[code] HitmanPro 3.7.14.265 www.hitmanpro.com Computer name . . . . : JA-KOMPUTER Windows . . . . . . . : 6.1.1.7601.X64/4 User name . . . . . . : Ja-Komputer\Ja UAC . . . . . . . . . : Enabled License . . . . . . . : Free Scan date . . . . . . : 2016-06-11 18:24:42 Scan mode . . . . . . : Normal Scan duration . . . . : 1m 34s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 1 Traces . . . . . . . : 74 Objects scanned . . . : 1 841 034 Files scanned . . . . : 54 994 Remnants scanned . . : 414 682 files / 1 371 358 keys Malware _____________________________________________________________________ C:\Users\Ja\AppData\Roaming\PriceFountainUpdateVer\SyncVersion.exe Size . . . . . . . : 307 712 bytes Age . . . . . . . : 0.1 days (2016-06-11 15:37:12) Entropy . . . . . : 6.9 SHA-256 . . . . . : 502B6D659B508E6951384A0755D9D7C9E322B21BBC25DEEC313572876B3BED00 > Bitdefender . . . : Gen:Variant.Adware.DealPly.49 > Kaspersky . . . . : not-a-virus:HEUR:AdWare.Win32.DealPly.gen Fuzzy . . . . . . : 110.0 Startup C:\Windows\system32\Tasks\{0C198DB8-3EB6-9D49-8CCE-77307CF6E832} Forensic Cluster -107.0s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a4e -100.1s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a4f -99.7s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a50 -99.4s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a51 -77.2s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a52 -77.1s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a53 -76.2s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a54 -75.8s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a55 -71.5s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_launch-manager.updatestar.com_0.localstorage -71.5s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_launch-manager.updatestar.com_0.localstorage-journal -68.2s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a56 -67.8s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a57 -65.9s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a58 -59.5s C:\ProgramData\Microsoft\Windows Defender\Scans\FilesStash\714F0B40-23FA-E7AE-B5EE-3FD67ABC3A8F_1d1c4af63290038 -58.1s C:\Users\Ja\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37570AF16029C559A6224EE4AF54691D -58.1s C:\Users\Ja\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37570AF16029C559A6224EE4AF54691D -57.2s C:\Users\Ja\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9F08575E2099C04869F34A6342C1C728_4E05EC5ABD53B89FC7349905A89A697F -57.2s C:\Users\Ja\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9F08575E2099C04869F34A6342C1C728_4E05EC5ABD53B89FC7349905A89A697F -48.8s C:\Users\Ja\AppData\Local\Microsoft\Windows\History\History.IE5\container.dat -48.4s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\1034107.32[1].png -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\Bomonobinok_v3[1].jpg -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\BG[1].jpg -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\Nininininon[1].png -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\Lolosobeken[1].jpg -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\Nafidiri[1].png -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\Bomonobinok_v1[1].jpg -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\bg[1].png -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\Bomonobinok_v2[1].jpg -46.5s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\Merococ[1].png -46.4s C:\Users\Ja\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\12B9DB160AD5C40A43865B2B20626F11_B2794E378DB5316B943F225562272C9E -46.4s C:\Users\Ja\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\12B9DB160AD5C40A43865B2B20626F11_B2794E378DB5316B943F225562272C9E -22.4s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\au4693[1].htm -22.2s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\adnl.min[1].js -21.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\1[1].js -21.9s C:\Users\Ja\AppData\Local\Microsoft\Internet Explorer\DOMStore\container.dat -21.9s C:\Users\Ja\AppData\Local\Microsoft\Internet Explorer\DOMStore\R56H9G3A\ -21.9s C:\Users\Ja\AppData\Local\Microsoft\Internet Explorer\DOMStore\EZTS37FI\ -21.9s C:\Users\Ja\AppData\Local\Microsoft\Internet Explorer\DOMStore\SQ24Z8LE\ -21.9s C:\Users\Ja\AppData\Local\Microsoft\Internet Explorer\DOMStore\19LFCYRY\ -21.9s C:\Users\Ja\AppData\Local\Microsoft\Internet Explorer\DOMStore\19LFCYRY\cdn.castplatform[1].xml -21.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\1a0211f9-a7d7-4c6b-ace8-686aca429e07[1].gif -21.8s C:\Users\Ja\AppData\Roaming\Microsoft\Windows\Cookies\TIOUYSQV.txt -21.8s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\1[1].gif -21.3s C:\Users\Ja\AppData\Local\Temp\ICSW1.22\ -13.3s C:\Users\Ja\AppData\Local\Temp\uninstaller.exe.37956868 -12.1s C:\Users\Ja\AppData\Local\Temp\BogymanFarrowed.dll -11.7s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\au4694[1].htm -11.4s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\1[2].js -11.3s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\1[1].gif -11.3s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\2ba6adbc-2050-4248-b230-1d36825e8b05[1].gif -9.7s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\install-report[1].txt -9.2s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\install-report[1].txt -8.8s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\install-report[1].txt -8.7s C:\Windows\System32\Tasks\JaExcoriatedRedistilledV2 -8.3s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\install-report[2].txt -7.8s C:\Users\Ja\AppData\Roaming\Dropbox\shellext\l\575c1400 -7.2s C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ -7.2s C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat -4.9s C:\Program Files (x86)\Launch Manager\MMDUtl.dll -3.8s C:\Program Files (x86)\Launch Manager\aipflib.dll -3.7s C:\Program Files (x86)\Launch Manager\temp.000 -3.7s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a5a -3.6s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a5b -3.2s C:\Users\Ja\AppData\Local\Temp\aiPlatformSetupAddOn.log -1.6s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001a5c -0.7s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\install-report[2].txt -0.1s C:\Users\Ja\AppData\Roaming\PriceFountainUpdateVer\ 0.0s C:\Users\Ja\AppData\Roaming\PriceFountainUpdateVer\SyncVersion.exe 0.8s C:\Windows\Tasks\{0C198DB8-3EB6-9D49-8CCE-77307CF6E832}.job 0.8s C:\Windows\System32\Tasks\{0C198DB8-3EB6-9D49-8CCE-77307CF6E832} 0.9s C:\Users\Ja\AppData\Roaming\PriceFountainUpdateVer\info.dat 1.4s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\event-report[1].txt 15.0s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_client.updatestar.com_0.localstorage 15.0s C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_client.updatestar.com_0.localstorage-journal Suspicious files ____________________________________________________________ C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\FRST64[1].exe Size . . . . . . . : 2 385 408 bytes Age . . . . . . . : 0.6 days (2016-06-11 05:06:56) Entropy . . . . . : 7.6 SHA-256 . . . . . : 0BDE8C5473C6DB7E4079FD58CF7329287616E84D75ACF009228FBBD9CD9A1713 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -0.9s C:\Users\Ja\AppData\Roaming\Microsoft\Windows\Cookies\OQVNT528.txt -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\ -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\ -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\ -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\ -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.dat -0.2s C:\Users\Ja\AppData\Roaming\Microsoft\Windows\Cookies\K1DERPEP.txt -0.2s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\82[1].htm -0.1s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\FRST64[1].exe 0.0s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\FRST64[1].exe 0.0s C:\Users\Ja\Downloads\fix\FRST64.exe 2.6s C:\Users\Ja\Downloads\fix\FRST-OlderVersion\ 6.1s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\up64[2] 7.7s C:\Users\Ja\Downloads\fix\FRST.txt 30.6s C:\Users\Ja\Downloads\fix\Addition.txt C:\Users\Ja\Downloads\fix\FRST-OlderVersion\FRST64.exe Size . . . . . . . : 2 385 408 bytes Age . . . . . . . : 5.9 days (2016-06-05 19:49:40) Entropy . . . . . : 7.6 SHA-256 . . . . . : 59D88FF4B60191F8ADFA44D1BC49A5FA44189C51E5DE85A4647BB7609C43D23C Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. C:\Users\Ja\Downloads\fix\FRST64.exe Size . . . . . . . : 2 385 408 bytes Age . . . . . . . : 0.6 days (2016-06-11 05:06:56) Entropy . . . . . : 7.6 SHA-256 . . . . . : 0BDE8C5473C6DB7E4079FD58CF7329287616E84D75ACF009228FBBD9CD9A1713 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. References HKU\S-1-5-21-601893080-2870670082-4129359601-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\Ja\Downloads\fix\FRST64.exe Forensic Cluster -0.9s C:\Users\Ja\AppData\Roaming\Microsoft\Windows\Cookies\OQVNT528.txt -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\ -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\ -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\ -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\ -0.9s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.dat -0.2s C:\Users\Ja\AppData\Roaming\Microsoft\Windows\Cookies\K1DERPEP.txt -0.2s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\07SBG6FW\82[1].htm -0.1s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z0XG3O8E\FRST64[1].exe 0.0s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6BC5082\FRST64[1].exe 0.0s C:\Users\Ja\Downloads\fix\FRST64.exe 2.6s C:\Users\Ja\Downloads\fix\FRST-OlderVersion\ 6.1s C:\Users\Ja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XUXLL4RV\up64[2] 7.7s C:\Users\Ja\Downloads\fix\FRST.txt 30.6s C:\Users\Ja\Downloads\fix\Addition.txt C:\Users\Ja\Downloads\FRST64.exe Size . . . . . . . : 2 385 408 bytes Age . . . . . . . : 3.9 days (2016-06-07 20:25:54) Entropy . . . . . : 7.6 SHA-256 . . . . . : A639F5D8231AB6A9759665C5316540F7D9A9D3669997DD1658A6C8505E35DC57 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. C:\Windows\SysWOW64\mscomm32.ocx Size . . . . . . . : 103 744 bytes Age . . . . . . . : 984.9 days (2013-09-30 20:09:03) Entropy . . . . . : 6.2 SHA-256 . . . . . : F50B97BFE26C89F531CB2983F945506DA098C56979577F1638ECA72BEB9034FE Product . . . . . : MSComm Publisher . . . . : Microsoft Corporation Description . . . : MSComm Version . . . . . : 6.00.8169 Copyright . . . . : Copyright © 1987-1998 Microsoft Corp. RSA Key Size . . . : 2048 LanguageID . . . . : 1033 Authenticode . . . : Invalid Fuzzy . . . . . . : 22.0 Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software. The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities. Potential Unwanted Programs _________________________________________________ C:\Users\Ja\Documents\Optimizer Pro\ (PCOptimizerPro) C:\Users\Ja\Documents\Optimizer Pro\CookiesException.txt (PCOptimizerPro) HKLM\SOFTWARE\Classes\AppID\{c9382aa4-b6b9-4e63-a13b-53061dd7fddf}\ (FilterResults) HKLM\SOFTWARE\Classes\AppID\{cd5da489-3013-4cd1-be62-f18393deab33}\ (FilterResults) HKLM\SOFTWARE\Classes\Interface\{9CBB6D98-5673-44C2-B429-45EF963301D9}\ (FilterResults) HKLM\SOFTWARE\Classes\TypeLib\{D8409F9B-C49C-432D-A7EF-F888F0B18497}\ (FilterResults) HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{c9382aa4-b6b9-4e63-a13b-53061dd7fddf}\ (FilterResults) HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{cd5da489-3013-4cd1-be62-f18393deab33}\ (FilterResults) HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{9CBB6D98-5673-44C2-B429-45EF963301D9}\ (FilterResults) HKLM\SOFTWARE\Classes\Wow6432Node\TypeLib\{D8409F9B-C49C-432D-A7EF-F888F0B18497}\ (FilterResults) HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}\ (SpaceSoundPro) HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_MPCKPT\ (MPC) HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_MPCKPT\ (MPC) HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPCKPT\ (MPC) Cookies _____________________________________________________________________ C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:1982700803.log.optimizely.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:2229372377.log.optimizely.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adaptv.advertising.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:addthis.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adfarm1.adition.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adform.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adformdsp.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adnxs.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.stickyadstv.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adscale.de C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adsrvr.org C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:adx.adform.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:atemda.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidswitch.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:bluekai.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:bs.serving-sys.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:contextweb.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:ctnsnet.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:cxense.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:erne.co C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:fr.sitestat.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:gwallet.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:ibillboard.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:ih.adscale.de C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:lijit.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:liverail.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:mathtag.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:mookie1.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:nexac.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:openx.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:owneriq.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:pixel.rubiconproject.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:pubmatic.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:rfihub.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:rubiconproject.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:scorecardresearch.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:server.adformdsp.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:sitescout.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:sxp.smartclip.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:tradedoubler.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:turn.com C:\Users\Ja\AppData\Local\Google\Chrome\User Data\Default\Cookies:xiti.com [/code]