Majdi Aref
Posts: 13 +0
Hello
I downloaded a few days ago a vpn called lepontier, then my homepage changed to arabyonline.com and ads kept going on every website I enter. I think I solved the issue using malwarebytes and hitmanpro but firefox shockwave and flash plugins keep on crashing whenever I enable them. in addition hitman pro keeps detecting cookies for ads. I can't find the source of this virus, I tried uninstalling the flashplayers and firefox but it didn't work. the log is attached and the hitmanpro log is pasted in this thread. please help as soon as possible.
thank you
Malware _____________________________________________________________________
C:\Users\MajdiAref\Downloads\SoftonicDownloader_for_ad-aware.exe -> Quarantined
Size . . . . . . . : 367,432 bytes
Age . . . . . . . : 0.6 days (2014-10-03 21:57:26)
Entropy . . . . . : 8.0
SHA-256 . . . . . : D10C17FF21ED5927F760D3E2DF24D8AF3B263B46EA30EE0E042CF9D08466C7AA
Product . . . . . : Application Installer
Publisher
Description . . . : Application Installer
Version . . . . . : 1.41.6.11
RSA Key Size . . . : 2048
LanguageID . . . . : 3082
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus
ownloader.Win32.Agent.bxib
Fuzzy . . . . . . : 106.0
Forensic Cluster
-37.7s C:\Windows\Prefetch\BACKGROUNDTRANSFERHOST.EXE-0F7FB435.pf
-37.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\Notifications\945701e44ac911e4bec100c2c61723b5\BB7gVtx[2].jpg
-37.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\Notifications\945701e44ac911e4bec100c2c61723b5\BB7fgGD[2].jpg
-37.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\Notifications\945701e44ac911e4bec100c2c61723b5\BB7gudM[2].jpg
-33.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\TheBestInternetNews[3].gif
-33.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\TheBestInternetNews[3].gif
-33.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\TheBestInternetNews[4].gif
-33.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\TheBestInternetNews[4].gif
-32.1s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\BXPC51JR\b2[10].jpg
-32.0s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\bmainXAJI1STM.jpg
-31.9s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\b3RLN4HV7L.jpg
-31.8s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\b12LD9389A.jpg
-31.7s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\BXPC51JR\b6XXEIT9CD.jpg
-31.5s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\BXPC51JR\b5XE692HID.jpg
-31.4s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\b8NW3Q5WQB.jpg
-31.2s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\b7387ZA937.jpg
-31.0s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\RL6RJ3VJ\b12FWUR6PVB.jpg
-31.0s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\b11902DC7P2.jpg
-30.8s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\RL6RJ3VJ\b4EDJCUWT7.jpg
-30.8s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\RL6RJ3VJ\b9NS3FXNLB.jpg
-30.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\BXPC51JR\b10FV82FCSX.jpg
-30.5s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\bsocial13RRGN9MM.jpg
-30.5s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\bsocial2DL2I96LV.jpg
-28.2s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\bici\bi001003.sqm
-27.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\Notifications\945701e44ac911e4bec100c2c61723b5\1619359_10203127639771539_849080467_n[2].jpg
-25.9s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\bici\bi000007.sqm
-25.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\2A2C98E8D9123DE7A43C7A340D1D9A375D605BD0
-22.8s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\3C1F3BD954D3048973938CA0D1470D3B953D244E
-1.6s C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending\7766a264-d5e2-4264-b3d4-8170a0a5bef6.dmp
-1.6s C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending\7766a264-d5e2-4264-b3d4-8170a0a5bef6.extra
-1.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\414627C7ABA0E70466AAD74FC3E2E98729C1C034
-0.0s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\56BB93E48A832D7B8B5C705D4E4CCD44592A6F29
0.0s C:\Users\MajdiAref\Downloads\SoftonicDownloader_for_ad-aware.exe
0.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\BD5EAB5DB874F65B4C95C0BB1EE86AACD4522558
0.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\F95F6950EEF542C2C27431982CE34926D636F7E6
1.8s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\thumbnails\d89d49f45468d28a31b587d3f2d7200d.png
18.2s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\31\8E5774564D63B913.dat
18.2s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{D8F1A4F8-491E-4923-9071-8D7292318A3C}
18.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\universaldownloader-prefetch[1].htm
19.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\81fe5-8ea63[1].js
21.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[1].gif
24.1s C:\Windows\Prefetch\SOFTONICDOWNLOADER_FOR_AD-AWA-D59DAA24.pf
25.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCookies\3IHT5OGP.txt
26.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[1].gif
31.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\campaign-100340,100860[1].htm
32.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\fad58-b3118[1].css
32.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\ad-aware-24-100x100[1].png
32.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\sd_100340_6d8d2[1].jpg
32.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\sd_100860_41d97[1].jpg
32.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\gradientbg[1].png
32.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\sd_icon_100860_d73dd[1].png
32.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\loading[1].gif
32.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\sprite[1].png
33.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\f[1].txt
33.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\f[1].txt
33.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\pubads_impl_51[1].js
33.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\container[1].htm
34.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\sd_100340_6d8d2[1].jpg
34.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\sd_100860_41d97[1].jpg
34.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[1].gif
34.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[2].gif
35.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[2].gif
35.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[2].gif
35.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[3].gif
35.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[1].gif
35.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[3].gif
35.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\SmartPlayerAPI[1].js
35.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\federated_f9[1]
35.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\1pix[1].gif
35.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\BrightcoveBootloader[1].swf
53.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[4].gif
68.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[3].gif
69.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[2].gif
69.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[5].gif
69.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[4].gif
69.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[4].gif
83.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[3].gif
83.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[6].gif
83.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[5].gif
83.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[6].gif
105.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[5].gif
105.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[4].gif
105.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[7].gif
105.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[6].gif
105.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\f[2].txt
106.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\f[1].txt
106.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\3085986924427351408[1].jpg
107.0s C:\Users\MajdiAref\Desktop\Adaware_Installer.exe
108.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\activeview[1].gif
125.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[7].gif
127.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[5].gif
128.1s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{8F1BDD8D-6799-4F13-84CC-7F8855BACDA8}
128.3s C:\Users\MajdiAref\AppData\Local\Temp\2386c19c-abc8-4964-b179-3d94cb325e2b\
128.3s C:\Users\MajdiAref\AppData\Local\Temp\2386c19c-abc8-4964-b179-3d94cb325e2b\AdAwareWebInstaller.exe
128.7s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\44\62B57D259F47A684.dat
137.6s C:\Windows\Prefetch\ADAWARE_INSTALLER.EXE-FC4A004A.pf
157.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[7].gif
157.4s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\35\97DD89F60FBEAAC3.dat
157.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[8].gif
157.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[6].gif
157.6s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{64D8BFA6-DDC0-47AF-ABAB-F7495B544C8E}
157.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[8].gif
157.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[8].gif
157.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[9].gif
157.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\f[3].txt
157.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[7].gif
157.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\ATAAY4GR.htm
157.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[9].gif
158.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\BrightcovePlayer[1].swf
158.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\default_icon_7[1].gif
158.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\f56d6[1].png
159.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\tracker[1].htm
159.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCookies\J3WODUU3.txt
159.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[10].gif
160.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\activeview[1].gif
164.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\crossdomain[1].xml
166.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\crossdomain[1].xml
166.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCookies\QAX8YQOD.txt
167.1s C:\Windows\Prefetch\ADAWAREWEBINSTALLER.EXE-9404029C.pf
167.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\brightcove-sd[1].xml
167.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\AdvertisingModule[1].swf
170.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\IMA3[1].swf
172.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\Minimal[1].swf
173.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\BCMenu[1].swf
174.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\adsapi_3[1].swf
174.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\1pix[1].gif
174.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\1pix[2].gif
175.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\1pix[1].gif
175.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\adsapi_3_0_156[1].swf
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D5ACC30AA2616C97153A8F836AF72C74CE64FA2B
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\179917EDFD56EADBE0BD446B4E88E8DACF2625A1
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\EC4D75773F0639A5EB0343F8F66D76E71AD9CADC
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\0F4878757559AFDA32C2330A39FF2EE9A9D5ADEE
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\07A44713066229352EA1E8ADB6A0D979BF4FE22D
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\0D31427B7F14E02DDCE26641CE72814B0C8F7339
196.3s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\2D34A7FF560E2060D1B8AF0336B6795CE7BF870B
196.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\8B352912A8BA7EAF5804F72C19EEF166649A4CCE
202.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\42035AE0077374ABF300651CCBE6C5C3BB9326C3
202.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D1FAD5A7735A58754E34A099C38A34BBFC607AD4
203.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\9663029F8794E7BC70AD88553988BE520A64B346
203.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\C21908EF8C3AE04FF6DA7DC3F1B4898469453108
204.2s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\678F1DF3809CBCE6B2EC6BFD9C22D40BB13DDCAA
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\BF5E079D2091BD3C6781EDAA85BC9D91C31DB274
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\5441BEB51A49C40D00CB5BE3860116B62B26800D
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\A734BA8200891D28521E833FDF058AB62AE16AC1
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\23CD98ED6E90EB10E1596350F08A0E011B8664EA
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\968C9B2B4543E1EB68A7890E918927732EB84710
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\553FD4D64155B570FD5A346EB558D2F4CD4BC2D3
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\4EC9DFCC8FBB1699EFA11329A188FC441BC5F5FA
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\C40C0FE5D70507B3130E80880284EFBDF8AD6C36
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\0164F07CB4D020F0AD0EA05AC1694294CAE31A7A
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\BAF1A9B02421C32C2D7E2A9453BEC78C74D40C45
207.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_FlashPlayerPlugi_d3e92c4a64d22ebec443e91ffff8c1dcc5deca8_3aa8f864_0d0fc8cf\
207.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_FlashPlayerPlugi_d3e92c4a64d22ebec443e91ffff8c1dcc5deca8_3aa8f864_0d0fc8cf\Report.wer
207.1s C:\Users\MajdiAref\AppData\Local\Temp\acro_rd_dir\FAPC8FE.tmp
208.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_FlashPlayerPlugi_18c1e3f53ff7e2d4b3bc8503c36dcdd35881dd1_3aa8f864_1273d022\
208.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_FlashPlayerPlugi_18c1e3f53ff7e2d4b3bc8503c36dcdd35881dd1_3aa8f864_1273d022\Report.wer
209.0s C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending\a39b53cf-0b36-4a52-919b-b3bd17a6452a.dmp
209.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\E37E2962D16FFAF873D5C131DEA71424B08BFFE5
209.1s C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending\a39b53cf-0b36-4a52-919b-b3bd17a6452a.extra
211.3s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\4F78544AE0089B0C2635F27BF4B8CBE0AA468CCD
211.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\35AC7E90DB3C5B2245397AE6A0774911FE696D2D
211.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\14CE51EE8F4204E2E0A1BC74294EF93B3E9D6768
211.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\A747BFB2B51C19A808AB3EAF6990EBC95BD8D356
211.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\45F2EC2AB1225D863F33C9C991DF8A3EF2C9D3C7
212.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D7E5CB99622AC1CC3D0DBFA18299053FFD9B60FB
212.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\A7053E207A367E4DB32152157D2A025906A1DD7D
212.6s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D087BA3DA7068E8F3E5A35ADDFF7E65688BBD040
212.6s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\25AC65AC9C5B3C94CB2CAC3852FC54F73B7372D5
212.6s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\AB50334B1C4619C48A0E45AF93092D64A44DA951
212.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\49F9D669E08A89F489496EFB48D57D03F75F6770
213.0s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\E15F2EA2C8C6407C1625AF2E91EB61651E5BF91C
213.0s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\FE2FB942077BA5489596ABB3A3ED13BC39E17236
213.0s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\DA6FF9DB829BDECB9ABEE22AD4398BD53987A71F
213.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\6D25ECB1E7AB4AD8DCEDC2730E99CA3F57D6B7FC
213.6s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\A4422480EF77D01C85B0E8F3010D5FA5D3AD280E
213.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\03AAAFDFAE5F1F3BC748A8A60C844385B5D1F52D
214.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\3FFC84F6E2774041EFF5846F9FB8E939C4D85CAC
214.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\0D887C10E54018D8481CB115C7A1B1857691AB6E
214.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\7CB130A35C87BEFFC657EF400D2C15F9905056F5
214.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\5426B2CCF83C1FBE3EA428A71824404569AD4599
214.2s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\73583C9454AC92B36902E6099BF258A7B239D0BD
214.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D04F7591F037F64B284A29B982D6F1ACED6D0D4F
Potential Unwanted Programs _________________________________________________
HKU\S-1-5-21-979933412-960713541-3746131152-1003\Software\Softonic\ (Softonic) -> Deleted
Cookies _____________________________________________________________________
C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCookies\EFN5LBMC.txt
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ad.360yield.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ad.kiosked.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ad.vikadsk.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ads.creative-serving.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ads.pubmatic.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ads.yahoo.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:adtech.de
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:adtechus.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:advertising.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:at.atwola.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:casalemedia.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:doubleclick.net
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:googleadservices.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:mediaplex.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:revsci.net
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ru4.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:serving-sys.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:zedo.com
[/code]
I downloaded a few days ago a vpn called lepontier, then my homepage changed to arabyonline.com and ads kept going on every website I enter. I think I solved the issue using malwarebytes and hitmanpro but firefox shockwave and flash plugins keep on crashing whenever I enable them. in addition hitman pro keeps detecting cookies for ads. I can't find the source of this virus, I tried uninstalling the flashplayers and firefox but it didn't work. the log is attached and the hitmanpro log is pasted in this thread. please help as soon as possible.
thank you
Malware _____________________________________________________________________
C:\Users\MajdiAref\Downloads\SoftonicDownloader_for_ad-aware.exe -> Quarantined
Size . . . . . . . : 367,432 bytes
Age . . . . . . . : 0.6 days (2014-10-03 21:57:26)
Entropy . . . . . : 8.0
SHA-256 . . . . . : D10C17FF21ED5927F760D3E2DF24D8AF3B263B46EA30EE0E042CF9D08466C7AA
Product . . . . . : Application Installer
Publisher
Description . . . : Application Installer
Version . . . . . : 1.41.6.11
RSA Key Size . . . : 2048
LanguageID . . . . : 3082
Authenticode . . . : Valid
> Kaspersky . . . . : not-a-virus
Fuzzy . . . . . . : 106.0
Forensic Cluster
-37.7s C:\Windows\Prefetch\BACKGROUNDTRANSFERHOST.EXE-0F7FB435.pf
-37.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\Notifications\945701e44ac911e4bec100c2c61723b5\BB7gVtx[2].jpg
-37.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\Notifications\945701e44ac911e4bec100c2c61723b5\BB7fgGD[2].jpg
-37.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\Notifications\945701e44ac911e4bec100c2c61723b5\BB7gudM[2].jpg
-33.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\TheBestInternetNews[3].gif
-33.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\TheBestInternetNews[3].gif
-33.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\TheBestInternetNews[4].gif
-33.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\TheBestInternetNews[4].gif
-32.1s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\BXPC51JR\b2[10].jpg
-32.0s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\bmainXAJI1STM.jpg
-31.9s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\b3RLN4HV7L.jpg
-31.8s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\b12LD9389A.jpg
-31.7s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\BXPC51JR\b6XXEIT9CD.jpg
-31.5s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\BXPC51JR\b5XE692HID.jpg
-31.4s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\b8NW3Q5WQB.jpg
-31.2s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\b7387ZA937.jpg
-31.0s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\RL6RJ3VJ\b12FWUR6PVB.jpg
-31.0s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\YJEXQ45D\b11902DC7P2.jpg
-30.8s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\RL6RJ3VJ\b4EDJCUWT7.jpg
-30.8s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\RL6RJ3VJ\b9NS3FXNLB.jpg
-30.6s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\BXPC51JR\b10FV82FCSX.jpg
-30.5s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\bsocial13RRGN9MM.jpg
-30.5s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\VW8P3VMG\bsocial2DL2I96LV.jpg
-28.2s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\bici\bi001003.sqm
-27.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\Notifications\945701e44ac911e4bec100c2c61723b5\1619359_10203127639771539_849080467_n[2].jpg
-25.9s C:\Users\MajdiAref\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\bici\bi000007.sqm
-25.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\2A2C98E8D9123DE7A43C7A340D1D9A375D605BD0
-22.8s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\3C1F3BD954D3048973938CA0D1470D3B953D244E
-1.6s C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending\7766a264-d5e2-4264-b3d4-8170a0a5bef6.dmp
-1.6s C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending\7766a264-d5e2-4264-b3d4-8170a0a5bef6.extra
-1.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\414627C7ABA0E70466AAD74FC3E2E98729C1C034
-0.0s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\56BB93E48A832D7B8B5C705D4E4CCD44592A6F29
0.0s C:\Users\MajdiAref\Downloads\SoftonicDownloader_for_ad-aware.exe
0.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\BD5EAB5DB874F65B4C95C0BB1EE86AACD4522558
0.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\F95F6950EEF542C2C27431982CE34926D636F7E6
1.8s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\thumbnails\d89d49f45468d28a31b587d3f2d7200d.png
18.2s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\31\8E5774564D63B913.dat
18.2s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{D8F1A4F8-491E-4923-9071-8D7292318A3C}
18.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\universaldownloader-prefetch[1].htm
19.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\81fe5-8ea63[1].js
21.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[1].gif
24.1s C:\Windows\Prefetch\SOFTONICDOWNLOADER_FOR_AD-AWA-D59DAA24.pf
25.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCookies\3IHT5OGP.txt
26.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[1].gif
31.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\campaign-100340,100860[1].htm
32.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\fad58-b3118[1].css
32.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\ad-aware-24-100x100[1].png
32.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\sd_100340_6d8d2[1].jpg
32.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\sd_100860_41d97[1].jpg
32.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\gradientbg[1].png
32.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\sd_icon_100860_d73dd[1].png
32.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\loading[1].gif
32.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\sprite[1].png
33.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\f[1].txt
33.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\f[1].txt
33.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\pubads_impl_51[1].js
33.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\container[1].htm
34.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\sd_100340_6d8d2[1].jpg
34.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\sd_100860_41d97[1].jpg
34.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[1].gif
34.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[2].gif
35.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[2].gif
35.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[2].gif
35.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[3].gif
35.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[1].gif
35.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[3].gif
35.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\SmartPlayerAPI[1].js
35.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\federated_f9[1]
35.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\1pix[1].gif
35.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\BrightcoveBootloader[1].swf
53.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[4].gif
68.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[3].gif
69.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[2].gif
69.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[5].gif
69.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[4].gif
69.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[4].gif
83.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[3].gif
83.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[6].gif
83.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[5].gif
83.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[6].gif
105.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[5].gif
105.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[4].gif
105.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[7].gif
105.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[6].gif
105.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\f[2].txt
106.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\f[1].txt
106.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\3085986924427351408[1].jpg
107.0s C:\Users\MajdiAref\Desktop\Adaware_Installer.exe
108.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\activeview[1].gif
125.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[7].gif
127.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[5].gif
128.1s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{8F1BDD8D-6799-4F13-84CC-7F8855BACDA8}
128.3s C:\Users\MajdiAref\AppData\Local\Temp\2386c19c-abc8-4964-b179-3d94cb325e2b\
128.3s C:\Users\MajdiAref\AppData\Local\Temp\2386c19c-abc8-4964-b179-3d94cb325e2b\AdAwareWebInstaller.exe
128.7s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\44\62B57D259F47A684.dat
137.6s C:\Windows\Prefetch\ADAWARE_INSTALLER.EXE-FC4A004A.pf
157.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[7].gif
157.4s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\35\97DD89F60FBEAAC3.dat
157.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[8].gif
157.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[6].gif
157.6s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{64D8BFA6-DDC0-47AF-ABAB-F7495B544C8E}
157.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[8].gif
157.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\__utm[8].gif
157.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[9].gif
157.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\f[3].txt
157.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\__utm[7].gif
157.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\ATAAY4GR.htm
157.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\__utm[9].gif
158.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\BrightcovePlayer[1].swf
158.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\default_icon_7[1].gif
158.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\f56d6[1].png
159.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\tracker[1].htm
159.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCookies\J3WODUU3.txt
159.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\__utm[10].gif
160.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\activeview[1].gif
164.3s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\crossdomain[1].xml
166.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\crossdomain[1].xml
166.4s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCookies\QAX8YQOD.txt
167.1s C:\Windows\Prefetch\ADAWAREWEBINSTALLER.EXE-9404029C.pf
167.1s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\brightcove-sd[1].xml
167.6s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\AdvertisingModule[1].swf
170.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\IMA3[1].swf
172.5s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\Minimal[1].swf
173.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\PQ3XE57Q\BCMenu[1].swf
174.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\adsapi_3[1].swf
174.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\1pix[1].gif
174.8s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\MXZ7NXQV\1pix[2].gif
175.2s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\K09TT7CG\1pix[1].gif
175.7s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCache\IE\2PEP5DGC\adsapi_3_0_156[1].swf
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D5ACC30AA2616C97153A8F836AF72C74CE64FA2B
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\179917EDFD56EADBE0BD446B4E88E8DACF2625A1
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\EC4D75773F0639A5EB0343F8F66D76E71AD9CADC
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\0F4878757559AFDA32C2330A39FF2EE9A9D5ADEE
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\07A44713066229352EA1E8ADB6A0D979BF4FE22D
191.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\0D31427B7F14E02DDCE26641CE72814B0C8F7339
196.3s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\2D34A7FF560E2060D1B8AF0336B6795CE7BF870B
196.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\8B352912A8BA7EAF5804F72C19EEF166649A4CCE
202.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\42035AE0077374ABF300651CCBE6C5C3BB9326C3
202.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D1FAD5A7735A58754E34A099C38A34BBFC607AD4
203.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\9663029F8794E7BC70AD88553988BE520A64B346
203.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\C21908EF8C3AE04FF6DA7DC3F1B4898469453108
204.2s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\678F1DF3809CBCE6B2EC6BFD9C22D40BB13DDCAA
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\BF5E079D2091BD3C6781EDAA85BC9D91C31DB274
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\5441BEB51A49C40D00CB5BE3860116B62B26800D
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\A734BA8200891D28521E833FDF058AB62AE16AC1
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\23CD98ED6E90EB10E1596350F08A0E011B8664EA
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\968C9B2B4543E1EB68A7890E918927732EB84710
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\553FD4D64155B570FD5A346EB558D2F4CD4BC2D3
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\4EC9DFCC8FBB1699EFA11329A188FC441BC5F5FA
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\C40C0FE5D70507B3130E80880284EFBDF8AD6C36
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\0164F07CB4D020F0AD0EA05AC1694294CAE31A7A
204.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\BAF1A9B02421C32C2D7E2A9453BEC78C74D40C45
207.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_FlashPlayerPlugi_d3e92c4a64d22ebec443e91ffff8c1dcc5deca8_3aa8f864_0d0fc8cf\
207.0s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_FlashPlayerPlugi_d3e92c4a64d22ebec443e91ffff8c1dcc5deca8_3aa8f864_0d0fc8cf\Report.wer
207.1s C:\Users\MajdiAref\AppData\Local\Temp\acro_rd_dir\FAPC8FE.tmp
208.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_FlashPlayerPlugi_18c1e3f53ff7e2d4b3bc8503c36dcdd35881dd1_3aa8f864_1273d022\
208.9s C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_FlashPlayerPlugi_18c1e3f53ff7e2d4b3bc8503c36dcdd35881dd1_3aa8f864_1273d022\Report.wer
209.0s C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending\a39b53cf-0b36-4a52-919b-b3bd17a6452a.dmp
209.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\E37E2962D16FFAF873D5C131DEA71424B08BFFE5
209.1s C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Crash Reports\pending\a39b53cf-0b36-4a52-919b-b3bd17a6452a.extra
211.3s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\4F78544AE0089B0C2635F27BF4B8CBE0AA468CCD
211.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\35AC7E90DB3C5B2245397AE6A0774911FE696D2D
211.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\14CE51EE8F4204E2E0A1BC74294EF93B3E9D6768
211.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\A747BFB2B51C19A808AB3EAF6990EBC95BD8D356
211.9s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\45F2EC2AB1225D863F33C9C991DF8A3EF2C9D3C7
212.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D7E5CB99622AC1CC3D0DBFA18299053FFD9B60FB
212.5s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\A7053E207A367E4DB32152157D2A025906A1DD7D
212.6s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D087BA3DA7068E8F3E5A35ADDFF7E65688BBD040
212.6s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\25AC65AC9C5B3C94CB2CAC3852FC54F73B7372D5
212.6s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\AB50334B1C4619C48A0E45AF93092D64A44DA951
212.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\49F9D669E08A89F489496EFB48D57D03F75F6770
213.0s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\E15F2EA2C8C6407C1625AF2E91EB61651E5BF91C
213.0s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\FE2FB942077BA5489596ABB3A3ED13BC39E17236
213.0s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\DA6FF9DB829BDECB9ABEE22AD4398BD53987A71F
213.4s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\6D25ECB1E7AB4AD8DCEDC2730E99CA3F57D6B7FC
213.6s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\A4422480EF77D01C85B0E8F3010D5FA5D3AD280E
213.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\03AAAFDFAE5F1F3BC748A8A60C844385B5D1F52D
214.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\3FFC84F6E2774041EFF5846F9FB8E939C4D85CAC
214.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\0D887C10E54018D8481CB115C7A1B1857691AB6E
214.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\7CB130A35C87BEFFC657EF400D2C15F9905056F5
214.1s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\5426B2CCF83C1FBE3EA428A71824404569AD4599
214.2s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\73583C9454AC92B36902E6099BF258A7B239D0BD
214.7s C:\Users\MajdiAref\AppData\Local\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cache2\entries\D04F7591F037F64B284A29B982D6F1ACED6D0D4F
Potential Unwanted Programs _________________________________________________
HKU\S-1-5-21-979933412-960713541-3746131152-1003\Software\Softonic\ (Softonic) -> Deleted
Cookies _____________________________________________________________________
C:\Users\MajdiAref\AppData\Local\Microsoft\Windows\INetCookies\EFN5LBMC.txt
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ad.360yield.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ad.kiosked.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ad.vikadsk.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ads.creative-serving.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ads.pubmatic.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ads.yahoo.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:adtech.de
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:adtechus.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:advertising.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:at.atwola.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:casalemedia.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:doubleclick.net
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:googleadservices.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:mediaplex.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:revsci.net
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:ru4.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:serving-sys.com
C:\Users\MajdiAref\AppData\Roaming\Mozilla\Firefox\Profiles\1w63kn5y.default-1412344396769\cookies.sqlite:zedo.com
[/code]