Advertisement
Guest User

HMP 3 Log

a guest
Oct 7th, 2014
84
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 23.13 KB | None | 0 0
  1. [code]
  2. HitmanPro 3.7.9.225
  3. www.hitmanpro.com
  4.  
  5. Computer name . . . . : JARED
  6. Windows . . . . . . . : 6.3.0.9600.X64/6
  7. User name . . . . . . : JARED\Jtpetch
  8. UAC . . . . . . . . . : Enabled
  9. License . . . . . . . : Trial (30 days left)
  10.  
  11. Scan date . . . . . . : 2014-10-07 14:44:16
  12. Scan mode . . . . . . : Normal
  13. Scan duration . . . . : 5m 20s
  14. Disk access mode . . : Direct disk access (SRB)
  15. Cloud . . . . . . . . : Internet
  16. Reboot . . . . . . . : Yes
  17.  
  18. Threats . . . . . . . : 2
  19. Traces . . . . . . . : 128
  20.  
  21. Objects scanned . . . : 1,978,248
  22. Files scanned . . . . : 71,826
  23. Remnants scanned . . : 676,202 files / 1,230,220 keys
  24.  
  25. Malware _____________________________________________________________________
  26.  
  27. C:\ProgramData\GoSavE\Ahrl1GTenAxTQPm.exe -> Quarantined
  28. Size . . . . . . . : 3,926,016 bytes
  29. Age . . . . . . . : 4.1 days (2014-10-03 11:15:18)
  30. Entropy . . . . . : 6.9
  31. SHA-256 . . . . . : 5D98BD3860712FE27204087B1D93E7A139FE04F817ED6E0525BBFCA141E6AEFD
  32. > Bitdefender . . . : Gen:Variant.Adware.MPlug.12
  33. Fuzzy . . . . . . : 108.0
  34.  
  35. C:\ProgramData\YoutUbeAdBlocke\I7xHDpzcpod24V4.exe -> Quarantined
  36. Size . . . . . . . : 3,827,712 bytes
  37. Age . . . . . . . : 4.1 days (2014-10-03 11:15:31)
  38. Entropy . . . . . : 6.8
  39. SHA-256 . . . . . : 7861D0FFF3C0A1B9F99B607F9DC41858D5CCDC48D073053F0A7C31A93F5F3D12
  40. > Bitdefender . . . : Gen:Variant.Adware.MPlug.12
  41. Fuzzy . . . . . . : 108.0
  42.  
  43.  
  44. Suspicious files ____________________________________________________________
  45.  
  46. C:\Users\Jtpetch\AppData\Local\PunkBuster\APB\pb\dll\wc002327.dll
  47. Size . . . . . . . : 968,536 bytes
  48. Age . . . . . . . : 84.8 days (2014-07-14 18:27:57)
  49. Entropy . . . . . : 7.6
  50. SHA-256 . . . . . : 5B7AAFE720F6D7E618784C9AC16A6FD2329B7B0170E24B642D0059971B6C5B7A
  51. RSA Key Size . . . : 2048
  52. Authenticode . . . : Valid
  53. Fuzzy . . . . . . : 22.0
  54. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  55. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  56. Authors name is missing in version info. This is not common to most programs.
  57. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  58. Program contains PE structure anomalies. This is not typical for most programs.
  59. Program is code signed with a valid Authenticode certificate.
  60.  
  61. C:\Users\Jtpetch\AppData\Local\PunkBuster\APB\pb\pbcl.dll
  62. Size . . . . . . . : 968,536 bytes
  63. Age . . . . . . . : 84.8 days (2014-07-14 18:42:28)
  64. Entropy . . . . . : 7.6
  65. SHA-256 . . . . . : 5B7AAFE720F6D7E618784C9AC16A6FD2329B7B0170E24B642D0059971B6C5B7A
  66. RSA Key Size . . . : 2048
  67. Authenticode . . . : Valid
  68. Fuzzy . . . . . . : 22.0
  69. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  70. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  71. Authors name is missing in version info. This is not common to most programs.
  72. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  73. Program contains PE structure anomalies. This is not typical for most programs.
  74. Program is code signed with a valid Authenticode certificate.
  75.  
  76. C:\Users\Jtpetch\AppData\Local\PunkBuster\APB\pb\pbclold.dll
  77. Size . . . . . . . : 968,536 bytes
  78. Age . . . . . . . : 84.9 days (2014-07-14 18:13:12)
  79. Entropy . . . . . : 7.6
  80. SHA-256 . . . . . : 5B7AAFE720F6D7E618784C9AC16A6FD2329B7B0170E24B642D0059971B6C5B7A
  81. RSA Key Size . . . : 2048
  82. Authenticode . . . : Valid
  83. Fuzzy . . . . . . : 22.0
  84. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  85. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  86. Authors name is missing in version info. This is not common to most programs.
  87. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  88. Program contains PE structure anomalies. This is not typical for most programs.
  89. Program is code signed with a valid Authenticode certificate.
  90.  
  91. C:\Users\Jtpetch\AppData\Local\PunkBuster\APB\pb\PnkBstrK.sys
  92. Size . . . . . . . : 139,656 bytes
  93. Age . . . . . . . : 84.9 days (2014-07-14 18:13:24)
  94. Entropy . . . . . : 7.7
  95. SHA-256 . . . . . : 0C20AD6DD97FF44B94AF48A1FC7A0FDEB8D94E8727A76333B3453B35F27B628F
  96. RSA Key Size . . . : 2048
  97. Authenticode . . . : Valid
  98. Fuzzy . . . . . . : 22.0
  99. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  100. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  101. Authors name is missing in version info. This is not common to most programs.
  102. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  103. Program contains PE structure anomalies. This is not typical for most programs.
  104. The file is a device driver. Device drivers run as trusted (highly privileged) code.
  105. Program is code signed with a valid Authenticode certificate.
  106.  
  107. C:\Users\Jtpetch\AppData\Local\PunkBuster\BF3\pb\dll\wc002342.dll
  108. Size . . . . . . . : 969,032 bytes
  109. Age . . . . . . . : 86.7 days (2014-07-12 22:58:34)
  110. Entropy . . . . . : 7.6
  111. SHA-256 . . . . . : FC5702BFEF687EDAF89499C7849E4FDA0AF9D72A5A632C5B4E20F2562468596C
  112. RSA Key Size . . . : 2048
  113. Authenticode . . . : Valid
  114. Fuzzy . . . . . . : 22.0
  115. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  116. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  117. Authors name is missing in version info. This is not common to most programs.
  118. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  119. Program contains PE structure anomalies. This is not typical for most programs.
  120. Program is code signed with a valid Authenticode certificate.
  121.  
  122. C:\Users\Jtpetch\AppData\Local\PunkBuster\BF3\pb\pbcl.dll
  123. Size . . . . . . . : 969,032 bytes
  124. Age . . . . . . . : 77.9 days (2014-07-21 16:40:23)
  125. Entropy . . . . . : 7.6
  126. SHA-256 . . . . . : FC5702BFEF687EDAF89499C7849E4FDA0AF9D72A5A632C5B4E20F2562468596C
  127. RSA Key Size . . . : 2048
  128. Authenticode . . . : Valid
  129. Fuzzy . . . . . . : 22.0
  130. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  131. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  132. Authors name is missing in version info. This is not common to most programs.
  133. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  134. Program contains PE structure anomalies. This is not typical for most programs.
  135. Program is code signed with a valid Authenticode certificate.
  136.  
  137. C:\Users\Jtpetch\AppData\Local\PunkBuster\BF3\pb\pbclold.dll
  138. Size . . . . . . . : 969,032 bytes
  139. Age . . . . . . . : 86.9 days (2014-07-12 16:00:36)
  140. Entropy . . . . . : 7.6
  141. SHA-256 . . . . . : FC5702BFEF687EDAF89499C7849E4FDA0AF9D72A5A632C5B4E20F2562468596C
  142. RSA Key Size . . . : 2048
  143. Authenticode . . . : Valid
  144. Fuzzy . . . . . . : 22.0
  145. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  146. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  147. Authors name is missing in version info. This is not common to most programs.
  148. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  149. Program contains PE structure anomalies. This is not typical for most programs.
  150. Program is code signed with a valid Authenticode certificate.
  151.  
  152. C:\Users\Jtpetch\AppData\Local\PunkBuster\BF3\pb\PnkBstrK.sys
  153. Size . . . . . . . : 140,072 bytes
  154. Age . . . . . . . : 86.9 days (2014-07-12 16:00:48)
  155. Entropy . . . . . : 7.7
  156. SHA-256 . . . . . : CC3F4E453FC246B64C09E81BB73741CECC897C805C13815336647E986A60301E
  157. RSA Key Size . . . : 2048
  158. Authenticode . . . : Valid
  159. Fuzzy . . . . . . : 22.0
  160. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  161. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  162. Authors name is missing in version info. This is not common to most programs.
  163. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  164. Program contains PE structure anomalies. This is not typical for most programs.
  165. The file is a device driver. Device drivers run as trusted (highly privileged) code.
  166. Program is code signed with a valid Authenticode certificate.
  167.  
  168. C:\Users\Jtpetch\AppData\Local\PunkBuster\BLR\pb\pbcl.dll
  169. Size . . . . . . . : 949,190 bytes
  170. Age . . . . . . . : 60.7 days (2014-08-07 21:33:55)
  171. Entropy . . . . . : 7.6
  172. SHA-256 . . . . . : DAF43E93528BEEECC015FA98D6EE6D6FD6D19A049321E47A65665144E4511F41
  173. Fuzzy . . . . . . : 29.0
  174. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  175. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  176. Authors name is missing in version info. This is not common to most programs.
  177. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  178. Program contains PE structure anomalies. This is not typical for most programs.
  179.  
  180. C:\Users\Jtpetch\AppData\Local\PunkBuster\BLR\pb\PnkBstrK.sys
  181. Size . . . . . . . : 140,360 bytes
  182. Age . . . . . . . : 60.7 days (2014-08-07 21:34:09)
  183. Entropy . . . . . : 7.8
  184. SHA-256 . . . . . : 0F41B3843E2D2D1BB1ACF8B7CAA293309CC1CF8CF478B1AC86DD6BB214928DC4
  185. RSA Key Size . . . : 2048
  186. Authenticode . . . : Valid
  187. Fuzzy . . . . . . : 22.0
  188. The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
  189. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  190. Authors name is missing in version info. This is not common to most programs.
  191. Version control is missing. This file is probably created by an individual. This is not typical for most programs.
  192. Program contains PE structure anomalies. This is not typical for most programs.
  193. The file is a device driver. Device drivers run as trusted (highly privileged) code.
  194. Program is code signed with a valid Authenticode certificate.
  195.  
  196. C:\Windows\SysWOW64\GameMon.des
  197. Size . . . . . . . : 3,191,392 bytes
  198. Age . . . . . . . : 47.1 days (2014-08-21 12:33:25)
  199. Entropy . . . . . : 8.0
  200. SHA-256 . . . . . : F65AF9FAF6899F7A8EC472FE24732F871B1E6F2FE9095DE9F4CF5CA1FF18D5ED
  201. Product . . . . . : nProtect Game Monitor
  202. Publisher . . . . : INCA Internet Co., Ltd.
  203. Description . . . : nProtect Game Monitor Rev 2090
  204. Version . . . . . : 2014.5.16.1
  205. RSA Key Size . . . : 2048
  206. Service . . . . . : npggsvc
  207. LanguageID . . . . : 1042
  208. Authenticode . . . : Valid
  209. Fuzzy . . . . . . : 25.0
  210. The file name extension of this program is not common.
  211. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
  212. The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
  213. Starts automatically as a service during system bootup.
  214. Program is code signed with a valid Authenticode certificate.
  215. Startup
  216. HKLM\SYSTEM\CurrentControlSet\Services\npggsvc\
  217.  
  218.  
  219. Potential Unwanted Programs _________________________________________________
  220.  
  221. homepage
  222. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Preferences
  223.  
  224. HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}\ (PCOptimizerPro) -> Deleted
  225. HKLM\SOFTWARE\Classes\s\ (Softonic) -> Deleted
  226. HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}\ (PCOptimizerPro) -> Deleted
  227. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}\ (AdBlocker) -> Deleted
  228. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}\ (iPumper) -> Deleted
  229. HKLM\SOFTWARE\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}\ (FLV Player) -> Deleted
  230. HKLM\SOFTWARE\Wow6432Node\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> Deleted
  231. HKLM\SOFTWARE\Wow6432Node\{77D46E27-0E41-4478-87A6-AABE6FBCF252}\ (PCBooster) -> Deleted
  232. HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> Deleted
  233. HKU\S-1-5-18\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> PendingDelete
  234. HKU\S-1-5-19\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> Deleted
  235. HKU\S-1-5-21-1704732030-4174627178-266599957-1001\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\ (PCOptimizerPro) -> Deleted
  236.  
  237. Cookies _____________________________________________________________________
  238.  
  239. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:247realmedia.com
  240. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:2o7.net
  241. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:a1.interclick.com
  242. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
  243. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.mlnadvertising.com
  244. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.newegg.com
  245. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.propellerads.com
  246. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adlegend.com
  247. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.ad4game.com
  248. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.altitude-arena.com
  249. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.creative-serving.com
  250. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.dragonfru.it
  251. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.mediade.sk
  252. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.nexage.com
  253. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.ookla.com
  254. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.p161.net
  255. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pointroll.com
  256. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pubmatic.com
  257. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.servebom.com
  258. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.stickyadstv.com
  259. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.undertone.com
  260. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.yahoo.com
  261. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserve.atedra.com
  262. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserver.adreactor.com
  263. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserverf1d263next.com
  264. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
  265. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
  266. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
  267. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertlets.com
  268. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ar.atwola.com
  269. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com
  270. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
  271. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:atwola.com
  272. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com
  273. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
  274. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
  275. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:chitika.net
  276. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:collective-media.net
  277. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:dmtracker.com
  278. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
  279. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:emjcd.com
  280. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net
  281. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:googleadservices.com
  282. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:in.getclicky.com
  283. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:interclick.com
  284. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:kontera.com
  285. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
  286. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
  287. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:microsoftsto.112.2o7.net
  288. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:mm.chitika.net
  289. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:oracle.112.2o7.net
  290. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:pcworldcommunication.122.2o7.net
  291. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:pointroll.com
  292. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:questionmarket.com
  293. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:realmedia.com
  294. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
  295. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
  296. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:server.cpmstar.com
  297. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
  298. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
  299. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:specificclick.net
  300. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:statcounter.com
  301. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:statse.webtrendslive.com
  302. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:survey.g.doubleclick.net
  303. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.at.atwola.com
  304. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.net
  305. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
  306. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.hubrus.com
  307. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.strife.com
  308. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:tribalfusion.com
  309. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:weborama.fr
  310. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
  311. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:xiti.com
  312. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:yadro.ru
  313. C:\Users\Jtpetch\AppData\Local\Google\Chrome\User Data\Default\Cookies:zedo.com
  314. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\217ZFWNT.txt
  315. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\2LQ1QKF2.txt
  316. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\31WH9ZLQ.txt
  317. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\47UVMVI6.txt
  318. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\4BYL75ZY.txt
  319. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\7YO171A5.txt
  320. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\84GP545L.txt
  321. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\8E6FD3XO.txt
  322. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\9YBJM827.txt
  323. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\ANKQFI7L.txt
  324. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\FL402LV1.txt
  325. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\HP0J27SJ.txt
  326. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\KP23Z79H.txt
  327. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\LTXFF4QK.txt
  328. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\N8MSIPC9.txt
  329. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\NFKILWCH.txt
  330. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\NTA2NWAQ.txt
  331. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\ORE6KCLB.txt
  332. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\QGSZBGOV.txt
  333. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\R3VRNTFQ.txt
  334. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\RM1WOWAK.txt
  335. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\TT7L3SW6.txt
  336. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\TT9OPTKG.txt
  337. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\XCV86MEM.txt
  338. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\XG8HMF21.txt
  339. C:\Users\Jtpetch\AppData\Local\Microsoft\Windows\INetCookies\YU7LWHC5.txt
  340.  
  341.  
  342. [/code]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement