[code] HitmanPro 3.7.3.194 www.hitmanpro.com Computer name . . . . : PC Windows . . . . . . . : 6.1.1.7601.X64/2 User name . . . . . . : PC\Adrian UAC . . . . . . . . . : Disabled License . . . . . . . : Trial (30 days left) Scan date . . . . . . : 2013-05-10 19:38:55 Scan mode . . . . . . : Normal Scan duration . . . . : 3m 45s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 9 Traces . . . . . . . : 75 Objects scanned . . . : 1 141 714 Files scanned . . . . : 22 264 Remnants scanned . . : 274 107 files / 845 343 keys Malware _____________________________________________________________________ C:\Users\Adrian\AppData\Local\Temp\OptimizerPro.exe -> Quarantined Size . . . . . . . : 4 159 008 bytes Age . . . . . . . : 21.0 days (2013-04-19 18:59:28) Entropy . . . . . : 8.0 SHA-256 . . . . . : A0D93F8F557E20D0CEF2A716B4DCACBF4E76458E75F65BBF5A2896DBD4E32F32 Product . . . . . : Optimizer Pro Publisher . . . . : PC Utilities Pro Description . . . : Fix, clean, optimize your PC! Version . . . . . : 3.0.1.0 Copyright . . . . : PC Utilities Pro RSA Key Size . . . : 2048 Authenticode . . . : Valid > Emsisoft . . . . . : Trojan.Win32.SpeedingUpMyPC.AMN!A2 Fuzzy . . . . . . : 101.0 Forensic Cluster -70.1s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\97831b93776fc642b3ad51950b28995a[1].htm -69.0s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLDK2TDI\tokyoLightGrayStripesBG[1].jpg -68.8s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GO119PIG\tokyo_sprite_full[1].png -65.5s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\storage[1].swf -65.2s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.bisrv.com\ -65.2s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.bisrv.com\settings.sol -65.2s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\ -65.2s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\js\ -65.2s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\js\libs\ -65.2s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\js\libs\storage.swf\ -65.0s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EI9F2XL9\ajax[1].htm -64.8s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLDK2TDI\dealply2[1].png -64.8s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLDK2TDI\pcutilitiespro[1].png -64.7s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\DownloadSource[1].png -64.4s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GO119PIG\LollipopInstaller_somoto_14693[1].exe -64.2s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.1 -64.2s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.0 -64.2s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.3 -64.2s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.2 -64.2s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.5 -64.2s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.4 -64.2s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.6 -64.2s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.7 -63.9s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GO119PIG\pinger[1].jpg -61.7s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\eula[1].htm -55.9s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EI9F2XL9\pinger[1].jpg -54.0s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EI9F2XL9\dp[1].exe -50.2s C:\Users\Adrian\AppData\Local\Temp\dp.exe -49.8s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLDK2TDI\OptimizerPro[1].exe -49.4s C:\Users\Adrian\AppData\Local\Temp\{1284AB3D-D24B-4E3C-BCFB-C9220CB4EC6D}\ -49.0s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GO119PIG\pinger[2].jpg -47.2s C:\Users\Adrian\AppData\Local\Temp\logs\ -47.2s C:\Users\Adrian\AppData\Local\Temp\logs\uninst.log -35.9s C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe -35.8s C:\Users\Adrian\AppData\Roaming\DealPly\ -35.8s C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\ -35.8s C:\Windows\System32\Tasks\DealPly -34.8s C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\config.dat -33.4s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\pinger[1].jpg -23.3s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\__utm[2].gif 0.0s C:\Users\Adrian\AppData\Local\Temp\OptimizerPro.exe 2.3s C:\Users\Adrian\AppData\Local\Temp\F5A5.tmp 2.9s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EI9F2XL9\cabexplr[1].zip 8.7s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\js\libs\storage.swf\biCDFC.sol C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe -> Quarantined Size . . . . . . . : 93 728 bytes Age . . . . . . . : 21.0 days (2013-04-19 18:58:52) Entropy . . . . . : 6.5 SHA-256 . . . . . : FBE35B275676164D6771087FCA59AFF7CA667647FAB1EE466C94ED00AEFDA455 RSA Key Size . . . : 2048 Authenticode . . . : Valid > Emsisoft . . . . . : Trojan.Win32.DealPly.AMN!A2 Fuzzy . . . . . . : 99.0 Forensic Cluster -34.2s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\97831b93776fc642b3ad51950b28995a[1].htm -33.1s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLDK2TDI\tokyoLightGrayStripesBG[1].jpg -32.9s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GO119PIG\tokyo_sprite_full[1].png -29.6s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\storage[1].swf -29.3s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.bisrv.com\ -29.3s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.bisrv.com\settings.sol -29.3s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\ -29.3s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\js\ -29.3s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\js\libs\ -29.3s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\js\libs\storage.swf\ -29.1s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EI9F2XL9\ajax[1].htm -28.9s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLDK2TDI\dealply2[1].png -28.9s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLDK2TDI\pcutilitiespro[1].png -28.8s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\DownloadSource[1].png -28.6s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GO119PIG\LollipopInstaller_somoto_14693[1].exe -28.3s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.1 -28.3s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.0 -28.3s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.3 -28.3s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.2 -28.3s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.5 -28.3s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.4 -28.3s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.6 -28.3s C:\Users\Adrian\AppData\Local\Temp\LollipopInstaller_somoto_14693.exe.7 -28.0s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GO119PIG\pinger[1].jpg -25.8s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\eula[1].htm -20.1s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EI9F2XL9\pinger[1].jpg -18.1s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EI9F2XL9\dp[1].exe -14.3s C:\Users\Adrian\AppData\Local\Temp\dp.exe -13.9s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GLDK2TDI\OptimizerPro[1].exe -13.5s C:\Users\Adrian\AppData\Local\Temp\{1284AB3D-D24B-4E3C-BCFB-C9220CB4EC6D}\ -13.1s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GO119PIG\pinger[2].jpg -11.3s C:\Users\Adrian\AppData\Local\Temp\logs\ -11.3s C:\Users\Adrian\AppData\Local\Temp\logs\uninst.log 0.0s C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe 0.0s C:\Users\Adrian\AppData\Roaming\DealPly\ 0.0s C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\ 0.1s C:\Windows\System32\Tasks\DealPly 1.0s C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\config.dat 2.4s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\pinger[1].jpg 12.6s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5BJ42TLM\__utm[2].gif 35.9s C:\Users\Adrian\AppData\Local\Temp\OptimizerPro.exe 38.1s C:\Users\Adrian\AppData\Local\Temp\F5A5.tmp 38.8s C:\Users\Adrian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EI9F2XL9\cabexplr[1].zip 44.6s C:\Users\Adrian\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\V4AT3YH6\static.bisrv.com\js\libs\storage.swf\biCDFC.sol C:\Users\Adrian\Desktop\Pulpit\nauka\choinka\fib\fib\bin\Debug\fib.exe -> Deleted Size . . . . . . . : 966 633 bytes Age . . . . . . . : 120.9 days (2013-01-09 20:55:02) Entropy . . . . . : 6.0 SHA-256 . . . . . : 4AD815995248850358A844FD1DBAB0F38BF0D794C010BBDF2F4A1B8FC78937D5 > G Data . . . . . . : Gen:Variant.Graftor.75362 > Ikarus . . . . . . : Trojan.Win32.Agent!IK Fuzzy . . . . . . : 106.0 C:\Users\Adrian\Desktop\Pulpit\nauka\choinka\fib\fib\main.exe -> Deleted Size . . . . . . . : 957 340 bytes Age . . . . . . . : 120.9 days (2013-01-09 20:55:02) Entropy . . . . . : 6.0 SHA-256 . . . . . : AC5648D7136334930E427AB9DA78B07B1D956123F614274B672659FFB2F1562F > G Data . . . . . . : Gen:Variant.Graftor.75362 > Ikarus . . . . . . : Trojan.Win32.Agent!IK Fuzzy . . . . . . : 106.0 C:\Users\Adrian\Desktop\Pulpit\nauka\choinka\main.exe -> Deleted Size . . . . . . . : 957 813 bytes Age . . . . . . . : 120.9 days (2013-01-09 20:55:00) Entropy . . . . . : 6.0 SHA-256 . . . . . : FCE62901C3ED220064CD55ACB09A3BC0BEE727021B3F3735BF32D67811C71E6F > G Data . . . . . . : Gen:Variant.Graftor.75362 > Ikarus . . . . . . : Trojan.Win32.Agent!IK Fuzzy . . . . . . : 106.0 C:\Users\Adrian\Desktop\Pulpit\studia\programowanie\petle.exe -> Quarantined Size . . . . . . . : 475 677 bytes Age . . . . . . . : 120.9 days (2013-01-09 20:55:16) Entropy . . . . . : 6.0 SHA-256 . . . . . : E950D433EAFE8145E990C3265E7DD789752419BD41DAE6E59B677920DA9F1B60 > Ikarus . . . . . . : Trojan.Win32.Shutdowner!IK Fuzzy . . . . . . : 106.0 C:\Users\Adrian\Desktop\Pulpit\studia\programowanie\Projekt2.exe -> Quarantined Size . . . . . . . : 475 677 bytes Age . . . . . . . : 120.9 days (2013-01-09 20:55:16) Entropy . . . . . : 6.0 SHA-256 . . . . . : F69EEF748FFAB9F4A33941E12661BC5351EF9997CB59107AD92F73BFC5A1DB8F > Ikarus . . . . . . : Trojan.Win32.Shutdowner!IK Fuzzy . . . . . . : 106.0 C:\Users\Adrian\Desktop\Pulpit\studia\programowanie\Projekt3.exe -> Quarantined Size . . . . . . . : 475 952 bytes Age . . . . . . . : 120.9 days (2013-01-09 20:55:16) Entropy . . . . . : 6.0 SHA-256 . . . . . : C906F73E88E1542356EE6746189194FE642CF3418447C5E708A39B2AF1463200 > Ikarus . . . . . . : Trojan.Win32.Shutdowner!IK Fuzzy . . . . . . : 106.0 C:\Users\Adrian\Desktop\Pulpit\studia\programowanie\tablice.exe -> Quarantined Size . . . . . . . : 475 677 bytes Age . . . . . . . : 120.9 days (2013-01-09 20:55:16) Entropy . . . . . : 6.0 SHA-256 . . . . . : 5A51D631CC1A2233EC3992A8FB2872D0F39FC6590D37F9D0D42352D350D6B09F > Ikarus . . . . . . : Trojan.Win32.Shutdowner!IK Fuzzy . . . . . . : 106.0 Suspicious files ____________________________________________________________ C:\Users\Adrian\AppData\Local\PunkBuster\COD4\pb\pbcl.dll Size . . . . . . . : 967 165 bytes Age . . . . . . . : 117.2 days (2013-01-13 14:42:55) Entropy . . . . . : 7.6 SHA-256 . . . . . : B1B32990F47ED2E39EB18AEA0839D9521B87E9ED18C0BCA8E2C6873FBA9D6494 Fuzzy . . . . . . : 29.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. C:\Users\Adrian\AppData\Local\PunkBuster\COD4\pb\PnkBstrK.sys Size . . . . . . . : 139 832 bytes Age . . . . . . . : 117.2 days (2013-01-13 14:43:16) Entropy . . . . . : 7.7 SHA-256 . . . . . : 3CB5C8CB071375FDE6E9269000B78E65DB29D585B2775E66C8B9F6E47E0012D1 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. The file is a device driver. Device drivers run as trusted (highly privileged) code. Program is code signed with a valid Authenticode certificate. Potential Unwanted Programs _________________________________________________ C:\Users\Adrian\AppData\Roaming\DealPly\ (Delta Search) C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\ (Delta Search) C:\Users\Adrian\AppData\Roaming\DealPly\UpdateProc\config.dat (Delta Search) Cookies _____________________________________________________________________ C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:1580034.fls.doubleclick.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.blueice.pl C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:cmp.112.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:collective-media.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:deusex.pl C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:dmtracker.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:eaeacom.112.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:edsa.122.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:fr.sitestat.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:gmeurope.112.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:hardsextube.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:hotlog.ru C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:microsoftsto.112.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:myroitracking.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:oracle.112.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:porn.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:pornhub.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:putmanmedia.122.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:sexvideomix.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:spylog.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:stats.paste2.org C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:stats.paypal.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:statse.webtrendslive.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:suckporntube.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:sun.112.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:tradedoubler.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:tribalfusion.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:uk.sitestat.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:warnerbros.112.2o7.net C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.erosexus.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.etracker.de C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.hardsextube.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.kissporntube.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.largeporntube.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.porn.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.pornhub.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.pornmd.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.pornoxo.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.sexrura.pl C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.sexvideomix.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.tubepornfilm.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:xiti.com C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Cookies:yadro.ru C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Cookies\79TUFOJY.txt C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Cookies\JZ9WGYW8.txt C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Cookies\M26N4QDU.txt C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Cookies\YW074ZYB.txt [/code]