Forum Clubic

Help virus détecté par AD-AWARE

SVP merci de votre aide
Virus trojan et ?

ArchiveData(auto-quarantine- 2007-12-12 22-03-30.bckp)
Referencefile : SE1R207 03.12.2007

WIN32.BACKDOOR.AGENT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=RegValue : .DEFAULT\software\microsoft\windows\currentversion\explorer “{f710fa10-2031-3106-8872-93a2b5c5c620}”
obj[1]=RegValue : S-1-5-18\software\microsoft\windows\currentversion\explorer “{f710fa10-2031-3106-8872-93a2b5c5c620}”
obj[4]=Fichier : C:\WINDOWS\system32\wsnpoem\audio.dll
obj[5]=Fichier : C:\WINDOWS\system32\wsnpoem\video.dll

WIN32.TROJAN.SPY
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[2]=RegValue : .DEFAULT\software\microsoft\windows\currentversion\explorer “{f710fa10-2031-3106-8872-93a2b5c5c620}”
obj[3]=RegValue : S-1-5-18\software\microsoft\windows\currentversion\explorer “{f710fa10-2031-3106-8872-93a2b5c5c620}”

Bonsoir Darksky1985,
AD-AWARE m’indique qu’il ne peut pas supprimer les fichiers

Voici le rapport

Logfile of HijackThis v1.99.1
Scan saved at 22:28:32, on 12/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
C:\Program Files\HIJACKTHIS VF\hijackthis vf.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr…
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: Aide pour le lien d’Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe”
O4 - HKLM…\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM…\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
O4 - HKLM…\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM…\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM…\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM…\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM…\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM…\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM…\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM…\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM…\Run: [TkBellExe] “C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe” -osboot
O4 - HKLM…\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM…\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM…\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM…\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM…\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
O4 - HKCU…\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU…\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: &Windows Live Search - C:\Program… Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - favorites.live.com…
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE…
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d’arrière-plan - C:\Program… Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?c57622565d7b451e94fb3c170c74b3bd
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - C:\Program… Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?c57622565d7b451e94fb3c170c74b3bd
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra ‘Tools’ menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra ‘Tools’ menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.wanadoo.fr… (file missing) (HKCU)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - messenger.zone.msn.com…
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - messenger.zone.msn.com…
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - security.symantec.com…
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - messenger.zone.msn.com…
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - security.symantec.com…
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - www.nanoscan.com…
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - messenger.zone.msn.com…
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - messenger.zone.msn.com…
O17 - HKLM\System\CCS\Services\Tcpip…{CF9F1256-85E9-41EE-B72B-B0C017A72C5B}: NameServer = 80.10.246.2,80.10.246.129
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSCamSvc - Unknown owner - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (file missing)
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe

Excuse mon anti-virus AVG je suis en train de faire un Scan
Les différents problèmes c’est que mon par feu se désactive tout seul, AVG détecte un Trojan


Non je n'ai encore rien essayé d'autre

voici un nouveau rapport

SmitFraudFix v2.265

Rapport fait à 22:49:29,17, 12/12/2007
Executé à partir de C:\Documents and Settings\HP_Propri?taire\Mes documents\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

Fichier hosts corrompu !

127.0.0.1 hk.digitaltrends.com
127.0.0.1 microsoft.com.org
127.0.0.1 www.www.microsoft.com.org

»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri?taire

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri?taire\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_PRO~1\Favoris

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler’s .dll

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
“AppInit_DLLs”=""

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“System”=""

»»»»»»»»»»»»»»»»»»»»»»»» Rustock

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Intel® PRO/100 VE Network Connection - Miniport d’ordonnancement de paquets
DNS Server Search Order: 15.243.128.51
DNS Server Search Order: 15.243.160.51

Description: Intel® PRO/100 VE Network Connection - Miniport d’ordonnancement de paquets
DNS Server Search Order: 192.168.1.1
DNS Server Search Order: 0.0.0.0

HKLM\SYSTEM\CCS\Services\Tcpip…{CF9F1256-85E9-41EE-B72B-B0C017A72C5B}: NameServer=80.10.246.2,80.10.246.129
HKLM\SYSTEM\CCS\Services\Tcpip…{DB97C907-CB7E-46BF-B9FD-31766915FB7F}: DhcpNameServer=192.168.1.1 0.0.0.0
HKLM\SYSTEM\CCS\Services\Tcpip…{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
HKLM\SYSTEM\CS1\Services\Tcpip…{CF9F1256-85E9-41EE-B72B-B0C017A72C5B}: NameServer=80.10.246.2,80.10.246.129
HKLM\SYSTEM\CS1\Services\Tcpip…{DB97C907-CB7E-46BF-B9FD-31766915FB7F}: DhcpNameServer=192.168.1.1 0.0.0.0
HKLM\SYSTEM\CS1\Services\Tcpip…{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
HKLM\SYSTEM\CS3\Services\Tcpip…{CF9F1256-85E9-41EE-B72B-B0C017A72C5B}: NameServer=80.10.246.2,80.10.246.129
HKLM\SYSTEM\CS3\Services\Tcpip…{DB97C907-CB7E-46BF-B9FD-31766915FB7F}: DhcpNameServer=192.168.1.1 0.0.0.0
HKLM\SYSTEM\CS3\Services\Tcpip…{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin

Ok machine désinfectée
nouveau rapport

SmitFraudFix v2.265

Rapport fait à 22:58:05,42, 12/12/2007
Executé à partir de C:\Documents and Settings\HP_Propri?taire\Mes documents\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler’s .dll

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 www.aaa-livedoor.net #[Trojan-PSW.Win32.Maran.ei]
127.0.0.1 www.abcsearcher.com #[Spamdexing][Microsoft.Strider]
127.0.0.1 abc-search.info
127.0.0.1 abloga.info #[Spamdexing]
127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net
127.0.0.1 b.abnad.net
127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
127.0.0.1 d.abnad.net
127.0.0.1 e.abnad.net
127.0.0.1 t.abnad.net
127.0.0.1 banners.absolpublisher.com
127.0.0.1 tracking.absolstats.com
127.0.0.1 adv.abv.bg
127.0.0.1 bimg.abv.bg
127.0.0.1 www2.a-counter.kiev.ua
127.0.0.1 accuserveadsystem.com
127.0.0.1 www.accuserveadsystem.com
127.0.0.1 gtcc1.acecounter.com
127.0.0.1 gtp1.acecounter.com #[eTrust.Tracking.Cookie]
127.0.0.1 acestats.com
127.0.0.1 www.acestats.com
127.0.0.1 ads.active.com
127.0.0.1 am1.activemeter.com
127.0.0.1 www.activemeter.com #[eTrust.Tracking.Cookie]
127.0.0.1 ads.activepower.net
127.0.0.1 stat.active24stats.nl #[eTrust.Tracking.Cookie]
127.0.0.1 at.ad2click.nl
127.0.0.1 cms.ad2click.nl
127.0.0.1 banner.ad.nu
127.0.0.1 ad-up.com
127.0.0.1 www.ad-up.com
127.0.0.1 www.adagencypro.com
127.0.0.1 ads.adap.tv
127.0.0.1 ad.pop1.adbn.ru
127.0.0.1 adserv.adbonus.com
127.0.0.1 www.adbonus.com
127.0.0.1 james.adbutler.de #[Tenebril.TrackingCookie]
127.0.0.1 www.adbutler.de #[SunBelt.AdButler.de]
127.0.0.1 adcp.adcentriconline.com
127.0.0.1 bell.adcentriconline.com #[Wildcard DNS]
127.0.0.1 content.adcentriconline.com
127.0.0.1 media.adcentriconline.com
127.0.0.1 publicis.adcentriconline.com
127.0.0.1 adcomplete.com
127.0.0.1 www.adcomplete.com
127.0.0.1 axa.addcontrol.net #[Ewido.TrackingCookie.Addcontrol]
127.0.0.1 ads.addynamix.com #[SpySweeper.Spy.Cookie]
127.0.0.1 e13.media.addynamix.com
127.0.0.1 www.adeos.eu
127.0.0.1 adcode.adengage.com
127.0.0.1 stats2.adengage.com
127.0.0.1 www.adengage.com
127.0.0.1 pt.server1.adexit.com
127.0.0.1 www.adexit.com
127.0.0.1 www.ad4ever.com
127.0.0.1 track.adform.net
127.0.0.1 www.adfusion.com
127.0.0.1 harvest.adgardener.com
127.0.0.1 harvest6.adgardener.com
127.0.0.1 harvest7.adgardener.com
127.0.0.1 harvest8.adgardener.com
127.0.0.1 harvest11.adgardener.com
127.0.0.1 harvest12.adgardener.com
127.0.0.1 harvest13.adgardener.com
127.0.0.1 harvest163.adgardener.com
127.0.0.1 harvest176.adgardener.com
127.0.0.1 seeds.adgardener.com
127.0.0.1 www.adgroups.net
127.0.0.1 www.ad-groups.com #[Ban Man Pro Banner Code]
127.0.0.1 www.adgauge.com
127.0.0.1 host1.adhese.be #[Adhese Datamine Tag]
127.0.0.1 host2.adhese.be
127.0.0.1 host3.adhese.be #[ad.be.doubleclick.net]
127.0.0.1 host4.adhese.be
127.0.0.1 ssl3.adhost.com
127.0.0.1 www2.adhost.com
127.0.0.1 ads.adhostingsolutions.com #[eTrust.Tracking.Cookie]
127.0.0.1 www.adimpact.com
127.0.0.1 www.adinventoryrecorder.com
127.0.0.1 adfarm1.adition.com
127.0.0.1 imagesrv.adition.com
127.0.0.1 ad.adition.net
127.0.0.1 adsearch.adkontekst.pl
127.0.0.1 community.adlandpro.com #[Ad-Aware Tracking.Cookie]
127.0.0.1 pk.adlandpro.com
127.0.0.1 te.adlandpro.com #[eTrust.Tracking.Cookie]
127.0.0.1 trafficex.adlandpro.com
127.0.0.1 www.adlandpro.com #[Ad-Aware Tracking.Cookie]
127.0.0.1 engine.adland.ru #[eTrust.Tracking.Cookie]
127.0.0.1 publicidad.adlead.com
127.0.0.1 ad.adlegend.com #[affects Webroot AlertNet]
127.0.0.1 media.adlegend.com #[eTrust.Tracking.Cookie]
127.0.0.1 www.adlimg03.com
127.0.0.1 classic.adlink.de
127.0.0.1 regio.adlink.de
127.0.0.1 west.adlink.de
127.0.0.1 rc.de.adlink.net #[eTrust.Tracking.Cookie]
127.0.0.1 tr.de.adlink.net
127.0.0.1 ads3.adman.gr #[eTrust.Tracking.Cookie]
127.0.0.1 r2d2.adman.gr
127.0.0.1 www.adminder.com #[SpySweeper.Spy.Cookie]
127.0.0.1 apps.admission.net #[Spotlight Ads]
127.0.0.1 appcache.admission.net
127.0.0.1 view.admission.net
127.0.0.1 rms.admeta.com #[admeta.basefarm.net][eTrust.Tracking.Cookie]
127.0.0.1 ads.admodus.com #[eTrust.Tracking.Cookie]
127.0.0.1 ad.adnet.biz #[eTrust.Tracking.Cookie]
127.0.0.1 engine.adnet.ru
127.0.0.1 ad2.adnetinteractive.com
127.0.0.1 ad.adnetwork.com.br
127.0.0.1 www.adnetworkonline.com
127.0.0.1 s1.ad.adocean.pl #[Ewido.Tracking.Cookie]
127.0.0.1 s2.ad.adocean.pl
127.0.0.1 s1.centrumcz.adocean.pl #[eTrust.Tracking.Cookie]
127.0.0.1 s1.czgde.adocean.pl
127.0.0.1 s1.skgde.adocean.pl
127.0.0.1 ad01.adonspot.com
127.0.0.1 ad02.adonspot.com
127.0.0.1 isohunt.adonspot.com
127.0.0.1 ab.adpro.com.ua
127.0.0.1 ac.adpro.com.ua
127.0.0.1 system.adquick.nl
127.0.0.1 www.adquest.nl
127.0.0.1 adreactor.com
127.0.0.1 adserver.adreactor.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 adx.adrenaline.cz
127.0.0.1 www.adsforindians.com
127.0.0.1 ad.adrefer.net
127.0.0.1 www.adreporting.com #[SunBelt.Adreporting.com]
127.0.0.1 gambling911.adrevolver.com
127.0.0.1 media.adrevolver.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 track.adrevolver.com #[McAfee.Cookie-Adrevolver]
127.0.0.1 cntr.adrime.com
127.0.0.1 images.adrime.com
127.0.0.1 ad.adriver.ru
127.0.0.1 www.adrotate.net
127.0.0.1 serv.ad-rotator.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ad.ads8.com
127.0.0.1 vip.ads8.com
127.0.0.1 www.ads183.com
127.0.0.1 antevenio.flux.ads-click.com
127.0.0.1 ad.ads.dk
127.0.0.1 tdkads.ads.dk
127.0.0.1 adservercentral.com
127.0.0.1 banners.adservercentral.com
127.0.0.1 www.adservercentral.com #[SunBelt.adservercentral.com]
127.0.0.1 adservicedomain.info
127.0.0.1 adsfac.net #[Facilitate Tracking Code]
127.0.0.1 images.adshuffle.com
127.0.0.1 this.content.served.by.adshuffle.com
127.0.0.1 ad-soft.net #[regfreeze.net]
127.0.0.1 adsaway.com #[HTML/TrojanDownloader.Agent.BP trojan]
127.0.0.1 www.adsaway.com #[Google.Warning]
127.0.0.1 adsfac.eu
127.0.0.1 www.adshot.de
127.0.0.1 network.adsmarket.com
127.0.0.1 allchix.adsmax.com
127.0.0.1 www2.adsmax.com
127.0.0.1 www.adsodainteractive.com
127.0.0.1 37.adsonar.com
127.0.0.1 ads.adsonar.com
127.0.0.1 foxnews.adsonar.com
127.0.0.1 js.adsonar.com
127.0.0.1 redir.adsonar.com
127.0.0.1 www.adspace.be
127.0.0.1 g.adspeed.net
127.0.0.1 serv.adspeed.com
127.0.0.1 ads.adsponse.de
127.0.0.1 banner.adsrevenue.net
127.0.0.1 creative.adsrevenue.net
127.0.0.1 popunder.adsrevenue.net
127.0.0.1 adserve.adster.com
127.0.0.1 images.adster.com
127.0.0.1 adsvert.com
127.0.0.1 o.adtargeter.com
127.0.0.1 ads.adtiger.de
127.0.0.1 www.adtiger.de
127.0.0.1 ads.adgoto.com
127.0.0.1 adsrv.admindshare.com
127.0.0.1 adtology.com
127.0.0.1 adtology2.com
127.0.0.1 ad.adtoma.com
127.0.0.1 downldcl.adtoolsinc.com
127.0.0.1 www.adtoolsinc.com
127.0.0.1 www.adtrade.net
127.0.0.1 www.adtrader.com
127.0.0.1 netshelter.adtrix.com
127.0.0.1 ads.advancedpcmedia.com
127.0.0.1 survey.advantageresearch.com
127.0.0.1 ad.adver.com.tw
127.0.0.1 www.adventideas.com #[Adcycle]
127.0.0.1 www.adversal.com
127.0.0.1 www.adversalservers.com
127.0.0.1 austria1.adverserve.net #[Ad-Aware.Tracking.Cookie]
127.0.0.1 ads.advertise.net
127.0.0.1 www.advertisingspaces.net
127.0.0.1 www.advertisingstats.com
127.0.0.1 advertisingpurchase.com
127.0.0.1 ad.adverticum.net
127.0.0.1 img.adverticum.net
127.0.0.1 imgs.adverticum.net
127.0.0.1 ads.advertisingz.com
127.0.0.1 ad.advertstream.com
127.0.0.1 adviva.com #[IE-SpyAd]
127.0.0.1 www.adviva.com
127.0.0.1 ads.adviva.net #[Panda.Spyware:Cookie/Adviva]
127.0.0.1 de.ads.adviva.net
127.0.0.1 adstats.adviva.net
127.0.0.1 www.traf.advscripts.com
127.0.0.1 ad.adworx.at
127.0.0.1 www.ad-z.de
127.0.0.1 banners.adzones.com
127.0.0.1 clicks.adzones.com
127.0.0.1 feeds.adzones.com
127.0.0.1 www.adzones.com
127.0.0.1 aeoworld.de
127.0.0.1 www.aeoworld.de #[W32/WMF-exploit]
127.0.0.1 banners.affilimatch.de
127.0.0.1 tracker.affistats.com #[msvrl.dll]
127.0.0.1 adz.afterdawn.net
127.0.0.1 ad.afy11.net
127.0.0.1 stats.agent.co.il
127.0.0.1 agentmediagroup.com #[Javascript.Exploit]
127.0.0.1 www.agentmediagroup.com
127.0.0.1 rmbannerserver.agestado.com.br
127.0.0.1 stats.agentinteractive.com
127.0.0.1 api.aggregateknowledge.com
127.0.0.1 aams1.aim4media.com
127.0.0.1 artwork.aim4media.com
127.0.0.1 www.aim4media.com #[SunBelt.Adserver.aim4media]
127.0.0.1 adlik.akavita.com
127.0.0.1 adlik2.akavita.com
127.0.0.1 adserver.akqa.net #[Ad-Aware Tracking.Cookie]
127.0.0.1 www.alaqiq.net #[Javascript.Exploit]
127.0.0.1 download.alexa.com #[Trackware.Alexa][SPYW_ALEXA.A]
127.0.0.1 download.china.alibaba.com #[Adware.AlibabaTB][AdWare.ToolBar.Alibabar.b]
127.0.0.1 tracking.allposters.com
127.0.0.1 ad.allstar.cz
127.0.0.1 bokee.allyes.com
127.0.0.1 demoafp.allyes.com
127.0.0.1 eastmoney.allyes.com
127.0.0.1 smarttrade.allyes.com
127.0.0.1 taobaoafp.allyes.com
127.0.0.1 tom.allyes.com
127.0.0.1 uuseeafp.allyes.com
127.0.0.1 www.almondnetworks.com
127.0.0.1 www.almoso3h.com #[Trojan-PSW.Win32.VB.cl]
127.0.0.1 www.alsaloumainvestment.com #[Win32/SpamTool.Gadina]
127.0.0.1 ad.altervista.org
127.0.0.1 marx2.altervista.org
127.0.0.1 pqwaker.altervista.org
127.0.0.1 bantam.ai.net
127.0.0.1 fiona.ai.net
127.0.0.1 adimg.alice.it
127.0.0.1 adv.alice.it
127.0.0.1 count1.altastat.com
127.0.0.1 altmedia101.com
127.0.0.1 www.alldep.com #[Spamdexing]
127.0.0.1 adserver.alt.com
127.0.0.1 c0.amazingcounters.com
127.0.0.1 c1.amazingcounters.com
127.0.0.1 c2.amazingcounters.com
127.0.0.1 c3.amazingcounters.com
127.0.0.1 c4.amazingcounters.com
127.0.0.1 c5.amazingcounters.com
127.0.0.1 c6.amazingcounters.com
127.0.0.1 c7.amazingcounters.com
127.0.0.1 c8.amazingcounters.com
127.0.0.1 www.amazingcounters.com
127.0.0.1 banner.ambercoastcasino.com
127.0.0.1 ads.amdmb.com
127.0.0.1 whos.amung.us #[WebBug]
127.0.0.1 advert.ananzi.co.za
127.0.0.1 advert2.ananzi.co.za
127.0.0.1 adserver.ancestry.com #[RealMedia]
127.0.0.1 adserver04.ancestry.com #[RealMedia]
127.0.0.1 andishecenter.com #[VBS/Envary.A]
127.0.0.1 www.andyhoppe.com
127.0.0.1 angpeu.info #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 ads.angryape.com
127.0.0.1 banners.ads.angryape.com
127.0.0.1 www.antarasystems.com
127.0.0.1 www.anticlown.com
127.0.0.1 ads.antionline.com
127.0.0.1 junior.apk.net
127.0.0.1 www.arcadebanners.com
127.0.0.1 www.arcadebannerexchange.com
127.0.0.1 ard114.info #[Spamdexing]
127.0.0.1 areabuyreal.com
127.0.0.1 act.areabuyreal.com #[Win32/TrojanDownloader.Zlob]
127.0.0.1 click.areabuyreal.com #[WildCard DNS]
127.0.0.1 www.areabuyreal.com
127.0.0.1 demiurge.arstechnica.com
127.0.0.1 artsklimited.info #[Win32/Padodor.NAQ]
127.0.0.1 banner.arttoday.com
127.0.0.1 ads.asia1.com.sg
127.0.0.1 asimpleinternet.com #[Tenebril.SpecialOffers]
127.0.0.1 www.asimpleinternet.com
127.0.0.1 ads.ask.com #[sv-click.looksmart.com]
127.0.0.1 www.askyaya.com #[SunBelt.AskYaya]
127.0.0.1 ads.aspalliance.com
127.0.0.1 ads.associatedcontent.com
127.0.0.1 dist.atlas-ia.com #[ADW_ATLAST.A]
127.0.0.1 www.atlas-ia.com #[Adware.OfferAgent][Adware-Atlas]
127.0.0.1 elitegaming.ath.cx #[Adware.AdSupport]
127.0.0.1 www.elitegaming.ath.cx
127.0.0.1 ads.auctionads.com
127.0.0.1 audiogalaxy.com
127.0.0.1 www.audiogalaxy.com
127.0.0.1 ads.auctioncity.co.nz
127.0.0.1 www.autosurfpro.com
127.0.0.1 ads.autotrader.co.za
127.0.0.1 adserving.autotrader.com #[SunBelt.AdServing.AutoTrader.com]
127.0.0.1 engine.awaps.net
127.0.0.1 www.axill.com
127.0.0.1 images.axill.in
127.0.0.1 www.axill.in
127.0.0.1 axload.to #[Adware.Webprefix][Trojan.Downloader.6588.E]
127.0.0.1 valid.axload.to
127.0.0.1 ayiosamvrosios.com #[Javascript.Exploit]
127.0.0.1 www.azads.net
127.0.0.1 azresults.com #[Spamdexing]
127.0.0.1 www.azresults.com
127.0.0.1 azsearch.org
127.0.0.1 babla.info #[Spamdexing]
127.0.0.1 adserver1.backbeatmedia.com
127.0.0.1 adserver1-images.backbeatmedia.com
127.0.0.1 bullseye.backbeatmedia.com
127.0.0.1 www.badhyip.org #[Google.Warning]
127.0.0.1 ads.badische-zeitung.de
127.0.0.1 bar.baidu.com #[Win32/Adware.Toolbar.Baidu][Sophos.JS/BDHelper-A]
127.0.0.1 download.baigoo.com #[AdWare.Win32.Baigoo.a][Trackware.Baigoo]
127.0.0.1 ad.baiso.com.cn #[Trojan.Baiso][ADSPY/BaiduBar.P][server down?]
127.0.0.1 balticaffiliate.com #[Spamdexing]
127.0.0.1 www.baltictop.com
127.0.0.1 adsrv.bankrate.com
127.0.0.1 click.banneradv.com
127.0.0.1 adserver.banneradministration.com
127.0.0.1 www.bannerbox.cn
127.0.0.1 bannerboxes.com #[BannerBoxes Ad Code]
127.0.0.1 clicks.bannerboxes.com
127.0.0.1 feeds.bannerboxes.com
127.0.0.1 www.bannerboxes.com
127.0.0.1 bannerbg.com
127.0.0.1 www.banner-exchange.nl
127.0.0.1 ad.bannerhost.ru
127.0.0.1 banners.bannerlandia.com.ar
127.0.0.1 www.bannermanagement.nl
127.0.0.1 www.bannerout.com
127.0.0.1 www.banneroverdrive.com
127.0.0.1 www.bannerpromotion.it
127.0.0.1 www.banner-mania.com
127.0.0.1 www.bannerspace.com
127.0.0.1 www3.bannerspace.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www5.bannerspace.com
127.0.0.1 www6.bannerspace.com
127.0.0.1 www7.bannerspace.com #[Tenebril.Tracking.Cookie]
127.0.0.1 www.bannerswap.ca
127.0.0.1 ads.vg.basefarm.net #[RealMedia]
127.0.0.1 media.baventures.com
127.0.0.1 ads.baz.ch
127.0.0.1 ad2.bbmedia.cz
127.0.0.1 bbeplayer.com #[WebBug]
127.0.0.1 autocontext.begun.ru
127.0.0.1 adlogger.bertgeens.be
127.0.0.1 www.belstat.be
127.0.0.1 www.belstat.com
127.0.0.1 www.belstat.nl
127.0.0.1 oas.benchmark.fr #[RealMedia]
127.0.0.1 bengilani.com #[VBS/Envary.A]
127.0.0.1 bestinfosearch.com
127.0.0.1 www.bestinfosearch.com #[Malicious.Links]
127.0.0.1 bestinshowjewelry.com #[HTML/TrojanDownloader.Agent.BP]
127.0.0.1 www.bestinshowjewelry.com
127.0.0.1 webtrends.besite.be
127.0.0.1 www.besttoolbars.net #[ADW_TBARWIN32.A]
127.0.0.1 ads.betanews.com
127.0.0.1 banner.betfred.com
127.0.0.1 www.bettertextads.com
127.0.0.1 big4top.com
127.0.0.1 www.big4top.com #[IFrame.Exploit]
127.0.0.1 ad0.bigmir.net
127.0.0.1 ad1.bigmir.net
127.0.0.1 ad4.bigmir.net
127.0.0.1 ad5.bigmir.net
127.0.0.1 ad6.bigmir.net
127.0.0.1 ad7.bigmir.net
127.0.0.1 adi.bigmir.net
127.0.0.1 c.bigmir.net #[SecuritySpace.WebBug]
127.0.0.1 i.bigmir.net
127.0.0.1 bigtracker.com
127.0.0.1 bighits.net
127.0.0.1 bigticker.bighits.net
127.0.0.1 bounty.bighits.net
127.0.0.1 www.bighits.net
127.0.0.1 counter.bigli.ru
127.0.0.1 bigstats.net
127.0.0.1 banex.bikers-engine.com
127.0.0.1 ad2.billboard.cz
127.0.0.1 adserver.bizhat.com
127.0.0.1 counter.bizland.com
127.0.0.1 dc.bizjournals.com
127.0.0.1 webads.bizservers.com
127.0.0.1 blackhatcrew.ru
127.0.0.1 www.black-hole.co.uk
127.0.0.1 ads2.blastro.com
127.0.0.1 ads3.blastro.com
127.0.0.1 ads4.blastro.com
127.0.0.1 blaze-search.com
127.0.0.1 ads.blick.ch
127.0.0.1 streamstats1.blinkx.com
127.0.0.1 ads.blizzard.com
127.0.0.1 blogadswap.com
127.0.0.1 tracker.blogbeat.net
127.0.0.1 ads.blogdrive.com
127.0.0.1 banners.blogexplosion.com
127.0.0.1 counter.blogexplosion.com
127.0.0.1 blogtextlinks.blogexplosion.com
127.0.0.1 rentblog.blogexplosion.com
127.0.0.1 mapstats.blogflux.com
127.0.0.1 www.blogpatrol.com
127.0.0.1 pcbutts1-therealtruth.blogspot.com
127.0.0.1 t.blogreaderproject.com #[WebBug]
127.0.0.1 ads1.prod.bluetape.com
127.0.0.1 blogmark.bokee.com #[Adware.BocaiToolbar]
127.0.0.1 count.blogscout.de
127.0.0.1 track.blogcounter.de
127.0.0.1 www.blogcounter.de
127.0.0.1 adserver.bluewin.ch
127.0.0.1 www.bmmetrix.com #[WebBug][Tracking.Cookie]
127.0.0.1 ads.boardtracker.com
127.0.0.1 ranks.boardtracker.com
127.0.0.1 adimage.bokee.com
127.0.0.1 ad.bol.bg
127.0.0.1 adv.bol.bg
127.0.0.1 ads.bomis.com
127.0.0.1 banners.bookmaker.com
127.0.0.1 ccc.boolans.com #[Adware.Rugo]
127.0.0.1 err.boom.ru
127.0.0.1 www.borlander.cn #[Adware.Borlan]
127.0.0.1 www.borlander.com.cn #[ADSPY/Boran.X.19.C]
127.0.0.1 astalavista.box.sk #[SiteAdvisor.astalavista.box.sk]
127.0.0.1 ads.brainiads.com
127.0.0.1 download.bravesentry.com #[McAfee.BraveSentry]
127.0.0.1 support.bravesentry.com
127.0.0.1 www.bravesentry.com #[NOD32.Win32/Adware.SpySheriff.variant]
127.0.0.1 ads.breakthru.com
127.0.0.1 bans.bride.ru
127.0.0.1 cc.bridgetrack.com
127.0.0.1 citi.bridgetrack.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 citi.bridgetrack.com.edgesuite.net
127.0.0.1 rccl.bridgetrack.com #[MVPS.Criteria]
127.0.0.1 banners.broadwayworld.com
127.0.0.1 www.browserplugin.com #[HJTH.EroticAccess][wobz.de]
127.0.0.1 bsdpng.info
127.0.0.1 btbilgisayarkursu.com #[Win32/TrojanDownloader.Small.AWA]
127.0.0.1 www.btbilgisayarkursu.com #[Win32/TrojanDownloader.Small.AWA]
127.0.0.1 www.bulletads.com
127.0.0.1 redemption.bullseye-media.net
127.0.0.1 users.bullseye-media.net
127.0.0.1 www.bullseye-media.net
127.0.0.1 bunnezone.com #[Win32/Jep.Russ]
127.0.0.1 burnsrecyclinginc.com #[Win32/TrojanDropper.Agent.NBX]
127.0.0.1 www.burnsrecyclinginc.com
127.0.0.1 www.bussines4me.net #[Win32/Persky.G][server down?]
127.0.0.1 ad1.bustcash.com
127.0.0.1 www.buy404s.com
127.0.0.1 www.buzzclick.com
127.0.0.1 tr.buzzlogic.com
127.0.0.1 byindia.com #[Spamdexing]
127.0.0.1 www.byip.cn #[Google.Warning]
127.0.0.1 multi.byulcom.com #[Win32/TrojanDownloader.Small.BIV]
127.0.0.1 ads.calgarystampede.com
127.0.0.1 canadianhw.ca #[VBS/Envary.A]
127.0.0.1 www.canadianhw.ca
127.0.0.1 ads.capablenet.com
127.0.0.1 images.cashfiesta.com #[AdWare.CashFiesta.a]
127.0.0.1 www.cashfiesta.com #[McAfee.Adware-CashFiesta]
127.0.0.1 www.cashfiesta.net
127.0.0.1 banner.casinoking.com #[AdWare.Win32.Casino.ae]
127.0.0.1 www.cashventure.com
127.0.0.1 ads.casino.com
127.0.0.1 ad.caradisiac.com
127.0.0.1 ads.cars.com
127.0.0.1 blockbuster.com.7.ccg360.com
127.0.0.1 blockbuster.med.ccg360.com
127.0.0.1 www.cd321.com
127.0.0.1 ads.cdfreaks.com #[eTrust.Ads.cdfreaks]
127.0.0.1 ads.cdrinfo.com
127.0.0.1 stats.cdrinfo.com #[WebBug]
127.0.0.1 www.celebritypicturesarchive.com #[Trojan-Downloader.Win32.IstBar.nn]
127.0.0.1 www.celebrity-pictures-world.com #[Trojan-Downloader.Win32.IstBar.nn]
127.0.0.1 clicktracker.centrum.cz
127.0.0.1 mds.centrport.net #[Ad-Aware.Tracking.Cookie]
127.0.0.1 cetrk.com
127.0.0.1 cesp.be #[HTML/TrojanDownloader.Agent.NAB]
127.0.0.1 adserver.cducinema.com
127.0.0.1 counter.cgiworld.net
127.0.0.1 tracker.cgiworld.net
127.0.0.1 abc.checkm8.com
127.0.0.1 rmm1u.checkm8.com
127.0.0.1 web.checkm8.com #[CHECKM8 AD TAGS]
127.0.0.1 web2.checkm8.com
127.0.0.1 ads.checkm8.co.za
127.0.0.1 ads.chellomedia.com
127.0.0.1 ads.china.com
127.0.0.1 www.china3q.com #[Trojan.Startpage.S]
127.0.0.1 ad.chip.de
127.0.0.1 www.chsniper.com #[Downloader.Sniper]
127.0.0.1 ad.cibleclick.com #[eTrust.Cibleclick]
127.0.0.1 www.cibleclick.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 cindyproject.info #[Spamdexing]
127.0.0.1 www.classicequipment.com #[Google.Warning]
127.0.0.1 board.classifieds1000.com
127.0.0.1 xp.classifieds1000.com
127.0.0.1 www.classifieds1000.com #[SiteAdvisor.classifieds1000.com]
127.0.0.1 images.clckm.com
127.0.0.1 pics.clckm.com #[Parking Service]
127.0.0.1 cleanfeed.info #[Spamdexing]
127.0.0.1 ads.clickad.com #[eTrust.Tracking.Cookie]
127.0.0.1 clickbank.net #[Ad-Aware.Tracking.Cookie]
127.0.0.1 hop.clickbank.net #[Adware.Clickbank][Adware.ClickDLoader]
127.0.0.1 ssl.clickbank.net
127.0.0.1 zzz.clickbank.net #[Ewido.TrackingCookie.Clickbank]
127.0.0.1 publishers.clickbooth.com #[directleads.com]
127.0.0.1 clickboothlnk.com
127.0.0.1 www.clickboothlnk.com
127.0.0.1 j.clickdensity.com
127.0.0.1 r.clickdensity.com
127.0.0.1 dsml.clickexperts.net
127.0.0.1 www.clicks2you.com
127.0.0.1 www.clickmanage.com
127.0.0.1 clicktopsite.com #[Spamdexing]
127.0.0.1 clicktracks.com #[McAfee.Cookie-Clicktracks]
127.0.0.1 stats.clicktracks.com #[Tenebril.Tracking.Cookie]
127.0.0.1 stats1.clicktracks.com # [eTrust.Tracking.Cookie]
127.0.0.1 stats2.clicktracks.com #[SpySweeper.Spy.Cookie]
127.0.0.1 stats3.clicktracks.com
127.0.0.1 stats4.clicktracks.com
127.0.0.1 www.clicktracks.com #[SunBelt.ClickTracks]
127.0.0.1 www.is1.clixgalore.com
127.0.0.1 www.clixgalore.com
127.0.0.1 hit.click2006.com
127.0.0.1 www2.click-fr.com
127.0.0.1 www3.click-fr.com
127.0.0.1 www4.click-fr.com
127.0.0.1 www.clickhouse.com #[SunBelt.ClickHouse]
127.0.0.1 www.click-power.com #[Win32/TrojanDownloader.VB.JL][Win32.Virtumonde.by]
127.0.0.1 www.clicks4u.com
127.0.0.1 www.clicksbroker.com
127.0.0.1 ad1.clickhype.com #[Ewido.TrackingCookie.Clickhype]
127.0.0.1 clickoly.com #[Spamdexing]
127.0.0.1 redirect.clickshield.net
127.0.0.1 clickthru.net
127.0.0.1 ads.clickthru.net
127.0.0.1 icon.clickthru.net
127.0.0.1 clicktorrent.info
127.0.0.1 static.clicktorrent.info
127.0.0.1 www.clicktorrent.info #[phpAds]
127.0.0.1 www1.clicktorrent.info
127.0.0.1 norbert_sirot.club.fr #[Trojan-Spy.Win32.Banker.anv]
127.0.0.1 banner.clubdicecasino.com
127.0.0.1 adserver.clix.pt
127.0.0.1 ad.cmfu.com
127.0.0.1 www.cnstats.com
127.0.0.1 ad.coas2.co.kr
127.0.0.1 ads.cobrad.com
127.0.0.1 collectiveads.net
127.0.0.1 www.combimedia.nl
127.0.0.1 bdx.comclick.com
127.0.0.1 br.comclick.com
127.0.0.1 ct2.comclick.com #[Tenebril.Tracking.Cookie]
127.0.0.1 fl01.ct2.comclick.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 ihm01.ct2.comclick.com
127.0.0.1 www.comclick.com #[Ewido.TrackingCookie.Comclick]
127.0.0.1 members.commissionmonster.com
127.0.0.1 aa.connextra.com
127.0.0.1 bb.connextra.com #[a22.g.akamai.net]
127.0.0.1 cc.connextra.com
127.0.0.1 dd.connextra.com
127.0.0.1 ee.connextra.com
127.0.0.1 ff.connextra.com #[a22.g.akamai.net]
127.0.0.1 data.connextra.com
127.0.0.1 linkexchange.consoleunderground.com
127.0.0.1 www.consoleunderground.com #[Adware.Begin2search]
127.0.0.1 ads.consumeraffairs.com
127.0.0.1 ads.contactmusic.com #[AdvertPro]
127.0.0.1 servedby.contextuad.org
127.0.0.1 svp.contextuad.org #[SunBelt.ContextuAd]
127.0.0.1 www.contextualclick.com #[Dynamic keywords analyser]
127.0.0.1 ads.console.net
127.0.0.1 su.copylouis.info #[SiteAdvisor.msiesettings.com]
127.0.0.1 banners.copyscape.com
127.0.0.1 www.countit.ch
127.0.0.1 counter.co.kz
127.0.0.1 www.counter-gratis.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 www.countercentral.com
127.0.0.1 www.counterguide.com
127.0.0.1 counter-shop.net
127.0.0.1 htm-pop-ky.counterstat.net
127.0.0.1 www.counting4free.com
127.0.0.1 www.counter.cz
127.0.0.1 www.counti.de
127.0.0.1 www.countmypage.com
127.0.0.1 log1.countomat.com
127.0.0.1 connectionzone.com
127.0.0.1 www.couponsandoffers.com #[Adware.TopMoxie]
127.0.0.1 data.coremetrics.com
127.0.0.1 test.coremetrics.com #[SpySweeper.Spy.Cookie]
127.0.0.1 twci.coremetrics.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 banner.coza.com
127.0.0.1 www.cpaclicks.com #[Spamdexing]
127.0.0.1 server.cpmstar.com #[ads.shizmoo.com]
127.0.0.1 cracks.am #[eTrust.Cracks.am][ADW_CRAMTB.A]
127.0.0.1 www.cracks.am #[fuck-portal.com][Adware.CramToolbar]
127.0.0.1 ads.cracked.com
127.0.0.1 track.cracked.com
127.0.0.1 www.crackserver.com #[StopBadware.Report]
127.0.0.1 new.crashextads.co.uk #[server down?]
127.0.0.1 crawl.ws
127.0.0.1 cont.crawl.ws #[AdWare.Win32.MegaKiss.b]
127.0.0.1 www.crawl.ws
127.0.0.1 counter.credo.ru
127.0.0.1 www.cridem.org #[Win32/Spy.Banker.AHY]
127.0.0.1 www.crispads.com
127.0.0.1 ads.crosswinds.net
127.0.0.1 ads.crucialparadigm.com
127.0.0.1 crunet.info #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 media.customeracquisitionsite.com #[customeracquisitionsite.adlegend.com]
127.0.0.1 cxss358.com #[HTML/TrojanDownloader.Agent.BP]
127.0.0.1 cyberbounty.com
127.0.0.1 clk.cyberbounty.com
127.0.0.1 pop.cyberbounty.com
127.0.0.1 serve.cyberbounty.com
127.0.0.1 www.cyberbounty.com
127.0.0.1 banner.cybertechdev.com
127.0.0.1 cybertown.ru
127.0.0.1 search.cygo.net
127.0.0.1 www.cygo.net #[McAfee.Adware-Cygo]
127.0.0.1 cytron.com #[DailyWinner][eTrust.Cytron]
127.0.0.1 www.cytron.com
127.0.0.1 www.d3m0n.biz #[server down?]
127.0.0.1 dabestdomain.info #[SiteAdvisor.msiesettings.com]
127.0.0.1 ads.dada.it
127.0.0.1 www.dailykeys.com #[Google.Warning]
127.0.0.1 mm.dalumm.com #[Win32/TrojanDownloader.Small.TZ]
127.0.0.1 www.data-jpn.com #[Trojan.Pajatan]
127.0.0.1 banner.date.com #[Tenebril.Tracking.Cookie]
127.0.0.1 www.dateclix.com #[DateClix.com Banner Exchange Code]
127.0.0.1 datingbanners.net
127.0.0.1 ads.datinggold.com
127.0.0.1 ad.db3nf.com
127.0.0.1 dcstat.com
127.0.0.1 deansplanet.com #[Malicious.Links.Zango]
127.0.0.1 www.deansplanet.com
127.0.0.1 au.track.decideinteractive.com
127.0.0.1 au.link.decideinteractive.com
127.0.0.1 eu.link.decideinteractive.com
127.0.0.1 link.decideinteractive.com
127.0.0.1 www.decideinteractive.com
127.0.0.1 www.decideinteractive.co.uk
127.0.0.1 deepcom.com #[SiteAdvisor.deepcom.com]
127.0.0.1 www.deepcom.com #[TrojanDropper.Win32.Small.gt]
127.0.0.1 collector.deepmetrix.com
127.0.0.1 geo.deepmetrix.com
127.0.0.1 www.deepmetrix.com #[Microsoft]
127.0.0.1 demsas-iran.com #[VBS/Envary.A]
127.0.0.1 ads.dennisnet.co.uk
127.0.0.1 ad.depositfiles.com
127.0.0.1 ad.detik.com
127.0.0.1 desire-search.com #[Spamdexing]
127.0.0.1 ads.deviantart.com
127.0.0.1 adsvr.deviantart.com
127.0.0.1 phpadsnew.devstart.com
127.0.0.1 banners.diariodelaltoaragon.es
127.0.0.1 track.did-it.com #[Panda.Spyware:Cookie/did-it]
127.0.0.1 counter.dieit.de
127.0.0.1 digiwexonline.com #[W32/Kibik.a]
127.0.0.1 www.digink.com #[PcTools.SysCheckBop32]
127.0.0.1 ads.digitalpoint.com
127.0.0.1 geo.digitalpoint.com
127.0.0.1 comm1.digits.com
127.0.0.1 counter.digits.com
127.0.0.1 ads.dir.bg
127.0.0.1 banners.dir.bg
127.0.0.1 ad.directaclick.com
127.0.0.1 direct-ip.com #[Adware-DirectIP][SecurityRisk.DirectIP]
127.0.0.1 www.direct-ip.com #[Adware-DirectIP][Adware-CommanderNET]
127.0.0.1 ad.directconnect.se
127.0.0.1 banners.directnic.com #[SecuritySpace.WebBug][MVPS.Criteria]
127.0.0.1 dnads.directnic.com
127.0.0.1 parked.directnic.com
127.0.0.1 stats.directnic.com
127.0.0.1 www.directnicparking.com
127.0.0.1 cache.directorym.com #[c2.mii.instacontent.net]
127.0.0.1 ads.directnetadvertising.net #[SiteAdvisor.directnetadvertising.net]
127.0.0.1 www.directnetadvertising.net #[Ad-Aware Tracking.Cookie]
127.0.0.1 ad.displayadsmedia.com
127.0.0.1 agentq.ditto.com
127.0.0.1 js.ditto.com
127.0.0.1 matrix.ditto.com
127.0.0.1 media.ditto.com #[a232.x.akamai.net]
127.0.0.1 www.ditto.com #[AdWare.Win32.Softomate.c]
127.0.0.1 cnads.dixcom.com
127.0.0.1 dcww.dmcast.com #[Adware-DesktopMedia]
127.0.0.1 ad1.dmcmedia.co.kr
127.0.0.1 dmdl.dmcast.com
127.0.0.1 install.dmcast.com #[Adware-DesktopMedia.dr]
127.0.0.1 track.dmipartners.com
127.0.0.1 ads.dmnews.com
127.0.0.1 ad.dmpi.net
127.0.0.1 ad2.dmpi.net
127.0.0.1 ad3.dmpi.net
127.0.0.1 ad4.dmpi.net
127.0.0.1 ubnm.dmpi.net
127.0.0.1 searchportal.dnparking.com #[Parking Service]
127.0.0.1 www.dnscaching.net #[SiteAdvisor.dnscaching.net]
127.0.0.1 dnv-counter.com
127.0.0.1 www.domamil.cz #[Trojan.Beagooz]
127.0.0.1 www.dodostats.com
127.0.0.1 dontouchmyad.com #[drivecleaner.com]
127.0.0.1 doorgen.com #[Spamdexing]
127.0.0.1 www.doorgen.com
127.0.0.1 ads.dotomi.com
127.0.0.1 www.down988.cn #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 www.download-services.com #[VBA32.Trojan-Downloader.Agent.26]
127.0.0.1 www.downseek.com #[SunBelt.DownSeek Search]
127.0.0.1 downloa-d.com
127.0.0.1 www.downloa-d.com #[Trojan-Clicker.Win32.Agent.ip]
127.0.0.1 banners.dpnet.com.br
127.0.0.1 drmx01.net #[Spamdexing]
127.0.0.1 counter.dreamhost.com
127.0.0.1 www.claus.drehteile-rieche.de #[Win32.Formglieder.B]
127.0.0.1 www.dreamadvert.com #[SunBelt.Dreamadvert]
127.0.0.1 www.dropthehammer.com #[Win32/Spy.Banker.AHY]
127.0.0.1 ads.drugs.com
127.0.0.1 b.ds1.nl
127.0.0.1 ddd.dudu.com #[Tenebril.DuDu Accelerator]
127.0.0.1 ulink4.dudu.com #[Adware.DDDClient][SunBelt.DuDuAccelerator]
127.0.0.1 ulink13.dudu.com #[Win32/Adware.DM]
127.0.0.1 www.dudu.com #[McAfee.Downloader-AVV]
127.0.0.1 www.duenow.com
127.0.0.1 www.dutty.de #[W32.Peerload.A]
127.0.0.1 gfx.dvlabs.com
127.0.0.1 klipads.dvlabs.com
127.0.0.1 www.dzy520.com #[Google.Warning]
127.0.0.1 hits.e.cl
127.0.0.1 banners.earnunited.com
127.0.0.1 blogads.ebanner.nl
127.0.0.1 www.e-bannerx.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 www.earncashontheinternet.com #[SunBelt.OpinionBar]
127.0.0.1 www.eash.info #[Spamdexing][Microsoft.Strider]
127.0.0.1 click.easilyfound.com #[Tenebril.AdTraffic]
127.0.0.1 www.easilyfound.com
127.0.0.1 www.eastworldnetwork.com
127.0.0.1 www.easycounter.com
127.0.0.1 banners.easydns.com
127.0.0.1 easyerror.info #[Trojan-Downloader.Win32.Delf.agw]
127.0.0.1 easyhitcounters.com
127.0.0.1 beta.easyhitcounters.com
127.0.0.1 www.ebannertraffic.com
127.0.0.1 easy-web-stats.com
127.0.0.1 adserv1.ebates.com #[WebSavings]
127.0.0.1 mailer.ebates.com
127.0.0.1 www.ebates.com #[Adware.MoeMoney]
127.0.0.1 ads.eccentrix.com
127.0.0.1 ads.ecrush.com #[AdvertPro]
127.0.0.1 www.eden21.net #[Win32/Haxdoor][TR/Dldr.Botol.D.1]
127.0.0.1 c6.edgesuite.net #[RealMedia]
127.0.0.1 ads.edirectme.com
127.0.0.1 qq.ee28.cn #[Javascript.Exploit]
127.0.0.1 einfachstarten.com #[Trojan.Firpage]
127.0.0.1 eisenstein.dk #[tracking.ping]
127.0.0.1 www.ejmx.com #[Adware.ElectroJMX]
127.0.0.1 ad.e-kolay.net
127.0.0.1 www.ek21.com #[Trojan.Chost.B]
127.0.0.1 www.elancenet.org #[Worm/Eyeveg.CH]
127.0.0.1 now.eloqua.com #[WebBug]
127.0.0.1 ads.eluniversal.com.mx
127.0.0.1 hits.eluniversal.com.mx
127.0.0.1 publicidad.eluniversal.com.mx
127.0.0.1 elwebsearch.info #[Malicious Links.Umax]
127.0.0.1 wwv.elwebsearch.info
127.0.0.1 www.elwebsearch.info
127.0.0.1 ad1.emediate.dk
127.0.0.1 ad1.emediate.se
127.0.0.1 www.emoinstaller.com #[Win32/Adware.NdotNet][SiteAdvisor.emoinstaller.com]
127.0.0.1 www.emusic.com #[McAfee.Adware-eMusic][F-Secure.Adware.eMusic]
127.0.0.1 dotnet.endai.com
127.0.0.1 stats.engineseeker.com
127.0.0.1 entk.net
127.0.0.1 log.enquisite.com
127.0.0.1 adv.entercasino.com #[Adware.Casino.V]
127.0.0.1 enthro.com
127.0.0.1 enthro.info #[Malicious.Links.DriveCleaner]
127.0.0.1 enthro.net
127.0.0.1 enthro.org
127.0.0.1 ads.eog.com
127.0.0.1 ads.e-planning.net
127.0.0.1 ads.us.e-planning.net
127.0.0.1 adserving00.epi.es
127.0.0.1 adserving03.epi.es
127.0.0.1 www.e-referrer.com
127.0.0.1 launcheruk.escritorioactivo.com
127.0.0.1 vipuk.escritorioactivo.com #[HJTH.123Messenger Hijacker]
127.0.0.1 www.escorcher.com #[eTrust.EScorcher]
127.0.0.1 www.eshopads2.com
127.0.0.1 gtb.etology.com
127.0.0.1 pages.etology.com
127.0.0.1 www.etracker.de
127.0.0.1 www.etxh.com #[Win32/Prosti.C]
127.0.0.1 ads.ero-advertising.com
127.0.0.1 adopt.euroclick.com #[Ewido.TrackingCookie.Euroclick]
127.0.0.1 cdn.euroclick.com
127.0.0.1 www.euroklik.nl #[EasyBar][HJTH.SinCity Dialer]
127.0.0.1 advert.eurotip.cz
127.0.0.1 www.euros4click.de
127.0.0.1 ad.eurosport.com #[oas.eurosport.com]
127.0.0.1 www.eurowebstats.com
127.0.0.1 www.everestpoker.com #[AdWare.Win32.Casino.t]
127.0.0.1 advert.exaccess.ru
127.0.0.1 dynamic.exaccess.ru
127.0.0.1 static.exaccess.ru
127.0.0.1 www.exchangead.com
127.0.0.1 exchange.bg
127.0.0.1 www.exchange.bg
127.0.0.1 exit-ad.de #[Ad-Aware.Tracking.Cookie]
127.0.0.1 exitexchange.com #[IE-SpyAd][SiteAdvisor.exitexchange.com]
127.0.0.1 ads.exitexchange.com
127.0.0.1 count.exitexchange.com #[McAfee.Cookie-Exitexchange]
127.0.0.1 images.exitexchange.com
127.0.0.1 www.exitexchange.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.exittrade.com
127.0.0.1 www.exittraffic.net #[SiteAdvisor.exittraffic.net]
127.0.0.1 syndication.exoclick.com
127.0.0.1 nyton.experclick.com #[p.mii.instacontent.net]
127.0.0.1 www.experclick.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ads.expressindia.com #[server down?]
127.0.0.1 banners.expressindia.com
127.0.0.1 cdn.eyewonder.com #[SunBelt.EyeWonder]
127.0.0.1 pixel1097.everesttech.net
127.0.0.1 pixel1324.everesttech.net
127.0.0.1 pixel1370.everesttech.net
127.0.0.1 www.evidence-eliminator.com
127.0.0.1 evilman.cn #[Win32/TrojanDownloader.VB.APY]
127.0.0.1 ads2.exhedra.com
127.0.0.1 ads.expedia.com
127.0.0.1 www.eyeget.com #[McAfee.Adware-EyeGet]
127.0.0.1 feedback.eyereturn.com
127.0.0.1 resources.eyereturn.com
127.0.0.1 timespent.eyereturn.com
127.0.0.1 voken.eyereturn.com
127.0.0.1 ads.ezboard.com
127.0.0.1 eziin.com #[Adware.Eziin]
127.0.0.1 www.eziin.com
127.0.0.1 www.ezurl.co.kr #[Spyware.Ezurl]
127.0.0.1 ads.facebook.com #[facebook-ads.vo.llnwd.net]
127.0.0.1 ads.ak.facebook.com
127.0.0.1 www.factorygames.com #[SiteAdvisor.factorygames.com]
127.0.0.1 banner.fairpoker.com #[AdWare.Win32.Casino.w]
127.0.0.1 tmp.farfly.org #[Trojan.Farfli]
127.0.0.1 www.fast-adv.it
127.0.0.1 www.fastfind.org #[TROJ_STARTPAG.KF][Win32/Adware.MediaBack]
127.0.0.1 fastonlineusers.com
127.0.0.1 fasttrack.nu
127.0.0.1 fastwebcounter.com
127.0.0.1 counter.fateback.com
127.0.0.1 counter1.fc2.com
127.0.0.1 www.ffxiforums.net #[Trojan-PSW.Win32.OnLineGames.kw]
127.0.0.1 alex.fileburst.com #[Win32/TrojanDropper.Agent.NBT]
127.0.0.1 adserver.filefront.com #[Ad-Aware.Tracking.Cookie]
127.0.0.1 findover.org #[Spamdexing]
127.0.0.1 search.findscout.com
127.0.0.1 www.findscout.com #[W32/Delf.KPZ]
127.0.0.1 ai.p.findology.com
127.0.0.1 banner.finn.no
127.0.0.1 ads.firingsquad.com
127.0.0.1 ads2.firingsquad.com
127.0.0.1 ads.firstgrand.com
127.0.0.1 fishclix.com
127.0.0.1 www.fishclix.com
127.0.0.1 www.fish-screensaver.com #[AdWare.Win32.Gator.1008]
127.0.0.1 www.fjordbergen.com #[Win32/Spy.Banker.BIG]
127.0.0.1 www.fjjyjy.net #[Win32/Hipigon][W32.Fijjy]
127.0.0.1 cdn.flashedmail.com #[Parked?]
127.0.0.1 tracker1.flashedmail.com #[IE-SpyAd]
127.0.0.1 adserver4.fluent.ltd.uk
127.0.0.1 adserver.fmpub.net
127.0.0.1 dynamic.fmpub.net
127.0.0.1 static.fmpub.net
127.0.0.1 ads.fmwinc.com
127.0.0.1 www.foofle.net #[Backdoor.Foobot]
127.0.0.1 adcycle.footymad.net
127.0.0.1 www.forodeortodoncia.com #[Backdoor.IRC.Zapchast]
127.0.0.1 js.forrestersurveys.com
127.0.0.1 socratos.forrestersurveys.com
127.0.0.1 akcr.free.fr #[Win32/Spy.Bancos.U]
127.0.0.1 googlelite.free.fr #[Spamdexing]
127.0.0.1 ad.freecity.de
127.0.0.1 ads05.freecity.de
127.0.0.1 freecounters.xp.tl
127.0.0.1 maurobb.freecounter.it
127.0.0.1 www.freecounter.it
127.0.0.1 securinews.free.fr #[Trojan.Hexem]
127.0.0.1 www.freedownloadhq.com #[SiteAdvisor.freedownloadhq.com]
127.0.0.1 ad.freefind.com
127.0.0.1 www.freehitwebcounters.com
127.0.0.1 adverts.freeloader.com
127.0.0.1 freelogs.com
127.0.0.1 bar.freelogs.com
127.0.0.1 goo.freelogs.com
127.0.0.1 htm.freelogs.com
127.0.0.1 ico.freelogs.com
127.0.0.1 joe.freelogs.com
127.0.0.1 mom.freelogs.com
127.0.0.1 xyz.freelogs.com
127.0.0.1 adserver.freenet.de
127.0.0.1 freeonlineusers.com
127.0.0.1 www.free-ranking.de
127.0.0.1 www.freerip.com #[AdTool.Win32.MyWebSearch.ak]
127.0.0.1 free-stats.com
127.0.0.1 abbyssh.freestats.com
127.0.0.1 insurancejournal.freestats.com
127.0.0.1 www.freestat.ws
127.0.0.1 www.freestats.ws
127.0.0.1 banners.freett.com
127.0.0.1 count.freett.com
127.0.0.1 counters.freewebs.com
127.0.0.1 ads.freeonlinegames.com
127.0.0.1 stats.freeonlinegames.com
127.0.0.1 error.freewebsites.com
127.0.0.1 www.freewebsites.com
127.0.0.1 media.ftv-publicite.fr #[RealMedia]
127.0.0.1 fullddl.com
127.0.0.1 www.fullddl.com #[HTML/TrojanDownloader.XXXToolbar]
127.0.0.1 404.funpic.de
127.0.0.1 funppc.com
127.0.0.1 www.funppc.com
127.0.0.1 ads.futurenetworkusa.com #[server down?]
127.0.0.1 ads.gad-network.com
127.0.0.1 adserver.gadu-gadu.pl #[server down?]
127.0.0.1 www.gamersbanner.com
127.0.0.1 ads.gameservers.com
127.0.0.1 ads.gamespy.com #[SpySweeper.Spy.Cookie]
127.0.0.1 adcontent.gamespy.com
127.0.0.1 ads.gamespyid.com
127.0.0.1 www.gameurdr.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 server.gamyun.net
127.0.0.1 www.gamyun.net #[Adware.GamyunIeToolbar]
127.0.0.1 ad.garantiarkadas.com
127.0.0.1 ads.gather.com
127.0.0.1 track.gawker.com #[WebBug]
127.0.0.1 haymarket-adserver.gcnpublishing.com
127.0.0.1 www.gebr-wachs.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 sda.geek.com #[AdvertPro]
127.0.0.1 adserver.geenstijl.nl
127.0.0.1 kassa.geenstijl.nl
127.0.0.1 adserver.geizkragen.de
127.0.0.1 gnt01.generation-nt.com
127.0.0.1 gd.geobytes.com #[obtains users location]
127.0.0.1 geotarget.info #[Whois.Blacklisted]
127.0.0.1 banners.geotarget.info
127.0.0.1 www.geotarget.info
127.0.0.1 www.geowhere.net #[SunBelt.GeoWhere Search]
127.0.0.1 get-access.host.sk #[McAfee.StartPage-IR]
127.0.0.1 getclicky.com
127.0.0.1 static.getclicky.com
127.0.0.1 www.getmusicvideocodes.com #[Malicious.Links.Zango]
127.0.0.1 www.getsmart.com
127.0.0.1 dlx.getupdate.com #[AdvWare.ToolBar.VB.b][Adware.Getup]
127.0.0.1 www.giantdating.com #[Spamdexing.adultfriendfinder]
127.0.0.1 banner.giantvegas.com
127.0.0.1 truehits.gits.net.th
127.0.0.1 truehits1.gits.net.th
127.0.0.1 ads.globo.com
127.0.0.1 ads.img.globo.com
127.0.0.1 glory-movy.net #[Javascript.Exploit]
127.0.0.1 duke.gocomics.com #[ads.uclick.com]
127.0.0.1 www.god74.com #[Trojan.Huanux]
127.0.0.1 www.godesktop.com #[SiteAdvisor.godesktop.com]
127.0.0.1 adserver2.goals365.com
127.0.0.1 www.go-and-search.com #[Spamdexing]
127.0.0.1 goglee.biz
127.0.0.1 www.goglee.biz
127.0.0.1 golden-keys.net #[Spamdexing]
127.0.0.1 banner.goldenpalace.com #[Tenebril.Tracking.Cookie]
127.0.0.1 stage.goldkey.com #[Parking Service]
127.0.0.1 goldstats.net
127.0.0.1 www.goldstats.net
127.0.0.1 www.goodhealth-search.com #[Spamdexing]
127.0.0.1 www.qooqlesearch.com #[Spamdexing]
127.0.0.1 www.goggle.com #[IE-SpyAd][typo squatter]
127.0.0.1 google-counter.com #[Win32/Spy.Banker.CKW]
127.0.0.1 www.google-counter.com #[Google.Warning]
127.0.0.1 google-moogle.com #[Spamdexing]
127.0.0.1 www.google-moogle.com
127.0.0.1 www.google-hard.com #[Win32/TrojanProxy.Agent.LK]
127.0.0.1 google-pharmacy.com #[Spamdexing]
127.0.0.1 goooglegulp.com #[Spamdexing]
127.0.0.1 www.gogogo.com #[PremiumTraffic.Parking Service]
127.0.0.1 partner.gonamic.de
127.0.0.1 www.goodsearchnow.com #[Trojan.Jakposh]
127.0.0.1 googlus.com #[Spamdexing]
127.0.0.1 adincl.gopher.com #[InfoSpace]
127.0.0.1 goserv.com #[VBS/Exploit.Phel.A]
127.0.0.1 stat.org.gosite.ws
127.0.0.1 gostats.com
127.0.0.1 as.gostats.com
127.0.0.1 c1.gostats.com
127.0.0.1 c2.gostats.com #[SpySweeper.Spy.Cookie]
127.0.0.1 c3.gostats.com
127.0.0.1 c4.gostats.com #[Panda.Spyware:Cookie/GoStats]
127.0.0.1 ded.gostats.com
127.0.0.1 monster.gostats.com
127.0.0.1 webcounter.goweb.de
127.0.0.1 ads.goyk.com
127.0.0.1 www.gpt-pal.com #[Javascript.Exploit]
127.0.0.1 graffitifonts.com
127.0.0.1 www.graffitifonts.com #[Malicious.Links.Zango]
127.0.0.1 graficastrigo.com #[Trojan.Tabela.E]
127.0.0.1 www.gratis-counter-gratis.de
127.0.0.1 www.gratis-toplist.de
127.0.0.1 adv.gratuito.st
127.0.0.1 greatfog.com #[Javascript.Exploit][server down?]
127.0.0.1 www.greasypalm.co.uk #[PcTools.GreasyPalm bar]
127.0.0.1 greencunt.org #[Javascript.Exploit][server down?]
127.0.0.1 grepblogs.net
127.0.0.1 grigcnt.info #[Javascript.Exploit]
127.0.0.1 adserver.gruprc.ro
127.0.0.1 publi.grupocorreo.es #[RealMedia]
127.0.0.1 ads.guru3d.com
127.0.0.1 www.g-wizzads.net #[adbureau.net]
127.0.0.1 www.h148.cn #[Google.Warning]
127.0.0.1 ads2.haber3.com
127.0.0.1 www.handyarchive.com #[SiteAdvisor.handyarchive.com]
127.0.0.1 www.haosf128.com #[Google.Warning]
127.0.0.1 streamit.hardwarezone.com
127.0.0.1 ad1.hardware.no #[AdvertPro]
127.0.0.1 adserver.hardwareanalysis.com
127.0.0.1 ad.harmony-central.com
127.0.0.1 ds1.harmony-central.com
127.0.0.1 www.harmonyhollow.net #[SiteAdvisor.harmonyhollow.net]
127.0.0.1 ads.harpers.org
127.0.0.1 hartim.com
127.0.0.1 ad0.haynet.com
127.0.0.1 ad.hbv.de
127.0.0.1 ads.heias.com
127.0.0.1 helpingfind.info #[SiteAdvisor.msiesettings.com]
127.0.0.1 www.henbang.net #[Adware.Henbang][SPYW_HAP.A]
127.0.0.1 www.hentaibanners.com
127.0.0.1 www.hentaicashmachine.com
127.0.0.1 www.hentaiclicks.com
127.0.0.1 www.hentaicounter.com
127.0.0.1 www.hentaihits.com
127.0.0.1 www.hentaipop.com #[Electronic Group Dialer]
127.0.0.1 www.hentaiseeker.com
127.0.0.1 www.hentaitoonami.com
127.0.0.1 ads.herbalsmokeshop.com
127.0.0.1 www.herbalsmokeshops.com
127.0.0.1 www2.hermoment.com
127.0.0.1 www.hermoment.com
127.0.0.1 ads.hexun.com
127.0.0.1 www.hey.lt
127.0.0.1 pubs.hiddennetwork.com
127.0.0.1 ads.highdefdigest.com
127.0.0.1 www.hiperstat.com
127.0.0.1 adserver.hispanoclick.com
127.0.0.1 www.hitscount.com
127.0.0.1 hits-counter.com
127.0.0.1 www.hits-counter.com
127.0.0.1 ctr.hitcounter-1.com
127.0.0.1 www.hit-counter-download.com
127.0.0.1 hithopper.com #[Adware.Hithopper]
127.0.0.1 www.hithopper.com #[ADW_HITHOPPER.A]
127.0.0.1 rdr.hitmngr.com
127.0.0.1 hitmodel.net
127.0.0.1 www.hit-counts.com
127.0.0.1 hit-now.com
127.0.0.1 www.hitscreamer.com
127.0.0.1 hitslog.com
127.0.0.1 h1.hitslog.com
127.0.0.1 s4.histats.com
127.0.0.1 s10.histats.com
127.0.0.1 s11.histats.com
127.0.0.1 www.hitstats.co.uk
127.0.0.1 hitstats.net
127.0.0.1 www.hittracking.com
127.0.0.1 images.hitwise.co.uk
127.0.0.1 anna.homeftp.net #[W32.Linkbot.A]
127.0.0.1 adserver.hostfinderguy.com
127.0.0.1 www.gontijoamaral.hpg.com.br #[Adware.Diginum]
127.0.0.1 www.adserver.home.pl #[server down?]
127.0.0.1 www.homeoffun.com #[SiteAdvisor.homeoffun.com]
127.0.0.1 counters.honesty.com
127.0.0.1 cgi.honesty.com #[MVPS.Criteria]
127.0.0.1 ad.hosting.pl
127.0.0.1 ns1.hosting101.biz #[JS/Small.DN]
127.0.0.1 hot8888.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 hot8888.cn #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 ad2.hotels.com
127.0.0.1 www.hot-lindsay.com #[Malicious.Links.Zango]
127.0.0.1 hotlinkbanners.com
127.0.0.1 www.hotlinkbanners.com
127.0.0.1 cgi.hotstat.nl
127.0.0.1 viewstat.hotstat.nl
127.0.0.1 hotstream.info
127.0.0.1 ads.hotword.com.br
127.0.0.1 ads2.hotword.com.br
127.0.0.1 ads3.hotword.com.br
127.0.0.1 ads4.hotword.com.br
127.0.0.1 ads5.hotword.com.br
127.0.0.1 ads6.hotword.com.br
127.0.0.1 ads7.hotword.com.br
127.0.0.1 ad.howstuffworks.com #[RealMedia][SpySweeper.Spy.Cookie]
127.0.0.1 hpod.com
127.0.0.1 www.htmate2.com #[Cursor.MySpace]
127.0.0.1 adserver.html.it
127.0.0.1 click.html.it
127.0.0.1 vip.huigezi.com #[Backdoor.Graybird.Q][W32.Looked.F]
127.0.0.1 down.hunll.com #[BDS/Agent.ahj.701]
127.0.0.1 ads.hurra.de
127.0.0.1 www.huxley-online.net #[Win32/Spy.Elite.10.A]
127.0.0.1 hyip-review.info #[Javascript.Exploit]
127.0.0.1 www.hypercounter.com
127.0.0.1 www.hypertracker.com #[SpySweeper.Spy.Cookie]
127.0.0.1 ads.iafrica.com
127.0.0.1 www.i-clicks.net
127.0.0.1 hits.icdirect.com #[SunBelt.ICDirect.com]
127.0.0.1 hitctr01.icdirect.com
127.0.0.1 tracker.icerocket.com
127.0.0.1 ads.idgnow.com.br
127.0.0.1 banners.idg.com.br
127.0.0.1 adidm07.idmnet.pl
127.0.0.1 adidm.idmnet.pl
127.0.0.1 ie-exe.com #[AdWare.Win32.Softomate.x]
127.0.0.1 ad.ifrance.com
127.0.0.1 ijk.cc #[JS/Downloader-BCP]
127.0.0.1 image-catcher.com
127.0.0.1 bar.iebar8.com #[Adware.Navihelper]
127.0.0.1 stats.surfaid.ihost.com
127.0.0.1 adserver.ig.com.br
127.0.0.1 gate.ilogbox.com
127.0.0.1 ads.imeem.com
127.0.0.1 bbn.img.com.ua
127.0.0.1 content-ads.impactengine.com
127.0.0.1 www.impregnable.net #[TrojanDownloader.Win32.VB.dw][Trojan.Win32.StartPage.kk]
127.0.0.1 ads.ims.nl
127.0.0.1 in2search.org #[JS/TrojanDropper.Tivso.gen]
127.0.0.1 1.in2search.org
127.0.0.1 2.in2search.org
127.0.0.1 dns.in2search.org
127.0.0.1 s201.indexstats.com
127.0.0.1 stats.indexstats.com #[Analytics Tracking Code]
127.0.0.1 stats.indextools.com #[eTrust.Tracking.Cookie]
127.0.0.1 campaign.indieclick.com
127.0.0.1 optimize.indieclick.com
127.0.0.1 adcenter.in2.com
127.0.0.1 get.inetbar.com #[SunBelt.INetBar]
127.0.0.1 juggler.inetinteractive.com
127.0.0.1 rotator.juggler.inetinteractive.com
127.0.0.1 banners.inetfast.com
127.0.0.1 adserving.infinite-ads.com
127.0.0.1 www.infineo.de #[Win32/Spy.Banker.AWA]
127.0.0.1 www.info–bits.com
127.0.0.1 infospot.infocious.com
127.0.0.1 ads.infospace.com #[ADW_DEALHELPER.C]
127.0.0.1 msxml.infospace.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.infotelsrl.com #[eTrust.Infotel srl]
127.0.0.1 ads.injersey.com #[RealMedia]
127.0.0.1 bimonline.insites.be
127.0.0.1 ads.intellicast.com #[weather.com]
127.0.0.1 strtt.interfree.it #[W32.Iberio]
127.0.0.1 counter.internet.ge
127.0.0.1 indiads.com
127.0.0.1 images.indiads.com
127.0.0.1 servedby.indiads.com #[RealMedia]
127.0.0.1 popups.infostart.com #[eTrust.Popups.infostart.com]
127.0.0.1 www.imiclk.com
127.0.0.1 inexplorer.com
127.0.0.1 toolbar.inexplorer.com #[Win32/Parite.B]
127.0.0.1 www.inexplorer.com
127.0.0.1 www.inpopo.com #[W32.Validin]
127.0.0.1 oc.inspectorclick.com
127.0.0.1 trax.inspectorclick.com
127.0.0.1 v2.inspectorclick.com
127.0.0.1 v3.inspectorclick.com
127.0.0.1 instantbuzz.com #[NOD32.Win32/Adware.InstantBuzz]
127.0.0.1 www2.instantbuzz.com
127.0.0.1 www.instantbuzz.com #[Adware.ToolBar.InstantBuzz.a]
127.0.0.1 media.intelia.it
127.0.0.1 anm.intelli-direct.com #[IntelliTracker]
127.0.0.1 info.intelli-direct.com
127.0.0.1 oxfam.intelli-direct.com
127.0.0.1 tui.intelli-direct.com
127.0.0.1 www.intelli-tracker.com
127.0.0.1 newadserver.interfree.it #[Adcycle]
127.0.0.1 internet-explorer.name #[Trojan-Clicker.Win32.Agent.ip]
127.0.0.1 www.internet-explorer.name
127.0.0.1 www.interstats.nl
127.0.0.1 www.intrastats.com
127.0.0.1 channels.intwined.com #[Adware/ToolBar.ISearch.c]
127.0.0.1 search.intwined.com
127.0.0.1 www.intwined.com #[McAfee.Adware-SSF!Hosts]
127.0.0.1 www.invinc.com #[Troj/Dloader-J]
127.0.0.1 www.ipcounter.de
127.0.0.1 ad2.ip.ro
127.0.0.1 ads.ipowerweb.com
127.0.0.1 www.ipqwe.com #[Exploit.ANI]
127.0.0.1 content.ipro.com #[WebBug]
127.0.0.1 www.ipstat.com
127.0.0.1 isecurepages.net #[Google.Warning]
127.0.0.1 www.isecurepages.net #[IFrame.Exploit]
127.0.0.1 a.isohunt.com
127.0.0.1 adserver1.isohunt.com
127.0.0.1 ads.isoftmarketing.com
127.0.0.1 banman.isoftmarketing.com
127.0.0.1 ads1.itadnetwork.co.uk
127.0.0.1 itcompany.com #[SunBelt.Family Cyber Alert]
127.0.0.1 www.itcompany.com #[Symantec.Spyware.CyberAlert]
127.0.0.1 itisbest.info #[Spamdexing]
127.0.0.1 www.itrackpages.com
127.0.0.1 ilead.itrack.it
127.0.0.1 adserver.itsfogo.com
127.0.0.1 partnerfeed.itsfogo.com
127.0.0.1 www1.itsun.com
127.0.0.1 www8.itsun.com
127.0.0.1 ads.itv.com #[adbureau.net]
127.0.0.1 barafranca.iwarp.com #[Win32/Spy.ProAgent]
127.0.0.1 www.iwebmusic.com
127.0.0.1 iwebtunes.com #[FTC Action]
127.0.0.1 www.iwebtunes.com
127.0.0.1 ad.jamba.de
127.0.0.1 ad.jamba.net
127.0.0.1 ad.jamster.com
127.0.0.1 www.jcount.com
127.0.0.1 www.jellycounter.com
127.0.0.1 www.jethit.com
127.0.0.1 t1.jfglass.net #[Trojan.Booha]
127.0.0.1 dl.jiangmin.com #[Adware-BDSearch.dr]
127.0.0.1 jimmybuttons.com #[eTrust.Win32/Nirbot]
127.0.0.1 www.jm-my.com #[BackDoor-CXI]
127.0.0.1 ad.joetec.net
127.0.0.1 jointmediagroup.com #[Trojan-Spy.Win32.Delf.uc]
127.0.0.1 ads.jokaroo.com
127.0.0.1 jpedownload.joltid.com
127.0.0.1 banners.joost.com
127.0.0.1 ads.jossip.com
127.0.0.1 pastorale.jpn.org #[Win32/Spy.Banker.AHY]
127.0.0.1 www.joltid.com #[Adware.P2PNetworking][SPYW_PPNETWORK.B]
127.0.0.1 promotion.jpds.com
127.0.0.1 www.jprmthome.com #[Trojan-PSW.Win32.Maran.ei]
127.0.0.1 www.jstracker.com
127.0.0.1 ads.jt.org
127.0.0.1 www.justfreegames.com #[AdWare.Win32.Relevant.a]
127.0.0.1 925.vip.jx828.net #[HTML/Exploit.IframeBof]
127.0.0.1 jxdoe.com #[Win32/TrojanDownloader.Ani.Gen]
127.0.0.1 www.k265.com #[Adware.Borlan]
127.0.0.1 stat.katalysatormedia.no
127.0.0.1 kazantip-top.com
127.0.0.1 www.kazantip-top.com #[HTML/Exploit.VMLFill]
127.0.0.1 ads.webfever.kadserver.com
127.0.0.1 ads.deblok.net.kadserver.com
127.0.0.1 ads.zebest-3000.net.kadserver.com
127.0.0.1 countus.get.kadserver.com
127.0.0.1 geo113prod.kadserver.com
127.0.0.1 get.kadserver.com
127.0.0.1 scripts.kataweb.it
127.0.0.1 kazaalite.pl
127.0.0.1 www.kazaalite.pl #[MHTMLRedir.Exploit]
127.0.0.1 gavzad.keenspot.com
127.0.0.1 ad.kewlbox.com
127.0.0.1 a.keyrun.com #[Adware-TargetAD]
127.0.0.1 u.keyrun.com
127.0.0.1 union.keyrun.com
127.0.0.1 ww.keyrun.com
127.0.0.1 www1.keyrun.com
127.0.0.1 www.keyrun.com
127.0.0.1 banner.kiev.ua
127.0.0.1 kikclick.com #[Spamdexing]
127.0.0.1 adserve.kikizo.com
127.0.0.1 union.db.kingsoft.com #[PopupAds]
127.0.0.1 www.kiss-search.net
127.0.0.1 www.kisssearch.com #[Umax]
127.0.0.1 ebay.kisswin.com #[Adware.Kiswin]
127.0.0.1 kjsc.org #[Win32/Spy.Banker.ANV]
127.0.0.1 ads.kleinman.com #[Adcycle]
127.0.0.1 www.klikvipresources.com #[Spamdexing]
127.0.0.1 gfx.klipmart.com #[gfx.dvlabs.com]
127.0.0.1 kt3.kliptracker.com
127.0.0.1 kt4.kliptracker.com
127.0.0.1 www.kliptracker.com
127.0.0.1 ads.klixxx.com
127.0.0.1 www.km-nyc.com #[W32.Lecna.A]
127.0.0.1 click.kmindex.ru
127.0.0.1 counter.kmindex.ru
127.0.0.1 counting.kmindex.ru
127.0.0.1 www.kmindex.ru
127.0.0.1 www.knacads.com
127.0.0.1 xx.ko51.com #[Google.Warning]
127.0.0.1 images.kolmic.com
127.0.0.1 pics.kolmic.com #[Parking Service]
127.0.0.1 ads.komli.com
127.0.0.1 www.kompass-intl.com #[Win32/Adware.Toolbar.PowerSearch]
127.0.0.1 de.komtrack.com
127.0.0.1 koolbar.net #[Adware Bundler][ADW_KOOLBAR.A]
127.0.0.1 www.koolbar.net #[eTrust.AutoSearch]
127.0.0.1 sitestat.kpn-is.nl
127.0.0.1 kuaiso.com #[AdWare.Win32.Kuaiso.a]
127.0.0.1 toolsbar.kuaiso.com #[Adware.Kuaiso]
127.0.0.1 www.kuaiso.com
127.0.0.1 kustusch.com #[Javascript.Exploit]
127.0.0.1 www.kz163.net #[Win32/Virut]
127.0.0.1 alwaysforfriend.land.ru #[Trojan-Downloader.Win32.Banload.bdp]
127.0.0.1 www.animacoes.land.ru #[Downloader.Swif.B]
127.0.0.1 landinghall.com #[Spamdexing]
127.0.0.1 www.latinbusca.com #[Adware-CommanderNET]
127.0.0.1 ads.lawnsite.com
127.0.0.1 layer-ads.de
127.0.0.1 www.layer-ads.de
127.0.0.1 banner.lbs.km.ru
127.0.0.1 iframe.leadacceptor.com
127.0.0.1 leakedcelebvideos.com #[Win32/TrojanDownloader.Agent.BCZ]
127.0.0.1 www.leakedcelebvideos.com
127.0.0.1 lem0n.info
127.0.0.1 pubs.lemonde.fr
127.0.0.1 www.leopardsearch.com
127.0.0.1 www.letusearch.com #[Google.Warning]
127.0.0.1 ts1.lexmark.com
127.0.0.1 leythosthestalker.com
127.0.0.1 www.leythosthestalker.com
127.0.0.1 adserver.libero.it
127.0.0.1 adv-banner.libero.it
127.0.0.1 phpads.lime.com
127.0.0.1 link.ru
127.0.0.1 link.link.ru
127.0.0.1 www.linkads.net
127.0.0.1 ads.linki.nl
127.0.0.1 www.linkads.de
127.0.0.1 linkbuddies.com
127.0.0.1 banners.linkbuddies.com
127.0.0.1 www.linkbuddies.com
127.0.0.1 www.linkcounter.com
127.0.0.1 linksexchange.net
127.0.0.1 linkexchange.ru
127.0.0.1 web.linkexchange.ru
127.0.0.1 www.linkexchange.ru
127.0.0.1 link4link.com
127.0.0.1 plus.link4link.com
127.0.0.1 www.links4trade.com
127.0.0.1 escati.linkopp.net
127.0.0.1 www.linkopp.net
127.0.0.1 click.linkstattrack.com #[SiteAdvisor.linkstattrack.com]
127.0.0.1 linktarget.com
127.0.0.1 banner.linktech.cn
127.0.0.1 www.linkworth.com
127.0.0.1 ads.linuxjournal.com
127.0.0.1 www.ligue13.com #[Win32/Spy.Banker.BIG]
127.0.0.1 www.liveads.org
127.0.0.1 livecounter.net
127.0.0.1 www.livecounter.net
127.0.0.1 image.adv.livedoor.com
127.0.0.1 js.livehelper.com
127.0.0.1 newbrowse.livehelper.com
127.0.0.1 ads.livescore.com
127.0.0.1 traffic.liveuniversenetwork.com
127.0.0.1 traffic.livevideo.com
127.0.0.1 broadent.vo.llnwd.net
127.0.0.1 lw.lnkworld.com
127.0.0.1 loadz.biz #[Javascript.Exploit]
127.0.0.1 omnituretrack.local.com
127.0.0.1 ads.locators.com
127.0.0.1 toolbar.locators.com #[AdWare.Win32.Locator.f]
127.0.0.1 www.lojastal.com.br #[Win32/Spy.Banker.ANV]
127.0.0.1 lol.to #[HTML/Exploit.Mht]
127.0.0.1 err.lolipop.jp
127.0.0.1 www.lookde5.com #[W32.Looked]
127.0.0.1 lookoutsoft.net #[SiteAdvisor.lookoutsoft.net]
127.0.0.1 screensavers.lookoutsoft.net
127.0.0.1 a.loomia.com #[Tracking.Cookie]
127.0.0.1 www.lookoutsoft.net #[AdWare.Win32.WinAD.b]
127.0.0.1 www.lords-of-havoc.de #[Trojan.Mitglieder.C][Backdoor.Gaster]
127.0.0.1 lottery-news.info #[HTML/TrojanDownloader.Agent.NAB]
127.0.0.1 adserv.lowyat.net
127.0.0.1 hexusads.fluent.ltd.uk
127.0.0.1 www.luxemil.com #[Google.Warning]
127.0.0.1 ads-apsa.lvz-online.de
127.0.0.1 www.lynxtrack.com
127.0.0.1 counter.lyricsdownload.com
127.0.0.1 m2k.ru
127.0.0.1 ad.m5prod.net
127.0.0.1 ad.m-adx.com
127.0.0.1 media.m-adx.com
127.0.0.1 www.macrcmedia.com #[Exploit.ANI]
127.0.0.1 www.macrcmedia.net
127.0.0.1 ads.madisonavenue.com
127.0.0.1 resource.madisonavenue.com
127.0.0.1 textads.madisonavenue.com
127.0.0.1 www.madrascements.com #[Win32/Spy.Banker.Big]
127.0.0.1 banner.magicboxcasino.com #[AdWare.Win32.Casino.w]
127.0.0.1 msn-sexoweb.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 humortadela.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 www.novogerador.mail15.com
127.0.0.1 www.uolcard.mail15.com #[Trojan-Spy.Win32.Banker.ark]
127.0.0.1 voegol.mail15.com #[Win32/Spy.Banker.ANV]
127.0.0.1 humortadela0.mail333.com #[Win32/Spy.Banker.AHY]
127.0.0.1 destino-gol.mail333.com #[Win32/Spy.Banker.BCK]
127.0.0.1 www.messengerbeta.mail333.com #[Win32/Spy.Banker.BCK]
127.0.0.1 mair.net #[Realtracker]
127.0.0.1 ads.marketing-internet.com
127.0.0.1 marketing-know-how.com #[TR/Dldr.iBill.V]
127.0.0.1 adsnew.maktoob.com #[AdvertPro]
127.0.0.1 aw.masterstats.com
127.0.0.1 erotic.masterstats.com
127.0.0.1 image.masterstats.com
127.0.0.1 link.masterstats.com
127.0.0.1 vw.masterstats.com #[Ewido.TrackingCookie.Masterstats]
127.0.0.1 adserver.matchcraft.com
127.0.0.1 www.maxi-music.fr #[Win32/Spy.Banker.ANV]
127.0.0.1 ads.maxivip.fr
127.0.0.1 sitestat.mayoclinic.com
127.0.0.1 ads.mcafee.com
127.0.0.1 directads.mcafee.com #[Tenebril.Tracking.Cookie]
127.0.0.1 md55.net #[Google.Warning]
127.0.0.1 www2.md80.cn
127.0.0.1 www.md80.cn #[W32.Validin]
127.0.0.1 tracker.measuremap.com
127.0.0.1 mcmads.mediacapital.pt #[DoubleClick]
127.0.0.1 matrix.mediavantage.de
127.0.0.1 adland.medialand.ru
127.0.0.1 adnet.medialand.ru
127.0.0.1 content.medialand.ru
127.0.0.1 ads.mediamayhemcorp.com
127.0.0.1 ads.mediaodyssey.com
127.0.0.1 acvs.mediaonenetwork.net
127.0.0.1 acvsrv.mediaonenetwork.net
127.0.0.1 ads1.mediaops.com.br
127.0.0.1 ad2.pl.mediainter.net
127.0.0.1 servedby.mediaplace.tv #[ad.firstadsolution.com]
127.0.0.1 media-servers.net
127.0.0.1 search.mediatarget.com
127.0.0.1 ads.mediaturf.net #[McAfee.Cookie-Mediaturf]
127.0.0.1 adv.medscape.com #[ads.webmd.com]
127.0.0.1 www.megapromition.net #[SiteAdvisor.megapromition.net]
127.0.0.1 www.megastats.com
127.0.0.1 exit.megago.com #[SpySweeper.Spy.Cookie]
127.0.0.1 www.megago.com #[typo squatter]
127.0.0.1 www.mercuras.com
127.0.0.1 reklama.metacafe.com
127.0.0.1 adserv2.meritdesigns.com
127.0.0.1 ads.metropol.dk
127.0.0.1 automagazine.metriweb.be
127.0.0.1 hln-frinfos.metriweb.be
127.0.0.1 levif.metriweb.be
127.0.0.1 line01.metriweb.be #[Ad-Aware.Tracking.Cookie]
127.0.0.1 line02.metriweb.be
127.0.0.1 line03.metriweb.be
127.0.0.1 line04.metriweb.be #[SpySweeper.Spy Cookie]
127.0.0.1 line05.metriweb.be
127.0.0.1 line06.metriweb.be
127.0.0.1 line07.metriweb.be #[Panda.Spyware:Cookie]
127.0.0.1 line08.metriweb.be
127.0.0.1 line09.metriweb.be
127.0.0.1 line10.metriweb.be
127.0.0.1 line11.metriweb.be
127.0.0.1 line12.metriweb.be
127.0.0.1 line13.metriweb.be
127.0.0.1 line14.metriweb.be
127.0.0.1 line15.metriweb.be
127.0.0.1 line16.metriweb.be
127.0.0.1 line17.metriweb.be
127.0.0.1 line18.metriweb.be
127.0.0.1 line19.metriweb.be
127.0.0.1 line20.metriweb.be
127.0.0.1 line24.metriweb.be
127.0.0.1 line26.metriweb.be
127.0.0.1 line32.metriweb.be
127.0.0.1 rtbf09.metriweb.be
127.0.0.1 skynet-news.metriweb.be
127.0.0.1 zattevrienden.metriweb.be
127.0.0.1 m-gallery.org #[Javascript.Exploit]
127.0.0.1 pubs.mgn.net #[Grolier Network]
127.0.0.1 www.mgshareware.com #[AdTool.Win32.MyWebSearch.ak]
127.0.0.1 ads.milenio.com
127.0.0.1 www.milesdebanners.com
127.0.0.1 adc1.mingpao.com
127.0.0.1 ads.mininova.org
127.0.0.1 www.mini-player.com #[5MOF Mini-Player]
127.0.0.1 counter.mirohost.net
127.0.0.1 miron555.org #[Javascript.Exploit]
127.0.0.1 misofthelp.com
127.0.0.1 www.misofthelp.com #[Google Warning]
127.0.0.1 banner.missbingo.com #[AdWare.Win32.Casino.ae]
127.0.0.1 banner.missingkids.com
127.0.0.1 misterbanner.com
127.0.0.1 ads.mixi.jp
127.0.0.1 img.ads.mixi.jp
127.0.0.1 www.mlclick.com
127.0.0.1 vod.mmdy.org #[McAfee.StartPage-JN!CC32C55]
127.0.0.1 timeout.mmy88.cn #[Google.Warning]
127.0.0.1 www.mnogotrafa.net #[Spamdexing]
127.0.0.1 banners.mobilesidewalk.com
127.0.0.1 ads.mobygames.com
127.0.0.1 survey2.modernmindsoftware.com
127.0.0.1 banners.mojoflix.com
127.0.0.1 ad.mokead.com #[Trojan.Daekom]
127.0.0.1 w5.mokead.com
127.0.0.1 www.mokead.com #[W32/DLoader.VZN]
127.0.0.1 ads.monster.com
127.0.0.1 adserver.monster.com #[SunBelt.AdServer.Monster.com]
127.0.0.1 adserver.a.in.monster.com
127.0.0.1 ads.monstermoving.com
127.0.0.1 cookie.monster.com #[SunBelt.cookie.monster]
127.0.0.1 www.moratoriumx.net #[JS/TrojanDownloader.Agent.BI]
127.0.0.1 m1.webstats.motigo.com
127.0.0.1 www.motioncodecs.com #[Win32/TrojanDownloader.Mediket]
127.0.0.1 www.movies.net.cn #[AdWare.Win32.AdBlaster.b]
127.0.0.1 www.mp3downloadhq.com #[SiteAdvisor.mp3downloadhq.com]
127.0.0.1 mp3today.net
127.0.0.1 mpamexit.com
127.0.0.1 adfarm.mserve.ca
127.0.0.1 www.messagetag.com #[Email tracker]
127.0.0.1 msgtag.com
127.0.0.1 img.msgtag.com
127.0.0.1 www.msgtag.com
127.0.0.1 redirect.msupdate.net #[AdWare.Win32.SaveNow.bj]
127.0.0.1 mswindowsupdate.info
127.0.0.1 www.mswindowsupdate.info
127.0.0.1 h.mt12.net #[Win32/PSW.Lineage.AEL][W32/HLLP.Philis.ar]
127.0.0.1 multi1.rmuk.co.uk #[RealMedia]
127.0.0.1 www.muangboranjournal.com #[Win32/Spy.Banker.AHY]
127.0.0.1 www.multiclinmed.com.br #[Win32/PSW.Legendmir.ATE]
127.0.0.1 mussicalcardss.smtp.ru #[Win32/Spy.Banker.AHY]
127.0.0.1 www.musicmass.com #[HJTH.C2Media/LOP variant]
127.0.0.1 www.mumy8.com #[Exploit.ANI]
127.0.0.1 click.myad.cn
127.0.0.1 click2.myad.cn
127.0.0.1 img.myad.cn
127.0.0.1 new.myad.cn
127.0.0.1 www.myadtrack.com #[Email Tracker]
127.0.0.1 ads.mybale.com
127.0.0.1 ipub.mybloglog.com
127.0.0.1 pub.mybloglog.com
127.0.0.1 track.mybloglog.com #[Yahoo Tracking Service]
127.0.0.1 track2.mybloglog.com
127.0.0.1 track3.mybloglog.com
127.0.0.1 mycashbank.co.kr
127.0.0.1 key.mycashbank.co.kr #[Trojan.Daum]
127.0.0.1 get.mycounter.com.ua
127.0.0.1 www.mycreditoweb.com
127.0.0.1 mydns-ns.info #[Win32/Spy.Banker.CKW]
127.0.0.1 www.myemessenger.com
127.0.0.1 www.myfriendspy.com
127.0.0.1 liveupdate.myim.cn #[Adware.BeSys]
127.0.0.1 www.mylinker.net #[Adware.MyLinker]
127.0.0.1 www.mylottoadserv.com
127.0.0.1 rm.myoc.com
127.0.0.1 wintercat.diy.myrice.com #[Win32/TrojanDownloader.Tiny.Y]
127.0.0.1 my-securedoc.com #[Downloader.Goobiz]
127.0.0.1 www.my-securedoc.com
127.0.0.1 mysessoblog.com
127.0.0.1 www.mysessoblog.com #[Downloader.Goobiz]
127.0.0.1 www.myspacebar.com #[SunBelt.Scam.MySpaceBar]
127.0.0.1 www.myspacetracer.com
127.0.0.1 myspacev.net #[MySpace.Exploit]
127.0.0.1 mystabcounter.info #[Google Warning]
127.0.0.1 stat.mystat.hu
127.0.0.1 www.mystats.nl
127.0.0.1 www2.mystats.nl
127.0.0.1 c.mystat-in.net
127.0.0.1 f2.n1.b.mystat-in.net
127.0.0.1 id.c.mystat-in.net #[Wildcard DNS]
127.0.0.1 061606084448.c.mystat-in.net
127.0.0.1 070806142521.c.mystat-in.net
127.0.0.1 090906042103.c.mystat-in.net
127.0.0.1 011707160008.c.mystat-in.net
127.0.0.1 102106151057.c.mystat-in.net
127.0.0.1 112006133326.c.mystat-in.net
127.0.0.1 hit.namimedia.com
127.0.0.1 ads.nandomedia.com #[McAfee.Cookie-Nandomedia]
127.0.0.1 adserver.nav2.net
127.0.0.1 adcreative.naver.com
127.0.0.1 nv1.ad.naver.com
127.0.0.1 c1.navrcholu.cz
127.0.0.1 popsearch.nbcsearch.com
127.0.0.1 xml.nbcsearch.com
127.0.0.1 www.nbcsearch.com #[exactsearch.net]
127.0.0.1 sd.ncast.cn #[Adware.NCast]
127.0.0.1 www.ncph.net #[Exploit.ANI]
127.0.0.1 img1.ncsreporting.com
127.0.0.1 www.ncsreporting.com
127.0.0.1 ndparking.com #[Parking Service]
127.0.0.1 www.ndparking.com
127.0.0.1 www.neima.net #[Win32/Spy.Banker.AHY]
127.0.0.1 ads.neogen.bg
127.0.0.1 ads.neogen.ro
127.0.0.1 monitor.neogen.ro
127.0.0.1 ads.neowin.net
127.0.0.1 neocounter.neoworx-blog-tools.net
127.0.0.1 banman.nepsecure.co.uk #[Ban Man Pro Banner Code]
127.0.0.1 banners.netcraft.com
127.0.0.1 www.netdirect.nl
127.0.0.1 beta-hints.netflame.cc
127.0.0.1 hints.netflame.cc #[Fireclick Web Analytics]
127.0.0.1 ssl-hints.netflame.cc
127.0.0.1 trizvez.netfirms.com #[Win32/Spy.Banker]
127.0.0.1 ad.netgoo.com
127.0.0.1 adv.netinfo.bg
127.0.0.1 tracker.netklix.com
127.0.0.1 stat.netlogic.ru #[NetLogic Logger]
127.0.0.1 webstats.netlogics.nl
127.0.0.1 www.netmaxx.com
127.0.0.1 counter.netmore.net
127.0.0.1 ads.netrition.com
127.0.0.1 servedby.netshelter.net #[Ad-Aware.Tracking.Cookie]
127.0.0.1 www.network-tool.net #[Trojan.Magise]
127.0.0.1 www.new-phpmailer.com #[Win32/Bifrose.E]
127.0.0.1 i.nuseek.com #[Parking Service]
127.0.0.1 www1.nuseek.com
127.0.0.1 www2.nuseek.com #[overture.com]
127.0.0.1 www3.nuseek.com
127.0.0.1 ads.newdream.net
127.0.0.1 ads.newgrounds.com
127.0.0.1 ads.newsint.co.uk
127.0.0.1 www.newweb.com.cn #[Adware.NewWeb]
127.0.0.1 ads1.nexdra.com
127.0.0.1 adq.nextag.com #[McAfee.Cookie-Nextag]
127.0.0.1 nextgenstats.com
127.0.0.1 www.nextgenstats.com
127.0.0.1 www.ngp-mac.com #[Win32/Spy.Banker.AHY]
127.0.0.1 www.nice8.org #[W32.Drom]
127.0.0.1 www.nipr.ws #[Trojan.Chuvazada]
127.0.0.1 www.nlbanner.nl
127.0.0.1 ads.nordichardware.com
127.0.0.1 ads.nordichardware.se
127.0.0.1 www.nordicgold.com #[Win32/Spy.Banker.AHY]
127.0.0.1 www.nortonproject.com #[AdWare.Win32.Softomate.j][Adware/ToolBar.ISearch.c]
127.0.0.1 ad.nozonedata.com #[Ad-Aware Tracking.Cookie]
127.0.0.1 ad1.nozonedata.com
127.0.0.1 ad.nrk.no
127.0.0.1 nsismedia.net #[SunBelt.NSIS Media]
127.0.0.1 www.nsismedia.net
127.0.0.1 ns2.iad1.nssrv.com
127.0.0.1 ntlligent.info #[Spamdexing]
127.0.0.1 ad.nttnavi.co.jp
127.0.0.1 banner.nttnavi.co.jp
127.0.0.1 synad.nuffnang.com.my
127.0.0.1 numeric.hk #[Javascript.Exploit]
127.0.0.1 cdn.nvero.net
127.0.0.1 e.nvero.net
127.0.0.1 ads.nyi.net
127.0.0.1 nzads.net.nz
127.0.0.1 adserver.o2.pl
127.0.0.1 banner.oddcast.com
127.0.0.1 banner-a.oddcast.com
127.0.0.1 banner-d.oddcast.com
127.0.0.1 oemtop.com #[Google Warning]
127.0.0.1 www.oemtop.com
127.0.0.1 www.ok8vs.com #[Exploit.ANI]
127.0.0.1 www.okvs8.com #[Exploit.ANI]
127.0.0.1 okcounter.com #[IE-SpyAd][eTrust.Tracking.Cookie]
127.0.0.1 www.okww.net #[Trojan.StartPage.C]
127.0.0.1 ads.oneplace.com
127.0.0.1 stat.onestat.com #[Panda.Spyware:Cookie/onestat.com][Ad-Aware.Tracking.Cookie]
127.0.0.1 www.onestat.com #[Ewido.TrackingCookie.Onestat]
127.0.0.1 www.onestatfree.com
127.0.0.1 one.ru
127.0.0.1 cnt.one.ru
127.0.0.1 stats0.one.ru
127.0.0.1 stats1.one.ru
127.0.0.1 stats2.one.ru
127.0.0.1 ads.onemodelplace.com
127.0.0.1 reklama.onet.pl
127.0.0.1 onlinecount.com
127.0.0.1 online-service.cc
127.0.0.1 www.online-service.cc #[Trojan.Magise]
127.0.0.1 adserver.online-tech.com
127.0.0.1 lifemediahouse1.onlinewelten.com
127.0.0.1 onlyfreebies.net #[Spamdexing]
127.0.0.1 www.onlyscreensavers.com #[SiteAdvisor.onlyscreensavers.com]
127.0.0.1 ads.ookla.com
127.0.0.1 www.openadnetwork.com
127.0.0.1 s17.opentracker.net
127.0.0.1 s27.opentracker.net
127.0.0.1 server1.opentracker.net
127.0.0.1 server10.opentracker.net
127.0.0.1 invitation.opinionbar.com
127.0.0.1 ccc00.opinionlab.com
127.0.0.1 ccc01.opinionlab.com #[msn.com]
127.0.0.1 rate.opinionlab.com
127.0.0.1 www.opinionlab.com
127.0.0.1 by.optimost.com
127.0.0.1 optlynx.com #[Adware.Optserve]
127.0.0.1 optmedia.jp
127.0.0.1 ad.orbitel.bg
127.0.0.1 ads.orsm.net
127.0.0.1 otx5.otxresearch.com
127.0.0.1 otx.ifilm.com #[OTXMedia.dll]
127.0.0.1 survey.otxresearch.com #[TrojanDownloader.OTXloader.A][MVPS.Criteria]
127.0.0.1 www.otxresearch.com #[Sophos.OTXLoader][Trojan.OTXLoader]
127.0.0.1 our-counter.biz #[ISANS.Alert]
127.0.0.1 liveupdate.ourxin.com #[Adware.AllSum]
127.0.0.1 www.ourxin.com #[Dr.Web.Adware.CFS][Trojan.Cfs]
127.0.0.1 adpopper.outblaze.com #[ADW_BBINSTALL.B][bargain-buddy.net]
127.0.0.1 adp4.us4.outblaze.com
127.0.0.1 adserver.hk.outblaze.com
127.0.0.1 adserver.us.outblaze.com
127.0.0.1 download2.us4.outblaze.com #[HJTH.Bargain Buddy]
127.0.0.1 www.overpeer.com #[Trojan.Wimad]
127.0.0.1 pub.oxado.com
127.0.0.1 oya.ru #[Javascript.Exploit]
127.0.0.1 www.p5ip.com #[Exploit.ANI]
127.0.0.1 ad1.pamedia.com.au
127.0.0.1 ad2.pamedia.c

AVG n’a pas fini son scan ca fait 1H06

Enfin fini,

Apparament il n’y a plus de trojan

Bojour,
Ce matin encore, mon par feu s’était désactivé j’ai refais un scan avec ad-aware il me dit avoir encore 6virus qu’il ne peut pas me supprimer …
que dois-je faire

Il me parle de système 32, je ne comprends rien du tout


voici le rapport de ce matin

ArchiveData(auto-quarantine- 2007-12-13 10-11-21.bckp)
Referencefile : SE1R207 03.12.2007

MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU FileReference : C:\Documents and Settings\HP_Propriétaire\recent\ad aware.lnk
obj[1]=MRU FileReference : C:\Documents and Settings\HP_Propriétaire\recent\ad-aware.lnk
obj[2]=MRU FileReference : C:\Documents and Settings\HP_Propriétaire\recent\Christian PEYRUSSE.lnk
obj[3]=MRU FileReference : C:\Documents and Settings\HP_Propriétaire\recent\host.lnk
obj[4]=MRU FileReference : C:\Documents and Settings\HP_Propriétaire\recent\hosts.lnk
obj[5]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru*
obj[6]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\microsoft\windows\currentversion\explorer\recentdocs.log
obj[7]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\microsoft\windows\currentversion\explorer\recentdocs.TXT
obj[8]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\microsoft\windows\currentversion\explorer\recentdocs.zip
obj[9]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
obj[11]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\nico mak computing\winzip\filemenu
obj[12]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\microsoft\internet explorer download directory
obj[13]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\microsoft\internet explorer\typedurls
obj[14]=MRU RegReference : S-1-5-21-3625721001-4144984955-4125544301-1008\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru

WIN32.BACKDOOR.AGENT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[9]=RegValue : S-1-5-18\software\microsoft\windows\currentversion\explorer “{f710fa10-2031-3106-8872-93a2b5c5c620}”
obj[14]=RegValue : software\microsoft\windows\currentversion\internet settings “proxyoverride”
obj[15]=Fichier : C:\WINDOWS\system32\wsnpoem\audio.dll
obj[16]=Fichier : C:\WINDOWS\system32\wsnpoem\video.dll

WIN32.TROJAN.SPY
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[10]=RegValue : .DEFAULT\software\microsoft\windows\currentversion\explorer “{02ffac45-0b10-5633-4296-1801f1a36678}”
obj[11]=RegValue : S-1-5-18\software\microsoft\windows\currentversion\explorer “{02ffac45-0b10-5633-4296-1801f1a36678}”
obj[12]=RegValue : .DEFAULT\software\microsoft\windows\currentversion\explorer “{f710fa10-2031-3106-8872-93a2b5c5c620}”
obj[13]=RegValue : S-1-5-18\software\microsoft\windows\currentversion\explorer “{f710fa10-2031-3106-8872-93a2b5c5c620}”