpyAd]
127.0.0.1 www.mercuras.com
127.0.0.1 adserv2.meritdesigns.com
127.0.0.1 ads.metropol.dk
127.0.0.1 automagazine.metriweb.be
127.0.0.1 hln-frinfos.metriweb.be
127.0.0.1 levif.metriweb.be
127.0.0.1 line01.metriweb.be #[Ad-Aware.Tracking Cookie]
127.0.0.1 line02.metriweb.be
127.0.0.1 line03.metriweb.be
127.0.0.1 line04.metriweb.be #[SpySweeper.Spy Cookie]
127.0.0.1 line05.metriweb.be
127.0.0.1 line06.metriweb.be
127.0.0.1 line07.metriweb.be #[Panda.Spyware:Cookie]
127.0.0.1 line08.metriweb.be
127.0.0.1 line09.metriweb.be
127.0.0.1 line10.metriweb.be
127.0.0.1 line11.metriweb.be
127.0.0.1 line12.metriweb.be
127.0.0.1 line13.metriweb.be
127.0.0.1 line14.metriweb.be
127.0.0.1 line15.metriweb.be
127.0.0.1 line16.metriweb.be
127.0.0.1 line17.metriweb.be
127.0.0.1 line18.metriweb.be
127.0.0.1 line19.metriweb.be
127.0.0.1 line20.metriweb.be
127.0.0.1 line24.metriweb.be
127.0.0.1 line26.metriweb.be
127.0.0.1 line32.metriweb.be
127.0.0.1 rtbf09.metriweb.be
127.0.0.1 skynet-news.metriweb.be
127.0.0.1 zattevrienden.metriweb.be
127.0.0.1 pubs.mgn.net #[Grolier Network]
127.0.0.1 www.mgshareware.com #[Adware Bundler][Parasite.MySearch]
127.0.0.1 microsoftout.com #[Phish.site]
127.0.0.1 ads.milenio.com
127.0.0.1 adc1.mingpao.com
127.0.0.1 ads.mininova.org
127.0.0.1 ads.miniclip.com #[eur56deliv.247realmedia.com]
127.0.0.1 www.mini-player.com #[5MOF Mini-Player]
127.0.0.1 banner.missingkids.com
127.0.0.1 ads.mixtraffic.com #[IE-SpyAd]
127.0.0.1 www.mlclick.com
127.0.0.1 vod.mmdy.org #[McAfee.StartPage-JN!CC32C55]
127.0.0.1 www.mnogotrafa.net #[Spamdexing]
127.0.0.1 banners.mobilesidewalk.com
127.0.0.1 smile.modchipstore.com
127.0.0.1 survey2.modernmindsoftware.com
127.0.0.1 ad.mokead.com
127.0.0.1 w5.mokead.com
127.0.0.1 www.mokead.com #[W32/DLoader.VZN]
127.0.0.1 ads.monster.com
127.0.0.1 adserver.monster.com #[SunBelt.AdServer.Monster.com]
127.0.0.1 adserver.a.in.monster.com
127.0.0.1 ads.monstermoving.com
127.0.0.1 cookie.monster.com #[SunBelt.cookie.monster]
127.0.0.1 www.movies.net.cn #[AdWare.Win32.AdBlaster.b]
127.0.0.1 www.mp3downloadhq.com #[SiteAdvisor.mp3downloadhq.com]
127.0.0.1 mp3today.net
127.0.0.1 mpamexit.com
127.0.0.1 adfarm.mserve.ca
127.0.0.1 www.messagetag.com #[Email tracker][IE-SpyAd]
127.0.0.1 msgtag.com
127.0.0.1 img.msgtag.com #[IE-SpyAd]
127.0.0.1 www.msgtag.com
127.0.0.1 h.mt12.net #[Win32/PSW.Lineage.AEL][W32/HLLP.Philis.ar]
127.0.0.1 multi1.rmuk.co.uk #[RealMedia]
127.0.0.1 www.muangboranjournal.com #[Win32/Spy.Banker.AHY]
127.0.0.1 www.multiclinmed.com.br #[Win32/PSW.Legendmir.ATE]
127.0.0.1 mussicalcardss.smtp.ru #[Win32/Spy.Banker.AHY]
127.0.0.1 www.musicmass.com #[HJTH.C2Media/LOP variant]
127.0.0.1 www.mumy8.com #[Exploit.ANI]
127.0.0.1 mvr3d.net #[Adware Bundler]
127.0.0.1 www.mvr3d.net
127.0.0.1 mvr.us #[Parasite.NavExcel]
127.0.0.1 www.mvr.us
127.0.0.1 www.myadtrack.com #[Email Tracker][IE-SpyAd]
127.0.0.1 www.myarmory.com #[Spyware.Bazookabar]
127.0.0.1 ipub.mybloglog.com
127.0.0.1 pub.mybloglog.com
127.0.0.1 track.mybloglog.com #[Yahoo Tracking Service]
127.0.0.1 track2.mybloglog.com
127.0.0.1 track3.mybloglog.com
127.0.0.1 mycashbank.co.kr
127.0.0.1 key.mycashbank.co.kr #[Trojan.Daum]
127.0.0.1 get.mycounter.com.ua
127.0.0.1 www.myemessenger.com
127.0.0.1 www.myfriendspy.com
127.0.0.1 liveupdate.myim.cn #[Adware.BeSys]
127.0.0.1 www.mylinker.net #[Adware.MyLinker]
127.0.0.1 www.mylottoadserv.com
127.0.0.1 rm.myoc.com
127.0.0.1 wintercat.diy.myrice.com #[Win32/TrojanDownloader.Tiny.Y]
127.0.0.1 www.myspacebar.com #[SunBelt.Scam.MySpaceBar]
127.0.0.1 www.myspacetracer.com
127.0.0.1 www.mystats.nl #[IE-SpyAd]
127.0.0.1 www2.mystats.nl
127.0.0.1 c.mystat-in.net
127.0.0.1 f2.n1.b.mystat-in.net
127.0.0.1 ___id___.c.mystat-in.net
127.0.0.1 102106151057.c.mystat-in.net
127.0.0.1 061606084448.c.mystat-in.net
127.0.0.1 070806142521.c.mystat-in.net
127.0.0.1 www.mytrackseraser.com #[HJTH.Holistyc Dialer]
# [N]
127.0.0.1 hit.namimedia.com #[IE-SpyAd]
127.0.0.1 ads.nandomedia.com #[McAfee.Cookie-Nandomedia]
127.0.0.1 adserver.nav2.net
127.0.0.1 c1.navrcholu.cz
127.0.0.1 popsearch.nbcsearch.com
127.0.0.1 xml.nbcsearch.com
127.0.0.1 www.nbcsearch.com #[exactsearch.net]
127.0.0.1 sd.ncast.cn #[Adware.NCast]
127.0.0.1 ndparking.com #[Parking Service]
127.0.0.1 www.ndparking.com
127.0.0.1 www.neima.net #[Win32/Spy.Banker.AHY]
127.0.0.1 ads.neogen.bg
127.0.0.1 ads.neogen.ro
127.0.0.1 ads.neowin.net
127.0.0.1 banman.nepsecure.co.uk #[Ban Man Pro Banner Code]
127.0.0.1 banners.netcraft.com
127.0.0.1 www.netdirect.nl
127.0.0.1 www.netflip.com #[IE-SpyAd]
127.0.0.1 beta-hints.netflame.cc
127.0.0.1 hints.netflame.cc #[Fireclick Web Analytics]
127.0.0.1 ssl-hints.netflame.cc
127.0.0.1 trizvez.netfirms.com #[Win32/Spy.Banker]
127.0.0.1 adv.netinfo.bg
127.0.0.1 tracker.netklix.com
127.0.0.1 stat.netlogic.ru #[NetLogic Logger]
127.0.0.1 webstats.netlogics.nl
127.0.0.1 www.netmaxx.com
127.0.0.1 counter.netmore.net
127.0.0.1 www.netpumper.com #[CounterSpy.Adware Bundler]
127.0.0.1 ads.netrition.com
127.0.0.1 servedby.netshelter.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.network-tool.net #[Trojan.Magise]
127.0.0.1 www.new-phpmailer.com #[Win32/Bifrose.E]
127.0.0.1 www1.nuseek.com
127.0.0.1 www2.nuseek.com #[overture.com]
127.0.0.1 ads.newdream.net
127.0.0.1 ads.newgrounds.com
127.0.0.1 ads.newsint.co.uk
127.0.0.1 newvidscodec.net #[Trojan-Downloader.Win32.Zlob.tz]
127.0.0.1 www.newvidscodec.net
127.0.0.1 www.newweb.com.cn #[Adware.NewWeb][IE-SpyAd]
127.0.0.1 ads1.nexdra.com
127.0.0.1 adq.nextag.com #[McAfee.Cookie-Nextag]
127.0.0.1 nextgenstats.com
127.0.0.1 www.nextgenstats.com
127.0.0.1 www.ngp-mac.com #[Win32/Spy.Banker.AHY]
127.0.0.1 www.nipr.ws #[Trojan.Chuvazada]
127.0.0.1 www.nlbanner.nl #[IE-SpyAd]
127.0.0.1 ads.nordichardware.com
127.0.0.1 ads.nordichardware.se
127.0.0.1 www.nordicgold.com #[Win32/Spy.Banker.AHY]
127.0.0.1 www.nortonproject.com #[AdWare.Win32.Softomate.j][Adware/ToolBar.ISearch.c]
127.0.0.1 ad.nozonedata.com #[Ad-Aware Tracking Cookie]
127.0.0.1 ad1.nozonedata.com
127.0.0.1 ad.nrk.no
127.0.0.1 nsismedia.net #[SunBelt.NSIS Media]
127.0.0.1 www.nsismedia.net
127.0.0.1 ns2.iad1.nssrv.com #[IE-SpyAd]
127.0.0.1 cdn.nvero.net
127.0.0.1 e.nvero.net
127.0.0.1 ads.nyi.net
127.0.0.1 nzads.net.nz
# [O]
127.0.0.1 adserver.o2.pl
127.0.0.1 banner.oddcast.com
127.0.0.1 www.officialtvoffers.com #[IE-SpyAd]
127.0.0.1 www.ok8vs.com #[Exploit.ANI]
127.0.0.1 www.okvs8.com #[Exploit.ANI]
127.0.0.1 okcounter.com #[IE-SpyAd][eTrust.Tracking Cookie]
127.0.0.1 www.okww.net #[Trojan.StartPage.C]
127.0.0.1 ads.oneplace.com
127.0.0.1 stat.onestat.com #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 www.onestat.com #[Ewido.TrackingCookie.Onestat]
127.0.0.1 www.onestatfree.com
127.0.0.1 one.ru
127.0.0.1 cnt.one.ru
127.0.0.1 stats0.one.ru
127.0.0.1 stats1.one.ru
127.0.0.1 stats2.one.ru
127.0.0.1 ads.oneandonlynetwork.com
127.0.0.1 www.oneandonlynetwork.com #[Ticketmaster][IE-SpyAd]
127.0.0.1 ads.onemodelplace.com
127.0.0.1 reklama.onet.pl
127.0.0.1 onlinecount.com
127.0.0.1 online-service.cc
127.0.0.1 www.online-service.cc #[Trojan.Magise]
127.0.0.1 adserver.online-tech.com
127.0.0.1 onlyfreebies.net #[Spamdexing]
127.0.0.1 www.onlyscreensavers.com #[SiteAdvisor.onlyscreensavers.com]
127.0.0.1 www.openadnetwork.com
127.0.0.1 s27.opentracker.net
127.0.0.1 server1.opentracker.net
127.0.0.1 server10.opentracker.net
127.0.0.1 ccc00.opinionlab.com
127.0.0.1 ccc01.opinionlab.com #[msn.com]
127.0.0.1 rate.opinionlab.com
127.0.0.1 www.opinionlab.com #[IE-SpyAd]
127.0.0.1 by.optimost.com
127.0.0.1 optlynx.com #[Adware.Optserve]
127.0.0.1 optmedia.jp
127.0.0.1 ad.orbitel.bg
127.0.0.1 orthone.com #[Javascript.Exploit]
127.0.0.1 www.orthone.com #[Google/StopBadware Warning]
127.0.0.1 ads.orsm.net
127.0.0.1 otx5.otxresearch.com
127.0.0.1 otx.ifilm.com #[OTXMedia.dll]
127.0.0.1 survey.otxresearch.com #[TrojanDownloader.OTXloader.A][MVPS.Criteria]
127.0.0.1 www.otxresearch.com #[OTXMovie Class]
127.0.0.1 our-counter.biz #[ISANS.Alert]
127.0.0.1 liveupdate.ourxin.com #[Adware.AllSum]
127.0.0.1 www.ourxin.com #[Dr.Web.Adware.CFS][Trojan.Cfs]
127.0.0.1 adpopper.outblaze.com #[ADW_BBINSTALL.B][bargain-buddy.net]
127.0.0.1 adp4.us4.outblaze.com
127.0.0.1 adserver.hk.outblaze.com
127.0.0.1 adserver.us.outblaze.com
127.0.0.1 download2.us4.outblaze.com #[HJTH.Bargain Buddy]
127.0.0.1 www.overpeer.com #[Trojan.Wimad]
127.0.0.1 pub.oxado.com
# [P]
127.0.0.1 www.p5ip.com #[Exploit.ANI]
127.0.0.1 ad1.pamedia.com.au
127.0.0.1 ad2.pamedia.com.au
127.0.0.1 panelka.info #[Spamdexing][server down?]
127.0.0.1 www.pantanalvip.com.br #[McAfee.Downloader-AFV]
127.0.0.1 images.parked.com
127.0.0.1 park.parkingpanel.com
127.0.0.1 parladent-doc.org #[Backdoor.Haxdoor.L]
127.0.0.1 ads.partnerlogic.net
127.0.0.1 static.partnerlogic.net
127.0.0.1 update.passivecow.com #[Trojan.Win32.VB.aft][Adware.Superlogy]
127.0.0.1 adtxt.prbn.ru
127.0.0.1 ad468.prbn.ru
127.0.0.1 b1.perfb.com
127.0.0.1 www.pcbutts1.com #[Unauthorized Downloads][SiteAdvisor.pcbutts1.com]
127.0.0.1 ads.pcper.com
127.0.0.1 www.pc-test.net
127.0.0.1 ads.pcworld.com.br
127.0.0.1 ad1.peel.com
127.0.0.1 ad3.peel.com #[SunBelt.Peel]
127.0.0.1 ads.peel.com
127.0.0.1 ad4.peel.com #[Tenebril.Tracking Cookie]
127.0.0.1 ads5.peel.com
127.0.0.1 freeps3.peel.com
127.0.0.1 www.peel.com #[IE-SpyAd]
127.0.0.1 www.peel.net
127.0.0.1 ads.pennyweb.com #[addynamix.com]
127.0.0.1 banners.pennyweb.com #[IE-SpyAd]
127.0.0.1 errors.perfectgonzo.com
127.0.0.1 pluginx.perfectgonzo.com
127.0.0.1 ads.periodistadigital.com
127.0.0.1 www.peruvianmarket.com #[Trojan.Beagooz.D]
127.0.0.1 www.pheedo.com #[RSS Advertising]
127.0.0.1 phenik.info #[Spamdexing]
127.0.0.1 a.photobucket.com #[photobkt.adbureau.net]
127.0.0.1 ads.photosight.ru
127.0.0.1 phpadsnew.com
127.0.0.1 www.phpadsnew.com
127.0.0.1 www.picturecentre.com #[Win32/Agent.RC][Backdoor.Tricker]
127.0.0.1 www.pkpsoft.com #[AdWare.Win32.SaveNow.bo][SiteAdvisor.pkpsoft.com]
127.0.0.1 ads.planetactive.com
127.0.0.1 ads.plantyours.com
127.0.0.1 ads2.playnet.com
127.0.0.1 counter.plugin.ws
127.0.0.1 www.plmq.com #[Exploit.ANI]
127.0.0.1 link.p0.com #[Web Bug][SiteAdvisor.p0.com]
127.0.0.1 pohuicnt.com #[Google Warning]
127.0.0.1 adserver.pollstar.com #[eTrust.Tracking Cookie]
127.0.0.1 ad2.pop.com.br
127.0.0.1 nosex.pop3.ru #[Win32/Agent.OH]
127.0.0.1 qwekissme.pop3.ru #[Win32/Spy.Banker.BCK]
127.0.0.1 musicalcardss.pop3.ru #[Win32/Spy.Banker.BIG]
127.0.0.1 popfind.net #[Adware.Ddpop]
127.0.0.1 www.popupsandbanners.com #[TR/Amisa.A][Troj/Winsysba-G]
127.0.0.1 www.popupad.net #[IE-SpyAd][SunBelt.PopUpAd]
127.0.0.1 popadstop.com #[Adware.PopAdStop]
127.0.0.1 www.popadstop.com
127.0.0.1 porcosnet.com #[Win32/TrojanDownloader.Tiny.NBP]
127.0.0.1 www.porcosnet.com
127.0.0.1 www2.portdetective.com
127.0.0.1 ad2.postroller.com
127.0.0.1 ad3.postroller.com
127.0.0.1 www.ppctracking.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 adview.ppro.de
127.0.0.1 x0x0l.pp.ru #[BKDR_CCT.A]
127.0.0.1 pr-cy.ru
127.0.0.1 prado7.com #[Google Warning]
127.0.0.1 www.praize.com #[Adware.Praize][SiteAdvisor.praize.com]
127.0.0.1 ads.premiereinteractive.com
127.0.0.1 prevedtraf.biz #[Google Warning][server down?]
127.0.0.1 www.prevedtraf.biz
127.0.0.1 ads.primeinteractive.net
127.0.0.1 ads.prisacom.com #[RealMedia]
127.0.0.1 ad.pro-advertising.com
127.0.0.1 cdn1.pro-advertising.com
127.0.0.1 adv.profantasysports.com
127.0.0.1 profileawareness.com #[Trojan-Spy:JS/Spacestalk.A]
127.0.0.1 www.profilepeep.com #[MySpace Tracker]
127.0.0.1 ad.profiwin.de
127.0.0.1 bn.profiwin.de
127.0.0.1 www.promarketingclub.com
127.0.0.1 www.promobenef.com
127.0.0.1 www.prtracker.com
127.0.0.1 www.profitzone.com #[SunBelt.ProfitZONE Adbar]
127.0.0.1 www.promo.com.au
127.0.0.1 www.prutect.com #[Spyware.e2give][Win32.Prutec.A]
127.0.0.1 ad.prv.pl
127.0.0.1 www.psbill.biz #[IE-SpyAd]
127.0.0.1 psefeed.com #[Spamdexing]
127.0.0.1 xml1.psefeed.com
127.0.0.1 www.psefeed.com
127.0.0.1 www.pstats.com
127.0.0.1 ads.psxextreme.com
127.0.0.1 pulsix.com #[maxalbums.com]
127.0.0.1 www.pulsix.com
127.0.0.1 ad.sma.punto.net
127.0.0.1 sma.punto.net
# [Q]
127.0.0.1 exchange.qclix.com #[directtrack.com]
127.0.0.1 e1.cdn.qnsr.com
127.0.0.1 l1.cdn.qnsr.com #[WebBug]
127.0.0.1 adserv.quality-channel.de
127.0.0.1 qualityhitz.net
127.0.0.1 ads-205.quarterserver.de
127.0.0.1 ads.queendom.com
127.0.0.1 www.quickbar.co.kr #[eTrust.IEFilter.A]
127.0.0.1 antispyware.qmake.org
127.0.0.1 www.qq886.com #[Backdoor.Semes]
127.0.0.1 quantserve.com
127.0.0.1 edge.quantserve.com
127.0.0.1 pixel.quantserve.com #[WebBug]

gatoramanda
2007-04-12, 18:41
# [R]
127.0.0.1 ads.radioactive.se
127.0.0.1 clientreport.random-logic.com #[McAfee.Adware-CasOnline]
127.0.0.1 ads.recoletos.es
127.0.0.1 reportinstaller.random-logic.com
127.0.0.1 www.random-logic.com
127.0.0.1 ranking-hits.de #[IE-SpyAd]
127.0.0.1 www.ranking-hits.de
127.0.0.1 counter.rapidcounter.com
127.0.0.1 www.rapidcounter.com
127.0.0.1 www.autoraskrutka.ru #[Spyware.Acext]
127.0.0.1 www.raskrutim.ru #[Spyware.Acext]
127.0.0.1 cnt.rate.ru
127.0.0.1 rb-net.com
127.0.0.1 count.rbc.ru
127.0.0.1 www.readnotify.com #[Email Tracker]
127.0.0.1 www.realclicks.com
127.0.0.1 ads.rediff.com
127.0.0.1 adworks.rediff.com
127.0.0.1 imadworks.rediff.com
127.0.0.1 www.redirad.de #[Adware.Redir]
127.0.0.1 js.redtram.com #[RedTramCookies]
127.0.0.1 js.en.redtram.com
127.0.0.1 referer.org
127.0.0.1 visit.referralware.com
127.0.0.1 regifast.com #[MVPS.Criteria][Adware.RegiFast]
127.0.0.1 www.regifast.com #[Trojan.RegiFast]
127.0.0.1 ads.register.com
127.0.0.1 www.registrarads.com
127.0.0.1 registrydoc.com
127.0.0.1 www.registrydoc.com
127.0.0.1 www.registrysweeper.com #[IE-SpyAd][Symantec.RegistrySweeper]
127.0.0.1 include.reinvigorate.net
127.0.0.1 stats.reinvigorate.net #[WebBug]
127.0.0.1 counter.relmaxtop.com
127.0.0.1 www.relmaxtop.com
127.0.0.1 banner.relcom.ru
127.0.0.1 adservice.recon-networks.com
127.0.0.1 www.rentyourdot.com
127.0.0.1 dn.research-int.se #[Insight XE TAGGING]
127.0.0.1 flnet.research-int.se
127.0.0.1 sn.research-int.se
127.0.0.1 tradera.research-int.se
127.0.0.1 dae.responsetarget.com #[AutoGK][IE-SpyAd][MVPS.Criteria]
127.0.0.1 banners.resultonline.com
127.0.0.1 www.returnreceipt.com #[Email Tracker]
127.0.0.1 cache.revenuedirect.com #[Parking Service]
127.0.0.1 traffic.revenuedirect.com
127.0.0.1 traffic.beta.revenuedirect.com
127.0.0.1 click.revenuepilot.com
127.0.0.1 search.revenuepilot.com
127.0.0.1 ads.revenews.com
127.0.0.1 www.reversecontext.com
127.0.0.1 revolt-search.com #[Spamdexing]
127.0.0.1 webtrends.reynoldswebsolutions.com #[hitbox.com]
127.0.0.1 ad.rd06.com
127.0.0.1 r.rd06.com
127.0.0.1 right-search.org #[Spamdexing]
127.0.0.1 rightstats.com
127.0.0.1 www.rightstats.com
127.0.0.1 www.ritztours.com #[Backdoor.Win32.Bifrose.kt]
127.0.0.1 rc.rizalof.com #[Win32/Boxed.BY][TR/Proxy.Horst.bl]
127.0.0.1 ads.rivals.net
127.0.0.1 m.rmbclick.com #[IE-SpyAd]
127.0.0.1 backoffice.roitracking.info
127.0.0.1 oas.romandie-online.ch
127.0.0.1 show.roogoo.com
127.0.0.1 www.roogoo.com #[Adware.Roogoo]
127.0.0.1 banner.royaldice.com
127.0.0.1 www.rgs-rostock.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 ad.ro2cn.com #[Adware.Ro2cn]
127.0.0.1 serving.rpowermedia.com #[AdvertPro]
127.0.0.1 ldkiekxc.rr.nu #[Backdoor.Ryejet.B]
127.0.0.1 upd.rssservice.net #[Trojan-Downloader.Win32.Small.cug]
127.0.0.1 update.rssservice.net
127.0.0.1 ru-traffic.com
127.0.0.1 banners.rushcommerce.com
# [S]
127.0.0.1 judo.salon.com
127.0.0.1 oas.salon.com
127.0.0.1 www.sapium.com #[NOD32.Win32/Spy.Banker.AHY]
127.0.0.1 tvinterativa.paginas.sapo.pt #[Win32/Spy.Banker.AHY]
127.0.0.1 amp.st.sageanalyst.net
127.0.0.1 matchnet.st.sageanalyst.net #[McAfee.Cookie-Sageanalyst]
127.0.0.1 st.sageanalyst.net #[IE-SpyAd][Ad-Aware.Tracking Cookie]
127.0.0.1 ads.sapo.pt
127.0.0.1 scaredback.com #[PWSteal.Tarno.R][Downloader-ATM]
127.0.0.1 scorpionsearch.com #[W32.Adclicker.C.Trojan]
127.0.0.1 www.scorpionsearch.com #[x10.com][Trojan.Clicker.NetBuie a-b]
127.0.0.1 www.scratchindian.com #[Backdoor.Samkams]
127.0.0.1 adsremote.scripps.com #[McAfee.Cookie-Scripps]
127.0.0.1 railads.scripps.com
127.0.0.1 te.scripps.com
127.0.0.1 horyzonix.sdv.fr #[RealMedia]
127.0.0.1 www.se911.com #[Win32/PSW.Legendmir.ATE]
127.0.0.1 s-e-arch.com
127.0.0.1 search4fast.com #[Spamdexing]
127.0.0.1 ads.search.bg
127.0.0.1 banner.search.bg
127.0.0.1 banex.search.bg
127.0.0.1 counter.search.bg #[IE-SpyAd]
127.0.0.1 ads.searchextreme.com
127.0.0.1 searchitquick.com #[IE-SpyAd]
127.0.0.1 tb.searchitquick.com #[hotwebsearch.com][HJTH.Begin2Search Adware]
127.0.0.1 www.searchitquick.com #[SunBelt.SearchItQuick Toolbar]
127.0.0.1 www.searchlab.info #[Spamdexing]
127.0.0.1 www.searchmachine.com #[IE-SpyAd]
127.0.0.1 www.searchrelevancy.com #[Spyware.Relevancy]
127.0.0.1 search-vip.net
127.0.0.1 www.searchvivor.com #[McAfee.Adware-DCToolbar]
127.0.0.1 plugin.secureservicepack.com #[HJTH.GoDOTLess]
127.0.0.1 images-pw.secureserver.net #[Parking Service][GoDaddy]
127.0.0.1 imagesak.secureserver.net
127.0.0.1 adserver.securityfocus.com #[RealMedia]
127.0.0.1 www.selfsurveys.com #[IE-SpyAd]
127.0.0.1 www.seehits.com
127.0.0.1 ads.seekingalpha.com
127.0.0.1 www.seekmp3.com #[HJTH.C2Media/LOP variant]
127.0.0.1 www.send-safe.com #[Spamware]
127.0.0.1 ad.sensismediasmart.com.au
127.0.0.1 seodrugs.com #[Spamdexing]
127.0.0.1 stats.seostats.com
127.0.0.1 serialkey.net #[Kephyr.PUP]
127.0.0.1 www.serialkey.net
127.0.0.1 www.serveads.com
127.0.0.1 pix.sexyads.net
127.0.0.1 www.sexyads.net #[SunBelt.SexyAds.net]
127.0.0.1 sincooweb.com #[Backdoor.Graybird.N]
127.0.0.1 www.slacker24.com #[Win32/Spy.Banker.AHY]
127.0.0.1 ads2.slickdeals.net
127.0.0.1 update.smartallyes.com #[Trojan.Smartallyes]
127.0.0.1 download.sidestep.com #[ADW_SIDESTEP.A]
127.0.0.1 images.sidestep.com
127.0.0.1 www.sidestep.com #[Win32/Adware.BHO.SideStep][MVPS.Criteria]
127.0.0.1 adimages.sina.com.hk
127.0.0.1 jsads.sina.com.hk
127.0.0.1 startpunt.nu.site-id.nl
127.0.0.1 www.sismodular.com #[Win32/Eyeveg.T]
127.0.0.1 www.site-id.nl
127.0.0.1 tracker.sitescout.com #[IE-SpyAd]
127.0.0.1 carde.sitesled.com #[Win32/Spy.Banker.ANV]
127.0.0.1 advertpro.sitepoint.com
127.0.0.1 www.sitestatslive.com
127.0.0.1 www.sitewebstats.com
127.0.0.1 ads.sixapart.com
127.0.0.1 adserver.sharewareonline.com #[nictechnetworks.com]
127.0.0.1 ads.shizmoo.com #[IE-SpyAd][Kephyr.PUP]
127.0.0.1 www.shockcounter.com #[IE-SpyAd]
127.0.0.1 ssh.showtr.biz #[Trojan-Proxy.Win32.Delf.bi][server down?]
127.0.0.1 ads.sina.com
127.0.0.1 www.skeech.com #[IE-SpyAd][SunBelt.Skeech]
127.0.0.1 www.small-tool.net #[Monitor.Win32.RemoteWatch.a]
127.0.0.1 www.smalltool.net #[Adware/LoopAd]
127.0.0.1 www.smartadserver.com #[SunBelt.SmartAdServer.com]
127.0.0.1 www.smartadstats.com #[IE-SpyAd]
127.0.0.1 smart-browser.com #[eTrust.SmartBrowser]
127.0.0.1 update.smart-browser.com #[SunBelt.SmartBrowser]
127.0.0.1 www.smart-browser.com #[Adware.SmartBrowser]
127.0.0.1 smartclicks.net #[IE-SpyAd]
127.0.0.1 www.smartclicks.net
127.0.0.1 smartseek.biz #[Trojan-Spy.Win32.Agent.ok]
127.0.0.1 www.smileyworld.com #[AdWare.Win32.SHBar.a][Adware.Smiley]
127.0.0.1 ads.sn.se
127.0.0.1 pub.softonic.com
127.0.0.1 update.cpc.sogou.com #[Adware.CPush]
127.0.0.1 ads.sopeng.com #[Adware.CPush]
127.0.0.1 a.sou7.com #[NOD32.NewHeur_PE]
127.0.0.1 ivox.socratos.net
127.0.0.1 www.softwareclub.ws #[Adware.SaveNow]
127.0.0.1 a.softpedia.com
127.0.0.1 adserver.softwareonline.com
127.0.0.1 www.someads.com
127.0.0.1 www1.spaex.com #[searchboss.com][IE-SpyAd]
127.0.0.1 www.specialstat.com #[IE-SpyAd]
127.0.0.1 www.spedia.net #[SunBelt.SpediaBar][Adware.Spedia]
127.0.0.1 speedsearcher.net #[Spamdexing][Microsoft.Strider]
127.0.0.1 www.sponsorads.de
127.0.0.1 sitestat3.sport1.de
127.0.0.1 www.spamcatchero.biz #[Backdoor.Mydopam]
127.0.0.1 www.speedcounter.net
127.0.0.1 ads-fr.spray.net #[SpySweeper.Spy.Cookie]
127.0.0.1 www.spyarsenal.com #[Spyware.DesktopSpy][Spyware.FamilyKeylog]
127.0.0.1 cracks.spb.ru #[Win32/TrojanDownloader.Adload.DS]
127.0.0.1 v.sodui.com
127.0.0.1 www.sodui.com #[Adware.SoduiSearch]
127.0.0.1 www.srchtop.com #[Spamdexing]
127.0.0.1 www.stacy-keibler-pictures.com #[Zango]
127.0.0.1 bannerads.standard.net
127.0.0.1 ads.starpulse.com #[SpySweeper.Spy.Cookie]
127.0.0.1 0.start.bz #[Trojan-Downloader.Win32.Small.dxg]
127.0.0.1 www.startsurfing.com #[McAfee.Adware-StartSurfing]
127.0.0.1 ads.stardoll.com
127.0.0.1 adsintl.starwave.com
127.0.0.1 js.statistici.ro
127.0.0.1 log.statistici.ro
127.0.0.1 s.statistici.ro #[IE-SpyAd]
127.0.0.1 www.statomatic.com #[IE-SpyAd]
127.0.0.1 statistik-gallup.net
127.0.0.1 s-t-a-t-s.com
127.0.0.1 www.stats4free.de
127.0.0.1 stats4you.com #[IE-SpyAd]
127.0.0.1 reg.stats4all.com
127.0.0.1 www.stats4you.com #[IE-SpyAd]
127.0.0.1 stat.statistiche.ws
127.0.0.1 www.statistiche.ws
127.0.0.1 log3.stats24.net #[IE-SpyAd]
127.0.0.1 www.statsmachine.com
127.0.0.1 www.statsector.hu
127.0.0.1 statswhere.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 www.stattrax.com
127.0.0.1 stattrader.biz #[Javascript.Exploit][server down?]
127.0.0.1 www.stattrader.biz
127.0.0.1 i.stealfrommvps.org
127.0.0.1 tac.ads.streamtheworld.com
127.0.0.1 ads.tetesacl.streamtheworld.com
127.0.0.1 adult.step57.info #[server down?]
127.0.0.1 cleo.step57.info
127.0.0.1 me.step57.info
127.0.0.1 traff.step57.info
127.0.0.1 www.step57.info
127.0.0.1 www.stickypops.com #[eTrust.Stickypops][IE-SpyAd]
127.0.0.1 gsorder.berlin.strato.de
127.0.0.1 www.streamxs.ws #[Trojan-Downloader.Win32.Tiny.dk]
127.0.0.1 www.sublimemedia.net
127.0.0.1 counter.surfcounters.com
127.0.0.1 clix.superclix.de #[IE-SpyAd]
127.0.0.1 www.superclix.de
127.0.0.1 ww2.superguadagni.net
127.0.0.1 www.superlogy.com #[AdvWare.ToolBar.VB.b][Adware.Superlogy]
127.0.0.1 adidm.supermedia.pl
127.0.0.1 super-portal.info
127.0.0.1 stat.superstat.info
127.0.0.1 www.superstat.info
127.0.0.1 adsuccess.surehits.com
127.0.0.1 adv.surinter.net
127.0.0.1 rd1.surfernetwork.com #[SurferNETWORK Plugin]
127.0.0.1 www.surfernetwork.com
127.0.0.1 www.surveynetworks.com
127.0.0.1 suwage.info #[Malicious Links]
127.0.0.1 sweetymail.ru #[TR/Small.DBY.AD.1]
127.0.0.1 adpick.switchboard.com
127.0.0.1 www.syamantec.com #[Typo Squatter][gotoo.com]
127.0.0.1 antispam.symlinks.org #[SpamBot]
127.0.0.1 adtag.sympatico.ca
127.0.0.1 www.system4.nl
127.0.0.1 sysregistry.com #[McAfee.FakeAlert-H]
127.0.0.1 www.sysregistry.com #[Prevx1.Malware:SysCovert]
# [T]
127.0.0.1 freeware-ad.t35.com #[umaxsearch.com]
127.0.0.1 hkvn99.t35.com
127.0.0.1 ijj.t35.com #[W32/Bagle.HQ][Wildcard DNS]
127.0.0.1 kuringao.t35.com #[Win32/TrojanDownloader.Banload.BDJ]
127.0.0.1 nolko.t35.com
127.0.0.1 spyware-re.t35.com #[umaxsearch.com]
127.0.0.1 ud7swe.t35.com #[W32.Dinoxi][W32/Style-A]
127.0.0.1 vbs.t35.com
127.0.0.1 bs.t-redirect.com
127.0.0.1 tabletsa.net #[Spamdexing]
127.0.0.1 www.tabletsa.net
127.0.0.1 www.tagexplosion.com #[AdWare.Win32.Eztracks.b]
127.0.0.1 ads.tagword.com
127.0.0.1 ad.uk.tangozebra.com
127.0.0.1 admin.targetad.net #[Adware-TargetAD]
127.0.0.1 dev.targetpoint.com
127.0.0.1 srs.targetpoint.com
127.0.0.1 stat-counter.tass-online.ru
127.0.0.1 tat-neftbank.ru #[Backdoor.Berbew.H]
127.0.0.1 ad.tbn.ru
127.0.0.1 ad.ent.tbn.ru
127.0.0.1 ad.gen.tbn.ru
127.0.0.1 ad.100.tbn.ru
127.0.0.1 ad.120-gen.tbn.ru
127.0.0.1 ad.text.tbn.ru
127.0.0.1 www.tdstats.com
127.0.0.1 www.teamtaylormade.com #[StopBadware.Warning]
127.0.0.1 www.tech-counter.com
127.0.0.1 banner.techarp.com
127.0.0.1 ads.telecinco.es
127.0.0.1 www.teligo-ads.de
127.0.0.1 navx3.tempdomainname.com #[SiteAdvisor.totallyfreegames.com]
127.0.0.1 www.tencent.com #[Backdoor.Prosti]
127.0.0.1 www.tenmonkey.com
127.0.0.1 adserver.teracent.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 adserver2.teracent.net
127.0.0.1 adserver1.teracent.net
127.0.0.1 adserver.terra.es
127.0.0.1 dy.testnet.nl
127.0.0.1 www.textads.biz
127.0.0.1 www.textlink.cz
127.0.0.1 www.text-link-ads.com
127.0.0.1 www.textlinkads.com
127.0.0.1 tdsru.info #[Spamdexing]
127.0.0.1 openad.tf1.fr #[RealMedia]
127.0.0.1 a.tfag.de
127.0.0.1 ak.tfag.de
127.0.0.1 www.tfcco.com #[W32/PFV-Exploit.A]
127.0.0.1 theaffiliateprogram.com
127.0.0.1 ads.the-bikini.com
127.0.0.1 thecoolpics.com #[W32.Imaut.J]
127.0.0.1 ads.thegauntlet.com
127.0.0.1 thegoodfind.com
127.0.0.1 www.thegoodfind.com
127.0.0.1 dclk.themarker.com
127.0.0.1 adbot.theonion.com
127.0.0.1 www.thepokerclub.com #[SecurityRisk.ClubPoker]
127.0.0.1 therichmedia.com
127.0.0.1 www.thevipsearch.com #[Spamdexing]
127.0.0.1 webtrends.thisis.co.uk #[Hitbox]
127.0.0.1 oas.tidningsnatet.se #[ads.realmedia.basefarm.net]
127.0.0.1 www.ting789.com #[McAfee.StartPage-HR]
127.0.0.1 mycounter.tinycounter.com
127.0.0.1 ad.tiscali.com
127.0.0.1 ad-cz.tiscali.com
127.0.0.1 ad-de.tiscali.com
127.0.0.1 ad-it.tiscali.com
127.0.0.1 ad-nl.tiscali.com
127.0.0.1 ad-sc.tiscali.com
127.0.0.1 ad-uk.tiscali.com
127.0.0.1 a.tiscali.co.uk #[ehg-tiscali.1p.hitbox.com]
127.0.0.1 sitestats.tiscali.co.uk #[WebBug]
127.0.0.1 adsweb.tiscali.cz
127.0.0.1 adsweb.tiscali.it #[Accipiter]
127.0.0.1 tiv4.info #[Malicious Links]
127.0.0.1 ads.as4x.tmcs.net
127.0.0.1 ads.tm-research.com
127.0.0.1 tnc4u.com #[Parasite.DownloadPlus]
127.0.0.1 new.tnc4u.com
127.0.0.1 www.tnc4u.com #[Adware.DownloadPlus]
127.0.0.1 tns-counter.ru
127.0.0.1 www.tns-counter.ru
127.0.0.1 toastystfc.com #[umax]
127.0.0.1 ads.tolshop.com
127.0.0.1 counter.top.ge
127.0.0.1 www.topbestsites.net #[Spamdexing]
127.0.0.1 hit.topc.org
127.0.0.1 banners.topcities.com
127.0.0.1 toplist.cz
127.0.0.1 www.toplist.cz
127.0.0.1 www.music.topsearch20.net #[Spamdexing]
127.0.0.1 log.traceics.ca
127.0.0.1 storage.traceics.ca
127.0.0.1 log.trafic.ro #[IE-SpyAd]
127.0.0.1 storage.trafic.ro
127.0.0.1 adserv.transindex.ro
127.0.0.1 top50sites.info #[Spamdexing]
127.0.0.1 ads.topix.net
127.0.0.1 ad.topstat.com
127.0.0.1 nl.topstat.com #[IE-SpyAd]
127.0.0.1 s26.topstat.com
127.0.0.1 xl.topstat.com
127.0.0.1 total-search.info #[ISANS.Alert]
127.0.0.1 banners.toteme.com
127.0.0.1 cachebanners.toteme.com
127.0.0.1 trackalyzer.com
127.0.0.1 t2.trackalyzer.com
127.0.0.1 ads.track-star.com #[SunBelt.Track-Star.com]
127.0.0.1 adserver.track-star.com
127.0.0.1 www.track-star.com
127.0.0.1 tracksy.com
127.0.0.1 ads.tradermedia.co.uk
127.0.0.1 rotator.tradetracker.nl
127.0.0.1 ti.tradetracker.nl
127.0.0.1 www.trafficcenter.de
127.0.0.1 textad.traficdublu.ro
127.0.0.1 www.trafficmasterz.net
127.0.0.1 s2.trafficmaxx.de
127.0.0.1 s3.trafficmaxx.de
127.0.0.1 ads.traderonline.com #[RealMedia]
127.0.0.1 www.traffic4u.com
127.0.0.1 traffic-acc.com #[Spyware.TrafficAccProc]
127.0.0.1 www.trafficbeamer.com
127.0.0.1 www.trafficbeamer.nl
127.0.0.1 trafficg.com #[IE-SpyAd]
127.0.0.1 www.trafficg.com
127.0.0.1 trafficfile.com #[IE-SpyAd]
127.0.0.1 www.trafficfile.com
127.0.0.1 www.trafficflame.com
127.0.0.1 trafficflare.com
127.0.0.1 www.trafficzap.com #[IE-SpyAd]
127.0.0.1 trackyourstats.com #[IE-SpyAd]
127.0.0.1 www.trackyourstats.com
127.0.0.1 hit.traxdb.net
127.0.0.1 media.travelzoo.com
127.0.0.1 media2.travelzoo.com
127.0.0.1 trfcnt.com
127.0.0.1 ads.triada.bg
127.0.0.1 ads.trinitymirror.co.uk #[eur56deliv.247realmedia.com]
127.0.0.1 adserver.tripsmarter.com
127.0.0.1 trudomain.com
127.0.0.1 www.trudomain.com #[Javascript.Exploit]
127.0.0.1 truefindpage.com
127.0.0.1 tracker.truehits.net
127.0.0.1 www.trusttoolbar.com #[eTrust.Trust Toolbar]
127.0.0.1 trywith.us #[Spamdexing]
127.0.0.1 www.tscounter.com
127.0.0.1 adclient1.tucows.com
127.0.0.1 counts.tucows.com
127.0.0.1 google.tucows.com
127.0.0.1 icornerstore.tumri.net #[TumriAds]
127.0.0.1 images.tumri.net
127.0.0.1 www.tumri.net
127.0.0.1 www.turls.info
127.0.0.1 ad.turn.com
127.0.0.1 ad.tv2.no #[RealMedia]
127.0.0.1 tvbad1.tvb.com
127.0.0.1 ads.tweakxp.com
127.0.0.1 ads1.tyroo.com
127.0.0.1 ads5.tyroo.com
127.0.0.1 serve.tyroo.com

gatoramanda
2007-04-12, 18:41
# [U]
127.0.0.1 patch2.u88.cn #[McAfee.PWS-Gogo]
127.0.0.1 mde.ubid.com #[RealMedia]
127.0.0.1 ads.ucomics.com #[RealMedia]
127.0.0.1 image.ugo.com
127.0.0.1 mediamgr.ugo.com #[McAfee.Cookie-UGOr]
127.0.0.1 deliver.ads.uigc.net #[RealMedia]
127.0.0.1 creativos.ads.uigc.net
127.0.0.1 ip2k.ads.uigc.net
127.0.0.1 www.ukbanners.com #[IE-SpyAd]
127.0.0.1 file.unionsms.net #[Win32/TrojanDownloader.QQHelper.NAF]
127.0.0.1 universaltoolbar.com #[AdWare.Win32.Simbar.e]
127.0.0.1 www.unlimits.net #[Javascript.Exploit]
127.0.0.1 ads.unlimitedbanners.com #[IE-SpyAd]
127.0.0.1 undertonenetworks.com #[zedo.com][IE-SpyAd]
127.0.0.1 www.undertonenetworks.com
127.0.0.1 managed.unexpand.com
127.0.0.1 update.unexpand.com #[SpamBot]
127.0.0.1 update.unflatten.com
127.0.0.1 ads.unison.ie
127.0.0.1 ads.universia.com.br
127.0.0.1 cyclops.prod.untd.com #[RealMedia]
127.0.0.1 track.untd.com
127.0.0.1 www.update05.com #[eTrust.Win32/Beovens]
127.0.0.1 ads1.updated.com
127.0.0.1 www.uplink.co.kr #[Adware.Uplink]
127.0.0.1 www.up-the-creek.com #[MHTMLRedir.Exploit]
127.0.0.1 upsearch.biz #[go.winantivirus.com][server down?]
127.0.0.1 www.upsearch.biz
127.0.0.1 www.upspiral.com #[Adware.UpSpiralBar]
127.0.0.1 www.urpo.com #[SunBelt.Urpo][IE-SpyAd]
127.0.0.1 banner.usacasino.com
127.0.0.1 usachoice.net #[IE-SpyAd]
127.0.0.1 usamedfarm.biz #[Spamdexing]
127.0.0.1 ads.userfriendly.org #[AdvertPro]
127.0.0.1 adsnew.userfriendly.org
127.0.0.1 www.usersonlinecounter.com
127.0.0.1 ads.ussearch.com
127.0.0.1 www.utarget.co.uk #[utarget Ad code]
127.0.0.1 rotabanner100.utro.ru
127.0.0.1 ads.ux-tm.net
127.0.0.1 hit.ux-tm.net
127.0.0.1 top.ux-tm.net
# [V]
127.0.0.1 beacon.valeoip.com
127.0.0.1 ad.jp.ap.valuecommerce.com
127.0.0.1 ad.valuehost.ru #[IE-SpyAd]
127.0.0.1 publicidad.vocento.com
127.0.0.1 ads.vegas.com
127.0.0.1 ad.vel.pl
127.0.0.1 counters.vendio.com
127.0.0.1 ads.vertele.com
127.0.0.1 www.verticlick.com #[IE-SpyAd]
127.0.0.1 spinbox.versiontracker.com #[McAfee.Cookie-Versiontrack]
127.0.0.1 www.view4cash.de
127.0.0.1 oas.villagevoice.com
127.0.0.1 ringtones-vip.org #[IFrame.Exploit]
127.0.0.1 search-vip.org #[Spamdexing]
127.0.0.1 banners.vipprofits.com
127.0.0.1 www.vistachecker.com #[Backdoor.Toob.B]
127.0.0.1 sniff.visistat.com
127.0.0.1 www.visa-check.net #[Win32/Bifrose.E]
127.0.0.1 vodka-house.com #[Spamdexing]
127.0.0.1 www.voonda.com #[Spyware.TAFbar]
127.0.0.1 ads2.vortexmediagroup.com #[AdvertPro]
127.0.0.1 vote4warez.com
127.0.0.1 www.vstats.net #[IE-SpyAd]
127.0.0.1 sevenc.vze.com #[VBS.Powcox@mm]
# [W]
127.0.0.1 w32-gen.net #[Exploit.HTML.IESlice.d]
127.0.0.1 www.w3exit.com
127.0.0.1 ad.wanderlist.com
127.0.0.1 www.warezenergy.com #[Adware.Begin2search]
127.0.0.1 ng3.ads.warnerbros.com
127.0.0.1 ads.weather.com
127.0.0.1 100webads.com #[IE-SpyAd]
127.0.0.1 adserver.webads.it
127.0.0.1 images.webads.it
127.0.0.1 data.webads.co.nz
127.0.0.1 ad.webadvertising.ch
127.0.0.1 adv.webadvertising.ch
127.0.0.1 nx-adv.webadvertising.ch #[RealMedia]
127.0.0.1 www.web-chart.de
127.0.0.1 blog1000.webcindario.com #[Win32/Spy.Banker.AWA]
127.0.0.1 horoscoponetvirt.webcindario.com #[Win32/Spy.Banker.BFW]
127.0.0.1 voxcartao.webcindario.com #[Win32/Spy.Banker.Big]
127.0.0.1 www.wecounthits.com
127.0.0.1 webcounter.com #[IE-SpyAd]
127.0.0.1 www.webcounter.com
127.0.0.1 banners.webmasterplan.com #[SecuritySpace.WebBug]
127.0.0.1 partners.webmasterplan.com
127.0.0.1 fc.webmasterpro.de
127.0.0.1 adv.webmd.com
127.0.0.1 banner.webmersion.com
127.0.0.1 webhits.de #[IE-SpyAd]
127.0.0.1 stat.webmedia.pl #[IE-SpyAd]
127.0.0.1 bannervip.web1000.com #[IE-SpyAd]
127.0.0.1 ads.webads360.com #[IE-SpyAd]
127.0.0.1 advertpro.webspawner.com
127.0.0.1 img.webring.com #[SecuritySpace.WebBug]
127.0.0.1 img1.webring.com
127.0.0.1 ss.webring.com
127.0.0.1 track.websitetrafficreport.com #[VisitorTrack Code]
127.0.0.1 5623.web-stats.org
127.0.0.1 www.webstat.net
127.0.0.1 www.webstat.se
127.0.0.1 fry.webtistic.com
127.0.0.1 www.webtistic.com #[IE-SpyAd]
127.0.0.1 toolbar.webtoolbars.com #[IE-SpyAd]
127.0.0.1 web-url.de #[SANS.Alert][Trojan.Muldrop]
127.0.0.1 www.web-url.de
127.0.0.1 ad.wedoo.com
127.0.0.1 adserver.wenters.com
127.0.0.1 werew0lf.net #[Trojan-PSW.Win32.LdPinch.bio]
127.0.0.1 www.werew0lf.net
127.0.0.1 www.wethere.com #[lop.com]
127.0.0.1 www.wg1630.com #[Win32/PSW.Legendmir.AVG]
127.0.0.1 partner1.whatsfind.com
127.0.0.1 www.whatsfind.com #[HTML_STARTPAGE.C]
127.0.0.1 oasads.whitepages.com #[RealMedia]
127.0.0.1 whoisonline.net
127.0.0.1 cache.winhundred.com
127.0.0.1 join1.winhundred.com
127.0.0.1 join2.winhundred.com
127.0.0.1 secure.winhundred.com
127.0.0.1 www.winhundred.com #[SiteAdvisor.winhundred.com]
127.0.0.1 window1.com #[IE-SpyAd]
127.0.0.1 ads1.winhelp2002.net
127.0.0.1 top.winrate.net
127.0.0.1 stats.wired.com
127.0.0.1 www.wisecounter.com
127.0.0.1 ads.winsite.com
127.0.0.1 winsoftwareupdate.org #[Trojan.Renver]
127.0.0.1 win-spy.com
127.0.0.1 www.win-spy.com #[eTrust.Win-Spy][Spyware.WinSpy]
127.0.0.1 winstream.com #[Parasite.Searchex]
127.0.0.1 www.winstream.com
127.0.0.1 clicktrack.wnu.com
127.0.0.1 stats.wordpress.com
127.0.0.1 analytics.worldnow.com #[WebBug]
127.0.0.1 www.worldmegasites.com #[eTrust.Win32/Donise][server down?]
127.0.0.1 www.wowchian.com #[Win32/PSW.Lineage.DN][W32.Looked.P]
127.0.0.1 www.wowrelax.com #[Spamdexing]
127.0.0.1 wowsearch.org
127.0.0.1 www.wowsearch.org
127.0.0.1 www.wowweb.net #[Adware.WWWBar]
127.0.0.1 adsearch.wp.pl
127.0.0.1 oas.wwwheise.de #[RealMedia]
127.0.0.1 ad.wz.cz
# [X]
127.0.0.1 xcounters.com
127.0.0.1 a.xcounters.com
127.0.0.1 www.xdol.de #[Win32/Bifrose]
127.0.0.1 www.xexe.info #[MHTMLRedir.Exploit]
127.0.0.1 count.xhit.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 nedstats.xs4all.nl
127.0.0.1 gostosa01.xpg.com.br #[Win32/Spy.Banker.ANV]
127.0.0.1 www.repressaoaocrime.xpg.com.br #[Win32/Spy.Banker.ANV]
127.0.0.1 new.xp-antispyware.com
127.0.0.1 update.xp-antispyware.com #[SpamBot]
127.0.0.1 ads.xtra.co.nz
# [Y]
127.0.0.1 freegames.yaboo.dk #[W32.Guapim]
127.0.0.1 ads.yadio.com
127.0.0.1 dl.yadio.com
127.0.0.1 www.yadio.com
127.0.0.1 ad.yadro.ru #[IE-SpyAd][SpySweeper.Spy.Cookie]
127.0.0.1 counter.yadro.ru #[McAfee.Cookie-Yadro][Panda.Spyware:Cookie/Yadro]
127.0.0.1 bs.yandex.ru #[SecuritySpace.WebBug]
127.0.0.1 www.yandex.ru #[SunBelt.Yandex][Adware.SecureServicePk]
127.0.0.1 ybex.com
127.0.0.1 crsky2004.yeah.net #[Backdoor.Singu.B]
127.0.0.1 yeahsearch.info #[Spamdexing]
127.0.0.1 www.yeahsearch.info
127.0.0.1 www.yfdmedia.com
127.0.0.1 yiqilai.com #[Trojan.Yigather]
127.0.0.1 www.yogakorea.or.kr #[Win32/Spy.Banker.Big]
127.0.0.1 adplus.yonhapnews.co.kr
127.0.0.1 www.yop24.com #[MVPS.Criteria]
127.0.0.1 yourbestresult.com #[JS/Mht.O]
127.0.0.1 www.yourenhancement.com #[eTrust.YourEnhancement][Trojan.Win32.VB.tg]
127.0.0.1 ad.yourmedia.com
127.0.0.1 ad1.yourmedia.com
127.0.0.1 www.yourtracking.net
127.0.0.1 ysearchus.com #[Parasite.TinyBar][SunBelt.TINYBAR]
127.0.0.1 www.ysearchus.com
127.0.0.1 www.y8ne.com #[Exploit.ANI]
127.0.0.1 www.yx2004.com #[AdWare.Win32.WinAD.ab]
127.0.0.1 www.yyc8.com #[Trojan.PWS.Wsgame][Exploit.ANI]
127.0.0.1 www.yyue.com #[TROJ_STARTPAG.OC]
# [Z]
127.0.0.1 ad.zanox.com
127.0.0.1 zanox-affiliate.de
127.0.0.1 www.zanox-affiliate.de
127.0.0.1 www.zapadserver2.com
127.0.0.1 banners.zbs.ru
127.0.0.1 www.zcounter.com
127.0.0.1 www.zhangweijp.com #[Win32/PSW.Lineage.DN]
127.0.0.1 download.zhongsou.com #[Adware.SearchNet]
127.0.0.1 pig.zhongsou.com #[Adware-PigSearch]
127.0.0.1 www.zinanjing.com #[Adware.Zhong]
127.0.0.1 update.znew.org #[SpamBot]
127.0.0.1 counter.zone.ee
127.0.0.1 mp3.zonebg.com #[HJTH.C2Media/LOP variant]
127.0.0.1 bannerads.zwire.com
# [Misc]
127.0.0.1 banner.0catch.com
127.0.0.1 bannerimages.0catch.com #[dist.belnk.com]
127.0.0.1 tarjetas.0catch.com #[Win32/Small.JS]
127.0.0.1 s4.0stats.com
127.0.0.1 www.0stats.com
127.0.0.1 www.060s.com #[Win32/Prosti.C]
127.0.0.1 banner.1and1.com
127.0.0.1 123topsearch.com #[ADSPY/Agent.AP.7]
127.0.0.1 www.11468.com #[W32/Startpage.BZU]
127.0.0.1 www.1mms.net #[Win32/SillyDl.CAS]
127.0.0.1 banner.1und1.com
127.0.0.1 banner.1and1.co.uk
127.0.0.1 123ads.nl
127.0.0.1 www.123hitcounter.com
127.0.0.1 123mania.com #[ADW_123MANIA.A]
127.0.0.1 www.123mania.com #[McAfee.Adware-123mania][Adware.MatrixSearch]
127.0.0.1 123stat.com #[IE-SpyAd]
127.0.0.1 ad2.163.com
127.0.0.1 adclient.163.com
127.0.0.1 images.163.com
127.0.0.1 popme.163.com
127.0.0.1 1234.2bro.com #[Adware.Satbo]
127.0.0.1 count.2ch.net
127.0.0.1 www.20dy.cn #[NOD32.NewHeur_PE]
127.0.0.1 adserv.20six.net
127.0.0.1 ads.24.com
127.0.0.1 www.241hits.com
127.0.0.1 counter.24log.com
127.0.0.1 tmp6.2ch.net #[Trojan.Sufiage]
127.0.0.1 2z0o.net #[Trojan.Popper]
127.0.0.1 pop1.2z0o.net #[admarketplace.net]
127.0.0.1 pop2.2z0o.net #[TROJ_DLOADER.AGS]
127.0.0.1 pop10.2z0o.net
127.0.0.1 req2.2z0o.net #[McAfee.Downloader-ACV]
127.0.0.1 www.369.com #[Adware.LoadEWXD][McAfee.StartPage-JI]
127.0.0.1 www.3d-icons.com #[SiteAdvisor.3d-icons.com]
127.0.0.1 www.3deepspace.com #[SiteAdvisor.3deepspace.com]
127.0.0.1 www.3241.com #[Troj/Zikdow-B]
127.0.0.1 guannan.3322.net #[IE-SpyAd]
127.0.0.1 jietyu007.3322.org #[Trojan.Agentdoc.C]
127.0.0.1 localhosts.3322.org #[Win32/Ginwui]
127.0.0.1 rxjhgsta.3322.org #[Trojan.Agentdoc.B]
127.0.0.1 sina109.3322.org #[Win32/Hupigon]
127.0.0.1 sysrec.3322.org #[Backdoor.Scarycrow][server down?]
127.0.0.1 download.35mb.com #[impregnable.net]
127.0.0.1 static.35mb.com #[HJTH.Win32.IstBar.fa]
127.0.0.1 www.35mb.com #[HJTH.MediaTickets Installer]
127.0.0.1 ad.37.com
127.0.0.1 4affiliate.net
127.0.0.1 www.40best.com #[HJTH.C2Media/LOP variant]
127.0.0.1 adserver.4clicks.org
127.0.0.1 r.4at1.com
127.0.0.1 banners.4d5.net
127.0.0.1 ad.stat.4u.pl
127.0.0.1 adstat.4u.pl
127.0.0.1 www.40drinks.net #[Trojan-Spy.Win32.Banker.ark]
127.0.0.1 41m.com #[HJTH.XXXToolbar Variant][Trojan.Clicker.BL]
127.0.0.1 msncheck.41m.com
127.0.0.1 www.41m.com
127.0.0.1 www.4yousearch.com #[Spamdexing]
127.0.0.1 www.4061.it #[Win32/Haxdoor]
127.0.0.1 www.475100.com #[Trojan.IEmax]
127.0.0.1 softads.50webs.com
127.0.0.1 www.51.com #[Backdoor.CVM]
127.0.0.1 count3.51yes.com
127.0.0.1 count8.51yes.com
127.0.0.1 count12.51yes.com
127.0.0.1 count24.51yes.com
127.0.0.1 www.54699.com #[Win32/Viking.AD]
127.0.0.1 www.ff.iij4u.or.jp #[Trojan.Upchan]
127.0.0.1 65552322.com
127.0.0.1 ads.7days.ae
127.0.0.1 www.702284.com #[Win32/PSW.Legendmir.AVG]
127.0.0.1 ad.71i.de
127.0.0.1 adserver.71i.de
127.0.0.1 7oo.meibu.com #[McAfee.BackDoor-CKB]
127.0.0.1 www.7939.com #[TROJ_DELF.CNV]
127.0.0.1 mydown.79725.com #[McAfee.Downloader-AZN]
127.0.0.1 soswxyz.8800.org #[Trojan.Riler.F]
127.0.0.1 888-it.com #[AdWare.Win32.Casino.q]
127.0.0.1 www.888-it.com
127.0.0.1 ajim.delphibbs.com #[Trojan.PSW.Ajim_bbs]
127.0.0.1 banners.dot.tk
127.0.0.1 www.9000music.com #[TR/Dldr.Small.dix]
127.0.0.1 imkill.98link.com #[TR/KillAV.AV.1]
127.0.0.1 popwin.9983.com #[Trojan.Popwin][TR/Agent.NFE]
127.0.0.1 web.9983.com #[McAfee.StartPage-JE]
127.0.0.1 www.9991.com #[Backdoor.CVM][Adware.PPRich]
127.0.0.1 www.999x.com #[Backdoor.CVM]
127.0.0.1 www.9ringtone.com
127.0.0.1 www.18hi.net #[McAfee.StartPage-HR]
127.0.0.1 www.19ku.com #[McAfee.StartPage-HR]
127.0.0.1 10000hits.net #[IE-SpyAd][SunBelt.Cookie.10000hits]
# [123Banners][123Greetings.com][TROJ_NALDEM.A][Trojan.Naldem]
127.0.0.1 www.123banners.com
127.0.0.1 ftp.123banners.com
127.0.0.1 123go.com
127.0.0.1 ns1.123go.net
# [180Solutions][CDT Inc][Zango Canada]
127.0.0.1 180solutions.com
127.0.0.1 ads.180solutions.com
127.0.0.1 ax.180solutions.com #[HJTH.nCase Variant]
127.0.0.1 bis.180solutions.com #[ADW_SOLU180.F]
127.0.0.1 config.180solutions.com #[eTrust.180SearchAssistant]
127.0.0.1 cts.180solutions.com
127.0.0.1 downloads.180solutions.com #[McAfee.Adware-ZangoSA.dldr]
127.0.0.1 his.180solutions.com
127.0.0.1 installs.180solutions.com
127.0.0.1 ping.180solutions.com
127.0.0.1 tv.180solutions.com
127.0.0.1 tvf.180solutions.com
127.0.0.1 www.180solutions.com #[Parasite.nCase]
127.0.0.1 www.180solutions.net
127.0.0.1 infinity.180searchassistant.com #[ADW_SOLU180.H]
127.0.0.1 msxml.180searchassistant.com #[msxml.infospace.com]
127.0.0.1 powered-by.180searchassistant.com
127.0.0.1 searchresults.180searchassistant.com
127.0.0.1 www.180searchassistant.com #[Adware.180Search]
127.0.0.1 www.abcfreedownloads.com
127.0.0.1 www.abcfreegames.com
127.0.0.1 www.captioncity.com #[server down?]
127.0.0.1 freegamesclub.com
127.0.0.1 www.fullarmorstudios.com
127.0.0.1 www.games4good.net
127.0.0.1 content.licenseacquisition.org #[Troj/QLowZon-EV]
127.0.0.1 drm.licenseacquisition.org #[Zango Canada]
127.0.0.1 media.licenseacquisition.org #[IE-SpyAd]
127.0.0.1 origin-cached.licenseacquisition.org
127.0.0.1 preview.licenseacquisition.org
127.0.0.1 loudcash.com
127.0.0.1 partners.loudcash.com
127.0.0.1 www.loudcash.com
127.0.0.1 metricsdirect.com
127.0.0.1 ads.metricsdirect.com
127.0.0.1 cts.metricsdirect.com
127.0.0.1 reports.metricsdirect.com
127.0.0.1 www.metricsdirect.com
127.0.0.1 www.myfreegamedownloads.com
127.0.0.1 n-case.com
127.0.0.1 www.n-case.com #[Panda.Adware/nCase]
127.0.0.1 page-not-found.org
127.0.0.1 search.prositefinder.com #[SunBelt.bho.180Solutions.ProSiteFinder]
127.0.0.1 seekmo.com #[Adware.180Solutions.SearchAssistant]
127.0.0.1 config.seekmo.com
127.0.0.1 cts.seekmo.com
127.0.0.1 downloads.seekmo.com
127.0.0.1 installs.seekmo.com
127.0.0.1 powered-by.seekmo.com
127.0.0.1 tvf.seekmo.com
127.0.0.1 allofthevideos.powered-by.seekmo.com
127.0.0.1 freeblowjobmovies.powered-by.seekmo.com
127.0.0.1 freeblowjobvideos.powered-by.seekmo.com
127.0.0.1 funberry.powered-by.seekmo.com
127.0.0.1 keyrastriptease.powered-by.seekmo.com
127.0.0.1 male-celeb-videos.powered-by.seekmo.com
127.0.0.1 pariswallpapers.powered-by.seekmo.com #[WildcardDNS]
127.0.0.1 slutmatrixfree.powered-by.seekmo.com
127.0.0.1 wallpapernudes.powered-by.seekmo.com
127.0.0.1 tv.seekmo.com #[MVPS.Criteria]
127.0.0.1 www.seekmo.com
127.0.0.1 tons-of-free-downloads.com
127.0.0.1 tons-of-free-games.com
127.0.0.1 www.tonsoffreedownloads.com
127.0.0.1 www.tonsoffreegames.com
127.0.0.1 www.totallycoolfreedownloads.com
127.0.0.1 www.totallyfreeadultstuff.com
127.0.0.1 www.totallyfreeadultvideos.com
127.0.0.1 totallyfunfreegames.com
127.0.0.1 www.totallyfunfreegames.com
127.0.0.1 white.totallyfunfreestuff.com
127.0.0.1 www.totallyfunfreestuff.com
127.0.0.1 winadclient.com
127.0.0.1 eula.winadclient.com
127.0.0.1 www.winadclient.com
127.0.0.1 windupdates.com #[Adware.WinTaskAd][Trojan.TrustedZones]
127.0.0.1 public.windupdates.com #[Windows SyncroAd]
127.0.0.1 static.windupdates.com #[ADW_WUPD.F][ADW_WINSTATX.A]
127.0.0.1 www.windupdates.com #[AdvWare.WinAD][ADSPY/WiAD.AF.1]
127.0.0.1 zango.com
127.0.0.1 cds.zango.com
127.0.0.1 acces.powered-by.zango.com
127.0.0.1 animeim.powered-by.zango.com
127.0.0.1 annakournikova.powered-by.zango.com
127.0.0.1 clickpixcursors.powered-by.zango.com
127.0.0.1 coolvuurwerk.powered-by.zango.com
127.0.0.1 dane-cook.powered-by.zango.com
127.0.0.1 davesemu.com.powered-by.zango.com
127.0.0.1 deansplanet.com.powered-by.zango.com #[WildcardDNS]
127.0.0.1 factorygames.powered-by.zango.com
127.0.0.1 fightvideos.powered-by.zango.com
127.0.0.1 fightvids.powered-by.zango.com
127.0.0.1 flashaddictinggames.powered-by.zango.com
127.0.0.1 frazoogames.powered-by.zango.com
127.0.0.1 free.karaoke.songs.powered-by.zango.com
127.0.0.1 freesudokus.powered-by.zango.com
127.0.0.1 freetoplay.ath.cx.powered-by.zango.com
127.0.0.1 games.byethost32.powered-by.zango.com
127.0.0.1 gate1.powered-by.zango.com
127.0.0.1 gate2.powered-by.zango.com
127.0.0.1 gate3.powered-by.zango.com
127.0.0.1 gate4.powered-by.zango.com
127.0.0.1 gate5.powered-by.zango.com
127.0.0.1 gate6.powered-by.zango.com
127.0.0.1 gate7.powered-by.zango.com
127.0.0.1 gate8.powered-by.zango.com
127.0.0.1 gate9.powered-by.zango.com
127.0.0.1 gate10.powered-by.zango.com
127.0.0.1 gate11.powered-by.zango.com
127.0.0.1 gate12.powered-by.zango.com
127.0.0.1 gauntletvideos.powered-by.zango.com
127.0.0.1 getmusicvideocodes.powered-by.zango.com
127.0.0.1 graffitifonts.powered-by.zango.com #[Wildcard DNS]
127.0.0.1 hot-lindsay.powered-by.zango.com
127.0.0.1 iconcave.powered-by.zango.com
127.0.0.1 idrink.powered-by.zango.com
127.0.0.1 lavacards.powered-by.zango.com
127.0.0.1 martinahingis.powered-by.zango.com
127.0.0.1 maratsafin.powered-by.zango.com
127.0.0.1 mediagecko.powered-by.zango.com
127.0.0.1 midis.powered-by.zango.com
127.0.0.1 mmocenter.org.powered-by.zango.com
127.0.0.1 musicvideocodes.powered-by.zango.com
127.0.0.1 mvcodezone.powered-by.zango.com
127.0.0.1 mydisplayimage.powered-by.zango.com
127.0.0.1 myfriendspy.powered-by.zango.com
127.0.0.1 mymoneymakers.powered-by.zango.com
127.0.0.1 myspace.powered-by.zango.com
127.0.0.1 myspace-backgrounds.powered-by.zango.com
127.0.0.1 myspace-codes.powered-by.zango.com
127.0.0.1 myspacegraphics.powered-by.zango.com
127.0.0.1 myspacegraphicsx.powered-by.zango.com
127.0.0.1 myspaceicons.powered-by.zango.com
127.0.0.1 myspaceiconsorg.powered-by.zango.com
127.0.0.1 myspacelayouts.powered-by.zango.com
127.0.0.1 mytop12.com.powered-by.zango.com
127.0.0.1 narutowallpaper.powered-by.zango.com
127.0.0.1 newgrounds.dressup.powered-by.zango.com
127.0.0.1 pbxanime.powered-by.zango.com
127.0.0.1 people2people.powered-by.zango.com
127.0.0.1 phoenixpeople.powered-by.zango.com
127.0.0.1 planet.nana.co.il.powered-by.zango.com
127.0.0.1 pokemonporn.powered-by.zango.com
127.0.0.1 screensaverparadise.powered-by.zango.com
127.0.0.1 sfondigratis.powered-by.zango.com
127.0.0.1 stacy-keibler-pictures.powered-by.zango.com
127.0.0.1 snapshot.powered-by.zango.com
127.0.0.1 theamazingracist.powered-by.zango.com
127.0.0.1 trenchracing.powered-by.zango.com
127.0.0.1 vcc.powered-by.zango.com
127.0.0.1 vimalonline.powered-by.zango.com
127.0.0.1 videocodesworld.powered-by.zango.com
127.0.0.1 whatsthatcode.com.powered-by.zango.com
127.0.0.1 wwedivas.powered-by.zango.com
127.0.0.1 xtreme-cheats.powered-by.zango.com
127.0.0.1 downloads.zango.com #[SunBelt.180Solutions.Zango.TVTimes]
127.0.0.1 games.zango.com #[SunBelt.Adw.Zango.Solitaire]
127.0.0.1 imp.games.zango.com
127.0.0.1 lp.zango.com #[McAfee.Adware-ZangoSA]
127.0.0.1 messenger.zango.com
127.0.0.1 msxml.zango.com #[msxml.infospace.com]
127.0.0.1 partner.zango.com
127.0.0.1 powered-by.zango.com
127.0.0.1 shared.zango.com
127.0.0.1 showtimes.zango.com #[SpySweeper.180search assistant/zango]
127.0.0.1 sitefinder.zango.com #[zangositefinder.simpli.com]
127.0.0.1 tv.zango.com
127.0.0.1 www.zango.com #[Adware.ZangoSearch]
127.0.0.1 zangocash.com #[SiteAdvisor.zangocash.com]
127.0.0.1 partner.zangocash.com
127.0.0.1 prompt.zangocash.com #[eTrust.Win32/Anyhomb.D]
127.0.0.1 public.zangocash.com
127.0.0.1 static.zangocash.com #[CVE-2006-2324][Troj/QLowZon-EV]
127.0.0.1 syndication.zangocash.com
127.0.0.1 www.zangogames.com
127.0.0.1 www.zangomessenger.com
127.0.0.1 www.zangopartner.com
127.0.0.1 www.zangopartner.net
# [2KDirect]
127.0.0.1 www.gms1.net #[McAfee.Adware-IEHost]
127.0.0.1 geo.precisionclick.com
127.0.0.1 servedby.precisionclick.com

gatoramanda
2007-04-12, 18:43
# [3721.COM][Yahoo]
127.0.0.1 cnsmin.3721.com
127.0.0.1 download.3721.com #[McAfee.Adware-BDSearch]
127.0.0.1 www.3721.com #[Adware.Chinet][ADW_CNSMIN.A]
127.0.0.1 count.3721.yahoo.com
# [411 Web Directory]
127.0.0.1 ad.411web.com
127.0.0.1 adtracker.411web.com
127.0.0.1 hits.411web.com
127.0.0.1 overture.411web.com
127.0.0.1 search.411web.com
127.0.0.1 static.411web.com
127.0.0.1 xml.411web.com
127.0.0.1 www.411web.com
127.0.0.1 search.letssearch.com
127.0.0.1 www.letssearch.com #[BrowserAid.LetsSearch]
# [7Search.com Networks][EMERgency 24, Inc]
127.0.0.1 7search.com #[Parasite.7FaSSt Search]
127.0.0.1 fstrack.7search.com
127.0.0.1 ia1.7search.com
127.0.0.1 mainws2.7search.com
127.0.0.1 meta.7search.com
127.0.0.1 impression.7search.com
127.0.0.1 www.7search.com #[Spyware.SevenSearch]
127.0.0.1 77search.com #[IE-SpyAd]
127.0.0.1 img.7meta.com
127.0.0.1 www.7metasearch.com
127.0.0.1 www.a1fax.com
127.0.0.1 adtactics.com #[IE-SpyAd]
127.0.0.1 bannerx.adtactics.com
127.0.0.1 www.adtactics.com
127.0.0.1 advertisingagent.com
127.0.0.1 ajokeaday.com #[IE-SpyAd]
127.0.0.1 bannersxchange.com
127.0.0.1 img.bannersxchange.com #[IE-SpyAd]
127.0.0.1 www.bannersxchange.com
127.0.0.1 bestsearch.com
127.0.0.1 scripts.bestsearch.com
127.0.0.1 www.bestsearch.com
127.0.0.1 browseraccelerator.com #[Spyware.BrowserAccel]
127.0.0.1 data.browseraccelerator.com
127.0.0.1 download.browseraccelerator.com
127.0.0.1 client.browseraccelerator.com
127.0.0.1 www.browseraccelerator.com #[IE-SpyAd]
127.0.0.1 www.buscamundo.com
127.0.0.1 internetsecurity.com
127.0.0.1 www.internetsecurity.com
127.0.0.1 www.payperranking.com
127.0.0.1 www.pay-per-search.com
127.0.0.1 paypertext.com
127.0.0.1 predictivesearch.com
127.0.0.1 seal.ranking.com
127.0.0.1 www.ranking.com
127.0.0.1 tracking.roispy.com #[IE-SpyAd]
127.0.0.1 www.roispy.com #[SunBelt.ROISpy.com]
127.0.0.1 ftp.sevenmetasearch.com
127.0.0.1 www.sevenmetasearch.com
127.0.0.1 tracking.spiderbait.com
127.0.0.1 www.spiderbait.com
127.0.0.1 www.textadvertising.com
127.0.0.1 www.thetop10.com
127.0.0.1 trustgauge.com
127.0.0.1 www.trustgauge.com
127.0.0.1 seal.validatedsite.com
127.0.0.1 www.validatedsite.com
127.0.0.1 www.watch24.com
# [About.com]
127.0.0.1 clicks.about.com
127.0.0.1 f.about.com
127.0.0.1 home.about.com
127.0.0.1 images.about.com
127.0.0.1 lunafetch.about.com
127.0.0.1 pixel3.about.com
127.0.0.1 sprinks-clicks.about.com
127.0.0.1 statistics.s5.com
127.0.0.1 ad.aboutwebservices.com
# [AboveNet Communications][IE-SpyAd]
127.0.0.1 btn.clickability.com
127.0.0.1 button.clickability.com #[Wildcard DNS]
127.0.0.1 cas.clickability.com
127.0.0.1 imp.clickability.com
127.0.0.1 ri.clickability.com #[SunBelt.Clickability.com]
127.0.0.1 s.clickability.com
127.0.0.1 sftp.clickability.com #[Tenebril.Tracking Cookie]
127.0.0.1 stats.clickability.com #[eTrust.Tracking Cookie]
# [Accipiter Solutions][IE-SpyAd]
127.0.0.1 ad101com.adbureau.net #[a900.g.akamai.net]
127.0.0.1 ad101com-images.adbureau.net #[Ad-Aware.Tracking Cookie]
127.0.0.1 adops.adbureau.net
127.0.0.1 capitali-images.adbureau.net #[a900.g.akamai.net]
127.0.0.1 cent.adbureau.net
127.0.0.1 creview.adbureau.net
127.0.0.1 creview-images.adbureau.net #[a900.g.akamai.net]
127.0.0.1 devart.adbureau.net
127.0.0.1 divx.adbureau.net
127.0.0.1 dnsstuff.adbureau.net
127.0.0.1 granada.adbureau.net
127.0.0.1 granada-images.adbureau.net
127.0.0.1 haynet-images.adbureau.net
127.0.0.1 ieee.adbureau.net
127.0.0.1 ieee-images.adbureau.net
127.0.0.1 imediac.adbureau.net
127.0.0.1 inl.adbureau.net
127.0.0.1 katu.adbureau.net
127.0.0.1 mediapst.adbureau.net
127.0.0.1 ozone-images.adbureau.net
127.0.0.1 pntm.adbureau.net
127.0.0.1 sixapart.adbureau.net
127.0.0.1 splendid.adbureau.net
127.0.0.1 sportsad.adbureau.net
127.0.0.1 studenti.adbureau.net
127.0.0.1 tripadv-images.adbureau.net
127.0.0.1 videoegg.adbureau.net
127.0.0.1 vmix.adbureau.net
127.0.0.1 vpoint-images.adbureau.net
127.0.0.1 www.adbureau.net
# [Accoona Corp]
127.0.0.1 www.accoona.cn
127.0.0.1 search.accoona.com
127.0.0.1 www.accoona.com #[Adware-Accoona][Adware.Atoolb][Panda.Accoona]
127.0.0.1 www.accoonachess.com
# [Acez Software][Adware-NuggetSearch.dr]
127.0.0.1 s1.acez.com
127.0.0.1 www.acez.com #[AdWare.BHO.MegaSearch.b][SiteAdvisor.acez.com]
127.0.0.1 www.acezsoftware.com
127.0.0.1 www.searchnugget.com #[Adware.SearchNugget]
127.0.0.1 www.screengizmos.com
127.0.0.1 www.siteerror.com #[siteError.dll]
# [AdBrite, Inc]
127.0.0.1 adbrite.com #[Ewido.TrackingCookie.Adbrite]
127.0.0.1 1.adbrite.com
127.0.0.1 2.adbrite.com #[SiteAdvisor.findwhatevernow.com]
127.0.0.1 3.adbrite.com
127.0.0.1 4.adbrite.com
127.0.0.1 ads.adbrite.com
127.0.0.1 click.adbrite.com
127.0.0.1 files.adbrite.com
127.0.0.1 site.www.adbrite.com
127.0.0.1 stats.adbrite.com
127.0.0.1 www.adbrite.com
127.0.0.1 www.avnads.com
127.0.0.1 1.httpads.com #[1adbrite.adbrite.com.akadns.net]
127.0.0.1 1.marketbanker.com #[IE-SpyAd]
127.0.0.1 2.marketbanker.com
127.0.0.1 www.marketbanker.com
# [Adknowledge]
127.0.0.1 adsvr.adknowledge.com #[IE-SpyAd]
127.0.0.1 bidsystem.adknowledge.com
127.0.0.1 web.adknowledge.com #[McAfee.Cookie-Adknowledge]
127.0.0.1 ak1.cc
127.0.0.1 dyn.ak1.cc
127.0.0.1 app.desktop.ak-networks.com #[aklsp.dll][TrojanDownloader.Win32.Agent.br]
127.0.0.1 updates.desktop.ak-networks.com
127.0.0.1 vlogic.ak-networks.com #[lspak.dll]
# [AdOrigin Corp][IE-SpyAd]
127.0.0.1 ads.adorigin.com #[SpySweeper.Spy.Cookie]
127.0.0.1 dev.adorigin.com
127.0.0.1 servedby.adorigin.com
127.0.0.1 www.adorigin.com #[Ewido.TrackingCookie.Adorigin]
127.0.0.1 blowsearch.com #[SunBelt.BlowSearch.com]
127.0.0.1 msxml.blowsearch.com
127.0.0.1 web.blowsearch.com #[infospace.com]
127.0.0.1 www.blowsearch.com #[Tenebril.Tracking Cookie]
# [ADSoft][Hot Lab][ADSoft-Development]
127.0.0.1 www.1-viagra-on-line.com
127.0.0.1 www.all-casinos.org
127.0.0.1 www.all-lyrics.org
127.0.0.1 www.best-poker.biz
127.0.0.1 www.chenjesu.com
127.0.0.1 halflemon.com #[Adware.HalfLemon][Trojan.Win32.StartPage.ya]
127.0.0.1 www.halflemon.com #[HJTH.HalfLemon Search Hijacker]
127.0.0.1 www.spycounter.net
127.0.0.1 www-start-page.com #[Adware.HalfLemon]
127.0.0.1 www.www-start-page.com #[Trojan.Win32.StartPage.ya]
127.0.0.1 www.start-page.net
127.0.0.1 www.start-page.org
127.0.0.1 the-roulette.net
127.0.0.1 www.usa-phendimetrazine.com
127.0.0.1 www.x-stats.info #[Spamdexing]
# [Ad-Souk AdServer]
127.0.0.1 www.ad-souk.com #[IE-SpyAd]
127.0.0.1 bilbob.com
127.0.0.1 didtal.com
127.0.0.1 quinst.com
# [Adteractive][IE-SpyAd]
127.0.0.1 cb.adprofile.net
127.0.0.1 content.adprofile.net
127.0.0.1 tx.adprofile.net
127.0.0.1 w2-ver.adprofile.net #[SpySweeper.Spy.Cookie]
127.0.0.1 adteractive.com
127.0.0.1 www.adteractive.com
127.0.0.1 icc.intellisrv.net
# [Adtegrity.com, Inc][IE-SpyAd]
127.0.0.1 adtegrity.com
127.0.0.1 www.adtegrity.com
127.0.0.1 webalize.com #[SearchCentrix][VisiCom.SearchCentric]
127.0.0.1 www.webalize.com #[Visicom Media Toolbar]
127.0.0.1 webalize.net
127.0.0.1 www.webalize.net
127.0.0.1 webalize.mygeek.com
# [Adtomi]
127.0.0.1 adtomi.com
127.0.0.1 ads.adtomi.com #[IE-SpyAd][ADW_ADTOMI.D]
127.0.0.1 www.adtomi.com #[Adware.Adtomi]
# [AdvertPro][Renegade Internet]
127.0.0.1 800comm.advertserve.com
127.0.0.1 aalbc.advertserve.com
127.0.0.1 adpowerzone.advertserve.com #[Whios.Blacklisted]
127.0.0.1 bayoubuzz.advertserve.com
127.0.0.1 candlefind.advertserve.com
127.0.0.1 circuit.advertserve.com
127.0.0.1 d2.advertserve.com
127.0.0.1 divavillage.advertserve.com
127.0.0.1 ecnext.advertserve.com
127.0.0.1 endi.advertserve.com
127.0.0.1 ergoweb.advertserve.com #[server down?]
127.0.0.1 findbliss.advertserve.com
127.0.0.1 fishandfly.advertserve.com
127.0.0.1 fx-charts.advertserve.com
127.0.0.1 gazetteextra.advertserve.com
127.0.0.1 glide.advertserve.com
127.0.0.1 himss.advertserve.com
127.0.0.1 ipt.advertserve.com
127.0.0.1 ipt-ltd.advertserve.com
127.0.0.1 iresources.advertserve.com
127.0.0.1 lan.advertserve.com
127.0.0.1 medbanner.advertserve.com
127.0.0.1 monstersandcritics.advertserve.com
127.0.0.1 musictowers.advertserve.com
127.0.0.1 observer.advertserve.com
127.0.0.1 oppknocks.advertserve.com
127.0.0.1 projectorreviews.advertserve.com
127.0.0.1 smartcpc.advertserve.com
127.0.0.1 switzerland.advertserve.com
127.0.0.1 topica.advertserve.com
127.0.0.1 tradearabia.advertserve.com
127.0.0.1 trucking.advertserve.com
127.0.0.1 unleash.advertserve.com
127.0.0.1 www.advertserve.com
# [Alex Walter][Spectre][4F8 Networks][Xyfex]
127.0.0.1 install.007guard.com
127.0.0.1 download.007guard.com #[007installer Control]
127.0.0.1 the.007guard.com
127.0.0.1 www.007guard.com #[SiteAdvisor.007guard.com]
127.0.0.1 2search.org #[Adware.2Search][eTrust.2Search]
127.0.0.1 feeds.2search.org
127.0.0.1 feeds2.2search.org #[McAfee.Adware-2Search.dr]
127.0.0.1 www.2search.org #[clickheretofind.com]
127.0.0.1 www.fake-mailer.com #[Trojan-Downloader.Win32.TSUpdate.o]
127.0.0.1 hotmsnnames.com #[Adware bundler]
127.0.0.1 emoticons.hotmsnnames.com
127.0.0.1 www.hotmsnnames.com
127.0.0.1 www.hottestgames.net
127.0.0.1 www.im-names.com #[Adware.IMNames]
127.0.0.1 www.msgr-names.com #[Win32/Adware.2Search]
127.0.0.1 adserver.shizzlehost.com
127.0.0.1 domains.shizzlehost.com
127.0.0.1 www.shizzlelyrics.com
127.0.0.1 www.shizzletraffic.com
127.0.0.1 webmasterz.biz
127.0.0.1 www.webmasterz.biz
127.0.0.1 www.xyfex.com
# [AlmondNet Ltd Group][Zeno Tecnico S.A][Think-Adz]
127.0.0.1 getsudoku4free.com #[AdWare.Win32.ZenoSearch.d]
127.0.0.1 www.getsudoku4free.com
127.0.0.1 ads.pro-market.net #[SpySweeper.Spy.Cookie][a1947.x.akamai.net]
127.0.0.1 pbid.pro-market.net
127.0.0.1 www.think-adz2.com
127.0.0.1 www.zenotecnico2.com #[IE-SpyAd]
# [Asher Nahmias]
127.0.0.1 clickyestoenter.net #[Parked.redirect]
127.0.0.1 www.clickyestoenter.net
127.0.0.1 gocybersearch.com
127.0.0.1 www.gocybersearch.com
127.0.0.1 hotpopup.com
127.0.0.1 search.hotpopup.com
127.0.0.1 www.hotpopup.com
127.0.0.1 hotsearchbox.com #[JAVA_STARTPAGE.F]
127.0.0.1 www.hotsearchbox.com
127.0.0.1 i--search.com #[SunBelt.SearchUpgrade]
127.0.0.1 www.i--search.com #[StartPage-FN]
127.0.0.1 jethomepage.com #[JS.Exception.Exploit]
127.0.0.1 www.jethomepage.com #[Troj/JetHome-B]
127.0.0.1 jetseeker.com #[CWS.Bootconf]
127.0.0.1 www.jetseeker.com
127.0.0.1 searchxl.com #[Adware.ZeroPopUpBar]
127.0.0.1 www.searchxl.com
127.0.0.1 tinybar.com
127.0.0.1 www.tinybar.com #[Parasite.TinyBar]
127.0.0.1 topsearcher.com #[JV/Goplanet]
127.0.0.1 www.topsearcher.com #[Troj/JetHome-J]
127.0.0.1 zeropopup.com #[Parasite.ZeroPopUp]
127.0.0.1 www.zeropopup.com #[Tellafriend.Trojan]
127.0.0.1 znext.com #[JS_TRAFFICHBAR.A][Parasite.TinyBar]
127.0.0.1 www.znext.com #[Parasite.ZeroPopUp][App/P0P-A]
# [AD TECH AG][Adtech.de][IE-SpyAd]
127.0.0.1 adtech.de #[Ad-Aware.Tracking Cookie]
127.0.0.1 adforce.adtech.de
127.0.0.1 adserver.adtech.de #[ADTECH Group JavaScript TAG]
127.0.0.1 im.adtech.de
127.0.0.1 imageserv.adtech.de
127.0.0.1 img-pcdn.adtech.de #[g1.panthercdn.com]
127.0.0.1 livingnet.adtech.de #[McAfee.Cookie-Adtech]
127.0.0.1 x86adserv001.adtech.de
127.0.0.1 x86adserv002.adtech.de
127.0.0.1 x86adserv003.adtech.de #[SunBelt.Adtech.de]
127.0.0.1 x86adserv004.adtech.de
127.0.0.1 x86adserv005.adtech.de
127.0.0.1 x86adserv006.adtech.de
127.0.0.1 x86adserv007.adtech.de #[Kephyr.PUP]
127.0.0.1 x86adserv008.adtech.de
127.0.0.1 x86adserv009.adtech.de
127.0.0.1 x86adserv010.adtech.de
127.0.0.1 x86adserv011.adtech.de #[MVPS.Criteria]
127.0.0.1 x86adserv012.adtech.de
127.0.0.1 x86adserv013.adtech.de
127.0.0.1 x86adserv014.adtech.de
127.0.0.1 x86adserv015.adtech.de #[Ewido.Spyware.Cookie.Adtech]
127.0.0.1 x86adserv016.adtech.de
127.0.0.1 x86adserv017.adtech.de
127.0.0.1 x86adserv018.adtech.de
127.0.0.1 adserver.adremedy.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 adserver.easyad.info
# [Advertising.com][AOL][IE-SpyAd]
127.0.0.1 cdn1.adsdk.com
127.0.0.1 cdn2.adsdk.com #[a1906.g.akamai.net][VirtualBouncer]
127.0.0.1 advertising.com
127.0.0.1 adserve.advertising.com
127.0.0.1 bannerfarm.ace.advertising.com #[Tenebril.Tracking Cookie]
127.0.0.1 dbs.advertising.com
127.0.0.1 demo.advertising.com
127.0.0.1 leadback.advertising.com #[adv.service.mirror-image.net]
127.0.0.1 opera1-servedby.advertising.com
127.0.0.1 secure.leadback.advertising.com #[adv.service.mirror-image.net]
127.0.0.1 servedby.advertising.com #[eTrust.Tracking Cookie]
127.0.0.1 rd.advertising.com
127.0.0.1 wap.advertising.com
127.0.0.1 www.advertising.com #[Ewido.Spyware.Cookie.Advertising]
127.0.0.1 clk4.com
127.0.0.1 dev.clk4.com
127.0.0.1 www.clk4.com
127.0.0.1 www.contextualclicks.com
127.0.0.1 fastseeker.com #[Adware.FastSeek]
127.0.0.1 www.fastseeker.com
127.0.0.1 bf.mocda1.com
127.0.0.1 spyblast.com #[SiteAdvisor.spyblast.com]
127.0.0.1 www.spyblast.com #[Rogue/Suspect]
127.0.0.1 www.thesearchster.com
# [Affiliation Networks][Tracking Service]
127.0.0.1 ads.ign.com #[McAfee.Cookie-IGN]
127.0.0.1 t.ign.com
127.0.0.1 tracker.ign.com
127.0.0.1 adserver.snowball.com
127.0.0.1 polls.snowball.com
127.0.0.1 t.snowball.com
127.0.0.1 tracker.snowball.com
# [Aleksej Novikov]
127.0.0.1 rotor6.newzfind.com
127.0.0.1 sutra.newzfind.com
# [Alex Korsakoff]
127.0.0.1 7art-screensavers.com #[AdWare.Win32.NavExcel.d]
127.0.0.1 flowers.7art-screensavers.com
127.0.0.1 www.7art-screensavers.com
127.0.0.1 silveragesoftware.com #[SiteAdvisor.silveragesoftware.com]
127.0.0.1 www.silveragesoftware.com
# [Alexej Rostaslavovitch]
127.0.0.1 www.crazygirls-world.com #[the-best-promos.com]
127.0.0.1 www.gad-network.com
127.0.0.1 www.games-desktop.com #[akamai.downloadv3.com]
127.0.0.1 www.go-astro.com #[Backdoor.Win32.Iroffer.Z]
127.0.0.1 www.go-turf.com
127.0.0.1 www.gomusic.com
127.0.0.1 www.gorecord.com
127.0.0.1 www.goremania.com #[the-best-promos.com]
127.0.0.1 www.hot-tv.com #[Win32/Skintrim!]
127.0.0.1 www.internetgamebox.com #[Backdoor.Win32.Iroffer.Z]
127.0.0.1 www.lastsoftwares.com #[zipzappromos.com]
127.0.0.1 www.mail-skinner.com
127.0.0.1 www.mailskinner.com #[Backdoor.Win32.Iroffer.Z][Trojan.Skintrim]
127.0.0.1 www.navi-recherche.com
127.0.0.1 www.navi-search.com
127.0.0.1 www.serialplayers.com #[the-best-promos.com]
127.0.0.1 www.sudoplanet.com #[Win32/Skintrim!]
127.0.0.1 www.web-mediaplayer.com #[Backdoor.Win32.Iroffer.Z]
127.0.0.1 www.videozapping.com
# [Altnet][Adware.BDE][Adware.Topsearch.B]
127.0.0.1 altnet.com
127.0.0.1 file.altnet.com
127.0.0.1 media.altnet.com
127.0.0.1 ts.altnet.com
127.0.0.1 tss.altnet.com
127.0.0.1 pm.altnet.com
127.0.0.1 www.altnet.com #[ADW_ALTNET.A]
127.0.0.1 www.altnetp2p.com
127.0.0.1 brilliantdigital.com #[Parasite.BDE]
127.0.0.1 st.brilliantdigital.com
127.0.0.1 www.brilliantdigital.com #[TROJ_KREPPER.Y]
127.0.0.1 b3d.com
127.0.0.1 bde3d.com
127.0.0.1 www.b3d.com
# [Andreas Pizsa]
127.0.0.1 www.behind-firewall.com #[AdWare.Win32.WebHancer.320]
127.0.0.1 www.bypass-censorship.com
127.0.0.1 www.firewall-tunnel.com
127.0.0.1 www.free-proxy.org
127.0.0.1 www.get-around-firwall.com
127.0.0.1 www.hide-ip.com
127.0.0.1 www.hopster.com #[AdWare.Win32.WebHancer.320]
127.0.0.1 www.http-proxy.com
127.0.0.1 www.http-tunnel.org
127.0.0.1 www.http-tunnel.net
127.0.0.1 www.http-tunneling.com
127.0.0.1 www.irc-proxy.com
127.0.0.1 www.kazaa-firewall.com
127.0.0.1 www.kazaa-proxy.com
127.0.0.1 www.kill-firewall.com
127.0.0.1 www.msn-firewall.com
127.0.0.1 www.msn-proxy.com
127.0.0.1 www.proxy-bypass.com
127.0.0.1 www.proxy-tunnel.com
127.0.0.1 www.socks-proxy.org
# [Applied Technologies Internet][Tracking Service][IE-SpyAd]
127.0.0.1 hit-parade.com
127.0.0.1 loga.hit-parade.com
127.0.0.1 logp.hit-parade.com
127.0.0.1 xiti.com
127.0.0.1 loga.xiti.com #[SpySweeper.Spy.Cookie]
127.0.0.1 logc2.xiti.com
127.0.0.1 logc7.xiti.com
127.0.0.1 logc8.xiti.com
127.0.0.1 logc13.xiti.com
127.0.0.1 logc14.xiti.com
127.0.0.1 logc15.xiti.com
127.0.0.1 logc16.xiti.com
127.0.0.1 logc19.xiti.com
127.0.0.1 logc25.xiti.com #[crossdomain.xml]
127.0.0.1 logc31.xiti.com
127.0.0.1 logi6.xiti.com
127.0.0.1 logi7.xiti.com
127.0.0.1 logi8.xiti.com
127.0.0.1 logi9.xiti.com
127.0.0.1 logi10.xiti.com
127.0.0.1 logi11.xiti.com
127.0.0.1 logi12.xiti.com
127.0.0.1 logp.xiti.com
127.0.0.1 logp3.xiti.com
127.0.0.1 logv1.xiti.com
127.0.0.1 logv2.xiti.com
127.0.0.1 logv3.xiti.com #[Panda.Spyware:Cookie/Xiti]
127.0.0.1 logv4.xiti.com
127.0.0.1 logv5.xiti.com
127.0.0.1 logv6.xiti.com
127.0.0.1 logv7.xiti.com
127.0.0.1 logv8.xiti.com
127.0.0.1 logv9.xiti.com
127.0.0.1 logv10.xiti.com
127.0.0.1 logv11.xiti.com
127.0.0.1 logv12.xiti.com
127.0.0.1 logv13.xiti.com
127.0.0.1 logv14.xiti.com
127.0.0.1 logv15.xiti.com
127.0.0.1 logv16.xiti.com
127.0.0.1 logv17.xiti.com
127.0.0.1 logv18.xiti.com #[SecuritySpace.web bug]
127.0.0.1 logv19.xiti.com
127.0.0.1 logv20.xiti.com
127.0.0.1 logv21.xiti.com
127.0.0.1 logv22.xiti.com
127.0.0.1 logv23.xiti.com
127.0.0.1 logv24.xiti.com
127.0.0.1 logv25.xiti.com
127.0.0.1 logv26.xiti.com
127.0.0.1 logv27.xiti.com
127.0.0.1 logv28.xiti.com
127.0.0.1 logv29.xiti.com
127.0.0.1 logv30.xiti.com
127.0.0.1 logv31.xiti.com
127.0.0.1 logv32.xiti.com
127.0.0.1 trafic.xiti.com
127.0.0.1 www.xiti.com

gatoramanda
2007-04-12, 18:43
# [aQuantive Inc][Avenue A][Atlasdmt][IE-SpyAd]
127.0.0.1 www.avenuea.com
127.0.0.1 click.atdmt.com #[McAfee.Cookie-Atdmt]
# 127.0.0.1 clk.atdmt.com #[disabled affects MS downloads]
127.0.0.1 image.atdmt.com
127.0.0.1 mir.atdmt.com #[p.mii.instacontent.net]
127.0.0.1 nc.atdmt.com #[EventTracking]
127.0.0.1 rmd.atdmt.com #[a898.x.akamai.net]
127.0.0.1 spd.atdmt.com #[a796.x.akamai.net]
127.0.0.1 spe.atdmt.com
127.0.0.1 srch.atdmt.com
# 127.0.0.1 switch.atdmt.com #[disabled affects Hotmail signup]
127.0.0.1 view.atdmt.com #[eTrust.Tracking Cookie]
127.0.0.1 www.atdmt.com #[AveA Action Tag][Ewido.TrackingCookie.Atdmt]
127.0.0.1 atlasdmt.com #[Panda.Spyware:Cookie/Atlas DMT]
127.0.0.1 www.atlasdmt.com
127.0.0.1 www.avenueainc.com
127.0.0.1 main.click-url.com #[SiteAdvisor.zango.com]
127.0.0.1 ads.toplayerserver.com
127.0.0.1 www1.toplayerserver.com
127.0.0.1 www.toplayerserver.com
127.0.0.1 track.roiservice.com #[McAfee.Cookie-Roiservice]
# [Arundel Group][Harris Digital Publishing]
127.0.0.1 www.affiliatesuccess.net #[System Detective]
127.0.0.1 spyware-removal.net
127.0.0.1 www.systemdetective.com #[Rogue/Suspect]
127.0.0.1 ztrack.net #[IE-SpyAd]
# [Aster Edward Umali][Azter Inc]
127.0.0.1 www.azter.com #[SiteAdvisor.azter.com]
127.0.0.1 www.bestsexycelebs.com
127.0.0.1 www.hunkymalecelebs.com
127.0.0.1 missdanicapatrick.com
127.0.0.1 www.missdanicapatrick.com #[Win32/TrojanDownloader.Adload.NAY]
127.0.0.1 missjessicasimpson.com
127.0.0.1 www.missjessicasimpson.com #[W32/WinAd.GQ]
127.0.0.1 sexybabesx.com #[Win32/TrojanDownloader.Adload.NBH]
127.0.0.1 adrianalima.sexybabesx.com
127.0.0.1 aliciakeys.sexybabesx.com #[AdWare.Win32.WinAD.bv]
127.0.0.1 amandabynes.sexybabesx.com
127.0.0.1 angelina.sexybabesx.com
127.0.0.1 annakournikova.sexybabesx.com
127.0.0.1 annapaquin.sexybabesx.com
127.0.0.1 annehathaway.sexybabesx.com
127.0.0.1 ashanti.sexybabesx.com
127.0.0.1 ashleesimpson.sexybabesx.com
127.0.0.1 ashleyolsen.sexybabesx.com
127.0.0.1 audreytautou.sexybabesx.com
127.0.0.1 avrillavigne.sexybabesx.com
127.0.0.1 beyonce.sexybabesx.com
127.0.0.1 brianabanks.sexybabesx.com
127.0.0.1 britney.sexybabesx.com
127.0.0.1 brooke.sexybabesx.com
127.0.0.1 brookeburns.sexybabesx.com
127.0.0.1 cameron.sexybabesx.com
127.0.0.1 carmen.sexybabesx.com
127.0.0.1 charlizetheron.sexybabesx.com
127.0.0.1 christina.sexybabesx.com
127.0.0.1 christinaricci.sexybabesx.com
127.0.0.1 ciara.sexybabesx.com
127.0.0.1 danicapatrick.sexybabesx.com
127.0.0.1 danielahantuchova.sexybabesx.com
127.0.0.1 demimoore.sexybabesx.com
127.0.0.1 denise.sexybabesx.com
127.0.0.1 elishacuthbert.sexybabesx.com
127.0.0.1 emmawatson.sexybabesx.com
127.0.0.1 ericablasberg.sexybabesx.com
127.0.0.1 evagreen.sexybabesx.com
127.0.0.1 evalongoria.sexybabesx.com
127.0.0.1 gellar.sexybabesx.com
127.0.0.1 giselebundchen.sexybabesx.com
127.0.0.1 gwenstefani.sexybabesx.com
127.0.0.1 gwynethpaltrow.sexybabesx.com
127.0.0.1 halleberry.sexybabesx.com
127.0.0.1 heathergraham.sexybabesx.com
127.0.0.1 heatherlocklear.sexybabesx.com
127.0.0.1 heidiklum.sexybabesx.com
127.0.0.1 hilaryduff.sexybabesx.com
127.0.0.1 hilaryswank.sexybabesx.com
127.0.0.1 janetjackson.sexybabesx.com
127.0.0.1 jennajameson.sexybabesx.com
127.0.0.1 jenniferaniston.sexybabesx.com
127.0.0.1 jenniferellison.sexybabesx.com
127.0.0.1 jennifergarner.sexybabesx.com
127.0.0.1 jenniferlopez.sexybabesx.com
127.0.0.1 hewitt.sexybabesx.com
127.0.0.1 jessicaalba.sexybabesx.com
127.0.0.1 jessicabiel.sexybabesx.com
127.0.0.1 jessicasimpson.sexybabesx.com
127.0.0.1 jojo.sexybabesx.com
127.0.0.1 josiemaran.sexybabesx.com
127.0.0.1 jossstone.sexybabesx.com
127.0.0.1 juliaroberts.sexybabesx.com
127.0.0.1 juliastiles.sexybabesx.com
127.0.0.1 katebeckinsale.sexybabesx.com
127.0.0.1 katehudson.sexybabesx.com
127.0.0.1 katemoss.sexybabesx.com
127.0.0.1 katewinslet.sexybabesx.com
127.0.0.1 katieholmes.sexybabesx.com
127.0.0.1 keiraknightley.sexybabesx.com
127.0.0.1 kellyclarkson.sexybabesx.com
127.0.0.1 kirsten.sexybabesx.com
127.0.0.1 kristinkreuk.sexybabesx.com
127.0.0.1 leeleesobieski.sexybabesx.com
127.0.0.1 lindsay.sexybabesx.com #[Win32/Adware.WinAd]
127.0.0.1 livtyler.sexybabesx.com
127.0.0.1 lucyliu.sexybabesx.com
127.0.0.1 lucypinder.sexybabesx.com
127.0.0.1 madonna.sexybabesx.com
127.0.0.1 mandy.sexybabesx.com
127.0.0.1 sharapova.sexybabesx.com
127.0.0.1 mariahcarey.sexybabesx.com
127.0.0.1 marisamiller.sexybabesx.com
127.0.0.1 menasuvari.sexybabesx.com
127.0.0.1 michellerodriguez.sexybabesx.com
127.0.0.1 michellewie.sexybabesx.com #[Win32/TrojanDownloader.Adload.NAY]
127.0.0.1 milakunis.sexybabesx.com
127.0.0.1 millajovovich.sexybabesx.com
127.0.0.1 mischabarton.sexybabesx.com
127.0.0.1 monicabellucci.sexybabesx.com
127.0.0.1 naomicampbell.sexybabesx.com
127.0.0.1 naomiwatts.sexybabesx.com
127.0.0.1 nataliegulbis.sexybabesx.com
127.0.0.1 natalieportman.sexybabesx.com
127.0.0.1 nevecampbell.sexybabesx.com
127.0.0.1 nickyhilton.sexybabesx.com
127.0.0.1 nicolekidman.sexybabesx.com
127.0.0.1 nicolerichie.sexybabesx.com
127.0.0.1 nicolevaidisova.sexybabesx.com
127.0.0.1 pamela.sexybabesx.com
127.0.0.1 parishilton.sexybabesx.com
127.0.0.1 penelope.sexybabesx.com
127.0.0.1 rachelbilson.sexybabesx.com
127.0.0.1 rachelmcadams.sexybabesx.com
127.0.0.1 rachelstevens.sexybabesx.com
127.0.0.1 rachelweisz.sexybabesx.com
127.0.0.1 reese.sexybabesx.com
127.0.0.1 renee.sexybabesx.com
127.0.0.1 roselynsanchez.sexybabesx.com
127.0.0.1 salma.sexybabesx.com
127.0.0.1 samairearmstrong.sexybabesx.com
127.0.0.1 sandra.sexybabesx.com
127.0.0.1 saniamirza.sexybabesx.com
127.0.0.1 sashacohen.sexybabesx.com
127.0.0.1 scarlett.sexybabesx.com
127.0.0.1 selitaebanks.sexybabesx.com
127.0.0.1 serenawilliams.sexybabesx.com
127.0.0.1 shakira.sexybabesx.com
127.0.0.1 shannendoherty.sexybabesx.com
127.0.0.1 sharonstone.sexybabesx.com
127.0.0.1 sherylcrow.sexybabesx.com
127.0.0.1 siennamiller.sexybabesx.com
127.0.0.1 sophiabush.sexybabesx.com
127.0.0.1 stacykeibler.sexybabesx.com
127.0.0.1 terapatrick.sexybabesx.com
127.0.0.1 terihatcher.sexybabesx.com
127.0.0.1 thorabirch.sexybabesx.com
127.0.0.1 tyrabanks.sexybabesx.com
127.0.0.1 umathurman.sexybabesx.com
127.0.0.1 venuswilliams.sexybabesx.com
127.0.0.1 www.sexybabesx.com #[AVG.Generic.MUM]
# [Avenue Media]
127.0.0.1 active-alert-server.com
127.0.0.1 www.active-alert-server.com #[IE-SpyAd]
127.0.0.1 amnv.net
127.0.0.1 www.amnv.net
127.0.0.1 avenuemedia.com
127.0.0.1 www.avenuemedia.com
127.0.0.1 climaxbucks.com #[ClimaxBucks.InternetOptimizer]
127.0.0.1 dyntraq.climaxbucks.com
127.0.0.1 mt1.climaxbucks.com
127.0.0.1 mt23.climaxbucks.com
127.0.0.1 mt32.climaxbucks.com
127.0.0.1 mt35.climaxbucks.com
127.0.0.1 mt122.climaxbucks.com
127.0.0.1 securei.climaxbucks.com
127.0.0.1 www.climaxbucks.com
127.0.0.1 cocktailcash.com
127.0.0.1 xbs.cocktailcash.com #[TROJ_DYFUCA.X]
127.0.0.1 www.cocktailcash.com
127.0.0.1 internet-optimizer.com #[Downloader.Dyfcia.F]
127.0.0.1 ads.internet-optimizer.com #[Parasite.Internet Optimizer]
127.0.0.1 configure.internet-optimizer.com #[TSPY_SMALL.SN]
127.0.0.1 help.internet-optimizer.com #[ADW_SIDEFIND.L][Adware-Adlogix]
127.0.0.1 www.internet-optimizer.com #[Adware.NetOptimizer]
127.0.0.1 www.lunasearch.com
127.0.0.1 movies-etc.com
127.0.0.1 cdn.movies-etc.com #[ADW_DYFUCA.K][Adware-Adlogix]
127.0.0.1 cdn2.movies-etc.com
127.0.0.1 www.movies-etc.com
127.0.0.1 yoogee.com #[Parasite.Internet Optimizer]
127.0.0.1 www.yoogee.com #[Panda.Spyware/Dyfuca]
# [Azoogle.com INC][Impulse Leads][IE-SpyAd]
127.0.0.1 i.1100i.com
127.0.0.1 images.1100i.com
127.0.0.1 www.adroz.com #[affiliate][AIM Smileys]
127.0.0.1 c.azjmp.com #[SpySweeper.Spy.Cookie][Adware-Fizzle]
127.0.0.1 i.azjmp.com
127.0.0.1 www.azjmp.com
127.0.0.1 images.azoogleads.com
127.0.0.1 images.azooimages.com
127.0.0.1 www.azoogleads.com
127.0.0.1 b1.bluetime.com
127.0.0.1 images.bluetime.com #[a1639.g.akamai.net][server down?]
127.0.0.1 www.bluetime.com
127.0.0.1 www.giftfox.com
127.0.0.1 images.hostimages.net
127.0.0.1 images.imagesbyaz.com
127.0.0.1 images.imgehost.com
127.0.0.1 impulseleads.com
127.0.0.1 www.impulseleads.com
127.0.0.1 images.imgserver.net
127.0.0.1 www.merchantportal.com
127.0.0.1 www.mport.com
127.0.0.1 www.mptrack.com #[Whois.Blacklisted]
127.0.0.1 www.mydishprovider.com
127.0.0.1 noadware.biz
127.0.0.1 www.noadware.biz #[hop.clickbank.net]
127.0.0.1 c.qckjmp.com
127.0.0.1 visit-link.com
# [Aztec Marketing][West Frontier Holdings][Offshorefleet Holdings S.A]
127.0.0.1 artella.biz #[AdWare.Win32.BHO.bh]
127.0.0.1 home.artella.biz
127.0.0.1 www.artella.biz
127.0.0.1 www2.click2begin.com
127.0.0.1 www3.click2begin.com
127.0.0.1 clickfast.biz #[SunBelt.Ezula.ClickFast]
127.0.0.1 www.clickfast.biz
127.0.0.1 desktoptraffic.net #[server down?]
127.0.0.1 toolbar.desktoptraffic.net
127.0.0.1 www2.hooowah.com
127.0.0.1 www3.hooowah.com
127.0.0.1 www4.hooowah.com
127.0.0.1 www5.hooowah.com
127.0.0.1 www6.hooowah.com
127.0.0.1 www7.hooowah.com
127.0.0.1 www8.hooowah.com
127.0.0.1 www9.hooowah.com
127.0.0.1 www10.hooowah.com
127.0.0.1 www.hooowah.com #[IE-SpyAd]
127.0.0.1 iconads.biz
127.0.0.1 www.iconads.biz #[SunBelt.AdRotator/IconAds][trafficsector.com]
127.0.0.1 www.pops-stop.com #[Spyware.SafeSurfing][trafficsector.com]
127.0.0.1 www1.pops-stop.com
127.0.0.1 popupsearches.com
127.0.0.1 www2.popupsearches.com
127.0.0.1 www.popupsearches.com #[SunBelt.PopUpSearches.com]
127.0.0.1 trafficgeneration.biz
127.0.0.1 toolbar.trafficgeneration.biz #[ADW_BEGINTO.DR][W32/HotSearchBar.D]
127.0.0.1 toolbar2.trafficgeneration.biz
127.0.0.1 toolbar3.trafficgeneration.biz
127.0.0.1 toolbar4.trafficgeneration.biz #[server down?]
127.0.0.1 toolbar5.trafficgeneration.biz
127.0.0.1 toolbar6.trafficgeneration.biz
127.0.0.1 www.trafficgeneration.biz
127.0.0.1 trafficsector.com #[Adware.Webext][SunBelt.SafeSurfing.RsyncMon]
127.0.0.1 new.trafficsector.com #[McAfee.Adware-Iconads]
127.0.0.1 www.trafficsector.com #[McAfee.Adware-BitLocker]
# [Masterly International S.A.][Kitten Holding Corp]
127.0.0.1 www2.1evidencekiller.com
127.0.0.1 www2.1historyeraser.com
127.0.0.1 www.1spywarekiller.com #[Rogue/Suspect]
127.0.0.1 www2.1spywarekiller.com #[Parasite.SpywareKiller]
127.0.0.1 www3.1spywarekiller.com
# [Actif Oiseau Alerte S.A.][Janerus, Inc][Mnetpower LTD]
127.0.0.1 www.adultmegaporn.com
127.0.0.1 www.eaffiliateinc.com
127.0.0.1 www.ewebadserver.com #[Begin2Search]
127.0.0.1 gpstool.globaladserver.com #[Win32/Adware.Beginto]
127.0.0.1 www.globaladserver.com
127.0.0.1 globalwebsearch.com #[Parasite.ILookup]
127.0.0.1 www.globalwebsearch.com #[Adware.ILookup]
127.0.0.1 goldmembersarea.com
127.0.0.1 www.goldmembersarea.com
127.0.0.1 gophersearch.com #[McAfee.Adware-WorldAnywhere]
127.0.0.1 www.gophersearch.com
127.0.0.1 secure.ivirtualcard.com
127.0.0.1 secure.memberareaplus.com
127.0.0.1 www.mnetpower.com
127.0.0.1 secure.pinkpays.com
127.0.0.1 www.pinkpays.com
127.0.0.1 vroomsearch.com
127.0.0.1 www.vroomsearch.com
# [BannerCPM]
127.0.0.1 bannercpm.com
127.0.0.1 www.bannercpm.com
127.0.0.1 cpmadz.com
127.0.0.1 www.cpmadz.com #[AdWare.Win32.TrafficSol.e]
127.0.0.1 mycpmads.com #[SunBelt.MyCPMAds Browser Optimizer]
127.0.0.1 www.mycpmads.com
# [Bariscloth INC][Daniel Wesley]
127.0.0.1 www.600.net
127.0.0.1 www.aimface.com #[Adware Bundler]
127.0.0.1 www.buddy-icons.us #[Kephyr.PUP]
127.0.0.1 www.funnyjoke.net
127.0.0.1 www.imbuddy.net #[Trojan-Dropper.Win32.ExeBundle.286]
127.0.0.1 www.ratepic.com
# [Belcaro Group][eTrust.Spyware.Belcaro GoldenRetriever]
127.0.0.1 1cat.com
127.0.0.1 i.1cat.com
127.0.0.1 www.1cat.com
127.0.0.1 gr1.cc
127.0.0.1 gr2.cc
127.0.0.1 gr3.cc #[IE-SpyAd]
127.0.0.1 gr4.cc
127.0.0.1 selectbonus.com
127.0.0.1 www.selectbonus.com
127.0.0.1 www.shopathome.com
127.0.0.1 shopathomeselect.com #[Parasite.ShopAtHomeSelect]
127.0.0.1 downloads.shopathomeselect.com #[SpySweeper.Adware.shopathomeselect]
127.0.0.1 www.shopathomeselect.com #[Adware.SAHAgent]
# [Bell Globemedia Interactive Inc]
127.0.0.1 adcounter.theglobeandmail.com
127.0.0.1 adrates.theglobeandmail.com
127.0.0.1 ads.globeandmail.com
127.0.0.1 ads1.theglobeandmail.com
127.0.0.1 visit.theglobeandmail.com
127.0.0.1 www1.theglobeandmail.com
# [Ben Vanderbildt][Adware Bundler]
127.0.0.1 www.albumgalaxy.com #[AdWare.Win32.Relevant.a]
127.0.0.1 www.kiwialpha.com #[SiteAdvisor.kiwialpha.com]
127.0.0.1 www.twistermp3.com #[AdWare.Win32.Relevant.a]
# [Bit Wise Publishing, LLC]
127.0.0.1 www.bitwisepublishing.com #[myglobalsearch.com]
127.0.0.1 www.free-patriotic-screensavers.com #[tafmaster.com]
127.0.0.1 www.my247eshop.com #[eShopper Search Bar]
127.0.0.1 www.scenicreflections.com #[SiteAdvisor.scenicreflections.com]
# [Bluestreak][Tracking Service][IE-SpyAd]
127.0.0.1 bluestreak.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 ak.bluestreak.com
127.0.0.1 ca1.bluestreak.com #[SunBelt.Bluestreak.com][a2.x.akamai.net]
127.0.0.1 fr.bluestreak.com
127.0.0.1 ion.bluestreak.com
127.0.0.1 s0.bluestreak.com #[Ewido.TrackingCookie.Bluestreak]
127.0.0.1 s0b.bluestreak.com
127.0.0.1 s2.bluestreak.com #[McAfee.Cookie-Bluestreak]
127.0.0.1 s3.bluestreak.com
127.0.0.1 s4.bluestreak.com
127.0.0.1 s5.bluestreak.com #[Panda.Spyware:Cookie/Bluestreak]
127.0.0.1 s6.bluestreak.com
127.0.0.1 s7.bluestreak.com #[Tenebril.Tracking Cookie]
127.0.0.1 s8.bluestreak.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.bluestreak.com
# [Bluetide Software][DeluxeCommunications]
127.0.0.1 www.bluetidesoftware.com #[SiteAdvisor.bluetidesoftware.com]
127.0.0.1 dxcdirect.com
127.0.0.1 dl.dxcdirect.com
127.0.0.1 media.dxcdirect.com
127.0.0.1 search.dxcdirect.com
127.0.0.1 www.dxcdirect.com
127.0.0.1 www.mycustomersdirect.com
127.0.0.1 surfsidekick.com #[ADW_SURFKICK.B]
127.0.0.1 ads.surfsidekick.com #[McAfee.Adware-SurfSideKick.dr]
127.0.0.1 dl.surfsidekick.com #[Parasite.TVMedia.SSK][TROJ_SMALL.AQC]
127.0.0.1 search.surfsidekick.com #[Panda.Spyware/SurfSideKick]
127.0.0.1 www.surfsidekick.com #[Adware.SurfSideKick]
# [Bob Jones][Tommy Davis][Adware.BlockChecker]
127.0.0.1 www.block-checker.com #[McAfee.Adclicker-DF]
127.0.0.1 www.system-processes.com #[Adware.SystemProcess]
# [Bobi Net]
127.0.0.1 secure.certone.com #[Adware.WebDir][SunBelt.WebDir]
127.0.0.1 www.filefront.net
127.0.0.1 www.gizmoyo.com #[IE-SpyAd]
127.0.0.1 www.torrentsearcher.net
127.0.0.1 www.xcode.info
127.0.0.1 files.xeol.net #[SiteAdvisor.xeol.net]
127.0.0.1 pr.xeol.net
# [Bonzi Software][Adware.Bonzi]
127.0.0.1 download.bonzi.com
127.0.0.1 images.bonzi.com
127.0.0.1 www.bonzi.com #[ADW_BONJING.A]
127.0.0.1 www.bonzibuddy.com
# [Boua Pcl][Sen Boua]
127.0.0.1 musah.info #[Trojan-Downloader.Win32.Delf.h][TROJ_DLOADER.AFB]
127.0.0.1 ownusa.info #[Trojan-Clicker.Agent.8]
# [BraveNet][Tracking Service][IE-SpyAd]
127.0.0.1 bravenet.com #[Tenebril.Tracking Cookie]
127.0.0.1 adserv.bravenet.com #[McAfee.Cookie-Bravenet]
127.0.0.1 counter1.bravenet.com
127.0.0.1 counter2.bravenet.com
127.0.0.1 counter3.bravenet.com
127.0.0.1 counter4.bravenet.com
127.0.0.1 counter5.bravenet.com
127.0.0.1 counter6.bravenet.com
127.0.0.1 counter7.bravenet.com
127.0.0.1 counter8.bravenet.com
127.0.0.1 counter9.bravenet.com
127.0.0.1 counter10.bravenet.com
127.0.0.1 counter11.bravenet.com
127.0.0.1 counter12.bravenet.com
127.0.0.1 counter13.bravenet.com
127.0.0.1 counter14.bravenet.com
127.0.0.1 counter15.bravenet.com
127.0.0.1 counter16.bravenet.com
127.0.0.1 counter17.bravenet.com
127.0.0.1 counter18.bravenet.com
127.0.0.1 counter19.bravenet.com
127.0.0.1 counter20.bravenet.com
127.0.0.1 counter21.bravenet.com
127.0.0.1 counter22.bravenet.com
127.0.0.1 counter23.bravenet.com
127.0.0.1 counter24.bravenet.com
127.0.0.1 counter25.bravenet.com
127.0.0.1 counter26.bravenet.com
127.0.0.1 counter27.bravenet.com
127.0.0.1 counter28.bravenet.com
127.0.0.1 counter29.bravenet.com
127.0.0.1 counter30.bravenet.com
127.0.0.1 counter31.bravenet.com
127.0.0.1 counter32.bravenet.com
127.0.0.1 counter33.bravenet.com
127.0.0.1 counter34.bravenet.com
127.0.0.1 counter35.bravenet.com
127.0.0.1 counter36.bravenet.com
127.0.0.1 counter37.bravenet.com
127.0.0.1 counter38.bravenet.com
127.0.0.1 counter39.bravenet.com
127.0.0.1 counter40.bravenet.com
127.0.0.1 counter41.bravenet.com
127.0.0.1 counter42.bravenet.com
127.0.0.1 counter43.bravenet.com
127.0.0.1 counter44.bravenet.com
127.0.0.1 counter45.bravenet.com
127.0.0.1 counter46.bravenet.com
127.0.0.1 counter47.bravenet.com
127.0.0.1 counter48.bravenet.com
127.0.0.1 counter49.bravenet.com
127.0.0.1 counter50.bravenet.com
127.0.0.1 images.bravenet.com #[SecuritySpace.WebBug]
127.0.0.1 linktrack.bravenet.com #[SunBelt.Bravenet.com]
127.0.0.1 pub2.bravenet.com #[Bravenet.com Service Code]
127.0.0.1 pub12.bravenet.com
127.0.0.1 pub16.bravenet.com
127.0.0.1 pub45.bravenet.com
127.0.0.1 pub49.bravenet.com
# [BrowserMedia \ BuyDomains.com]
127.0.0.1 www47.buydomains.com #[Panda.Spyware:Cookie/Buydomains]
127.0.0.1 www48.seeq.com #[Panda.Spyware:Cookie/Seeq]
127.0.0.1 bannerx.seeq.com
127.0.0.1 smds.seeq.com
# [BUDS Inc. Ad Network][IE-SpyAd][SPYW_SOFTOMATE.A]
127.0.0.1 www.addfreegames.com
127.0.0.1 affiliate.budsinc.com #[directtrack.com]
127.0.0.1 content.budsinc.com
127.0.0.1 show.budsinc.com
127.0.0.1 www.budsinc.com
127.0.0.1 www.musicfeet.com
127.0.0.1 www.noadnetwork.com
# [BurstMedia][Tracking Service][IE-SpyAd]
127.0.0.1 ads.addesktop.com #[McAfee.Cookie-Addesktop]
127.0.0.1 www.burstbeacon.com #[Panda.Spyware:Cookie/BurstBeacon]
127.0.0.1 burstmedia.com
127.0.0.1 roscoe.burstmedia.com #[SunBelt.BurstMedia]
127.0.0.1 survey.burstmedia.com
127.0.0.1 web.burstmedia.com
127.0.0.1 websurvey.burstmedia.com
127.0.0.1 ads.burstnet.com #[SpySweeper.Spy.Cookie]
127.0.0.1 gifs.burstnet.com
127.0.0.1 sj.burstnet.com #[SunBelt.BurstNet]
127.0.0.1 te.burstnet.com
127.0.0.1 text.burstnet.com
127.0.0.1 www.burstnet.com #[eTrust.Tracking Cookie]
127.0.0.1 www2.burstnet.com
127.0.0.1 www3.burstnet.com #[Tenebril.Tracking Cookie]
127.0.0.1 www4.burstnet.com
127.0.0.1 www5.burstnet.com
127.0.0.1 www6.burstnet.com
127.0.0.1 www.burstnet.akadns.net
# [Casale Media][Comspec Communications][IE-SpyAd]
127.0.0.1 casalemedia.com #[McAfee.Cookie-Casalemedia]
127.0.0.1 as.casalemedia.com #[Ewido.TrackingCookie.Casalemedia]
127.0.0.1 b.casalemedia.com #[a1083.g.akamai.net][McAfee.Adware-SrchExplorer]
127.0.0.1 c.casalemedia.com #[Ad-Aware.Tracking Cookie]
127.0.0.1 i.casalemedia.com #[Tenebril.Tracking Cookie]
127.0.0.1 img.casalemedia.com #[SunBelt.casalemedia.com]
127.0.0.1 js.casalemedia.com #[a883.g.akamai.net]
127.0.0.1 lb01.casalemedia.com #[SpySweeper.Spy.Cookie]
127.0.0.1 r.casalemedia.com #[Symantec.SpywareStormer]
127.0.0.1 www.casalemedia.com
127.0.0.1 www.errorguard.com #[PcTools.ErrorGuard][McAfee.ErrorGuard]
127.0.0.1 spywarestormer.com #[Rogue/Suspect]
127.0.0.1 www.spywarestormer.com #[Symantec.SpywareStormer][Adware-SpyStormer]
127.0.0.1 www.oofun.com
127.0.0.1 00fun.com #[Tenebril.Tracking Cookie]
127.0.0.1 www.00fun.com

gatoramanda
2007-04-12, 18:45
Should I keep posting the hosts file? There have got to be like at least 10 more posts needed....

gatoramanda
2007-04-12, 19:11
Okay - how I figured out that Google AFE was the cause for my redirection problem... Basically, my pages started redirecting worse and worse on myspace only. They changed from being more than just yieldmanager redirects - they started having additional names. I was really frustrated because the redirect didn't just take me to a google redirect page, but was incorporated with a dell search page...weird enough...I looked through my program files lists in add/remove programs....and I saw this "Google AFE" and didn't know what it was....so of course, I googled it....found out that it is a page redirector...and that it comes with other names as well...here is the first page that I googled that the person was having a familiar sounding problem:

http://www.dellcommunity.com/supportforums/board/message?board.id=si_virus&message.id=47502


Here is another article that confirmed my suspicions and names additional redirectors that cause problems with web pages....

http://discoveryeducation.typepad.com/implementation/2007/01/crazy_google_er.html

All I did after this was go to add/remove programs search for any programs in the list - including the google afe (which is the only one I had on this computer) and deleted it - it went away! Poof - gone!

Thanks for all of your help Phil....much appreciated! I hope this information helps another lost soul!

pskelley
2007-04-14, 13:12
Hi Amanda, no I don't need to see the complete hosts file, looks like you are using http://www.mvps.org/winhelp2002/hosts.htm and those are the junk your Hosts file is blocking. If all is well, I will close your topic.

Thanks...Phil

pskelley
2007-04-14, 13:15
As the problem appears to be resolved this topic has been closed.

If you need it re-opened please send me or a forum staff member a private message (pm) and provide a link to the thread; this applies only to the original topic starter.

Anyone else with similar problems please start a new topic.

Thanks